> SELinux. It's a patch over the UNIX security model
SELinux is built into the kernel. It may appear to be 'a patch' because ordinary users can be set to operate in an 'unconfined' domain where the usual permission system operates.
Biting the hand that feeds IT © 1998–2019