# access to perflock allow untrusted_app mpctl_socket:dir r_dir_perms; unix_socket_send(untrusted_app, mpctl, perfd) unix_socket_connect(untrusted_app, mpctl, perfd) unix_socket_send(untrusted_app, mpctl, mpdecision) unix_socket_connect(untrusted_app, mpctl, mpdecision)