+
     Gi	  c                   s    ^ RI t ^ RIt^RIHt ^RI5 ^ RIt^ RIHt ^ RI	H
t
 ]P                  P                  4       t ! R R]P                  4      tR# )    N)base)Z*)
exceptions)commandsc                   s   a a ] tR t^t oRt]R 4       tV 3R lt]R 4       tR t	R t
]! R4      R 4       t]! R4      R	 4       tR
tVtV ;t# )SelinuxPlugina  
Plug-in for tuning SELinux options.

SELinux decisions, such as allowing or denying access, are
cached. This cache is known as the Access Vector Cache (AVC). When
using these cached decisions, SELinux policy rules need to be checked
less, which increases performance. The [option]`avc_cache_threshold`
option allows adjusting the maximum number of AVC entries.

NOTE: Prior to changing the default value, evaluate the system
performance with care. Increasing the value could potentially
decrease the performance by making AVC slow.

.Increase the AVC cache threshold for hosts with containers.
====
----
[selinux]
avc_cache_threshold=8192
----
====
c                s    R p\         P                  P                  V4      '       g*   Rp\         P                  P                  V4      '       g   RpV# )z/sys/fs/selinuxz/selinuxN)ospathZexists)selfr   s   & A/usr/lib/python3.14/site-packages/tuned/plugins/plugin_selinux.py_get_selinux_pathZSelinuxPlugin._get_selinux_path"   s<    	$			
4
''..

D	+    c                s   < \        4       V n        V P                  4       V n        V P                  f   \        P
                  ! R4      h\        P                  P                  V P                  RR4      V n	        \        \        V `2  ! V/ VB  R # )NzFSELinux is not enabled on your system or incompatible version is used.ZavcZcache_threshold)r   _cmdr	   _selinux_pathr   ZNotSupportedPluginExceptionr   r   Zjoin_cache_threshold_pathZsuperr   __init__)r   ZargsZkwargs	__class__s   &*,r   r   ZSelinuxPlugin.__init__+   so    j$)--/$			/	/0x	yy!ww||D,>,>GXY$t%t6v6r
   c                s
    R R/# )avc_cache_thresholdN )r   s   &r   _get_config_optionsZ!SelinuxPlugin._get_config_options3   s     4
 r
   c                s"    R Vn         RVn        R# )TFN)Z_has_static_tuningZ_has_dynamic_tuningr   instance   &&r   _instance_initZSelinuxPlugin._instance_init9   s     $(!&(r
   c                s    R # )Nr   r   r   r   _instance_cleanupZSelinuxPlugin._instance_cleanup=   s    r
   r   c                s    Vf   R # \        V4      pV^ 8  dL   V'       gB   V P                  P                  V P                  TV'       d   \        P
                  .MRR7       V# R # )NF)Zno_error)intr   Zwrite_to_filer   errnoZENOENT)r   valuer   ZsimZremoveZ	thresholds   &&&&& r   _set_avc_cache_thresholdZ&SelinuxPlugin._set_avc_cache_threshold@   sT    
]
%j)!^
IID66	"(e  5

r
   c                s    V P                   P                  V P                  4      p\        V4      ^ 8  d   \	        V4      # R# )r    N)r   Z	read_filer   Zlenr   )r   r   r   s   && r   _get_avc_cache_thresholdZ&SelinuxPlugin._get_avc_cache_thresholdM   s4    
))

d88
9%Z!^
e*	r
   )r   r   r   )Z__name__Z
__module__Z__qualname__Z__firstlineno__Z__doc__Zclassmethodr	   r   r   r   r   Zcommand_setr   Zcommand_getr   Z__static_attributes__Z__classdictcell__Z__classcell__)r   Z__classdict__s   @@r   r   r      sz     ,  7  
' #$
 %
 #$ % r
   r   )r   r   Z r   Z
decoratorsZ
tuned.logsZtunedZtuned.pluginsr   Ztuned.utils.commandsr   ZlogsZgetZlogZPluginr   r   r
   r   <module>r      s<    	     $ )jjnnGDKK Gr
   