diff --git a/unconfined.te b/unconfined.te index c3355c7451aa328dbb44f76add03b6c6d30c7496..9b5f8c9e69bad3a29e40ed788f28ae1f6e413e8d 100644 --- a/unconfined.te +++ b/unconfined.te @@ -16,7 +16,7 @@ # The use of this template is discouraged. ###################################################### -allow unconfineddomain self:capability ~{ sys_ptrace sys_rawio mknod sys_module }; +allow unconfineddomain self:capability ~{ sys_ptrace sys_rawio mknod sys_module audit_write audit_control }; allow unconfineddomain self:capability2 ~{ mac_override mac_admin }; allow unconfineddomain kernel:security ~{ load_policy setenforce setcheckreqprot setbool setsecparam }; allow unconfineddomain kernel:system *;