1allow kernel device:dir { add_name write remove_name rmdir create setattr getattr unlink}; 2allow kernel device:chr_file { create setattr getattr unlink}; 3allow kernel self:capability { mknod }; 4