This is by design. There is a seperation between confined and unconfined. sysadm_t is the confined equivalent of the unconfined unconfined_t.
It is true though that sysadm_t (and the policy in general) is incomplete, and that it needs more attention. You are ofcourse free and encouranged to tailor the policy to your personal requirements. -- Key fingerprint = 5F4D 3CDB D3F8 3652 FBD8 02D5 3B6C 5F1D 2C7B 6B02 https://sks-keyservers.net/pks/lookup?op=get&search=0x3B6C5F1D2C7B6B02 Dominick Grift