Straightforward way of expressing policy inspired by a similar syntax in SELinux. Bug: 70165717 Test: no neverallows hit Test: manually checking neverallow rules by changing them/adding violations Change-Id: I7e15a0094d1861391bfe21a2ea30797d7593c142