>i'm using the latest rawhide versions of today, with >pam-0.79-10 >audit-0.9.7-1 >audit-libs-0.9.7-1 These are all the right ones. FWIW, I use the same ones, except I build audit/pam myself and use stock kernel. I'm not seeing a problem. Other configs aren't supposed to be a problem. >checked the files login, sshd, gdm in /etc/pam.d/ but there is no >pam_loginuid.so line in these files for me. (?) OK that's fine. These would only be in rawhide if anywhere. I didn't want too much audit stuff into FC4 since this is all new. >maybe my problem is that i'm not using selinux (because of reiserfs) ? No. They are independant. SE Linux uses the audit system to report AVC denials, but thats as far as it goes. >what log/info is needed to help debug this? Actually, what I need is the return code from sendto. You should be able to upgrade, run "strace su - root" and then attach that to bz#160929 (altering any sensitive information first). That is assuming that su misbehaves, too. Thanks, -Steve __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com