# Life begins with the kernel. type kernel, domain; permissive kernel; # The kernel is unconfined. unconfined_domain(kernel)