On Tue, 2014-04-15 at 15:19 -0400, Stephen Smalley wrote: > On 04/15/2014 03:18 PM, Eric Paris wrote: > > Why didn't it fail in the kernel on policy load? > > AFAICS you aren't checking for conflicts (and are ignoring duplicates) > in your kernel side code that loads the entries. Oh right, that whole 'system wasn't booting' thing. Which pointed out this bug, and then I never fixed it. Perfect. Glad I've been reminded...