I have a few UFS2 filesystems with multilabel enabled, and some areas of each are designated mls/high. Do I need to set the MAC labels of the corresponding character devices to mls/high to adequately prevent read access to those areas? I know I can raise kern.securelevel to protect them from writing, but the point of mac_mls is to prevent reading. The kernel runs at mls/equal, but I'm wondering if it will deny access to mls/low files from mls/low processes. Thanks!
Kevin Barry
Kevin Barry