On Wed, Mar 31, 2010 at 09:18:38AM -0400, Daniel J Walsh wrote: > df is searching through all of the toplevel mountpoint directories, df > does not search through any of the subdirectories. Ok, that would explain the behaviour (even though I don't see why it would access the _parent_ directory; all I can see in strace output is a statfs call directly to the mounted directory. But maybe I don't need to completely understand everything.) > Your custom policy does not need a boolean. I would just add Yep. It's just what I usually do while I'm still testing things, so I can more easily switch it on and off at will. Thank you very much for sheding light to where I had a dark spot. Kurt -- selinux mailing list selinux@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/selinux