From Debian package 0.0.20080702-6 and 0.2.20100524-3 In russell-20080929.diff 0.0.20080702-6: Label /lib/init/rw as var_run_t Doesn't seem optimal to me 0.2.20100524-3: Label the contents of /lib/init/rw as well Part to mark var_run_t as a mountpoint type was merged upstream in r2885 Index: policy/modules/kernel/devices.fc =================================================================== --- policy/modules/kernel/devices.fc.orig +++ policy/modules/kernel/devices.fc @@ -6,7 +6,6 @@ /dev/\.static -d gen_context(system_u:object_r:device_t,s0) /dev/\.static/dev -d gen_context(system_u:object_r:device_t,s0) /dev/\.static/dev/(.*)? <> -/lib/init/rw -d gen_context(system_u:object_r:device_t,s0) ') /dev/.* gen_context(system_u:object_r:device_t,s0) Index: policy/modules/kernel/files.fc =================================================================== --- policy/modules/kernel/files.fc.orig +++ policy/modules/kernel/files.fc @@ -256,4 +256,7 @@ ifdef(`distro_debian',` /var/run/motd -- gen_context(system_u:object_r:etc_runtime_t,s0) +# on Debian /lib/init/rw is a tmpfs used like /var/run but +# before /var is mounted +/lib/init/rw(/.*)? gen_context(system_u:object_r:var_run_t,s0-mls_systemhigh) ')