Hi, When expanding the role_set_t used in user_datum_t or role_allow and role_transition rules, the pointer to the policydb_t of the out module should always be used, I guess when user_copy_callback() invokes role_set_expand(), the pointer to the policydb_t of the base module is mistakenly passed. Thanks, Harry -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.