dontaudit fsadm_t device_t:blk_file { getattr };
That sound right? tom
Sep 16 10:50:36 fedora kernel: ACPI: Sleep Button (CM) [FUTS]
Sep 16 10:50:36 fedora kernel: audit(1095357002.303:0): avc: denied { getattr } for pid=1839 exe=/sbin/fsck.ext3 path=/dev/root dev=tmpfs ino=2028 scontext=system_u:system_r:fsadm_t tcontext=system_u:object_r:device_t tclass=blk_file
Sep 16 10:50:36 fedora kernel: EXT3 FS on hda2, internal journal Sep 16 10:50:36 fedora kernel: device-mapper: 4.1.0-ioctl (2003-12-10) initialised: dm@xxxxxxxxxxxxxx Sep 16 10:50:36 fedora kernel: audit(1095357004.327:0): avc: denied { getattr } for pid=2074 exe=/sbin/fsck.ext3 path=/dev/root dev=tmpfs ino=2028 scontext=system_u:system_r:fsadm_t tcontext=system_u:object_r:device_t tclass=blk_file