> On Jun 09, 2007, at 01:18:40,
david@lang.hm wrote:
>> SELinux is like a default allow IPS system, you have to describe EVERYTHING
>> to the system so that it knows what to allow and what to stop.
>
> WRONG. You clearly don't understand SELinux at all. Try booting in
> enforcing mode with an empty policy file (well, not quite empty, there are a
> few mandatory labels you have to create before it's a valid policy file).
> /sbin/init will load the initial policy, attempt to re-exec() itself... and
> promptly grind to a halt. End-of-story.