selinux-policy/unconfined_permissive.patch

15 lines
454 B
Diff

diff --git a/policy/modules/system/unconfined.if b/policy/modules/system/unconfined.if
index 683497a..6717658 100644
--- a/policy/modules/system/unconfined.if
+++ b/policy/modules/system/unconfined.if
@@ -136,7 +136,8 @@ interface(`unconfined_domain',`
attribute unconfined_services;
')
- unconfined_domain_noaudit($1)
+permissive $1;
+# unconfined_domain_noaudit($1)
tunable_policy(`allow_execheap',`
auditallow $1 self:process execheap;