Is that what I see here (current Greybeard, MicroOS with selinux-policy-targeted-20230321-1.1)? root@stitny ~# ausearch -m AVC -ts today| audit2allow #============= local_login_t ============== allow local_login_t xserver_t:process signal; root@stitny ~# ausearch -m AVC -ts today ---- time->Thu Apr 6 04:29:42 2023 type=AVC msg=audit(1680748182.835:702): avc: denied { signal } for pid=1056 comm="login" scontext=system_u:system_r:local_login_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:xserver_t:s0-s0:c0.c1023 tclass=process permissive=0 ---- ... [ it repeats multiple times ] ... root@stitny ~#