关于 SELinux 的各种理论知识
在用户态部署 SELinux SELinux 架构图(源自 SELinux Notebook ):
正如此文 所述:
There can only be one Security Server, which resides in the kernel. However, the AVCs and OMs can reside both in the kernel and in userspace.
Security Server 即二进制策略储存处,内核 LSM 中又称 policydb,有且仅有一份,处于内核中; Access Vector Cache(AVC)缓存 Security Server 对近期一些访问行为的决定,既可在 …