I've just been trying out proftpd on a Rawhide box with /var/run on tmpfs, and got this AVC: time->Wed Dec 1 16:33:16 2010 type=SYSCALL msg=audit(1291221196.017:128): arch=40000003 syscall=5 success=no exit=-13 a0=1c3f6c a1=a0142 a2=180 a3=9665f78 items=0 ppid=1213 pid=1336 auid=500 uid=0 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 tty=(none) ses=8 comm="proftpd" exe="/usr/sbin/proftpd" subj=system_u:system_r:ftpd_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1291221196.017:128): avc: denied { search } for pid=1336 comm="proftpd" name="user" dev=tmpfs ino=12173 scontext=system_u:system_r:ftpd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_auth_t:s0 tclass=dir It's trying to look in /var/run/user I think. I don't know why it was trying to do this (maybe related to pam_systemd?) but it didn't seem to stop it working. Paul. -- selinux mailing list selinux@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/selinux