Description of problem: Could you modify bcfg2-server so that is uses inotify instead of gam_server. From SELinux policy point of view it's very difficult to confine a service that invokes gam_server. Version-Release number of selected component (if applicable): bcfg2-web-1.2.1-1.el6.noarch bcfg2-1.2.1-1.el6.noarch bcfg2-server-1.2.1-1.el6.noarch bcfg2-doc-1.2.1-1.el6.noarch
I haven't had much to do with bcfg2 lately, but this is something that would be better suited for upstream to deal with, so that Fedora doesn't need to be carrying a patch indefinitely.
Upstream is considering this for 1.3.0 http://trac.mcs.anl.gov/projects/bcfg2/milestone/Bcfg2%201.3.0%20Release
This functionality has been added upstream and will be included in 1.3.0.
Now using inotify.