P.S. The java policy had dontaudit tty rules and not allow.
I changed them by accident. Should they be changed back, or
do you think allow is correct?
I don't have that policy in our tree. Is it for the java plugin run
from mozilla or for java run by a user domain? If the former, likely
want dontaudit. If the latter, likely want/need allow.
Well, it's the one Daniel Walsh has been writing, and he said it's for
a java plugin, so I guess I'll revert to dontaudit for now.
Thank you for the input - will send patches against FC.