<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Security-Enhanced Linux</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Security-Enhanced_Linux"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Security-Enhanced_Linux rootpage-Security-Enhanced_Linux skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Security-Enhanced Linux</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr"><style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">SELinux</th></tr><tr><td colspan="2" class="infobox-image logo"><span typeof="mw:File"></span></td></tr><tr><td colspan="2" class="infobox-image logo"><div class="infobox-caption">Screenshot of <code>seinfo</code> and <code>semanage</code> showing SELinux information of a policy file used by the system, users of SELinux, and file labels related to <a href="Simple_Desktop_Display_Manager" title="Simple Desktop Display Manager">Simple Desktop Display Manager</a></div></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Original author(s)</a></th><td class="infobox-data"><a href="NSA" class="mw-redirect" title="NSA">NSA</a> and <a href="Red_Hat" title="Red Hat">Red Hat</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data"><a href="Red_Hat" title="Red Hat">Red Hat</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Initial release</th><td class="infobox-data">22 December 2000<span style="display:none"> (<span class="bday dtstart published updated">2000-12-22</span>)</span><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Stable release</a></th><td class="infobox-data"><div style="margin:0px;">3.9<sup id="cite_ref-wikidata-e60d71b26bd00c83b5ec059fcd39fa34d0494261-v20_2-0" class="reference"><a href="#cite_note-wikidata-e60d71b26bd00c83b5ec059fcd39fa34d0494261-v20-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
/ 16 July 2025<span style="display:none"> (<span class="bday dtstart published updated">16 July 2025</span>)</span></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Repository_(version_control)" title="Repository (version control)">Repository</a></th><td class="infobox-data"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */
.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}
/* end https://en.wikipedia.org/ */
</style><div class="plainlist"><ul><li><span class="url"><a rel="nofollow" class="external text" href="https://github.com/SELinuxProject/selinux">github<wbr>.com<wbr>/SELinuxProject<wbr>/selinux</a></span> </li></ul>
</div></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Written in</th><td class="infobox-data"><a href="C_(programming_language)" title="C (programming language)">C</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data"><a href="Linux" title="Linux">Linux</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data">Security, <a href="Linux_Security_Modules" title="Linux Security Modules">Linux Security Modules</a> (LSM)</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data"><a href="GNU_GPL" class="mw-redirect" title="GNU GPL">GNU GPL</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://selinuxproject.org">selinuxproject<wbr>.org</a></span>, <span class="url"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20201022103915/https://www.nsa.gov/what-we-do/research/selinux/">https://www.nsa.gov/what-we-do/research/selinux/</a></span></td></tr></tbody></table>
<p><b>Security-Enhanced Linux</b> (<b>SELinux</b>) is a <a href="Linux_kernel" title="Linux kernel">Linux kernel</a> <a href="Linux_Security_Modules" title="Linux Security Modules">security module</a> that provides a mechanism for supporting <a href="Access_control" title="Access control">access control</a> security policies, including <a href="Mandatory_access_control" title="Mandatory access control">mandatory access controls</a> (MAC).
</p><p>SELinux is a set of kernel modifications and user-space tools that have been added to various <a href="Linux_distribution" title="Linux distribution">Linux distributions</a>. Its <a href="Software_architecture" title="Software architecture">architecture</a> strives to separate enforcement of security decisions from the security policy, and streamlines the amount of software involved with security policy enforcement.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> The key concepts underlying SELinux can be traced to several earlier projects by the <a href="United_States" title="United States">United States</a> <a href="National_Security_Agency" title="National Security Agency">National Security Agency (NSA).</a>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Overview">Overview</h2></div>
<p>The NSA Security-enhanced Linux Team describes NSA SELinux as<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<blockquote><p>a set of <a href="Patch_(computing)" title="Patch (computing)">patches</a> to the <a href="Linux_kernel" title="Linux kernel">Linux kernel</a> and utilities to provide a strong, flexible, mandatory access control (MAC) architecture into the major subsystems of the kernel. It provides an enhanced mechanism to enforce the separation of information based on confidentiality and integrity requirements, which allows threats of tampering, and bypassing of application security mechanisms, to be addressed and enables the confinement of damage that can be caused by malicious or flawed applications. It includes a set of sample security policy configuration files designed to meet common, general-purpose security goals.</p></blockquote>
<p>A Linux kernel integrating SELinux enforces mandatory access control policies that confine user programs and system services, as well as access to files and network resources. Limiting privilege to the minimum required to work reduces or eliminates the ability of these programs and <a href="Daemon_(computing)" title="Daemon (computing)">daemons</a> to cause harm if faulty or compromised (for example via <a href="Buffer_overflow" title="Buffer overflow">buffer overflows</a> or misconfigurations). This confinement mechanism operates independently of the traditional Linux (<a href="Discretionary_access_control" title="Discretionary access control">discretionary</a>) access control mechanisms. It has no concept of a "root" <a href="Superuser" title="Superuser">superuser</a>, and does not share the well-known shortcomings of the traditional Linux security mechanisms, such as a dependence on <a href="Setuid" title="Setuid">setuid</a>/<a href="Setgid" class="mw-redirect" title="Setgid">setgid</a> binaries.
</p><p>The security of an "unmodified" Linux system (a system without SELinux) depends on the correctness of the kernel, of all the privileged applications, and of each of their configurations. A fault in any one of these areas may allow the compromise of the entire system. In contrast, the security of a "modified" system (based on an SELinux kernel) depends primarily on the correctness of the kernel and its security-policy configuration. While problems with the correctness or configuration of applications may allow the limited compromise of individual user programs and system daemons, they do not necessarily pose a threat to the security of other user programs and system daemons or to the security of the system as a whole.
</p><p>From a purist perspective, SELinux provides a hybrid of concepts and capabilities drawn from mandatory access controls, <a href="Mandatory_integrity_control" class="mw-redirect" title="Mandatory integrity control">mandatory integrity controls</a>, <a href="Role-based_access_control" title="Role-based access control">role-based access control</a> (RBAC), and <a href="Type_enforcement_architecture" class="mw-redirect" title="Type enforcement architecture">type enforcement architecture</a>. Third-party tools enable one to build a variety of security policies.
</p>
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>The earliest work directed toward standardizing an approach providing mandatory and discretionary access controls (MAC and DAC) within a UNIX (more precisely, POSIX) computing environment can be attributed to the <a href="National_Security_Agency" title="National Security Agency">National Security Agency</a>'s Trusted UNIX (TRUSIX) Working Group, which met from 1987 to 1991 and published one <a href="Rainbow_Series" title="Rainbow Series">Rainbow Book</a> (#020A), and produced a formal model and associated evaluation evidence prototype (#020B) that was ultimately unpublished.
</p><p>SELinux was designed to demonstrate the value of mandatory access controls to the Linux community and how such controls could be added to Linux. Originally, the patches that make up SELinux had to be explicitly applied to the Linux kernel source; SELinux was merged into the <a href="Linux_kernel_mainline" class="mw-redirect" title="Linux kernel mainline">Linux kernel mainline</a> in the 2.6 series of the Linux kernel.
</p><p>The NSA, the original primary developer of SELinux, released the first version to the <a href="Open-source_software" title="Open-source software">open source</a> development community under the <a href="GNU_GPL" class="mw-redirect" title="GNU GPL">GNU GPL</a> on December 22, 2000.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> The software was merged into the mainline Linux kernel 2.6.0-test3, released on 8 August 2003. Other significant contributors include <a href="Red_Hat" title="Red Hat">Red Hat</a>, <a href="Network_Associates" class="mw-redirect" title="Network Associates">Network Associates</a>, <a href="Secure_Computing_Corporation" title="Secure Computing Corporation">Secure Computing Corporation</a>, Tresys Technology, and Trusted Computer Solutions. Experimental ports of the <a href="FLASK" title="FLASK">FLASK</a>/TE implementation have been made available via the <a href="TrustedBSD" class="mw-redirect" title="TrustedBSD">TrustedBSD</a> Project for the <a href="FreeBSD" title="FreeBSD">FreeBSD</a> and <a href="Darwin_(operating_system)" title="Darwin (operating system)">Darwin</a> operating systems.
</p><p>Security-Enhanced Linux implements the <a href="FLASK" title="FLASK">Flux Advanced Security Kernel</a> (FLASK). Such a kernel contains architectural components prototyped in the Fluke operating system. These provide general support for enforcing many kinds of mandatory access control policies, including those based on the concepts of <a href="Type_enforcement" title="Type enforcement">type enforcement</a>, <a href="Role-based_access_control" title="Role-based access control">role-based access control</a>, and <a href="Multilevel_security" title="Multilevel security">multilevel security</a>. FLASK, in turn, was based on DTOS, a Mach-derived Distributed Trusted Operating System, as well as on Trusted Mach, a research project from <a href="Trusted_Information_Systems" title="Trusted Information Systems">Trusted Information Systems</a> that had an influence on the design and implementation of DTOS.
</p>
<div class="mw-heading mw-heading3"><h3 id="Original_and_external_contributors">Original and external contributors</h3></div>
<p>A comprehensive list of the original and external contributors to SELinux was hosted at the NSA website until maintenance ceased sometime in 2009. The following list reproduces the original as <a rel="nofollow" class="external text" href="https://web.archive.org/web/20081018034429/http://www.nsa.gov/selinux/info/contrib.cfm">preserved</a> by the Internet Archive Wayback Machine. The scope of their contributions was listed in the page and has been omitted for brevity, but it can be accessed through the archived copy.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */
.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}
/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 20em;">
<ul><li><a href="National_Security_Agency" title="National Security Agency">The National Security Agency</a> (NSA)</li>
<li><a href="Network_Associates_Laboratories" class="mw-redirect" title="Network Associates Laboratories">Network Associates Laboratories</a> (NAI Labs)</li>
<li><a href="Mitre_Corporation" title="Mitre Corporation">The MITRE Corporation</a></li>
<li><a href="Secure_Computing_Corporation" title="Secure Computing Corporation">Secure Computing Corporation</a> (SCC)</li>
<li>Matt Anderson</li>
<li>Ryan Bergauer</li>
<li>Bastian Blank</li>
<li>Thomas Bleher</li>
<li>Joshua Brindle</li>
<li><a href="Russell_Coker" title="Russell Coker">Russell Coker</a></li>
<li>John Dennis</li>
<li>Janak Desai</li>
<li>Ulrich Drepper</li>
<li>Lorenzo Hernandez Garcia-Hierro</li>
<li>Darrel Goeddel</li>
<li>Carsten Grohmann</li>
<li>Steve Grubb</li>
<li>Ivan Gyurdiev</li>
<li>Serge Hallyn</li>
<li>Chad Hanson</li>
<li>Joerg Hoh</li>
<li>Trent Jaeger</li>
<li>Dustin Kirkland</li>
<li>Kaigai Kohei</li>
<li>Paul Krumviede</li>
<li>Joy Latten</li>
<li>Tom London</li>
<li>Karl MacMillan</li>
<li>Brian May</li>
<li>Frank Mayer</li>
<li>Todd Miller</li>
<li>Roland McGrath</li>
<li>Paul Moore</li>
<li>James Morris</li>
<li>Yuichi Nakamura</li>
<li>Greg Norris</li>
<li>Eric Paris</li>
<li>Chris PeBenito</li>
<li><a href="Red_Hat" title="Red Hat">Red Hat</a></li>
<li>Petre Rodan</li>
<li>Shaun Savage</li>
<li>Chad Sellers</li>
<li>Rogelio Serrano Jr.</li>
<li>Justin Smith</li>
<li>Manoj Srivastava</li>
<li>Tresys Technology</li>
<li>Michael Thompson</li>
<li>Trusted Computer Solutions</li>
<li>Tom Vogt</li>
<li>Reino Wallin</li>
<li>Dan Walsh</li>
<li>Colin Walters</li>
<li>Mark Westerman</li>
<li>David A. Wheeler</li>
<li>Venkat Yekkirala</li>
<li>Catherine Zhang</li></ul></div>
<div class="mw-heading mw-heading2"><h2 id="Users,_policies_and_security_contexts">Users, policies and security contexts</h2></div>
<p>SELinux users and roles do not have to be related to the actual system users and roles. For every current user or process, SELinux assigns a three string context consisting of a username, role, and domain (or type). This system is more flexible than normally required: as a rule, most of the real users share the same SELinux username, and all access control is managed through the third tag, the domain. The circumstances under which a process is allowed into a certain domain must be configured in the policies. The command <code>runcon</code> allows for the launching of a process into an explicitly specified context (user, role, and domain), but SELinux may deny the transition if it is not approved by the policy.
</p><p>Files, network ports, and other hardware also have an SELinux context, consisting of a name, role (seldom used), and type. In the case of file systems, mapping between files and the security contexts is called labeling. The labeling is defined in policy files but can also be manually adjusted without changing the policies. Hardware types are quite detailed, for instance, <code>bin_t</code> (all files in the folder /bin) or <code>postgresql_port_t</code> (PostgreSQL port, 5432). The SELinux context for a remote file system can be specified explicitly at mount time.
</p><p>SELinux adds the <code>-Z</code> switch to the shell commands <code>ls</code>, <code>ps</code>, and some others, allowing the security context of the files or process to be seen.
</p><p>Typical policy rules consist of explicit permissions, for example, which domains the user must possess to perform certain actions with the given target (read, execute, or, in case of network port, bind or connect), and so on. More complex mappings are also possible, involving roles and security levels.
</p><p>A typical policy consists of a mapping (labeling) file, a rule file, and an interface file, that define the domain transition. These three files must be compiled together with the SELinux tools to produce a single policy file. The resulting policy file can be loaded into the kernel to make it active. Loading and unloading policies does not require a reboot. The policy files are either hand written or can be generated from the more user friendly SELinux management tool. They are normally tested in permissive mode first, where violations are logged but allowed. The <code>audit2allow</code> tool can be used later to produce additional rules that extend the policy to allow all legitimate activities of the application being confined.
</p>
<div class="mw-heading mw-heading2"><h2 id="Features">Features</h2></div>
<p>SELinux features include:
</p>
<ul><li>Clean separation of policy from enforcement</li>
<li>Well-defined policy interfaces</li>
<li>Support for applications querying the policy and enforcing access control (for example, <a href="Cron" title="Cron">crond</a> running jobs in the correct context)</li>
<li>Independence of specific policies and policy languages</li>
<li>Independence of specific security-label formats and contents</li>
<li>Individual labels and controls for kernel objects and services</li>
<li>Support for policy changes</li>
<li>Separate measures for protecting system integrity (domain-type) and data confidentiality (<a href="Multilevel_security" title="Multilevel security">multilevel security</a>)</li>
<li>Flexible policy</li>
<li>Controls over process initialization and inheritance, and program execution</li>
<li>Controls over file systems, directories, files, and open <a href="File_descriptor" title="File descriptor">file descriptors</a></li>
<li>Controls over sockets, messages, and network interfaces</li>
<li>Controls over the use of "capabilities"</li>
<li>Cached information on access-decisions via the <i>Access Vector Cache</i> (AVC)<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Whitelisting" class="mw-redirect" title="Whitelisting">Default-deny</a> policy (anything not explicitly specified in the policy is disallowed)<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Adoption">Adoption</h2></div>
<p>SELinux has been implemented in <a href="Android_(operating_system)" title="Android (operating system)">Android</a> since version 4.3.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>Among free community-supported Linux distributions, <a href="Fedora_(operating_system)" class="mw-redirect" title="Fedora (operating system)">Fedora</a> was one of the earliest adopters, including support for it by default since Fedora Core 2. Other distributions include support for it such as <a href="Debian" title="Debian">Debian</a> as of version 9 Stretch release<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> and <a href="Ubuntu_(operating_system)" class="mw-redirect" title="Ubuntu (operating system)">Ubuntu</a> as of 8.04 Hardy Heron.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> As of version 11.1, <a href="SUSE_Linux" class="mw-redirect" title="SUSE Linux">openSUSE</a> contains SELinux "basic enablement".<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> <a href="SUSE_Linux_Enterprise" title="SUSE Linux Enterprise">SUSE Linux Enterprise</a> (SLE) 11 features SELinux as a "technology preview".<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p><p>SELinux is popular in systems based on <a href="Linux_containers" class="mw-redirect" title="Linux containers">Linux containers</a>, such as <a href="Container_Linux_by_CoreOS" class="mw-redirect" title="Container Linux by CoreOS">CoreOS Container Linux</a> and rkt.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> It is useful as an additional security control to help further enforce isolation between deployed containers and their host.
</p><p>SELinux is available since 2005 as part of <a href="Red_Hat_Enterprise_Linux" title="Red Hat Enterprise Linux">Red Hat Enterprise Linux</a> (RHEL) version 4 and all future releases. This presence is also reflected in corresponding versions of derived systems such as <a href="CentOS" title="CentOS">CentOS</a>, <a href="Scientific_Linux" title="Scientific Linux">Scientific Linux</a>, <a href="AlmaLinux" title="AlmaLinux">AlmaLinux</a> and <a href="Rocky_Linux" title="Rocky Linux">Rocky Linux</a>. The supported policy in RHEL4 is targeted policy which aims for maximum ease of use and thus is not as restrictive as it might be. Future versions of RHEL are planned to have more targets in the targeted policy which will mean more restrictive policies. RHEL version 5 introduced <a href="Multilevel_security" title="Multilevel security">multilevel security</a> (MLS) policy for servers only. Fedora Linux 10 introduced a minimum policy, designed for certain platforms such as low-memory devices and <a href="Virtual_machine" title="Virtual machine">virtual machines</a>.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>openSUSE Tumbleweed transitioned from <a href="AppArmor" title="AppArmor">AppArmor</a> to SELinux for new installation since 11 February 2025, upcoming SLE/openSUSE Leap 16 will be shipped with SELinux by default as well.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> openSUSE/SLE adopted RHEL/Fedora policies for its SELinux implementation although with some differences.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> AppArmor is retained for existing Tumbleweed and SLE/openSUSE Leap 15.x installation (users can manually migrate their existing installation to SELinux). AppArmor is also available as install-time selection for users who prefer it.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Use_case_scenarios">Use case scenarios</h2></div>
<p>SELinux can potentially control which activities a system allows each user, process, and daemon, with very precise specifications. It is used to confine <a href="Daemon_(computer_software)" class="mw-redirect" title="Daemon (computer software)">daemons</a> such as database engines or web servers that have clearly defined data access and activity rights. This limits potential harm from a confined daemon that becomes compromised.
</p><p>Command-line utilities include:<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
<code>chcon</code>,<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
<code>restorecon</code>,<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
<code>restorecond</code>,<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
<code>runcon</code>,<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
<code>secon</code>,<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
<code>fixfiles</code>,<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup>
<code>setfiles</code>,<sup id="cite_ref-auto_29-0" class="reference"><a href="#cite_note-auto-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
<code>load_policy</code>,<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
<code>booleans</code>,<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
<code>getsebool</code>,<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup>
<code>setsebool</code>,<sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
<code>togglesebool</code><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup>
<code>setenforce</code>,
<code>semodule</code>,
<code>postfix-nochroot</code>,
<code>check-selinux-installation</code>,
<code>semodule_package</code>,
<code>checkmodule</code>,
<code>selinux-config-enforcing</code>,<sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
<code>selinuxenabled</code>,<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup>
and <code>selinux-policy-upgrade</code><sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Examples">Examples</h3></div>
<p>To put SELinux into enforcing mode:
</p>
<dl><dd><code>setenforce 1</code></dd></dl>
<p>To query the SELinux status:
</p>
<dl><dd><code>getenforce</code></dd></dl>
<div class="mw-heading mw-heading2"><h2 id="Comparison_with_AppArmor">Comparison with AppArmor</h2></div>
<p>SELinux represents one of several possible approaches to the problem of restricting the actions that installed software can take. Another popular alternative is called <a href="AppArmor" title="AppArmor">AppArmor</a> and is available on <a href="SUSE_Linux_Enterprise_Server" class="mw-redirect" title="SUSE Linux Enterprise Server">SUSE Linux Enterprise Server</a> (SLES), <a href="OpenSUSE" title="OpenSUSE">openSUSE</a>, and <a href="List_of_Linux_distributions#Debian-based" title="List of Linux distributions">Debian-based</a> platforms. AppArmor was developed as a component to the now-defunct <a href="Immunix" title="Immunix">Immunix Linux</a> platform. Because AppArmor and SELinux differ radically from one another, they form distinct alternatives for software control. Whereas SELinux re-invents certain concepts to provide access to a more expressive set of policy choices, AppArmor was designed to be simple by extending the same administrative semantics used for <a href="Discretionary_Access_Control" class="mw-redirect" title="Discretionary Access Control">DAC</a> up to the mandatory access control level.
</p><p>There are several key differences:
</p>
<ul><li>One important difference is that AppArmor identifies file system objects by path name instead of inode. This means that, for example, a file that is inaccessible may become accessible under AppArmor when a hard link is created to it, while SELinux would deny access through the newly created hard link.
<ul><li>As a result, AppArmor can be said not to be a <a href="Type_enforcement" title="Type enforcement">type enforcement</a> system, as files are not assigned a type; instead, they are merely referenced in a configuration file.</li></ul></li>
<li>SELinux and AppArmor also differ significantly in how they are administered and how they integrate into the system.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup></li>
<li>Since it endeavors to recreate traditional DAC controls with MAC-level enforcement, AppArmor's set of operations is also considerably smaller than those available under most SELinux implementations. For example, AppArmor's set of operations consist of: read, write, append, execute, lock, and link.<sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup> Most SELinux implementations will support numbers of operations orders of magnitude more than that. For example, SELinux will usually support those same permissions, but also includes controls for mknod, binding to network sockets, implicit use of POSIX capabilities, loading and unloading kernel modules, various means of accessing shared memory, etc.</li>
<li>There are no controls in AppArmor for categorically bounding POSIX capabilities. Since the current implementation of capabilities contains no notion of a subject for the operation (only the actor and the operation) it is usually the job of the MAC layer to prevent privileged operations on files outside the actor's enforced realm of control (i.e. "Sandbox"). AppArmor can prevent its own policy from being altered, and prevent file systems from being mounted/unmounted, but does nothing to prevent users from stepping outside their approved realms of control.
<ul><li>For example, it may be deemed beneficial for help desk employees to change ownership or permissions on certain files even if they don't own them (for example, on a departmental file share). The administrator does not want to give the user(s) root access on the box so they give them <code>CAP_FOWNER</code> or <code>CAP_DAC_OVERRIDE</code>. Under SELinux the administrator (or platform vendor) can configure SELinux to deny all capabilities to otherwise unconfined users, then create confined domains for the employee to be able to transition into after logging in, one that can exercise those capabilities, but only upon files of the appropriate type.</li></ul></li>
<li>There is no notion of multilevel security with AppArmor, thus there is no hard <a href="Bell%E2%80%93LaPadula_model" title="Bell–LaPadula model">BLP</a> or <a href="Biba_Model" title="Biba Model">Biba</a> enforcement available..</li>
<li>AppArmor configuration is done using solely regular flat files. SELinux (by default in most implementations) uses a combination of flat files (used by administrators and developers to write human readable policy before it's compiled) and extended attributes.</li>
<li>SELinux supports the concept of a "remote policy server" (configurable via /etc/selinux/semanage.conf) as an alternative source for policy configuration. Central management of AppArmor is usually complicated considerably since administrators must decide between configuration deployment tools being run as root (to allow policy updates) or configured manually on each server.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Similar_systems_and_enhancements">Similar systems and enhancements</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">See also: <a href="Samsung_Knox" title="Samsung Knox">Samsung Knox</a></div>
<p>Isolation of processes can also be accomplished by mechanisms such as <a href="Operating_system-level_virtualization" class="mw-redirect" title="Operating system-level virtualization">virtualization</a>; the <a href="OLPC" class="mw-redirect" title="OLPC">OLPC</a> project, for example, in its first implementation<sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup> <a href="Sandbox_(computer_security)" title="Sandbox (computer security)">sandboxed</a> individual applications in lightweight <a href="Vserver" class="mw-redirect" title="Vserver">Vservers</a>. Also, the <a href="NSA" class="mw-redirect" title="NSA">NSA</a> has adopted some of the SELinux concepts in Security-Enhanced <a href="Android_(operating_system)" title="Android (operating system)">Android</a>.<sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup>
</p><p><a href="General_Dynamics" title="General Dynamics">General Dynamics</a> builds and distributes PitBull Trusted Operating System,<sup id="cite_ref-42" class="reference"><a href="#cite_note-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup> a <a href="Multilevel_security" title="Multilevel security">multilevel security</a> (MLS) enhancement for <a href="Red_Hat_Enterprise_Linux" title="Red Hat Enterprise Linux">Red Hat Enterprise Linux</a>.
</p><p>Multi-Category Security (MCS) is an enhancement to SELinux for <a href="Red_Hat_Enterprise_Linux" title="Red Hat Enterprise Linux">Red Hat Enterprise Linux</a> that allows users to label files with categories, in order to further restrict access through discretionary access control and type enforcement. Categories provide additional compartments within sensitivity levels used by <a href="Multilevel_security" title="Multilevel security">multilevel security</a> (MLS).<sup id="cite_ref-43" class="reference"><a href="#cite_note-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1266661725">
/* start https://en.wikipedia.org/ */
.mw-parser-output .portalbox{padding:0;margin:0.5em 0;display:table;box-sizing:border-box;max-width:175px;list-style:none}.mw-parser-output .portalborder{border:1px solid var(--border-color-base,#a2a9b1);padding:0.1em;background:var(--background-color-neutral-subtle,#f8f9fa)}.mw-parser-output .portalbox-entry{display:table-row;font-size:85%;line-height:110%;height:1.9em;font-style:italic;font-weight:bold}.mw-parser-output .portalbox-image{display:table-cell;padding:0.2em;vertical-align:middle;text-align:center}.mw-parser-output .portalbox-link{display:table-cell;padding:0.2em 0.2em 0.2em 0.3em;vertical-align:middle}@media(min-width:720px){.mw-parser-output .portalleft{margin:0.5em 1em 0.5em 0}.mw-parser-output .portalright{clear:right;float:right;margin:0.5em 0 0.5em 1em}}
/* end https://en.wikipedia.org/ */
</style>
<ul><li><a href="AppArmor" title="AppArmor">AppArmor</a> – Linux kernel security module</li>
<li><a href="Astra_Linux" title="Astra Linux">Astra Linux</a> – Russian Linux-based computer operating system</li>
<li><a href="Red_Star_OS" title="Red Star OS">Red Star OS</a> – North Korean Linux-based operating system</li>
<li><a href="RSBAC" title="RSBAC">Rule Set Based Access Control (RSBAC)</a> – Access control framework for Linux kernel</li>
<li><a href="Simplified_Mandatory_Access_Control_Kernel" class="mw-redirect" title="Simplified Mandatory Access Control Kernel">Simplified Mandatory Access Control Kernel</a> – Linux kernel security module<span style="display:none" class="category-annotation-with-redirected-description">Pages displaying short descriptions of redirect targets</span></li>
<li><a href="Solaris_Trusted_Extensions" title="Solaris Trusted Extensions">Solaris Trusted Extensions</a> – Security extensions for Solaris operating system</li>
<li><a href="TOMOYO_Linux" class="mw-redirect" title="TOMOYO Linux">Tomoyo</a> – Linux kernel security module<span style="display:none" class="category-annotation-with-redirected-description">Pages displaying short descriptions of redirect targets</span></li>
<li><a href="TrustedBSD" class="mw-redirect" title="TrustedBSD">TrustedBSD</a> – Free and open-source Unix-like operating system<span style="display:none" class="category-annotation-with-redirected-description">Pages displaying short descriptions of redirect targets</span></li>
<li><a href="Unix_security" title="Unix security">Unix security</a></li>
<li><a href="Qubes_OS" title="Qubes OS">Qubes OS</a> – Security-focused Linux-based operating system</li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://marc.info/?l=linux-kernel&m=97749381725894">"Security-enhanced Linux available at NSA site - MARC"</a>. <i><a href="MARC_(archive)" title="MARC (archive)">MARC</a></i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20190317053151/https://marc.info/?l=linux-kernel&m=97749381725894">Archived</a> from the original on 17 March 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">24 December</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-wikidata-e60d71b26bd00c83b5ec059fcd39fa34d0494261-v20-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-wikidata-e60d71b26bd00c83b5ec059fcd39fa34d0494261-v20_2-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/SELinuxProject/selinux/releases/tag/3.9">"Release SELinux userspace release 3.9 · SELinuxProject/selinux"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">19 July</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20180918010353/https://www.nsa.gov/what-we-do/research/selinux/faqs.shtml">"SELinux Frequently Asked Questions (FAQ) - NSA/CSS"</a>. National Security Agency. Archived from <a rel="nofollow" class="external text" href="https://www.nsa.gov/what-we-do/research/selinux/faqs.shtml">the original</a> on 18 September 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFLoscoccoSmalley2001" class="citation web cs1">Loscocco, Peter; Smalley, Stephen (February 2001). <a rel="nofollow" class="external text" href="https://www.nsa.gov/resources/everyone/digital-media-center/publications/research-papers/assets/files/flexible-support-for-security-policies-into-linux-feb2001-report.pdf">"Integrating Flexible Support for Security Policies into the Linux Operating System"</a> <span class="cs1-format">(PDF)</span>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180918010853/https://www.nsa.gov/resources/everyone/digital-media-center/publications/research-papers/assets/files/flexible-support-for-security-policies-into-linux-feb2001-report.pdf">Archived</a> <span class="cs1-format">(PDF)</span> from the original on 18 September 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">23 August</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20201022103915/https://www.nsa.gov/what-we-do/research/selinux/">"Security-Enhanced Linux - NSA/CSS"</a>. National Security Agency. 15 January 2009. Archived from <a rel="nofollow" class="external text" href="https://www.nsa.gov/what-we-do/research/selinux/">the original</a> on 22 October 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">21 April</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text">Compare <cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20180918025937/https://www.nsa.gov/news-features/press-room/press-releases/2001/se-linux.shtml">"National Security Agency Shares Security Enhancements to Linux"</a>. <i>NSA Press Release</i>. Fort George G. Meade, Maryland: National Security Agency Central Security Service. 2 January 2001. Archived from <a rel="nofollow" class="external text" href="https://www.nsa.gov/news-features/press-room/press-releases/2001/se-linux.shtml">the original</a> on 18 September 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">21 April</span> 2021</span>. <q>The NSA is pleased to announce that it has developed, and is making available to the public, a prototype version of a security-enhanced Linux operating system.</q></cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20081018034429/http://www.nsa.gov/selinux/info/contrib.cfm">"Contributors to SELinux"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.nsa.gov/selinux/info/contrib.cfm">the original</a> on 18 October 2008.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFFedora_Documentation_Project2010" class="citation book cs1">Fedora Documentation Project (2010). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=feDeO4IglRkC"><i>Fedora 13 Security-Enhanced Linux User Guide</i></a>. Fultus Corporation. p. 18. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-59682-215-3</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">22 February</span> 2012</span>. <q>SELinux decisions, such as allowing or disallowing access, are cached. This cache is known as the Access Vector Cache (AVC). Caching decisions decreases how often SELinux rules need to checked, which increases performance.</q></cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://wiki.gentoo.org/wiki/SELinux/Quick_introduction#SELinux_policy">"SELinux/Quick introduction - Gentoo Wiki"</a>. <i>wiki.gentoo.org</i>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.linode.com/docs/security/getting-started-with-selinux/">"Getting Started with SELinux"</a>. <i>Linode Guides & Tutorials</i>. 18 March 2020. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20190808110700/https://www.linode.com/docs/security/getting-started-with-selinux/">Archived</a> from the original on 8 August 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">8 August</span> 2019</span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20190808110700/https://selinuxproject.org/page/NB_Overview">"NB Overview - SELinux Wiki"</a>. <i>selinuxproject.org</i>. Archived from <a rel="nofollow" class="external text" href="https://selinuxproject.org/page/NB_Overview">the original</a> on 8 August 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">8 August</span> 2019</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://source.android.com/security/selinux/">"Security-Enhanced Linux in Android"</a>. Android Open Source Project. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180104113527/https://source.android.com/security/selinux/">Archived</a> from the original on 4 January 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">31 January</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://wiki.debian.org/SELinux">"SELinux"</a>. <i>debian.org</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200813103319/https://wiki.debian.org/SELinux">Archived</a> from the original on 13 August 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">23 August</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://ubuntu-tutorials.com/2008/03/18/how-to-install-selinux-on-ubuntu-804-hardy-heron/">"How To Install SELinux on Ubuntu 8.04 "Hardy Heron""</a>. <i>Ubuntu Tutorials</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20170705102909/https://ubuntu-tutorials.com/2008/03/18/how-to-install-selinux-on-ubuntu-804-hardy-heron/">Archived</a> from the original on 5 July 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">23 August</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://news.opensuse.org/2008/08/20/opensuse-to-add-selinux-basic-enablement-in-111/">"openSUSE News"</a>. 20 August 2008. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200928155140/https://news.opensuse.org/2008/08/20/opensuse-to-add-selinux-basic-enablement-in-111/">Archived</a> from the original on 28 September 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">23 August</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.novell.com/linux/releasenotes/x86_64/SUSE-SLED/11/#02">"Release Notes for SUSE Linux Enterprise Desktop 11"</a>. <a href="Novell" title="Novell">Novell</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160313095523/http://www.novell.com/linux/releasenotes/x86_64/SUSE-SLED/11/#02">Archived</a> from the original on 13 March 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://coreos.com/os/docs/latest/selinux.html">"SELinux on CoreOS"</a>. <i>CoreOS Docs</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180926032756/https://coreos.com/os/docs/latest/selinux.html">Archived</a> from the original on 26 September 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">15 December</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://fedoraproject.org/wiki/SELinux/Policies">"SELinux/Policies - Fedora Project Wiki"</a>. <i><a href="Fedora_Linux" title="Fedora Linux">Fedora Project</a> Wiki</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20250211201338/https://fedoraproject.org/wiki/SELinux/Policies">Archived</a> from the original on 11 February 2025<span class="reference-accessdate">. Retrieved <span class="nowrap">14 February</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite id="CITEREFGompa2025" class="citation web cs1">Gompa, Neal (13 February 2025). <a rel="nofollow" class="external text" href="https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/message/3JUSAOAXUWDXG4BSU3CEKY4Z3QUMI2US/">"Re: Announcement: SELinux as default MAC system on new Tumbleweed installations - openSUSE Factory"</a>. <i>openSUSE Mailing Lists</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20250218131724/https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/message/3JUSAOAXUWDXG4BSU3CEKY4Z3QUMI2US/">Archived</a> from the original on 18 February 2025<span class="reference-accessdate">. Retrieved <span class="nowrap">14 February</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://en.opensuse.org/Portal:SELinux/Differences_to_fedora_policy">"Portal:SELinux/Differences to fedora policy - openSUSE Wiki"</a>. <i><a href="OpenSUSE" title="OpenSUSE">openSUSE</a> Wiki</i><span class="reference-accessdate">. Retrieved <span class="nowrap">15 February</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFDeMaio2025" class="citation web cs1">DeMaio, Douglas (13 February 2025). <a rel="nofollow" class="external text" href="https://news.opensuse.org/2025/02/13/tw-plans-to-adopt-selinux-as-default/">"Tumbleweed Adopts SELinux as Default"</a>. <i>openSUSE News</i><span class="reference-accessdate">. Retrieved <span class="nowrap">13 February</span> 2025</span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://fedoraproject.org/wiki/SELinux/Commands">"SELinux/Commands - FedoraProject"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20201024024509/https://fedoraproject.org/wiki/SELinux/Commands">Archived</a> from the original on 24 October 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">25 November</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20041024211853/http://linuxcommand.org/man_pages/chcon1.html">"chcon"</a>. Linuxcommand.org. Archived from <a rel="nofollow" class="external text" href="http://linuxcommand.org/man_pages/chcon1.html">the original</a> on 24 October 2004<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/restorecon">"restorecon(8) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20210227145344/https://linux.die.net/man/8/restorecon">Archived</a> from the original on 27 February 2021<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/restorecond">"restorecond(8) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20170827014845/https://linux.die.net/man/8/restorecond">Archived</a> from the original on 27 August 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/1/runcon">"runcon(1) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200501180729/https://linux.die.net/man/1/runcon">Archived</a> from the original on 1 May 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/1/secon">"secon(1) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20191026154733/https://linux.die.net/man/1/secon">Archived</a> from the original on 26 October 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/fixfiles">"fixfiles(8): fix file SELinux security contexts - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200503094354/https://linux.die.net/man/8/fixfiles">Archived</a> from the original on 3 May 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-auto-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-auto_29-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/setfiles">"setfiles(8): set file SELinux security contexts - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200501204848/https://linux.die.net/man/8/setfiles">Archived</a> from the original on 1 May 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/load_policy">"load_policy(8) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20191026143702/https://linux.die.net/man/8/load_policy">Archived</a> from the original on 26 October 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/booleans">"booleans(8) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200603200637/https://linux.die.net/man/8/booleans">Archived</a> from the original on 3 June 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/getsebool">"getsebool(8): SELinux boolean value - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200603194859/https://linux.die.net/man/8/getsebool">Archived</a> from the original on 3 June 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/setsebool">"setsebool(8): set SELinux boolean value - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20191026153420/https://linux.die.net/man/8/setsebool">Archived</a> from the original on 26 October 2019<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://linux.die.net/man/8/togglesebool">"togglesebool(8) - Linux man page"</a>. Linux.die.net. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200826183017/https://linux.die.net/man/8/togglesebool">Archived</a> from the original on 26 August 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20121220020432/http://manpages.ubuntu.com/manpages/natty/man8/selinux-config-enforcing.8.html">"Ubuntu Manpage: selinux-config-enforcing - change /etc/selinux/config to set enforcing"</a>. <a href="Canonical_Ltd" class="mw-redirect" title="Canonical Ltd">Canonical Ltd</a>. Archived from <a rel="nofollow" class="external text" href="http://manpages.ubuntu.com/manpages/natty/man8/selinux-config-enforcing.8.html">the original</a> on 20 December 2012<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20130209033811/http://manpages.ubuntu.com/manpages/natty/man1/selinuxenabled.1.html">"Ubuntu Manpage: selinuxenabled - tool to be used within shell scripts to determine if"</a>. <a href="Canonical_Ltd" class="mw-redirect" title="Canonical Ltd">Canonical Ltd</a>. Archived from <a rel="nofollow" class="external text" href="http://manpages.ubuntu.com/manpages/natty/man1/selinuxenabled.1.html">the original</a> on 9 February 2013<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20120404160143/http://manpages.ubuntu.com/manpages/natty/man8/selinux-policy-upgrade.8.html">"Ubuntu Manpage: selinux-policy-upgrade - upgrade the modules in the SE Linux policy"</a>. <a href="Canonical_Ltd" class="mw-redirect" title="Canonical Ltd">Canonical Ltd</a>. Archived from <a rel="nofollow" class="external text" href="http://manpages.ubuntu.com/manpages/natty/man8/selinux-policy-upgrade.8.html">the original</a> on 4 April 2012<span class="reference-accessdate">. Retrieved <span class="nowrap">6 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.suse.com/documentation/sles11/book_security/data/sect1_chapter_book_security.html">"SELinux backgrounds"</a>. <i>SELinux</i>. Security Guide. SUSE. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160701143049/https://www.suse.com/documentation/sles11/book_security/data/sect1_chapter_book_security.html">Archived</a> from the original on 1 July 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">8 June</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20131017094320/http://manpages.ubuntu.com/manpages/hardy/man5/apparmor.d.5.html">"apparmor.d - syntax of security profiles for AppArmor"</a>. Archived from <a rel="nofollow" class="external text" href="http://manpages.ubuntu.com/manpages/hardy/man5/apparmor.d.5.html">the original</a> on 17 October 2013.</cite></span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://wiki.laptop.org/go/Rainbow">"Rainbow"</a>. <i>laptop.org</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20201225051029/http://wiki.laptop.org/go/Rainbow">Archived</a> from the original on 25 December 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">2 March</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20180220212206/https://www.nsa.gov/what-we-do/research/selinux/related-work/">"SELinux Related Work"</a>. <i>NSA.gov</i>. Archived from <a rel="nofollow" class="external text" href="https://www.nsa.gov/what-we-do/research/selinux/related-work/">the original</a> on 20 February 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">23 August</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-42">^</a></b></span> <span class="reference-text"><cite id="CITEREFGeneral_Dynamics" class="citation web cs1">General Dynamics. <a rel="nofollow" class="external text" href="https://gdmissionsystems.com/products/platform-security/pitbull-trusted-operating-system">"PitBull Trusted Operating System"</a>.</cite></span>
</li>
<li id="cite_note-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-43">^</a></b></span> <span class="reference-text"><cite id="CITEREFRed_Hat,_Inc." class="citation web cs1">Red Hat, Inc. <a rel="nofollow" class="external text" href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/5/html/deployment_guide/sec-mcs-ov">"49.4. Multi-Category Security (MCS)"</a>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://selinuxproject.org/">Official website</a></span></span></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20081018040612/https://www.nsa.gov/selinux/">Security-Enhanced Linux</a> at the <a href="National_Security_Agency" title="National Security Agency">National Security Agency</a> in the <a href="Internet_Archive" title="Internet Archive">Internet Archive</a></li>
<li><a rel="nofollow" class="external text" href="https://github.com/SELinuxProject/selinux">SELinux</a> on <a href="GitHub" title="GitHub">GitHub</a></li>
<li><cite id="CITEREFWalsh2013" class="citation web cs1">Walsh, Daniel J (13 November 2013). <a rel="nofollow" class="external text" href="https://opensource.com/business/13/11/selinux-policy-guide">"Visual how-to guide for SELinux policy enforcement"</a>. Opensource.com.</cite></li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Linux_kernel514" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Linux_kernel514" style="font-size:114%;margin:0 4em"><a href="Linux_kernel" title="Linux kernel">Linux kernel</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Organization</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th id="Kernel19" scope="row" class="navbox-group" style="width:1%">Kernel</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Linux_Foundation" title="Linux Foundation">Linux Foundation</a></li>
<li><a href="Linux_Mark_Institute" title="Linux Mark Institute">Linux Mark Institute</a></li>
<li><a href="Linus's_law" title="Linus's law">Linus's law</a></li>
<li><a href="Tanenbaum%E2%80%93Torvalds_debate" title="Tanenbaum–Torvalds debate">Tanenbaum–Torvalds debate</a></li>
<li><a href="Tux_(mascot)" title="Tux (mascot)">Tux</a></li>
<li><a href="SCO%E2%80%93Linux_disputes" title="SCO–Linux disputes">SCO disputes</a></li>
<li><a href="Linaro" title="Linaro">Linaro</a></li>
<li><a href="GNU_General_Public_License#Version_2" title="GNU General Public License">GNU GPL v2</a></li>
<li><a href="Menuconfig" title="Menuconfig">menuconfig</a></li>
<li><a href="List_of_Linux-supported_computer_architectures" title="List of Linux-supported computer architectures">Supported computer architectures</a></li>
<li><a href="Linux_kernel_version_history" title="Linux kernel version history">Version history</a></li>
<li><a href="Criticism_of_Linux" title="Criticism of Linux">Criticism</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Support</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>Developers
<ul><li><i><a href="The_Linux_Programming_Interface" title="The Linux Programming Interface">The Linux Programming Interface</a></i></li>
<li><a href="Kernel.org" title="Kernel.org">kernel.org</a></li>
<li><a href="Linux_kernel_mailing_list" title="Linux kernel mailing list">LKML</a></li>
<li><a href="Linux_conference" class="mw-redirect" title="Linux conference">Linux conferences</a></li></ul></li>
<li>Users
<ul><li><a href="Linux_user_group" title="Linux user group">Linux User Group (LUG)</a></li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">People</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Werner_Almesberger" title="Werner Almesberger">Werner Almesberger</a></li>
<li><a href="H._Peter_Anvin" title="H. Peter Anvin">H. Peter Anvin</a></li>
<li><a href="Jens_Axboe" title="Jens Axboe">Jens Axboe</a></li>
<li><a href="Moshe_Bar_(investor)" title="Moshe Bar (investor)">Moshe Bar</a></li>
<li><a href="Suparna_Bhattacharya" title="Suparna Bhattacharya">Suparna Bhattacharya</a></li>
<li><a href="Andries_Brouwer" title="Andries Brouwer">Andries Brouwer</a></li>
<li><a href="R%C3%A9my_Card" title="Rémy Card">Rémy Card</a></li>
<li><a href="Alan_Cox_(computer_programmer)" title="Alan Cox (computer programmer)">Alan Cox</a></li>
<li><a href="Matthew_Garrett" title="Matthew Garrett">Matthew Garrett</a></li>
<li><a href="Avi_Kivity" title="Avi Kivity">Avi Kivity</a></li>
<li><a href="Con_Kolivas" title="Con Kolivas">Con Kolivas</a></li>
<li><a href="Greg_Kroah-Hartman" title="Greg Kroah-Hartman">Greg Kroah-Hartman</a></li>
<li><a href="Benson_Leung" title="Benson Leung">Benson Leung</a></li>
<li><a href="Robert_Love" title="Robert Love">Robert Love</a></li>
<li><a href="David_S._Miller" title="David S. Miller">David S. Miller</a></li>
<li><a href="Ingo_Moln%C3%A1r" title="Ingo Molnár">Ingo Molnár</a></li>
<li><a href="Andrew_Morton_(computer_programmer)" title="Andrew Morton (computer programmer)">Andrew Morton</a></li>
<li><a href="Hans_Reiser" title="Hans Reiser">Hans Reiser</a></li>
<li><a href="Rusty_Russell" title="Rusty Russell">Rusty Russell</a></li>
<li><a href="Shuah_Khan" title="Shuah Khan">Shuah Khan</a></li>
<li><a href="Linus_Torvalds" title="Linus Torvalds">Linus Torvalds</a></li>
<li><a href="Theodore_Ts'o" title="Theodore Ts'o">Theodore Ts'o</a></li>
<li><a href="Stephen_Tweedie" title="Stephen Tweedie">Stephen Tweedie</a></li>
<li><a href="Harald_Welte" title="Harald Welte">Harald Welte</a></li>
<li><a href="Chris_Wright_(programmer)" title="Chris Wright (programmer)">Chris Wright</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Technical</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Debugging</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CRIU" title="CRIU">CRIU</a></li>
<li><a href="Ftrace" title="Ftrace">ftrace</a></li>
<li><a href="Kdump_(Linux)" title="Kdump (Linux)">kdump</a></li>
<li><a href="Linux_kernel_oops" title="Linux kernel oops">Linux kernel oops</a></li>
<li><a href="SystemTap" title="SystemTap">SystemTap</a></li>
<li><a href="Berkeley_Packet_Filter" title="Berkeley Packet Filter">BPF</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Booting_process_of_Linux" title="Booting process of Linux">Startup</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Vmlinux" title="Vmlinux">vmlinux</a></li>
<li><a href="System.map" title="System.map">System.map</a></li>
<li><a href="Dracut_(software)" title="Dracut (software)">dracut</a></li>
<li><a href="Initrd" class="mw-redirect" title="Initrd">initrd</a></li>
<li><a href="Initramfs" class="mw-redirect" title="Initramfs">initramfs</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_kernel_interfaces" title="Linux kernel interfaces">ABIs</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Linux_Standard_Base" title="Linux Standard Base">Linux Standard Base</a></li>
<li><a href="X32_ABI" title="X32 ABI">x32 ABI</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_kernel_interfaces" title="Linux kernel interfaces">APIs</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Kernel</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_kernel_interfaces#SCI" title="Linux kernel interfaces">System Call<br>Interface</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="POSIX" title="POSIX">POSIX</a>
<ul><li><a href="Ioctl" title="Ioctl">ioctl</a></li>
<li><a href="Select_(Unix)" title="Select (Unix)">select</a></li>
<li><a href="Open_(system_call)" title="Open (system call)">open</a></li>
<li><a href="Read_(system_call)" title="Read (system call)">read</a></li>
<li><a href="Close_(system_call)" title="Close (system call)">close</a></li>
<li><a href="Sync_(Unix)" title="Sync (Unix)">sync</a></li>
<li>…</li></ul></li>
<li><a href="Linux_kernel_interfaces#Additions_to_POSIX" title="Linux kernel interfaces">Linux-only</a>
<ul><li><a href="Futex" title="Futex">futex</a></li>
<li><a href="Epoll" title="Epoll">epoll</a></li>
<li><a href="Splice_(system_call)" title="Splice (system call)">splice</a></li>
<li><a href="Dnotify" title="Dnotify">dnotify</a></li>
<li><a href="Inotify" title="Inotify">inotify</a></li>
<li><a href="Readahead" title="Readahead">readahead</a></li>
<li>…</li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_kernel_interfaces#In–kernel_APIs" title="Linux kernel interfaces">In-kernel</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Advanced_Linux_Sound_Architecture" title="Advanced Linux Sound Architecture">ALSA</a></li>
<li><a href="Crypto_API_(Linux)" title="Crypto API (Linux)">Crypto API</a></li>
<li><a href="Io_uring" title="Io uring">io uring</a></li>
<li><a href="Direct_Rendering_Manager" title="Direct Rendering Manager">DRM</a></li>
<li><a href="Kernfs_(Linux)" title="Kernfs (Linux)">kernfs</a></li>
<li><a href="Memory_barrier" title="Memory barrier">Memory barrier</a></li>
<li><a href="New_API" title="New API">New API</a></li>
<li><a href="Read-copy-update" title="Read-copy-update">RCU</a></li>
<li><a href="Video4Linux" title="Video4Linux">Video4Linux</a></li>
<li><a href="IIO_Framework" title="IIO Framework">IIO</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="User_space_and_kernel_space" title="User space and kernel space">Userspace</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Daemon_(computing)" title="Daemon (computing)">Daemons</a>,<br><a href="Virtual_file_system" title="Virtual file system">File systems</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li>bpffs</li>
<li><a href="Configfs" title="Configfs">configfs</a></li>
<li><a href="Devfs" class="mw-redirect" title="Devfs">devfs</a></li>
<li><a href="Devpts" title="Devpts">devpts</a></li>
<li><a href="Debugfs" title="Debugfs">debugfs</a></li>
<li><a href="Filesystem_in_Userspace" title="Filesystem in Userspace">FUSE</a></li>
<li>hugetlbfs</li>
<li>pipefs</li>
<li><a href="Procfs" title="Procfs">procfs</a></li>
<li>securityfs</li>
<li>sockfs</li>
<li><a href="Sysfs" title="Sysfs">sysfs</a></li>
<li><a href="Tmpfs" title="Tmpfs">tmpfs</a></li>
<li><a href="Systemd" title="Systemd">systemd</a>
<ul><li><a href="Udev" title="Udev">udev</a></li></ul></li>
<li><a href="Kmscon" title="Kmscon">Kmscon</a></li>
<li><a href="Binfmt_misc" title="Binfmt misc">binfmt_misc</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Wrapper_library" title="Wrapper library">Wrapper<br>libraries</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="C_standard_library" title="C standard library">C standard library</a>
<ul><li><a href="Glibc" title="Glibc">glibc</a></li>
<li><a href="UClibc" title="UClibc">uClibc</a></li>
<li><a href="Bionic_(software)" title="Bionic (software)">Bionic</a>
<ul><li><a href="Libhybris" title="Libhybris">libhybris</a></li></ul></li>
<li><a href="Dietlibc" title="Dietlibc">dietlibc</a></li>
<li><a href="Embedded_GLIBC" class="mw-redirect" title="Embedded GLIBC">EGLIBC</a></li>
<li><a href="Klibc" title="Klibc">klibc</a></li>
<li><a href="Musl" title="Musl">musl</a></li>
<li><a href="Newlib" title="Newlib">Newlib</a></li></ul></li>
<li><a href="Cgroups" title="Cgroups">libcgroup</a></li>
<li><a href="Direct_Rendering_Manager" title="Direct Rendering Manager">libdrm</a></li>
<li><a href="Advanced_Linux_Sound_Architecture" title="Advanced Linux Sound Architecture">libalsa</a></li>
<li><a href="Evdev" title="Evdev">libevdev</a></li>
<li><a href="Libusb" title="Libusb">libusb</a></li>
<li><a href="Io_uring" title="Io uring">liburing</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Components</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Loadable_kernel_module" title="Loadable kernel module">Kernel modules</a></li>
<li><a href="BlueZ" class="mw-redirect" title="BlueZ">BlueZ</a></li>
<li><a href="Cgroups" title="Cgroups">cgroups</a></li>
<li><a href="Linux_console" title="Linux console">Console</a></li>
<li><a href="Bcache" title="Bcache">bcache</a></li>
<li><a href="Device_mapper" title="Device mapper">Device mapper</a></li>
<li><a href="Dm-cache" title="Dm-cache">dm-cache</a></li>
<li><a href="Dm-crypt" title="Dm-crypt">dm-crypt</a></li>
<li><a href="Direct_Rendering_Manager" title="Direct Rendering Manager">DRM</a></li>
<li><a href="EDAC_(Linux)" class="mw-redirect" title="EDAC (Linux)">EDAC</a></li>
<li><a href="Evdev" title="Evdev">evdev</a></li>
<li><a href="Kernel_same-page_merging" title="Kernel same-page merging">Kernel same-page merging</a> (KSM)</li>
<li><a href="LIO_(SCSI_target)" title="LIO (SCSI target)">LIO</a></li>
<li><a href="Linux_framebuffer" title="Linux framebuffer">Framebuffer</a></li>
<li><a href="Logical_Volume_Manager_(Linux)" title="Logical Volume Manager (Linux)">LVM</a></li>
<li><a href="KMS_driver" class="mw-redirect" title="KMS driver">KMS driver</a></li>
<li><a href="Netfilter" title="Netfilter">Netfilter</a></li>
<li><a href="Netlink" title="Netlink">Netlink</a></li>
<li><a href="Nftables" title="Nftables">nftables</a></li>
<li><a href="Network_scheduler" title="Network scheduler">Network scheduler</a></li>
<li><a href="Perf_(Linux)" title="Perf (Linux)">perf</a></li>
<li><a href="SLUB_(software)" title="SLUB (software)">SLUB</a></li>
<li><a href="Zram" title="Zram">zram</a></li>
<li><a href="Zswap" title="Zswap">zswap</a></li></ul>
<ul><li><a href="Scheduling_(computing)#Linux" title="Scheduling (computing)">Process and I/O schedulers</a>:</li>
<li><a href="Brain_Fuck_Scheduler" title="Brain Fuck Scheduler">Brain Fuck Scheduler</a></li>
<li><a href="Completely_Fair_Scheduler" title="Completely Fair Scheduler">Completely Fair Scheduler</a> (CFS)</li>
<li><a href="Earliest_eligible_virtual_deadline_first_scheduling" title="Earliest eligible virtual deadline first scheduling">Earliest eligible virtual deadline first</a> (EEVDF)</li>
<li><a href="Noop_scheduler" title="Noop scheduler">Noop scheduler</a></li>
<li><a href="O(n)_scheduler" title="O(n) scheduler">O(n) scheduler</a></li>
<li><a href="O(1)_scheduler" title="O(1) scheduler">O(1) scheduler</a></li>
<li><a href="SCHED_DEADLINE" title="SCHED DEADLINE">SCHED_DEADLINE</a></li>
<li><a href="SCHED_FIFO" class="mw-redirect" title="SCHED FIFO">SCHED_FIFO</a></li>
<li><a href="SCHED_RR" class="mw-redirect" title="SCHED RR">SCHED_RR</a></li></ul>
<ul><li><a href="Linux_Security_Modules" title="Linux Security Modules">Security Modules</a>: <a href="AppArmor" title="AppArmor">AppArmor</a></li>
<li><a href="Exec_Shield" title="Exec Shield">Exec Shield</a></li>
<li><a href="Seccomp" title="Seccomp">seccomp</a></li>
<li><a href="Smack_(software)" title="Smack (software)">Smack</a></li>
<li><a href="Tomoyo_Linux" title="Tomoyo Linux">Tomoyo Linux</a></li>
<li><a href="Linux_PAM" title="Linux PAM">Linux PAM</a></li></ul>
<ul><li><a href="Device_driver" title="Device driver">Device drivers</a>
<ul><li><a href="Comparison_of_open-source_wireless_drivers" title="Comparison of open-source wireless drivers">802.11</a></li>
<li><a href="Free_and_open-source_graphics_device_driver" title="Free and open-source graphics device driver">graphics</a></li></ul></li>
<li><a href="Raw_device" title="Raw device">Raw device</a></li></ul>
<ul><li><a href="Initramfs" class="mw-redirect" title="Initramfs">initramfs</a></li>
<li><a href="KernelCare" title="KernelCare">KernelCare</a></li>
<li><a href="Kexec" title="Kexec">kexec</a></li>
<li><a href="KGraft" title="KGraft">kGraft</a></li>
<li><a href="Kpatch" title="Kpatch">kpatch</a></li>
<li><a href="Ksplice" title="Ksplice">Ksplice</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Variants</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Mainline_Linux" class="mw-redirect" title="Mainline Linux">Mainline</a>
<ul><li><a href="Linux_kernel" title="Linux kernel">Linux kernel</a></li>
<li><a href="Linux-libre" title="Linux-libre">Linux-libre</a></li></ul></li>
<li><a href="High-performance_computing" title="High-performance computing">High-performance computing</a>
<ul><li><a href="INK_(operating_system)" title="INK (operating system)">INK</a></li>
<li><a href="Compute_Node_Linux" title="Compute Node Linux">Compute Node Linux</a></li>
<li><a href="Slurm_Workload_Manager" title="Slurm Workload Manager">SLURM</a></li></ul></li>
<li><a href="Real-time_computing" title="Real-time computing">Real-time computing</a>
<ul><li><a href="RTLinux" title="RTLinux">RTLinux</a></li>
<li><a href="RTAI" title="RTAI">RTAI</a></li>
<li><a href="Xenomai" title="Xenomai">Xenomai</a></li>
<li><a href="PREEMPT_RT" title="PREEMPT RT">PREEMPT_RT</a></li></ul></li>
<li><a href="Memory_management_unit" title="Memory management unit">MMU</a>-less
<ul><li><a href="%CE%9CClinux" title="ΜClinux">μClinux</a></li>
<li><a href="PSXLinux" title="PSXLinux">PSXLinux</a></li></ul></li></ul>
</div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th id="Virtualization18" scope="row" class="navbox-group" style="width:1%"><a href="Virtualization" title="Virtualization">Virtualization</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Hypervisor" title="Hypervisor">Hypervisor</a>
<ul><li><a href="Kernel-based_Virtual_Machine" title="Kernel-based Virtual Machine">KVM</a></li>
<li><a href="Xen" title="Xen">Xen</a></li></ul></li>
<li><a href="OS-level_virtualization" title="OS-level virtualization">OS-level virtualization</a>
<ul><li><a href="Linux-VServer" title="Linux-VServer">Linux-VServer</a></li>
<li><a href="Lguest" title="Lguest">Lguest</a></li>
<li><a href="LXC" title="LXC">LXC</a></li>
<li><a href="OpenVZ" title="OpenVZ">OpenVZ</a></li></ul></li>
<li>Other
<ul><li><a href="L4Linux" title="L4Linux">L4Linux</a></li>
<li><a href="User-mode_Linux" title="User-mode Linux">User-mode Linux</a></li>
<li><a href="MkLinux" title="MkLinux">MkLinux</a></li>
<li><a href="Cooperative_Linux" title="Cooperative Linux">coLinux</a></li></ul></li></ul>
</div></td></tr></tbody></table><div>
</div></td></tr></tbody></table><div></div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_adoption" title="Linux adoption">Adoption</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"></div><table class="nowraplinks navbox-subgroup" style="border-spacing:0"><tbody><tr><th id="Rangeof_use48" scope="row" class="navbox-group" style="width:1%"><a href="Linux_range_of_use" title="Linux range of use">Range<br>of use</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Linux_desktop_environments" class="mw-redirect" title="Linux desktop environments">Desktop</a></li>
<li><a href="Linux_on_embedded_systems" title="Linux on embedded systems">Embedded</a></li>
<li><a href="Video_games_and_Linux" title="Video games and Linux">Gaming</a></li>
<li>Thin client:
<ul><li><a href="Linux_Terminal_Server_Project" title="Linux Terminal Server Project">LTSP</a></li></ul></li>
<li>Server:
<ul><li><a href="LAMP_(software_bundle)" title="LAMP (software bundle)">LAMP</a></li>
<li><a href="LYME_(software_bundle)" title="LYME (software bundle)">LYME-LYCE</a></li></ul></li>
<li><a href="Linux-powered_device" title="Linux-powered device">Devices</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Adopters</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="List_of_Linux_adopters" title="List of Linux adopters">List of Linux adopters</a></li></ul>
</div></td></tr></tbody></table><div></div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><b><span class="nowrap"><span class="noviewer" typeof="mw:File"></span> </span><a href="Portal%3ALinux" title="Portal:Linux">Linux portal</a></b></li>
<li><b><span class="nowrap"><span class="noviewer" typeof="mw:File"><span></span></span> </span><a href="Portal%3AFree_and_open-source_software" title="Portal:Free and open-source software">Free and open-source software portal</a></b></li>
<li><span class="noviewer" typeof="mw:File"><span title="Category"></span></span> <b>Category</b></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox" aria-labelledby="Linux634" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Linux634" style="font-size:114%;margin:0 4em"><a href="Linux" title="Linux">Linux</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_kernel" title="Linux kernel">Linux kernel</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="History_of_Linux" title="History of Linux">History</a></li>
<li><a href="Linus's_law" title="Linus's law">Linus's law</a></li>
<li><a href="Linux-libre" title="Linux-libre">Linux-libre</a></li>
<li><a href="Booting_process_of_Linux" title="Booting process of Linux">Booting process</a></li>
<li><a href="Linux_kernel_oops" title="Linux kernel oops">Kernel oops</a></li>
<li><a href="Tux_(mascot)" title="Tux (mascot)">Tux</a></li>
<li><i>more…</i></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Controversies</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Criticism_of_Linux" title="Criticism of Linux">Criticism of Linux</a></li>
<li><a href="Criticism_of_desktop_Linux" title="Criticism of desktop Linux">Criticism of desktop Linux</a></li>
<li><a href="GNU/Linux_naming_controversy" title="GNU/Linux naming controversy">GNU/Linux naming controversy</a></li>
<li><a href="Tanenbaum%E2%80%93Torvalds_debate" title="Tanenbaum–Torvalds debate">Tanenbaum–Torvalds debate</a></li>
<li><a href="SCO%E2%80%93Linux_disputes" title="SCO–Linux disputes">SCO and Linux</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_distribution" title="Linux distribution">Distributions</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Comparison_of_Linux_distributions" title="Comparison of Linux distributions">General comparison</a></li>
<li><a href="List_of_Linux_distributions" title="List of Linux distributions">Distributions list</a></li>
<li><a href="Comparison_of_netbook-oriented_Linux_distributions" title="Comparison of netbook-oriented Linux distributions">Netbook-specific comparison</a></li>
<li><a href="List_of_Linux_distributions_that_run_from_RAM" title="List of Linux distributions that run from RAM">Distributions that run from RAM</a></li>
<li><a href="Light-weight_Linux_distribution" class="mw-redirect" title="Light-weight Linux distribution">Lightweight</a></li>
<li><a href="Security-focused_operating_system#Linux" title="Security-focused operating system">Security-focused operating system</a></li>
<li><a href="Package_manager" title="Package manager">Package manager</a>
<ul><li><a href="Package_format" title="Package format">Package format</a></li>
<li><a href="List_of_software_package_management_systems" title="List of software package management systems">List of software package managers</a></li></ul></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Organizations</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="LinuxChix" title="LinuxChix">LinuxChix</a></li>
<li><a href="Linux_Counter" title="Linux Counter">Linux Counter</a></li>
<li><a href="Linux_Documentation_Project" title="Linux Documentation Project">Linux Documentation Project</a></li>
<li><a href="Linux_Foundation" title="Linux Foundation">Linux Foundation</a></li>
<li><a href="Linux_Mark_Institute" title="Linux Mark Institute">Linux Mark Institute</a></li>
<li><a href="Linux_user_group" title="Linux user group">Linux User Group (LUG)</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Linux_adoption" title="Linux adoption">Adoption</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="List_of_Linux_adopters" title="List of Linux adopters">Adopters</a></li>
<li><a href="Linux_desktop_environments" class="mw-redirect" title="Linux desktop environments">Desktop</a></li>
<li><a href="Linux_on_embedded_systems" title="Linux on embedded systems">Embedded</a></li>
<li><a href="Linux_gaming" class="mw-redirect" title="Linux gaming">Gaming</a></li>
<li><a href="Linux_for_mobile_devices" title="Linux for mobile devices">Mobile</a></li>
<li><a href="Linux_range_of_use" title="Linux range of use">Range of use</a></li>
<li><a href="Linux_malware" title="Linux malware">Linux malware</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Media</th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="DistroWatch" title="DistroWatch">DistroWatch</a></li>
<li><i><a href="Free_Software_Magazine" title="Free Software Magazine">Free Software Magazine</a></i></li>
<li><i><a href="Full_Circle_(magazine)" title="Full Circle (magazine)">Full Circle</a></i></li>
<li><a href="Linux.com" title="Linux.com">Linux.com</a></li>
<li><i><a href="Linux_Format" title="Linux Format">Linux Format</a></i></li>
<li><i><a href="Linux_Gazette" title="Linux Gazette">Linux Gazette</a></i></li>
<li><i><a href="Linux_Journal" title="Linux Journal">Linux Journal</a></i></li>
<li><i><a href="Linux_Magazine" title="Linux Magazine">Linux Magazine</a></i></li>
<li><i><a href="LinuxUser" title="LinuxUser">LinuxUser</a></i>
<ul><li><i><a href="Ubuntu_User" title="Ubuntu User">Ubuntu User</a></i></li></ul></li>
<li><a href="Linux_Outlaws" title="Linux Outlaws">Linux Outlaws</a></li>
<li><i><a href="Linux_Voice" title="Linux Voice">Linux Voice</a></i></li>
<li><a href="LugRadio" title="LugRadio">LugRadio</a></li>
<li><a href="LWN.net" title="LWN.net">LWN.net</a></li>
<li><a href="Phoronix_Test_Suite#Phoronix_website" title="Phoronix Test Suite">Phoronix</a></li>
<li><i><a href="Revolution_OS" title="Revolution OS">Revolution OS</a></i></li>
<li><a href="The_Code_(2001_film)" title="The Code (2001 film)"><i>The Code</i></a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="List_of_computer_security_certifications" title="List of computer security certifications">Security<br>certifications</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CompTIA_Linux%2B" class="mw-redirect" title="CompTIA Linux+">CompTIA Linux+</a></li>
<li><a href="Linux_Foundation_Linux_Certification" class="mw-redirect" title="Linux Foundation Linux Certification">Linux Foundation</a></li>
<li><a href="Red_Hat_Certification_Program" title="Red Hat Certification Program">Red Hat</a></li></ul>
</div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><b><span class="nowrap"><span class="noviewer" typeof="mw:File"></span> </span><a href="Portal%3ALinux" title="Portal:Linux">Linux portal</a></b></li>
<li><b><span class="nowrap"><span class="noviewer" typeof="mw:File"><span></span></span> </span><a href="Portal%3AFree_and_open-source_software" title="Portal:Free and open-source software">Free and open-source software portal</a></b></li>
<li><span class="noviewer" typeof="mw:File"><span title="Category"></span></span> <b>Category</b></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox authority-control" aria-label="Navbox390" style="padding:3px"><table class="nowraplinks hlist navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Authority control databases: National </th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"><ul><li><span class="uid"><a rel="nofollow" class="external text" href="https://d-nb.info/gnd/4805017-9">Germany</a></span></li></ul></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-08-04" href="https://en.wikipedia.org/wiki/?title=Security-Enhanced_Linux&oldid=1304187959">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>