Daniel J Walsh writes: > It is getting it via an attribute of dosfs_t > allow nfsd_t { noexattrfile file_type -shadow_t }:dir { read getattr > lock search ioctl }; > type dosfs_t, fs_type, noexattrfile, sysadmfile; Hm, right. Looks like it should work then. These allows are guarded by the nfs_export booleans as you mentioned, but they are both active, so that should be ok. Seem like something is broken in my installation after all then. I thought I checked that first, but I'll double check. -- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-selinux-list