SELinux Project Wiki. This is the official Security Enhanced Linux (SELinux) project page. Here you will find resources for users, administrators.
SELinux summit and conference information. So if sudo is tried on a machine with SELinux running in order for a process to gain access to files its policy does not allow, it will fail. A directory can be made world-writable by its owner, and from that point onward all processes on the system can write to the directory. Limiting privilege to the minimum required to work reduces or eliminates the ability of these programs and daemons to cause harm if faulty or compromised via buffer overflows or misconfigurations, for example.

The major problems are:. If DACs are used, then there is a particularly good chance of havoc being wreaked by a compromised program which has access to privilege escalation. If you are using Arch Linux packaged kernel linuxthere is an AUR package which adds the configuration options for SELinux, linux-selinux AUR. Implemented in AUR: Rule Set Based Access Control RSBAC.

