I tried to go through documentation of selinux but I don't even where to start...
So, my question: is it possoble to restrict with selinux root power that it cannot even do:
-change seliux (load new policy etc.
-install/remove software
-change /etc/ /boot/ and other important data
shortly: just read

And all administratory work done by other user or when the selinux is disabled durnig boot.
Thank You for help. Just give me a tip where to start (but please not like that: "read documentation"

).