Running targeted/enforcing, latest rawhide (.1261) Examining /var/log/messages, I notice some 'corrupted' avc messages, e.g.: Apr 23 13:05:33 localhost kernel: audit(1114286729.835:0): avc: denied { search } for name=3228 dev=proc ino=211550210 scontext=system_u:system_r:initss=dir Apr 23 13:06:31 localhost kernel: audit(1114286790.120:0): avc: denied { search } for name=3228 dev=proc ino=211550210 scontext=system_u:system_r:i127:0): avc: denied { search } for name=1780 dev=proc ino=116654082 scontext=system_u:system_r:init_t tcontext=system_u:system_r:kernel_t tclass=dir Apr 23 13:06:41 localhost kernel: audit(1114286800.202:0): avc: denied { search } for name=3 dev=proc ino=196610 scontext=system_u:system_r:inystem_r:init_t tcontext=system_u:system_r:kernel_t tclass=dir [initss? i127? inystem? there are more....] Is there a lock problem with auditing? tom -- Tom London -- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx http://www.redhat.com/mailman/listinfo/fedora-selinux-list