These files don't exist under proc so this rule does nothing. They are protected against by docker's default cgroup devices since they're both character devices and not explicitly allowed. Signed-off-by: Tycho Andersen <tycho@docker.com> Upstream-commit: b4a6ccbc5fe695062111cad5a20bb3d0ac5a94db Component: engine