On 22/07/15 14:03, Simon Sekidde wrote:
----- Original Message -----
> From: "m roth" <m.roth(a)5-cent.us>
> To: "selinux" <selinux(a)lists.fedoraproject.org>
> Sent: Tuesday, July 21, 2015 12:01:14 PM
> Subject: fedora 22
>
> Hi, folks,
>
> My manager just updated his fedora box from 20 to 22, and it appears as
> though selinux, in permissive mode, is logging *EVERY* command run by
> the system as root to syslog, even though the auditd's running. I am
> talking successes, not failures.
>
Sure its not an audit.rule?
# auditctl -l
I suspect more likely
https://bugzilla.redhat.com/show_bug.cgi?id=1227379
T