This patch fixes an inconsistency, if not a clear bug, with the extended permissions. To quote from the original discussion [1]:
The behavior of dontauditx and auditallowx appears to be broken making them useless.
[1] https://lore.kernel.org/selinux/6a791504-7728-3026-17ee-c22cbff8c3d1@gmail.c...
bauen1 (1): selinux: allow dontauditx and auditallowx rules to take effect without allowx
security/selinux/ss/services.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-)