e965edfda2
to force the allocation of MAC labels for all mbufs regardless of whether a configured policy requires labeling when the mbuf is allocated. This can be useful it you anticipate loading a fully labeled policy after boot and don't want mbufs to exist without label storage, for performance measurement purposes, etc. It also slightly lowers the overhead of m_tag labeling due to removing the decision logic. While here, improve commenting of other MAC options. Obtained from: TrustedBSD Project Sponsored by: DARPA, Network Associates Laboratories