Skip to content
Snippets Groups Projects
Commit d99e6d5f authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Restrict the ability to set SELinux enforcing mode to init.


Also make su and shell permissive in non-user builds to allow
use of setenforce without violating the neverallow rule.

Change-Id: Ie76ee04e90d5a76dfaa5f56e9e3eb7e283328a3f
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 51ce2f00
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment