> Wouldn't QP1 require different access control than QP0 due to SA clients > on every end node ? QP1 still allows modification of the fabric (e.g. multicast join) or an DoS attack against the SA. Though the latter probably requires restricting how a UD QP may be used. _______________________________________________ Selinux mailing list Selinux@xxxxxxxxxxxxx To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx. To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.