From Debian package 0.0.20080702-4 Allow getattr on /selinux in selinux_validate_context Index: policy/modules/kernel/selinux.if =================================================================== --- policy/modules/kernel/selinux.if.orig +++ policy/modules/kernel/selinux.if @@ -544,6 +544,7 @@ allow $1 security_t:dir list_dir_perms; allow $1 security_t:file rw_file_perms; + allow $1 security_t:filesystem getattr; allow $1 security_t:security check_context; ')