allow fsck diag_partition_device:blk_file rw_file_perms; allow fsck persist_file:dir getattr;
allow fsck self:capability { dac_override dac_read_search };
allow fsck tmpfs:blk_file getattr;