audit2allow
Generate SELinux policy allow rules from audit logs.
TLDR
Generate allow rules
SYNOPSIS
audit2allow [OPTIONS]
DESCRIPTION
audit2allow generates SELinux policy allow rules from audit logs. It reads denial messages from the audit subsystem and creates type enforcement rules that would permit the denied operations.
The tool can produce simple allow rules for quick troubleshooting or generate complete loadable policy modules with the -M option. When used with -R, it generates reference policy using standard macros, producing cleaner and more maintainable rules. It is typically used after audit2why has identified the root cause of denials.
PARAMETERS
-a, --all
Read input from audit log-i, --input file
Read input from specified file-M, --module name
Generate loadable policy module--why
Explain why denials occurred-e, --explain
Show detailed information about denials-R, --reference
Generate reference policy using macros-v, --verbose
Enable verbose output
CAVEATS
Generated policies should be reviewed before installation. Blindly allowing all denials can create security vulnerabilities. Use audit2why first to understand why denials occurred.
HISTORY
audit2allow is part of policycoreutils-python-utils, providing SELinux policy development tools.
