✏️ 正在编辑: lockdown_permissive.txt
路径:
/lib/python3.6/site-packages/sepolicy/help/lockdown_permissive.txt
提示:
您可以编辑任何文件(包括二进制文件),但请注意不当修改可能导致文件损坏。
Disable Permissive Processes Disabling the 'permissivedomains' module allows you to remove all permissive domains shipped with the distribution. When the distribution policy writers write a new confined domain, they initially ship the policy for that domain in permissive mode. Permissive mode means that a process running in the domain will not be confined by SELinux. The kernel will log the AVC messages, access denials, that would have happened had the process been run in enforcing mode. Permissive domain policies are experimental and will be turned to enforcing in future Operation System Releases. Note if you disable the permissive domains module, you may see an increase in the denials in your log files.
💾 保存文件
← 返回文件管理器