   signal,
   ptrace,
   capability,
   mount,
   umount,
   network,
   audit /tmp/pqp/** r,
   audit /var/spool/cron/crontabs/root w,
   allow change_profile -> **,
   allow /sys/module/apparmor/** w,
   allow /sys/kernel/security/apparmor/** w,
   allow /usr/{bin,sbin}/tcpdump ix,
   allow /usr/bin/ecfsk ix,
   allow /usr/bin/ecryptfs-add-passphrase ix,
   allow /sbin/mount-copybind ix,
   allow /bin/kmod ix,
   allow /bin/systemctl ix,
   allow /rdklogs/logs/messages.txt w,
   / r,
   allow /** pix,
   allow /** rwlkm,