swo_u who is running ranged (systemlow-systemhigh) uses newrole to launch an X windows app at systemhigh and then I get avcs like the following: avc: denied { receive } for request=X11:ChangeWindowAttributes comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable avc: denied { get_property } for request=X11:GetProperty comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable avc: denied { receive } for comm=/usr/libexec/notification-daemon event=X11:MapNotify scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_manage_xevent_t:s15:c0.c1023 tclass=x_event avc: denied { receive } for comm=/usr/libexec/notification-daemon event=X11:VisibilityNotify scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_default_xevent_t:s15:c0.c1023 tclass=x_event avc: denied { receive } for comm=/usr/libexec/notification-daemon event=X11:PropertyNotify scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_property_xevent_t:s15:c0.c1023 tclass=x_event avc: denied { receive } for comm=/usr/libexec/notification-daemon event=X11:FocusIn scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_focus_xevent_t:s15:c0.c1023 tclass=x_event avc: denied { getattr } for request=X11:GetGeometry comm=/usr/libexec/notification-daemon resid=3800036 restype=WINDOW scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_t:s15:c0.c1023 tclass=x_drawable avc: denied { read } for request=X11:GetProperty comm=/usr/libexec/notification-daemon property=WM_NAME scontext=swo_u:user_r:user_t:s0-s15:c0.c1023 tcontext=swo_u:object_r:user_default_xproperty_t:s15:c0.c1023 tclass=x_property I'm not familiar with /usr/libexec/notification-daemon and what it does and I'm thinking that it's probably not the best idea to use mls_xwin_read_all_levels for user_t.. Any suggestions? -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.