Running latest Rawhide, targeted. Running in enforcing mode, audio-entropyd fails to start. Flipping to permissive mode and restarting, I get these: type=AVC msg=audit(1181506748.052:78): avc: denied { read write } for pid=8712 comm="audio-entropyd" name="random" dev=tmpfs ino=3167 scontext=system_u:system_r:entropyd_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file type=SYSCALL msg=audit(1181506748.052:78): arch=40000003 syscall=5 success=yes exit=4 a0=804a2b3 a1=2 a2=0 a3=bfbbdef0 items=0 ppid=1 pid=8712 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) comm="audio-entropyd" exe="/usr/sbin/audio-entropyd" subj=system_u:system_r:entropyd_t:s0 key=(null) type=AVC msg=audit(1181506748.052:79): avc: denied { dac_override } for pid=8712 comm="audio-entropyd" capability=1 scontext=system_u:system_r:entropyd_t:s0 tcontext=system_u:system_r:entropyd_t:s0 tclass=capability type=SYSCALL msg=audit(1181506748.052:79): arch=40000003 syscall=5 success=yes exit=5 a0=804a268 a1=0 a2=45ef7fc0 a3=804a268 items=0 ppid=1 pid=8712 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) comm="audio-entropyd" exe="/usr/sbin/audio-entropyd" subj=system_u:system_r:entropyd_t:s0 key=(null) Looks like it wants read/write access to /dev/random plus dac_override. tom -- Tom London -- fedora-selinux-list mailing list fedora-selinux-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-selinux-list