# Security-Enhanced Linux
Security-Enhanced Linux is a protocol, standard, or security technology recorded in [[Scanned_20260730-1706|Scanned_20260730-1706]]. In the reconstruction, SELinux is a mandatory-access-control framework.
## Historical and Technical Context
[[Security-Enhanced Linux|SELinux]] is a mandatory-access-control framework. `setools-gui` provides graphical inspection of SELinux policy. “host / guest — gui” links policy inspection to the notebook's virtualization work.
## Role in Scanned_20260730-1706
The author is extending recovery and virtualization beyond availability into **policy visibility**: a host/guest system must be administrable and its security labels inspectable.
## Notebook Evidence
- [[Scanned_20260730-1706|Scanned_20260730-1706]], PDF page 19: SELinux and host/guest GUI.
**Evidentiary status:** The page occurrence and transcription are notebook evidence. Technical identification follows the source reconstruction’s cited research. Co-occurrence does not by itself prove ownership, deployment, or a direct operational relationship.
## Relationships and Overlays
Security-Enhanced Linux is linked to the notebook source and its source-specific indexes; no additional page-level relationship is asserted.
## Cross-Notebook Significance
SELinux adds mandatory access control and policy visibility to the Linux recovery environment. It operationalizes the policy layer discussed in [[Security Governance|Security Governance]] and complements the Linux service inventory in [[Scanned_20260730-1802|Scanned_20260730-1802]].
## Missed Signals and Open Leads
Determine whether SELinux was to be enabled on Ubuntu, used inside a guest, or evaluated as part of another distribution.
## Sources
- [[Scanned_20260730-1706|Scanned_20260730-1706]], especially PDF page(s) 19.
- `Scanned_20260730-1706.pdf`, cited as a plain archival filename; the PDF is not linked from `wiki-notes`.
- External research citations used for identification remain preserved in the source reconstruction.
## Scanned_20260730-1659 overlay
**Source evidence:** [[Scanned_20260730-1659#PDF page 15 — SELinux, App Ops, and Android permission utilities|page 15]], [[Scanned_20260730-1659#PDF page 26 — ADB over TCP, LineageOS, SELinux, and ownCloud|page 26]].
[[Security-Enhanced Linux|SELinux]] is kernel-enforced mandatory access control; [[App Ops|App Ops]] is Android's framework-level operation/permission control. The remaining entries are user-facing package organizers, uninstallers, permission viewers, antivirus, lockers, movers, and app-list exporters. Similar names do not guarantee a single developer or trustworthy provenance.
**Relationship overlay:** [[Android Debug Bridge|Android Debug Bridge]] · [[Android Permissions|Android Permissions]] · [[Android Security Utilities|Android Security Utilities]] · [[App Ops|App Ops]] · [[Application Locker|Application Locker]] · [[LineageOS|LineageOS]] · [[ownCloud|ownCloud]] · [PERSON REDACTED] · [[Port 5555|Port 5555]] · [[Transmission Control Protocol|Transmission Control Protocol]].
This evidence supplements rather than replaces earlier notebook interpretations. It connects the existing note to [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Scanned_20260730-1659|Scanned_20260730-1659]].