Description of problem: Please provide a way to a) disable the user_home_dir_t magic completely (homedirs on my machines are either NFS mounted, or there are no homedirs at all), or b) filter-out certain accounts; the current heuristic (/sbin/nologin shell or uid < 500) does not suffice. I have several system-accounts which require a regular shell (e.g. because they start jobs through ~/.ssh/authorized_keys). Currently, these accounts are handled like normal users and filesystem is completely mislabeled (e.g. /etc and /usr/share are user_home_dir_t). Version-Release number of selected component (if applicable): policycoreutils-2.0.47-2.fc9.x86_64
Add disable-genhomedircon = true to /etc/selinux/semanage.conf