Modes and policies, labels and contexts, boolean switches, and how to actually fix it when it blocks something
Modes, policies, and status — what Security-Enhanced Linux actually is and how mandatory access control works.
Read Part 1 →
Labels, chcon, and restorecon —
every file, process, port, and user has a context, and this is how
it's managed.
getsebool, setsebool, and
semanage boolean — the built-in on/off switches
for common policy exceptions.
audit2allow, ausearch, and
sealert — SELinux problems always leave
evidence; here's how to read it.