diff --git a/policy/modules/kernel/ubac.if b/policy/modules/kernel/ubac.if index 7477750..464f759 100644 --- a/policy/modules/kernel/ubac.if +++ b/policy/modules/kernel/ubac.if @@ -5,13 +5,26 @@ ######################################## ## -## Constrain by user-based access control. +## Constrain by user-based access control (UBAC). ## +## +##

+## Constrain the specified type by user-based +## access control (UBAC). Typically, these are +## user processes or user files that need to be +## differentiated by SELinux user. Normally this +## does not include administrative or privileged +## programs. For the UBAC rules to be enforced, +## both the subject (source) type and the object +## (target) types must be UBAC constrained. +##

+##
## ## ## Type to be constrained by UBAC. ## ## +## # interface(`ubac_constrained',` gen_require(`