On Sat, 2005-01-08 at 13:41, Tom London wrote: > Running strict/enforcing, latest Rawhide. > > After downloading today's updates, including > kernel-2.6.10-1.1074_FC4, and rebooting, > (and before the kernel oops with a kernel > page fault): > > firefox refuses to start in enforcing mode. Here > are the AVCs: > > Jan 8 10:28:01 fedora kernel: audit(1105208881.086:0): avc: denied > { execmod } for pid=4242 comm=java path=/lib/ld-2.3.4.so dev=hda2 > ino=3178514 scontext=user_u:user_r:user_t > tcontext=system_u:object_r:ld_so_t tclass=file This one is suspect. Can you reproduce with a kernel booted with audit=1 enabled so that we can also get the syscall auditing information for this denial? Also, possibly run it under strace and collect the output? -- Stephen Smalley <sds@xxxxxxxxxxxxxx> National Security Agency