From Debian package 0.2.20091117-2 and 0.2.20100524-1 0.2.20091117-2: Let lvm dontaudit its access to ptys. 0.2.20100524-1: * Allow lvm_t to create semaphores. Index: policy/modules/system/lvm.te =================================================================== --- policy/modules/system/lvm.te.orig +++ policy/modules/system/lvm.te @@ -41,6 +41,8 @@ type lvm_tmp_t; files_tmp_file(lvm_tmp_t) +allow lvm_t self:sem create_sem_perms; + ######################################## # # Cluster LVM daemon local policy @@ -178,6 +180,7 @@ allow lvm_t self:unix_stream_socket { connectto create_stream_socket_perms }; allow lvm_t clvmd_t:unix_stream_socket { connectto rw_socket_perms }; +term_dontaudit_use_generic_ptys(lvm_t) manage_dirs_pattern(lvm_t, lvm_tmp_t, lvm_tmp_t) manage_files_pattern(lvm_t, lvm_tmp_t, lvm_tmp_t)