rpm needs to downgrade files in the policy package. Added policy for ada to be allowed execmem privs (gnat) Java is installed in yet another directory New mono apps are communicating with userspace via dbus. So need dbus capabilities. /dev/dvb/* v41 devices pam needs to be able to setattr on usbfs Apache can_network_connect_db for scripts was missing. automount wants to read certs bluetooth needs ipc_lock, also wants to communicate with X cupsd needs setattr on cupsd_var_run_t bug in gpm policy Hal continues to grow towards unconfined ... mysql wants to talk to ldap networkmanager needs to signal nscd (Reread /etc/resolv.conf ???) rsync policy was broken. snmp wants to read kernel device sysctls bluetooth wants to read/write xdm sock file. (This might be a FD Leak) getty want to write to /var/spool/fax getty wants to send mail Lots more textrel_shlib_t changes mount cifs needs setuid setgid. Commenting out execstack execmem auditallows for now, to prevent flooding log files. secadm needs to be able to relabel anything. q