> > This one is suspect. Can you reproduce with a kernel booted with > > audit=1 enabled so that we can also get the syscall auditing information > > for this denial? Also, possibly run it under strace and collect the > > output? > > > Uhhh..I came home, put libjavaplugin_oji.so back into /usr/mozilla/plugins (I had moved it into /usr/mozilla), and rebooted with audit=1 as your suggested. I know this is going to sound crazy, but it no longer fails as before. I'm running selinux-policy-strict-1.20.1-3 now (was running earlier policy when I filed the report). I see that mozilla_macros.te has allow $1_mozilla_t self:process { execmem setrlimit setsched }; Could this have 'fixed' this? tom -- Tom London