> -----Original Message----- > From: owner-selinux@xxxxxxxxxxxxx [mailto:owner-selinux@xxxxxxxxxxxxx] On > Behalf Of Dominick Grift > Sent: Wednesday, September 03, 2008 2:25 AM > To: Murray McAllister > Cc: SE Linux > Subject: Re: user guide draft: "Targeted Policy" review > > On Wed, 2008-09-03 at 17:41 +1000, Murray McAllister wrote: > > Hi, > > > Are there any SELinux restrictions on what users can do when they run > > unconfined? > > Yes i think unconfined users cannot do execmem, execstack, execheap by > default. > Otherwise they're exempted from policy enforcement i think. In RHEL5, constraints still apply to applications running in the unconfined_t domain, so all the MLS constraints apply. I'm not familiar with Fedora 10, so it may be different. > > -- > Dominick Grift <domg472@xxxxxxxxx> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.