diff --git a/policy/modules/system/locallogin.te b/policy/modules/system/locallogin.te index 0a114c0c7..2b5e96e1b 100644 --- a/policy/modules/system/locallogin.te +++ b/policy/modules/system/locallogin.te @@ -216,7 +216,8 @@ optional_policy(` # Sulogin local policy # -allow sulogin_t self:capability { dac_override sys_admin sys_tty_config }; +dontaudit sulogin_t self:capability dac_override; +allow sulogin_t self:capability { dac_read_search sys_admin sys_tty_config }; allow sulogin_t self:process setexec; allow sulogin_t self:fd use; allow sulogin_t self:fifo_file rw_fifo_file_perms;