The rule mount options=(rw,make-slave) -> **,
ends up allowing mount -t proc proc /mnt
which it shouldn't as it should be restricted to commands with a make-slave flag
The rule (rw,make- slave) -> **,
mount options=
ends up allowing
mount -t proc proc /mnt
which it shouldn't as it should be restricted to commands with a make-slave flag