neverallow isolated_app host1x_device:chr_file { rw_file_perms execute };