> Some shots in the dark: > > # get past dyntransition kiddy lock > domain_dyntrans_type(sshd_t) > > # get past subject identity change kiddy lock > domain_subj_id_change_exemption(sshd_t) > > # get past role change kiddy lock > domain_role_change_exemption(sshd_t) Nada on all counts! When I try to compile it as part of my (modified) policy I am ending up with a syntax error like: ERROR 'syntax error' at token 'typeattribute' on line 8921: #line 283 typeattribute sshd_t set_curr_context; I'll submit a bug with Fedora - I've had enough of this! -- selinux mailing list selinux@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/selinux