What is the best way to handle this? If I add a rule allow file_type self:filesystem associate; Will that cause and explosion in rules? Will this open a security risk? We tell people to use the mount -o context flags but policy can not handle most of them without the above rule. Dan --