1 # Label inodes with the fs label. 2 genfscon rootfs / u:object_r:rootfs:s0 3 # proc labeling can be further refined (longest matching prefix). 4 genfscon proc / u:object_r:proc:s0 5 genfscon proc /net u:object_r:proc_net:s0 6 genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0 7 genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0 8 genfscon proc /sysrq-trigger u:object_r:proc_sysrq:s0 9 genfscon proc /sys/fs/protected_hardlinks u:object_r:proc_security:s0 10 genfscon proc /sys/fs/protected_symlinks u:object_r:proc_security:s0 11 genfscon proc /sys/fs/suid_dumpable u:object_r:proc_security:s0 12 genfscon proc /sys/kernel/core_pattern u:object_r:usermodehelper:s0 13 genfscon proc /sys/kernel/dmesg_restrict u:object_r:proc_security:s0 14 genfscon proc /sys/kernel/hotplug u:object_r:usermodehelper:s0 15 genfscon proc /sys/kernel/kptr_restrict u:object_r:proc_security:s0 16 genfscon proc /sys/kernel/modprobe u:object_r:usermodehelper:s0 17 genfscon proc /sys/kernel/modules_disabled u:object_r:proc_security:s0 18 genfscon proc /sys/kernel/poweroff_cmd u:object_r:usermodehelper:s0 19 genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0 20 genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0 21 genfscon proc /sys/net u:object_r:proc_net:s0 22 genfscon proc /sys/vm/mmap_min_addr u:object_r:proc_security:s0 23 # selinuxfs booleans can be individually labeled. 24 genfscon selinuxfs / u:object_r:selinuxfs:s0 25 genfscon cgroup / u:object_r:cgroup:s0 26 # sysfs labels can be set by userspace. 27 genfscon sysfs / u:object_r:sysfs:s0 28 genfscon inotifyfs / u:object_r:inotify:s0 29 genfscon vfat / u:object_r:vfat:s0 30 genfscon debugfs / u:object_r:debugfs:s0 31 genfscon fuse / u:object_r:fuse:s0 32 genfscon pstore / u:object_r:pstorefs:s0 33 genfscon functionfs / u:object_r:functionfs:s0 34 genfscon usbfs / u:object_r:usbfs:s0 35