Chapter 7. Constraints
In this chapter
• 7.1 Closer Look at the Access Decision Algorithm
• 7.3 Label Transition Constraints
SELinux provides a constraint mechanism to further restrict the access allowed by the policy regardless of the policy allow
rules. In this chapter, we explore the constraint feature in SELinux.
7.1 A Closer Look at the Access Decision Algorithm
To understand the purpose of constraints, let’s revisit the SELinux Linux Security Module (LSM). Recall the SELinux kernel architecture discussed in Chapter 3, “Architecture,” the salient portion of which is depicted again in Figure 7-1.
We want to take a closer look at how the access ...
Get SELinux by Example: Using Security Enhanced Linux now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.