On Sat, Jan 14, 2012 at 03:20:02PM +0100, Sven Vermeulen wrote: > An initramfs' /init will run in the kernel_t domain (and unconfined until > load_policy is called ?) Not unconfined, permissive. Wkr, Sven Vermeulen -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.