diff --git a/www/api-docs/admin.html b/www/api-docs/admin.html new file mode 100644 index 00000000..b2feaf8a --- /dev/null +++ b/www/api-docs/admin.html @@ -0,0 +1,88 @@ + +
+Module: | Description: |
+ + dmesg | +Policy for dmesg. |
+
+
+ + rpm | +Policy for the RPM package manager. |
+
+
+ + usermanage | +Policy for managing user accounts. |
+
+
Policy for dmesg.
+ ++ Execute dmesg in the dmesg domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute dmesg in the caller domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for the RPM package manager.
+ ++ Execute rpm programs in the rpm domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read RPM package database. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read from a RPM pipe. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute RPM programs in the RPM domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to allow the RPM domain. + + | +No + |
+terminal + | + + The type of the terminal allow the RPM domain to use. + + | +No + |
+ Inherit and use file descriptors from RPM. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for managing user accounts.
+ ++ Execute chfn in the chfn domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute groupadd in the groupadd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute passwd in the passwd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute useradd in the useradd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute chfn in the chfn domain, and + allow the specified role the chfn domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the chfn domain. + + | +No + |
+terminal + | + + The type of the terminal allow the chfn domain to use. + + | +No + |
+ Execute groupadd in the groupadd domain, and + allow the specified role the groupadd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the groupadd domain. + + | +No + |
+terminal + | + + The type of the terminal allow the groupadd domain to use. + + | +No + |
+ Execute passwd in the passwd domain, and + allow the specified role the passwd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the passwd domain. + + | +No + |
+terminal + | + + The type of the terminal allow the passwd domain to use. + + | +No + |
+ Execute useradd in the useradd domain, and + allow the specified role the useradd domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the useradd domain. + + | +No + |
+terminal + | + + The type of the terminal allow the useradd domain to use. + + | +No + |
Module: | Description: |
+ + dmesg | +Policy for dmesg. |
+
+
+ + rpm | +Policy for the RPM package manager. |
+
+
+ + usermanage | +Policy for managing user accounts. |
+
+
Module: | Description: |
+ + bootloader | +Policy for the kernel modules, kernel image, and bootloader. |
+
+
+ + corenetwork | +Policy controlling access to network objects |
+
+
+ + devices | ++Device nodes and interfaces for many basic system devices. + |
+
+
+ + filesystem | +Policy for filesystems. |
+
+
+ + kernel | ++Policy for kernel threads, proc filesystem, +and unlabeled processes and objects. + |
+
+
+ + selinux | ++Policy for kernel security interface, in particular, selinuxfs. + |
+
+
+ + storage | +Policy controlling access to storage devices |
+
+
+ + terminal | +Policy for terminals. |
+
+
Module: | Description: |
+ + mta | +Policy common to all email tranfer agents. |
+
+
+ + remotelogin | +Policy for rshd, rlogind, and telnetd. |
+
+
+ + sendmail | +Policy for sendmail. |
+
+
Module: | Description: |
+ + authlogin | +Common policy for authentication and user login. |
+
+
+ + clock | +Policy for reading and setting the hardware clock. |
+
+
+ + corecommands | ++Core policy for shells, and generic programs +in /bin, /sbin, /usr/bin, and /usr/sbin. + |
+
+
+ + domain | +Core policy for domains. |
+
+
+ + files | ++Basic filesystem types and interfaces. + |
+
+
+ + getty | +Policy for getty. |
+
+
+ + hostname | +Policy for changing the system host name. |
+
+
+ + hotplug | ++Policy for hotplug system, for supporting the +connection and disconnection of devices at runtime. + |
+
+
+ + init | +System initialization programs (init and init scripts). |
+
+
+ + iptables | +Policy for iptables. |
+
+
+ + libraries | +Policy for system libraries. |
+
+
+ + locallogin | +Policy for local logins. |
+
+
+ + logging | +Policy for the kernel message logger and system logging daemon. |
+
+
+ + lvm | +Policy for logical volume management programs. |
+
+
+ + miscfiles | +Miscelaneous files. |
+
+
+ + modutils | +Policy for kernel module utilities |
+
+
+ + mount | +Policy for mount. |
+
+
+ + selinuxutil | +Policy for SELinux policy and userland applications. |
+
+
+ + sysnetwork | +Policy for network configuration: ifconfig and dhcp client. |
+
+
+ + udev | +Policy for udev. |
+
+
+ + userdomain | +Policy for user domains |
+
+
+ Create, read, and write device nodes. The node + will be transitioned to the type provided. +
++ Create a directory in the device directory. +
++ Allow read, write, and create for generic character device files. +
++ Delete symbolic links in device directories. +
++ Delete the lvm control device. +
++ Dontaudit getattr on all block file device nodes. +
++ Dontaudit getattr on all character file device nodes. +
++ Dontaudit getattr on generic block devices. +
++ Dontaudit getattr for generic character device files. +
++ Dontaudit getattr on generic pipes. +
++ Dontaudit attempts to list all device nodes. +
++ Dontaudit read and write on the dri devices. +
++ Dontaudit getattr for generic device files. +
++ Getattr the agp devices. +
++ Getattr on all block file device nodes. +
++ Getattr on all character file device nodes. +
++ Allow getattr on generic block devices. +
++ Allow getattr for generic character device files. +
++ List all of the device nodes in a device directory. +
++ Read, write, create, and delete all block device files. +
++ Read, write, create, and delete all character device files. +
++ Create, delete, read, and write device nodes in device directories. +
++ Allow read, write, create, and delete for generic + block files. +
++ Create, delete, read, and write block device files. +
++ Create, delete, read, and write character device files. +
++ Create, delete, read, and write symbolic links in device directories. +
++ Make the passed in type a type appropriate for + use on device nodes (usually files in /dev). +
++ Read the multiplexed input device (/dev/input). +
++ Read the framebuffer device. +
++ Read the multiplexed input device (/dev/input). +
++ Read the lvm comtrol device. +
++ Read miscellaneous devices. +
++ Read the mouse devices. +
++ Read the mtrr device. +
++ Read from random devices (e.g., /dev/random) +
++ Read raw memory devices (e.g. /dev/mem). +
++ Read the realtime clock (/dev/rtc). +
++ Read the sound devices. +
++ Read the sound mixer devices. +
++ Read from pseudo random devices (e.g., /dev/urandom) +
++ Allow full relabeling (to and from) of all device nodes. +
++ Allow full relabeling (to and from) of directories in /dev. +
++ Read and write the agp devices. +
++ Read and write the the cpu microcode device. This + is required to load cpu microcode. +
++ Read and write the dri devices. +
++ Read and write the lvm control device. +
++ Read and write to the null device (/dev/null). +
++ Read and write the the power management device. +
++ Read the realtime clock (/dev/rtc). +
++ Read and write the the scanner device. +
++ Read and write to the zero device (/dev/zero). +
++ Read, write, and execute the zero device (/dev/zero). +
++ Read and execute raw memory devices (e.g. /dev/mem). +
++ Setattr on all block file device nodes. +
++ Setattr on all character file device nodes. +
++ Write the framebuffer device. +
++ Write miscellaneous devices. +
++ Write the mtrr device. +
++ Write to the random device (e.g., /dev/random). This adds + entropy used to generate the random data read from the + random device. +
++ Write raw memory devices (e.g. /dev/mem). +
++ Read the realtime clock (/dev/rtc). +
++ Write the sound devices. +
++ Write the sound mixer devices. +
++ Write to the pseudo random device (e.g., /dev/urandom). This + sets the random number generator seed. +
++ Write and execute raw memory devices (e.g. /dev/mem). +
+Module: | Description: |
+ + bootloader | +Policy for the kernel modules, kernel image, and bootloader. |
+
+
+ + corenetwork | +Policy controlling access to network objects |
+
+
+ + devices | ++Device nodes and interfaces for many basic system devices. + |
+
+
+ + filesystem | +Policy for filesystems. |
+
+
+ + kernel | ++Policy for kernel threads, proc filesystem, +and unlabeled processes and objects. + |
+
+
+ + selinux | ++Policy for kernel security interface, in particular, selinuxfs. + |
+
+
+ + storage | +Policy controlling access to storage devices |
+
+
+ + terminal | +Policy for terminals. |
+
+
Policy for the kernel modules, kernel image, and bootloader.
+ ++ Install a kernel into the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Install a system.map into the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the bootloader + temporary data in /tmp. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Delete a kernel from /boot. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Delete a system.map in the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute bootloader in the bootloader domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to search the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ List the contents of the kernel module directories. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Create, read, write, and delete + kernel module files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read the bootloader configuration file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read kernel module files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read system.map in the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute bootloader interactively and do + a domain transition to the bootloader domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the bootloader domain. + + | +No + |
+terminal + | + + The type of the terminal allow the bootloader domain to use. + + | +No + |
+ Read and write symbolic links + in the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the bootloader + configuration file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the bootloader + temporary data in /tmp. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Search the /boot directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Write kernel module files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy controlling access to network objects
+ ++ Receive raw IP packets on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive raw IP packets on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send raw IP packets on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive raw IP packets on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node compat_ipv4. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node inaddr_any. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node link_local. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node lo. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node mapped_ipv4. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node multicast. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node site_local. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to node unspec. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind TCP sockets to the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the general interfaces. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP network traffic on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive TCP traffic on the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Bind UDP sockets to the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP network traffic on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Receive UDP traffic on the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP network traffic on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send UDP traffic on the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the compat_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the inaddr_any node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the link_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the lo node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the mapped_ipv4 node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the multicast node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the site_local node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the unspec node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the amanda port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the dbskkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the dhcpc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the dhcpd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the dict port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the dns port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the eth0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the eth1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the eth2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the fingerd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ftp_data port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the howl port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the http_cache port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the http port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the inetd_child port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the innd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ipp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the ippp0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the ipsec0 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the ipsec1 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the kerberos_admin port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the kerberos_master port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the kerberos port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ktalkd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ldap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP network traffic on the lo interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the mail port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the mysqld port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the nmbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the pop port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the portmap port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the postgresql port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the printer port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the pxe port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the radacct port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the radius port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the rsh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the rsync port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the smbd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the smtp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the snmp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the ssh port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the swat port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the syslogd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the telnetd port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the tftp port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the vnc port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the xserver port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send and receive UDP traffic on the zebra port. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+
+This module creates the device node concept and provides +the policy for many of the device files. Notable exceptions are +the mass storage and terminal devices that are covered by other +modules. +
+
+This module creates the concept of a device node. That is a +char or block device file, usually in /dev. All types that +are used to label device nodes should use the dev_node macro. +
+
+Additionally, this module controls access to three things: +
+
+ ++ Create, read, and write device nodes. The node + will be transitioned to the type provided. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+file + | + + Type to which the created node will be transitioned. + + | +No + |
+objectclass(es) + | + + Object class(es) (single or set including {}) for which this + the transition will occur. + + | +No + |
+ Create a directory in the device directory. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed to create the directory. + + | +No + |
+ Allow read, write, and create for generic character device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Delete symbolic links in device directories. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Delete the lvm control device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Dontaudit getattr on all block file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Dontaudit getattr on all character file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Dontaudit getattr on generic block devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Dontaudit getattr for generic character device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Dontaudit getattr on generic pipes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit. + + | +No + |
+ Dontaudit attempts to list all device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit listing of device nodes. + + | +No + |
+ Dontaudit read and write on the dri devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Dontaudit getattr for generic device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain to dontaudit access. + + | +No + |
+ Getattr the agp devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Getattr on all block file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Getattr on all character file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Allow getattr on generic block devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Allow getattr for generic character device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ List all of the device nodes in a device directory. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed to list device nodes. + + | +No + |
+ Allow caller to get a list of usb hardware. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type getting the list. + + | +No + |
+ Read, write, create, and delete all block device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read, write, create, and delete all character device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Create, delete, read, and write device nodes in device directories. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Allow read, write, create, and delete for generic + block files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Create, delete, read, and write block device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Create, delete, read, and write character device files. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Create, delete, read, and write symbolic links in device directories. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Make the passed in type a type appropriate for + use on device nodes (usually files in /dev). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+object_type + | + + The object type that will be used on device nodes. + + | +No + |
+ Read the multiplexed input device (/dev/input). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the framebuffer device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the multiplexed input device (/dev/input). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the lvm comtrol device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read miscellaneous devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the mouse devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the mtrr device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read from random devices (e.g., /dev/random) +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read raw memory devices (e.g. /dev/mem). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the realtime clock (/dev/rtc). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the sound devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the sound mixer devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Allow caller to read hardware state information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type reading hardware state information. + + | +No + |
+ Read from pseudo random devices (e.g., /dev/urandom) +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read USB hardware information using + the usbfs filesystem interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow full relabeling (to and from) of all device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed to relabel. + + | +No + |
+ Allow full relabeling (to and from) of directories in /dev. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed to relabel. + + | +No + |
+ Read and write the agp devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write the the cpu microcode device. This + is required to load cpu microcode. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write the dri devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write the lvm control device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write to the null device (/dev/null). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write the the power management device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the realtime clock (/dev/rtc). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and write the the scanner device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Allow caller to modify hardware state information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type modifying hardware state information. + + | +No + |
+ Allow caller to modify usb hardware configuration files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type modifying the options. + + | +No + |
+ Read and write to the zero device (/dev/zero). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read, write, and execute the zero device (/dev/zero). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read and execute raw memory devices (e.g. /dev/mem). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Search the directory containing hardware information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Search the directory containing USB hardware information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Setattr on all block file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Setattr on all character file device nodes. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write the framebuffer device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write miscellaneous devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write the mtrr device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write to the random device (e.g., /dev/random). This adds + entropy used to generate the random data read from the + random device. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write raw memory devices (e.g. /dev/mem). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Read the realtime clock (/dev/rtc). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write the sound devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write the sound mixer devices. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write to the pseudo random device (e.g., /dev/urandom). This + sets the random number generator seed. +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
+ Write and execute raw memory devices (e.g. /dev/mem). +
++ Send and receive raw IP packets on the ipsec2 interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Domain allowed access. + + | +No + |
Policy for filesystems.
+ ++ Associate the specified file type to persistent + filesystems with extended attributes. This + allows a file of this type to be created on + a filesystem such as ext3, JFS, and XFS. +
Parameter: | Description: | Optional: |
---|---|---|
+file_type + | + + The type of the to be associated. + + | +No + |
+ Associate the specified file type to + filesystems which lack extended attributes + support. This allows a file of this type + to be created on a filesystem such as + FAT32, and NFS. +
Parameter: | Description: | Optional: |
---|---|---|
+file_type + | + + The type of the to be associated. + + | +No + |
+ Allow the type to associate to tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+type + | + + The type of the object to be associated. + + | +No + |
+ Do not audit attempts to + get the attributes of a persistent + filesystem which has extended + attributes, such as ext3, JFS, or XFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain to not audit. + + | +No + |
+ Execute files on a CIFS or SMB + network filesystem, in the caller + domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain executing the files. + + | +No + |
+ Execute files on a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain executing the files. + + | +No + |
+ Get the quotas of all filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain getting quotas. + + | +No + |
+ Get the attributes of all persistent + filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of an automount + pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a CIFS or + SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a DOS + filesystem, such as FAT32 or NTFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a NFS server + pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a RAM filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a ROM + filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a RPC pipe + filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a tmpfs + filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Get the attributes of a persistent + filesystem which has extended + attributes, such as ext3, JFS, or XFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Transform specified type into a filesystem type. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Transform specified type into a filesystem + type which does not have extended attribute + support. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Create, read, write, and delete directories + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the directories. + + | +No + |
+ Create, read, write, and delete files + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the files. + + | +No + |
+ Create, read, write, and delete named pipes + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the pipes. + + | +No + |
+ Create, read, write, and delete named sockets + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the sockets. + + | +No + |
+ Create, read, write, and delete symbolic links + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the symbolic links. + + | +No + |
+ Create, read, write, and delete directories + on a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the directories. + + | +No + |
+ Create, read, write, and delete files + on a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the files. + + | +No + |
+ Create, read, write, and delete named pipes + on a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the pipes. + + | +No + |
+ Create, read, write, and delete named sockets + on a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the sockets. + + | +No + |
+ Create, read, write, and delete symbolic links + on a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain managing the symbolic links. + + | +No + |
+ Read and write, create and delete block nodes + on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write, create and delete character + nodes on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Mount all filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount an automount pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a DOS filesystem, such as + FAT32 or NTFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount an iso9660 filesystem, which + is usually used on CDs. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Get the attributes of an iso9660 + filesystem, which is usually used on CDs. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain doing the + getattr on the filesystem. + + | +No + |
+ Mount a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Unmount a NFS filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Mount a NFS server pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a RAM filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a ROM filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a RPC pipe filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a tmpfs filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Mount a persistent filesystem which + has extended attributes, such as + ext3, JFS, or XFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Register an interpreter for new binary + file types, using the kernel binfmt_misc + support. A common use for this is to + register a JVM as an interpreter for + Java byte code. Registered binaries + can be directly executed on a command line + without specifying the interpreter. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain registering + the interpreter. + + | +No + |
+ Relabel block nodes on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Relabel character nodes on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow changing of the label of a + DOS filesystem using the context= mount option. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Allow changing of the label of a + filesystem with extended attributes + using the context= mount option. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Remount all filesystems. This + allows some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Remount an automount pseudo filesystem + This allows some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a CIFS or SMB network filesystem. + This allows some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Remount a DOS filesystem, such as + FAT32 or NTFS. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount an iso9660 filesystem, which + is usually used on CDs. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a NFS filesystem. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Mount a NFS server pseudo filesystem. + This allows some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a RAM filesystem. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a ROM filesystem. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a RPC pipe filesystem. This + allows some mount option to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a tmpfs filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Remount a persistent filesystem which + has extended attributes, such as + ext3, JFS, or XFS. This allows + some mount options to be changed. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain remounting the filesystem. + + | +No + |
+ Set the quotas of all filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain setting quotas. + + | +No + |
+ Unmount all filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount an automount pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a CIFS or SMB network filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain mounting the filesystem. + + | +No + |
+ Unmount a DOS filesystem, such as + FAT32 or NTFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount an iso9660 filesystem, which + is usually used on CDs. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a NFS server pseudo filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a RAM filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a ROM filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a RPC pipe filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a tmpfs filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Unmount a persistent filesystem which + has extended attributes, such as + ext3, JFS, or XFS. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain unmounting the filesystem. + + | +No + |
+ Read and write block nodes on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write character nodes on tmpfs filesystems. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+Policy for kernel threads, proc filesystem, +and unlabeled processes and objects. +
+ ++ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ Allows the caller to clear the ring buffer. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type clearing the buffer. + + | +No + |
+ Do not audit attempts to get the attributes of + core kernel interfaces. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to not audit. + + | +No + |
+ Do not audit attempts by caller to get the attributes of kernel + message interfaces. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type not to audit. + + | +No + |
+ Do not audit attempts by caller to get attributes for + unlabeled block devices. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type not to audit. + + | +No + |
+ Do not audit attempts to read the ring buffer. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The domain to not audit. + + | +No + |
+ Do not audit attempts by caller to + read system state information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type not to audit. + + | +No + |
+ Do not audit attempts by caller to search sysctl network directories. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type not to audit. + + | +No + |
+ Do not audit attempts by caller to search the sysctl directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type not to audit. + + | +No + |
+ Do not audit attempts to use + kernel file descriptors. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of process not to audit. + + | +No + |
+ Get information on all System V IPC objects. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ Allows caller to get attribues of core kernel interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type getting the attibutes. + + | +No + |
+ Allow caller to get the attributes of kernel message + interface (/proc/kmsg). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type getting the attributes. + + | +No + |
+ Send a kill signal to unlabeled processes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allows caller to load kernel modules +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to allow to load kernel modules. + + | +No + |
+ Allow caller to read all sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to read the device sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to allow to read the device sysctls. + + | +No + |
+ Read filesystem sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read the hotplug sysctl. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read IRQ sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read generic kernel sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to read kernel messages + using the /proc/kmsg interface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type reading the messages. + + | +No + |
+ Read the modprobe sysctl. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to read network sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to read the network state information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type reading the state. + + | +No + |
+ Allows caller to read the ring buffer. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type allowed to read the ring buffer. + + | +No + |
+ Allow caller to read the state information for software raid. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type reading software raid state. + + | +No + |
+ Allows caller to read system state information. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type reading the system state information. + + | +No + |
+ Allow caller to read unix domain + socket sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to read virtual memory sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to relabel unlabeled objects. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type relabeling the objects. + + | +No + |
+ Allows the kernel to mount filesystems on + the specified directory type. +
Parameter: | Description: | Optional: |
---|---|---|
+directory_type + | + + The type of the directory to use as a mountpoint. + + | +No + |
+ Read and write all sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write device sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write fileystem sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the hotplug sysctl. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write IRQ sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write generic kernel sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the modprobe sysctl. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow caller to modiry contents of sysctl network files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write unix domain + socket sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write virtual memory sysctls. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allows the kernel to share state information with + the caller. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process with which to share state information. + + | +No + |
+ Send a child terminated signal to unlabeled processes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send general signals to unlabeled processes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send a null signal to unlabeled processes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send a stop signal to unlabeled processes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Permits caller to use kernel file descriptors. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process using the descriptors. + + | +No + |
+ Allows to start userland processes + by transitioning to the specified domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type entered by kernel. + + | +No + |
+entrypoint + | + + The executable type for the entrypoint. + + | +No + |
+Policy for kernel security interface, in particular, selinuxfs. +
+ ++ Allows caller to compute an access vector. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type allowed to compute an access vector. + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to + + | +No + |
+ Allows caller to compute possible contexts for a user. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type allowed to compute user contexts. + + | +No + |
+ Allows the caller to get the mode of policy enforcement + (enforcing or permissive mode). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to allow to get the enforcing mode. + + | +No + |
+ Gets the caller the mountpoint of the selinuxfs filesystem. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type requesting the selinuxfs mountpoint. + + | +No + |
+ Allow caller to load the policy into the kernel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type that will load the policy. + + | +No + |
+ Allow caller to set the state of Booleans to + enable or disable conditional portions of the policy. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type allowed to set the Boolean. + + | +No + |
+booltype + | + + The type of Booleans the caller is allowed to set. + + | +yes + |
+ Allow caller to set the mode of policy enforcement + (enforcing or permissive mode). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to allow to set the enforcement mode. + + | +No + |
+ Allow caller to set selinux security parameters. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to allow to set security parameters. + + | +No + |
+ Allows caller to validate security contexts. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type permitted to validate contexts. + + | +No + |
Policy controlling access to storage devices
+ ++ Create block devices in /dev with the fixed disk type. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts made by the caller to get + the attributes of fixed disk device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Do not audit attempts made by the caller to get + the attributes of removable devices device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Allow the caller to get the attributes of fixed disk + device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to get the attributes of removable + devices device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Get attributes of the device nodes + for the SCSI generic inerface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to get the attributes + of device nodes of tape devices. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Create, read, write, and delete fixed disk device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read from a fixed disk. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read from a logical volume. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read from + a removable device. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly write to a fixed disk. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read from a logical volume. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly write to + a removable device. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read, in a + generic fashion, from any SCSI device. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read + a tape device. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to set the attributes of fixed disk + device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to set the attributes of removable + devices device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Set attributes of the device nodes + for the SCSI generic inerface. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to set the attributes + of device nodes of tape devices. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly write, in a + generic fashion, from any SCSI device. + This is extremly dangerous as it can bypass the + SELinux protections for filesystem objects, and + should only be used by trusted domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to directly read + a tape device. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for terminals.
+ ++ Create a pty in the /dev/pts directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process creating the pty. + + | +No + |
+pty_type + | + + The type of the pty. + + | +No + |
+ Do not audit attempts to get the + attributes of any user tty + device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to read the + /dev/pts directory to. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Do not audit attempts to read any + user ptys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Do not audit attempts to read or write + any user ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attemtps to read from + or write to the console. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Dot not audit attempts to read and + write the generic pty type. This is + generally only used in the targeted policy. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Do not audit attempts to read and + write the pty multiplexor (/dev/ptmx). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Do not audit attempts to read or + write unallocated ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process to not audit. + + | +No + |
+ Get the attributes of all user + pty device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Get the attributes of all user tty + device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Get the attributes of all unallocated + tty device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read the /dev/pts directory to + list all ptys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Transform specified type into a pty type. +
Parameter: | Description: | Optional: |
---|---|---|
+pty_type + | + + An object type that will applied to a pty. + + | +No + |
+ Relabel from and to all user + user tty device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Relabel from and to the unallocated + tty type. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Relabel from all user tty types to + the unallocated tty type. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Set the attributes of all user tty + device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Set the attributes of the console + device node. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Set the attributes of all unallocated + tty device nodes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Transform specified type into a tty type. +
Parameter: | Description: | Optional: |
---|---|---|
+tty_type + | + + An object type that will applied to a tty. + + | +No + |
+ Read and write the console, all + ttys and all ptys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write all user ptys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write all user to all user ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read from and write to the console. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the controlling + terminal (/dev/tty). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write the generic pty + type. This is generally only used in + the targeted policy. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write unallocated ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Transform specified type into an user + pty type. This allows it to be relabeled via + type change by login programs such as ssh. +
Parameter: | Description: | Optional: |
---|---|---|
+userdomain + | + + The type of the user domain associated with + this pty. + + | +No + |
+object_type + | + + An object type that will applied to a pty. + + | +No + |
+ Write to all user ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Write to the console. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Write to unallocated ttys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Module: | Description: |
+ + mta | +Policy common to all email tranfer agents. |
+
+
+ + remotelogin | +Policy for rshd, rlogind, and telnetd. |
+
+
+ + sendmail | +Policy for sendmail. |
+
+
Policy common to all email tranfer agents.
+ ++ Read mail address aliases. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for rshd, rlogind, and telnetd.
+ ++ Domain transition to the remote login domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for sendmail.
+ ++ Domain transition to sendmail. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Module: | Description: |
+ + authlogin | +Common policy for authentication and user login. |
+
+
+ + clock | +Policy for reading and setting the hardware clock. |
+
+
+ + corecommands | ++Core policy for shells, and generic programs +in /bin, /sbin, /usr/bin, and /usr/sbin. + |
+
+
+ + domain | +Core policy for domains. |
+
+
+ + files | ++Basic filesystem types and interfaces. + |
+
+
+ + getty | +Policy for getty. |
+
+
+ + hostname | +Policy for changing the system host name. |
+
+
+ + hotplug | ++Policy for hotplug system, for supporting the +connection and disconnection of devices at runtime. + |
+
+
+ + init | +System initialization programs (init and init scripts). |
+
+
+ + iptables | +Policy for iptables. |
+
+
+ + libraries | +Policy for system libraries. |
+
+
+ + locallogin | +Policy for local logins. |
+
+
+ + logging | +Policy for the kernel message logger and system logging daemon. |
+
+
+ + lvm | +Policy for logical volume management programs. |
+
+
+ + miscfiles | +Miscelaneous files. |
+
+
+ + modutils | +Policy for kernel module utilities |
+
+
+ + mount | +Policy for mount. |
+
+
+ + selinuxutil | +Policy for SELinux policy and userland applications. |
+
+
+ + sysnetwork | +Policy for network configuration: ifconfig and dhcp client. |
+
+
+ + udev | +Policy for udev. |
+
+
+ + userdomain | +Policy for user domains |
+
+
Common policy for authentication and user login.
+ ++ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ Execute a login_program in the target domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+target_domain + | + + The type of the login_program process. + + | +No + |
+ Execute pam programs in the pam domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute utempter programs in the utempter domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ Manage all files on the filesystem, except + the shadow passwords and listed exceptions. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain perfoming this action. + + | +No + |
+exception_types + | + + The types to be excluded. Each type or attribute + must be negated by the caller. + + | +yes + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ Relabel all files on the filesystem, except + the shadow passwords and listed exceptions. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain perfoming this action. + + | +No + |
+exception_types + | + + The types to be excluded. Each type or attribute + must be negated by the caller. + + | +yes + |
+ Execute pam programs in the PAM domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to allow the PAM domain. + + | +No + |
+terminal + | + + The type of the terminal allow the PAM domain to use. + + | +No + |
+ Execute utempter programs in the utempter domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to allow the utempter domain. + + | +No + |
+terminal + | + + The type of the terminal allow the utempter domain to use. + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + + + | +No + |
+ +
Parameter: | Description: | Optional: |
---|---|---|
+userdomain_prefix + | + + + + | +No + |
Policy for reading and setting the hardware clock.
+ ++ Execute hwclock in the clock domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute hwclock +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute hwclock in the clock domain, and + allow the specified role the hwclock domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the clock domain. + + | +No + |
+terminal + | + + The type of the terminal allow the clock domain to use. + + | +No + |
+ Allow executing domain to modify clock drift +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+Core policy for shells, and generic programs +in /bin, /sbin, /usr/bin, and /usr/sbin. +
+ ++ Execute a shell in the target domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+target_domain + | + + The type of the shell process. + + | +No + |
+ Execute a shell in the target domain. This + is an explicit transition, requiring the + caller to use setexeccon(). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+target_domain + | + + The type of the shell process. + + | +No + |
Core policy for domains.
+ ++ Do not audit attempts to get the attributes + of all domains TCP sockets. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to get the attributes + of all domains UDP sockets. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to get the attributes + of all domains unix datagram sockets. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to get the attributes + of all domains unnamed pipes. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to read the process state + directories of all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Get the session ID of all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send a kill signal to all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Makes caller an exception to the constraint preventing + changing the user identity in object contexts. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to make an exception to the constraint. + + | +No + |
+ Read the process state (/proc/pid) of all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Makes caller an exception to the constraint preventing + changing of role. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to make an exception to the constraint. + + | +No + |
+ Send a child terminated signal to all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send general signals to all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send a null signal to all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send a stop signal to all domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Makes caller an exception to the constraint preventing + changing of user identity. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The process type to make an exception to the constraint. + + | +No + |
+
+ This module contains basic filesystem types and interfaces. This +includes: +
+
+ ++ Create an object in the root directory, with a private + type. If no object class is specified, the + default is file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+private type + | + + The type of the object to be created. If no type + is specified, the type of the root directory will + be used. + + | +yes + |
+object + | + + The object class of the object being created. If + no class is specified, file will be used. + + | +yes + |
+ Delete system configuration files in /etc. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to ioctl daemon runtime data files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to write to daemon runtime data files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute programs in /usr/src in the caller domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Get listing home home directories. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Manage all files on the filesystem, except + the listed exceptions. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain perfoming this action. + + | +No + |
+exception_types + | + + The types to be excluded. Each type or attribute + must be negated by the caller. + + | +yes + |
+ Relabel all files on the filesystem, except + the listed exceptions. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the domain perfoming this action. + + | +No + |
+exception_types + | + + The types to be excluded. Each type or attribute + must be negated by the caller. + + | +yes + |
+ Transform the type into a file, for use on a + virtual memory filesystem (tmpfs). +
Parameter: | Description: | Optional: |
---|---|---|
+type + | + + The type to be transformed. + + | +No + |
Policy for getty.
+ ++ Execute gettys in the getty domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow process to edit getty config file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow process to read getty config file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow process to read getty log file. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for changing the system host name.
+ ++ Execute hostname in the hostname domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + Has a sigchld signal backchannel. + + | +No + |
+ Execute hostname in the hostname domain, and + Has a sigchld signal backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute hostname in the hostname domain, and + allow the specified role the hostname domain. + Has a sigchld signal backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the hostname domain. + + | +No + |
+terminal + | + + The type of the terminal allow the hostname domain to use. + + | +No + |
+Policy for hotplug system, for supporting the +connection and disconnection of devices at runtime. +
+ ++ Read the configuration files for hotplug. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
System initialization programs (init and init scripts).
+ ++ Read the process state (/proc/pid) of the init scripts. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write init script temporary data. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for iptables.
+ ++ Execute iptables in the iptables domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute iptables in the caller domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute iptables in the iptables domain, and + allow the specified role the iptables domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the iptables domain. + + | +No + |
+terminal + | + + The type of the terminal allow the iptables domain to use. + + | +No + |
Policy for system libraries.
+ ++ Execute ldconfig in the ldconfig domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute the dynamic link/loader in the caller's + domain. This is commonly needed for the + /usr/bin/ldd program. Note: this can be used + to execute any binary that the caller can + read, even if the caller does not have execute + permissions. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute library scripts in the caller domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Use the dynamic link/loader for automatic loading + of shared libraries with legacy support. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Load and execute functions from shared libraries, + with legacy support. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read files in the library directories, such + as static libraries. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute ldconfig in the ldconfig domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to allow the ldconfig domain. + + | +No + |
+terminal + | + + The type of the terminal allow the ldconfig domain to use. + + | +No + |
+ Modify the dynamic link/loader's cached listing + of shared libraries. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Use the dynamic link/loader for automatic loading + of shared libraries. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Load and execute functions from shared libraries. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for local logins.
+ ++ Execute local logins in the locallogin domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow processes to inherit local login file descriptors +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for the kernel message logger and system logging daemon.
+ ++ Allows the domain to open a file in the + log directory, but does not allow the listing + of the contents of the log directory. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for logical volume management programs.
+ ++ Execute lvm programs in the lvm domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read LVM configuration files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute lvm programs in the lvm domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to allow the LVM domain. + + | +No + |
+terminal + | + + The type of the terminal allow the LVM domain to use. + + | +No + |
Miscelaneous files.
+ ++ Allow process to read legacy time localization info +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Type type of the process performing this action. + + | +No + |
+ Allow process to read fonts files +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Type type of the process performing this action. + + | +No + |
+ Allow process to read localization info +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Type type of the process performing this action. + + | +No + |
+ Allow process to read manpages +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Type type of the process performing this action. + + | +No + |
+ Allow process to create files and dirs in /var/cache/man + and /var/catman/ +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + Type type of the process performing this action. + + | +No + |
Policy for kernel module utilities
+ ++ Execute depmod in the depmod domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute insmod in the insmod domain. Has a + sigchld backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute depmod in the depmod domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read the dependencies of kernel modules. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read the configuration options used when + loading modules. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute depmod in the depmod domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the depmod domain. + + | +No + |
+terminal + | + + The type of the terminal allow the depmod domain to use. + + | +No + |
+ Execute insmod in the insmod domain, and + allow the specified role the insmod domain, + and use the caller's terminal. Has a sigchld + backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the insmod domain. + + | +No + |
+terminal + | + + The type of the terminal allow the insmod domain to use. + + | +No + |
+ Execute update_modules in the update_modules domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the update_modules domain. + + | +No + |
+terminal + | + + The type of the terminal allow the update_modules domain to use. + + | +No + |
Policy for mount.
+ ++ Execute mount in the mount domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute mount in the mount domain, and + allow the specified role the mount domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the mount domain. + + | +No + |
+terminal + | + + The type of the terminal allow the mount domain to use. + + | +No + |
+ Allow the mount domain to send nfs requests for mounting + network drives +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Use file descriptors for mount. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for SELinux policy and userland applications.
+ ++ Execute checkpolicy in the checkpolicy domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute load_policy in the load_policy domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute newrole in the load_policy domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute restorecon in the restorecon domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute run_init in the run_init domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute setfiles in the setfiles domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit the caller attempts to send + a signal to newrole. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow the caller to relabel a file to the binary policy type. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute checkpolicy in the checkpolicy domain, and + allow the specified role the checkpolicy domain, + and use the caller's terminal. + Has a SIGCHLD signal backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the checkpolicy domain. + + | +No + |
+terminal + | + + The type of the terminal allow the checkpolicy domain to use. + + | +No + |
+ Execute load_policy in the load_policy domain, and + allow the specified role the load_policy domain, + and use the caller's terminal. + Has a SIGCHLD signal backchannel. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the load_policy domain. + + | +No + |
+terminal + | + + The type of the terminal allow the load_policy domain to use. + + | +No + |
+ Execute newrole in the newrole domain, and + allow the specified role the newrole domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the newrole domain. + + | +No + |
+terminal + | + + The type of the terminal allow the newrole domain to use. + + | +No + |
+ Execute restorecon in the restorecon domain, and + allow the specified role the restorecon domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the restorecon domain. + + | +No + |
+terminal + | + + The type of the terminal allow the restorecon domain to use. + + | +No + |
+ Execute run_init in the run_init domain, and + allow the specified role the run_init domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the run_init domain. + + | +No + |
+terminal + | + + The type of the terminal allow the run_init domain to use. + + | +No + |
+ Execute setfiles in the setfiles domain, and + allow the specified role the setfiles domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the setfiles domain. + + | +No + |
+terminal + | + + The type of the terminal allow the setfiles domain to use. + + | +No + |
Policy for network configuration: ifconfig and dhcp client.
+ ++ Execute dhcp client in dhcpc domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute ifconfig in the ifconfig domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow network init to read network config files. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute ifconfig in the ifconfig domain, and + allow the specified role the ifconfig domain, + and use the caller's terminal. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+role + | + + The role to be allowed the ifconfig domain. + + | +No + |
+terminal + | + + The type of the terminal allow the ifconfig domain to use. + + | +No + |
Policy for udev.
+ ++ Execute udev in the udev domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow process to read list of devices. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Allow process to modify list of devices. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
Policy for user domains
+ ++ Do not audit attempts to use admin ttys and ptys. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Do not audit attempts to inherit the + file descriptors from all user domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read all files in all users home directories. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Search all users home directories. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute a shell in the sysadm domain. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Send general signals to all user domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Execute a shell in all user domains. This + is an explicit transition, requiring the + caller to use setexeccon(). +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Inherit the file descriptors from all user domains +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Read and write administrative users + physical and pseudo terminals. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |
+ Inherit the file descriptors from all user domains. +
Parameter: | Description: | Optional: |
---|---|---|
+domain + | + + The type of the process performing this action. + + | +No + |