srivasta@debian.org--etch/refpolicy--debian--0.0--versionfix-4 In Manoj's topic--pythonsupport branch (doesn't belong there) For targeted policy, allow semanage to use the initrc_t file descriptor. Index: policy/modules/system/selinuxutil.te =================================================================== --- policy/modules/system/selinuxutil.te.orig +++ policy/modules/system/selinuxutil.te @@ -435,6 +435,10 @@ allow semanage_t semanage_tmp_t:file manage_file_perms; files_tmp_filetrans(semanage_t, semanage_tmp_t, { file dir }) +ifdef(`targeted_policy',` + allow semanage_t initrc_t:fd use; +') + kernel_read_system_state(semanage_t) kernel_read_kernel_sysctls(semanage_t)