From 4afbc35e79688c020792b6253a9b3d9e40f4976d Mon Sep 17 00:00:00 2001 From: Guido Trentalancia Date: Sat, 16 Sep 2017 23:39:04 +0200 Subject: [PATCH] xserver: do not audit ioctl operations on log files Do not audit ioctl operation attempts whenever write operations on the xserver log should not be audited. Signed-off-by: Guido Trentalancia --- policy/modules/services/xserver.if | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/policy/modules/services/xserver.if b/policy/modules/services/xserver.if index 13f800936..e0c5be82a 100644 --- a/policy/modules/services/xserver.if +++ b/policy/modules/services/xserver.if @@ -1129,7 +1129,7 @@ interface(`xserver_dontaudit_write_log',` type xserver_log_t; ') - dontaudit $1 xserver_log_t:file { append write }; + dontaudit $1 xserver_log_t:file { append ioctl write }; ') ########################################