it should be clarified because it is questionable.

If a "system_dbusd_domain" would need this permission then the permission would
have been enclosed with "system_dbusd_domain()"

Looking at
it seems that this file descriptor gets passed to dbusd

So at least now that part is explained.

ideally the dbusd.if header would have exported an
"dbus_rw_inherited_system_unix_stream_sockets()" interface for you to call, but
there is not so just change line:

to look like:

allow system_dbusd_t tabrmd_t:unix_stream_socket { read write};

Optionally add a comment: # TODO: add to dbus.if:
dbus_rw_inherited_system_unix_stream_sockets() and call that instead

