Hi -

I'm trying to allow guest_u user to execute 'screen' command. When guest_u executes screen ,access gets denied,
but I can't find any logs under /var/log/audit/audit.log . If SElinux disabled, guest_u can properly execute screen command.

# grep screen /var/log/audit/audit.log | audit2allow -M screen
Nothing to do

How to provide screen command access to guest_u in a safe manner ? Such a policy open up any other security issues?
Thanks for any pointers/help.

FOSS Programmer.