On Wed, 2009-08-05 at 17:39 +0430, mina elnino wrote: > dear list, > i need to know if there is a special module in source code of selinux > which is responsible to check every access to resources of the system. > i mean is there a specific function that reads binary policy file and > according to it, grants or prohibits the action. > regards. Sounds like you need to do some reading on the architecture and implementation of SELinux, e.g.: http://www.nsa.gov/research/_files/selinux/papers/slinux-abs.shtml http://www.nsa.gov/research/_files/selinux/papers/module-abs.shtml The SELinux by Example book may be a useful resource. You may find this recent thread to be informative: http://marc.info/?t=124816978000005&r=1&w=2 -- Stephen Smalley National Security Agency -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.