On Tue, 2004-12-14 at 13:47, Orion Poplawski wrote: > I've installed a kernel.org 2.6.9 kernel updated to acpi 20041203. I'm > seeing lots of SElinux audit messages that I don't see with the Fedora > kernels. Is there something I can do short of disabling SElinux? > > audit(1103024554.837:0): avc: denied { read write } for pid=656 > exe=/sbin/minilogd name=console dev=tmpfs ino=1138 > scontext=user_u:system_r:syslogd_t tcontext=user_u:object_r:tmpfs_t > tclass=chr_file In order for SELinux to work with udev and a tmpfs /dev, you need tmpfs xattr support. That exists in 2.6.10-rc3, as well as in the Fedora kernels. -- Stephen Smalley <sds@xxxxxxxxxxxxxx> National Security Agency