This patch fixes an inconsistency, if not a clear bug, with the extended permissions. To quote from the original discussion [1]: > The behavior of dontauditx and auditallowx appears to be broken making them useless. [1] https://lore.kernel.org/selinux/6a791504-7728-3026-17ee-c22cbff8c3d1@xxxxxxxxx/T/ bauen1 (1): selinux: allow dontauditx and auditallowx rules to take effect without allowx security/selinux/ss/services.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) -- 2.25.1