Enabling MCS for Users
MCS is active by default in SELinux, but isn't configured for users. To configure MCS for
users, you must create a policy module that adds a rule to assign the
mcs_constrained_type
attribute to the user domain.
You can add the mcs_constrained_type
attribute to any other SELinux
domain in the same way.