HEX
Server: LiteSpeed
System: Linux ws4.angoweb.net 5.14.0-611.13.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Dec 11 04:57:59 EST 2025 x86_64
User: tswangoe (2287)
PHP: 8.1.33
Disabled: show_source, system, shell_exec, passthru, exec, phpinfo, popen, proc_open
Upload Files
File: //proc/thread-self/root/lib/python3.9/site-packages/sepolicy/help/lockdown_permissive.txt
Disable Permissive Processes


Disabling the 'permissivedomains' module allows you to remove all permissive domains shipped with the distribution.

When the distribution policy writers write a new confined domain, they initially ship the policy for that domain in permissive mode.  Permissive mode means that a process running in the domain will not be confined by SELinux.  The kernel will log the AVC messages, access denials, that would have happened had the process been run in enforcing mode.

Permissive domain policies are experimental and will be turned to enforcing in future Operation System Releases.

Note if you disable the permissive domains module, you may see an increase in the denials in your log files.