SELinuxHostTest:  Add testMLSAttributes test.

Using the sepolicy-analyze attribute support added by
Ie19361c02feb1ad14ce36862c6aace9e66c422bb, check that
mlstrustedsubject does not include the untrusted_app domain
and that mlstrustedobject does not include the app_data_file type.
Either of these cases would defeat the purpose of enabling
levelFrom=user in seapp_contexts for per-user isolation of
normal apps.

Change-Id: I5c77283e419363bf8834731bfefa61977402d661
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
1 file changed