diff --git a/private/seapp_contexts b/private/seapp_contexts
index 5416eda..f5d778f 100644
--- a/private/seapp_contexts
+++ b/private/seapp_contexts
@@ -192,6 +192,12 @@ user=_app isPrivApp=true domain=priv_app type=privapp_data_file levelFrom=user
 user=_app isPrivApp=true name=com.google.android.permissioncontroller domain=permissioncontroller_app type=privapp_data_file levelFrom=all
 user=_app seinfo=media isPrivApp=true name=com.android.providers.media.module domain=mediaprovider_app type=privapp_data_file levelFrom=all
 user=_app seinfo=media isPrivApp=true name=com.android.providers.media.module:* domain=mediaprovider_app type=privapp_data_file levelFrom=all
+# CK7n: fallback for MediaProvider mainline module.
+# Some builds do not assign seinfo=media to com.android.providers.media.module,
+# causing it to fall back to priv_app and fail FUSE external/emulated storage.
+user=_app isPrivApp=true name=com.android.providers.media.module domain=mediaprovider_app type=privapp_data_file levelFrom=all
+user=_app isPrivApp=true name=com.android.providers.media.module:* domain=mediaprovider_app type=privapp_data_file levelFrom=all
+
 user=_app isPrivApp=true name=com.google.android.providers.media.module domain=mediaprovider_app type=privapp_data_file levelFrom=all
 user=_app isPrivApp=true name=com.google.android.providers.media.module:* domain=mediaprovider_app type=privapp_data_file levelFrom=all
 user=_app seinfo=platform isPrivApp=true name=com.android.permissioncontroller domain=permissioncontroller_app type=privapp_data_file levelFrom=all
@@ -215,3 +221,17 @@ user=_app fromRunAs=true domain=runas_app levelFrom=user
 user=_app isPrivApp=true name=com.android.virtualization.terminal domain=vmlauncher_app type=privapp_data_file levelFrom=all
 user=_app isPrivApp=true name=com.android.virtualization.terminal:* domain=vmlauncher_app type=privapp_data_file levelFrom=all
 user=_app isPrivApp=true name=com.google.android.adservices.api domain=adservices type=privapp_data_file levelFrom=all
+
+# CK7n: Mediatek IMS runs as radio UID from system_ext priv-app.
+# Log showed uid 1001, so this must be user=radio, not user=_app.
+
+# CK7n: Mediatek IMS is radio UID + priv-app from system_ext.
+user=radio isPrivApp=true domain=radio type=radio_data_file
+
+# CK7n bring-up fallback rules:
+# Some fixed-UID platform priv-apps are coming through with seinfo=default,
+# causing zygote selinux_android_setcontext() crashes.
+user=system isPrivApp=true domain=system_app type=system_app_data_file
+user=network_stack isPrivApp=true domain=network_stack type=app_data_file
+user=nfc isPrivApp=true domain=nfc type=nfc_data_file
+user=secure_element isPrivApp=true domain=secure_element type=app_data_file
