From 885e753682c881a0fdd47c6bd922ee9cafa73e12 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Wed, 7 Dec 2005 15:46:38 +0000 Subject: [PATCH] update for release --- www/api-docs/admin.html | 8 + www/api-docs/admin_acct.html | 3 + www/api-docs/admin_amanda.html | 335 + www/api-docs/admin_anaconda.html | 3 + www/api-docs/admin_consoletype.html | 3 + www/api-docs/admin_dmesg.html | 3 + www/api-docs/admin_dmidecode.html | 3 + www/api-docs/admin_firstboot.html | 3 + www/api-docs/admin_kudzu.html | 3 + www/api-docs/admin_logrotate.html | 3 + www/api-docs/admin_netutils.html | 3 + www/api-docs/admin_quota.html | 3 + www/api-docs/admin_rpm.html | 46 + www/api-docs/admin_su.html | 45 + www/api-docs/admin_sudo.html | 3 + www/api-docs/admin_tmpreaper.html | 3 + www/api-docs/admin_updfstab.html | 3 + www/api-docs/admin_usermanage.html | 83 + www/api-docs/admin_vpn.html | 3 + www/api-docs/global_booleans.html | 108 +- www/api-docs/global_tunables.html | 206 +- www/api-docs/index.html | 234 +- www/api-docs/interfaces.html | 8388 +++++++++++++++-- www/api-docs/kernel.html | 29 + www/api-docs/kernel_bootloader.html | 9 + ...commands.html => kernel_corecommands.html} | 281 +- www/api-docs/kernel_corenetwork.html | 1565 +++ www/api-docs/kernel_devices.html | 278 +- ...{system_domain.html => kernel_domain.html} | 502 +- .../{system_files.html => kernel_files.html} | 825 +- www/api-docs/kernel_filesystem.html | 695 +- www/api-docs/kernel_kernel.html | 685 +- www/api-docs/kernel_mls.html | 9 + www/api-docs/kernel_selinux.html | 74 +- www/api-docs/kernel_storage.html | 52 +- www/api-docs/kernel_terminal.html | 69 +- www/api-docs/services.html | 168 + www/api-docs/services_apache.html | 148 + www/api-docs/services_apm.html | 105 + www/api-docs/services_arpwatch.html | 105 + www/api-docs/services_avahi.html | 329 + www/api-docs/services_bind.html | 148 + www/api-docs/services_bluetooth.html | 275 +- www/api-docs/services_canna.html | 328 + www/api-docs/services_comsat.html | 63 + www/api-docs/services_cpucontrol.html | 63 + www/api-docs/services_cron.html | 234 +- www/api-docs/services_cups.html | 625 ++ www/api-docs/services_cvs.html | 63 + www/api-docs/services_cyrus.html | 329 + www/api-docs/services_dbskk.html | 282 + www/api-docs/services_dbus.html | 109 + www/api-docs/services_dhcp.html | 63 + www/api-docs/services_dictd.html | 63 + www/api-docs/services_distcc.html | 282 + www/api-docs/services_dovecot.html | 328 + www/api-docs/services_finger.html | 63 + www/api-docs/services_ftp.html | 129 + www/api-docs/services_gpm.html | 63 + www/api-docs/services_hal.html | 282 +- www/api-docs/services_howl.html | 111 +- www/api-docs/services_i18n_input.html | 328 + www/api-docs/services_inetd.html | 105 + www/api-docs/services_inn.html | 63 + www/api-docs/services_irqbalance.html | 282 + www/api-docs/services_kerberos.html | 63 + www/api-docs/services_ktalk.html | 63 + www/api-docs/services_ldap.html | 63 + www/api-docs/services_lpd.html | 533 ++ www/api-docs/services_mailman.html | 63 + www/api-docs/services_mta.html | 393 + www/api-docs/services_mysql.html | 63 + www/api-docs/services_networkmanager.html | 456 + www/api-docs/services_nis.html | 275 +- www/api-docs/services_nscd.html | 63 + www/api-docs/services_ntp.html | 63 + www/api-docs/services_pegasus.html | 282 + www/api-docs/services_portmap.html | 147 + www/api-docs/services_postfix.html | 1099 +++ www/api-docs/services_postgresql.html | 63 + www/api-docs/services_ppp.html | 110 +- www/api-docs/services_privoxy.html | 63 + www/api-docs/services_procmail.html | 370 + www/api-docs/services_radius.html | 328 + www/api-docs/services_radvd.html | 63 + www/api-docs/services_rdisc.html | 282 + www/api-docs/services_remotelogin.html | 63 + www/api-docs/services_rlogin.html | 63 + www/api-docs/services_rpc.html | 767 ++ www/api-docs/services_rshd.html | 63 + www/api-docs/services_rsync.html | 63 + www/api-docs/services_samba.html | 233 +- www/api-docs/services_sasl.html | 111 +- www/api-docs/services_sendmail.html | 191 +- www/api-docs/services_snmp.html | 111 +- www/api-docs/services_spamassassin.html | 472 + www/api-docs/services_squid.html | 147 + www/api-docs/services_ssh.html | 63 + www/api-docs/services_stunnel.html | 63 + www/api-docs/services_tcpd.html | 63 + www/api-docs/services_telnet.html | 63 + www/api-docs/services_tftp.html | 63 + www/api-docs/services_timidity.html | 282 + www/api-docs/services_uucp.html | 63 + www/api-docs/services_xdm.html | 282 + www/api-docs/services_xfs.html | 328 + www/api-docs/services_zebra.html | 63 + www/api-docs/system.html | 29 - www/api-docs/system_authlogin.html | 344 +- www/api-docs/system_clock.html | 9 - www/api-docs/system_fstools.html | 9 - www/api-docs/system_getty.html | 9 - www/api-docs/system_hostname.html | 9 - www/api-docs/system_hotplug.html | 9 - www/api-docs/system_init.html | 453 +- www/api-docs/system_ipsec.html | 9 - www/api-docs/system_iptables.html | 9 - www/api-docs/system_libraries.html | 52 +- www/api-docs/system_locallogin.html | 9 - www/api-docs/system_logging.html | 51 +- www/api-docs/system_lvm.html | 9 - www/api-docs/system_miscfiles.html | 93 +- www/api-docs/system_modutils.html | 51 +- www/api-docs/system_mount.html | 9 - www/api-docs/system_pcmcia.html | 55 +- www/api-docs/system_raid.html | 9 - www/api-docs/system_selinuxutil.html | 9 - www/api-docs/system_sysnetwork.html | 94 +- www/api-docs/system_udev.html | 51 +- www/api-docs/system_unconfined.html | 195 +- www/api-docs/system_userdomain.html | 1084 ++- www/api-docs/templates.html | 489 +- 132 files changed, 29796 insertions(+), 1979 deletions(-) create mode 100644 www/api-docs/admin_amanda.html rename www/api-docs/{system_corecommands.html => kernel_corecommands.html} (84%) rename www/api-docs/{system_domain.html => kernel_domain.html} (88%) rename www/api-docs/{system_files.html => kernel_files.html} (90%) create mode 100644 www/api-docs/services_avahi.html create mode 100644 www/api-docs/services_canna.html create mode 100644 www/api-docs/services_cups.html create mode 100644 www/api-docs/services_cyrus.html create mode 100644 www/api-docs/services_dbskk.html create mode 100644 www/api-docs/services_distcc.html create mode 100644 www/api-docs/services_dovecot.html create mode 100644 www/api-docs/services_i18n_input.html create mode 100644 www/api-docs/services_irqbalance.html create mode 100644 www/api-docs/services_lpd.html create mode 100644 www/api-docs/services_networkmanager.html create mode 100644 www/api-docs/services_pegasus.html create mode 100644 www/api-docs/services_postfix.html create mode 100644 www/api-docs/services_procmail.html create mode 100644 www/api-docs/services_radius.html create mode 100644 www/api-docs/services_rdisc.html create mode 100644 www/api-docs/services_rpc.html create mode 100644 www/api-docs/services_spamassassin.html create mode 100644 www/api-docs/services_timidity.html create mode 100644 www/api-docs/services_xdm.html create mode 100644 www/api-docs/services_xfs.html diff --git a/www/api-docs/admin.html b/www/api-docs/admin.html index 7d129659..32da35d1 100644 --- a/www/api-docs/admin.html +++ b/www/api-docs/admin.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -120,6 +123,11 @@ acct

Berkeley process accounting

+ + + amanda +

Automated backup program.

+ anaconda diff --git a/www/api-docs/admin_acct.html b/www/api-docs/admin_acct.html index 30672e1e..8f2a542f 100644 --- a/www/api-docs/admin_acct.html +++ b/www/api-docs/admin_acct.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_amanda.html b/www/api-docs/admin_amanda.html new file mode 100644 index 00000000..cf9d616e --- /dev/null +++ b/www/api-docs/admin_amanda.html @@ -0,0 +1,335 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: admin

+

Module: amanda

+ +

Description:

+ +

Automated backup program.

+ + + + +

Interfaces:

+ + +
+ + +
+ +amanda_domtrans_recover( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute amrecover in the amanda_recover domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +amanda_dontaudit_read_dumpdates( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read /etc/dumpdates. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +amanda_run_recover( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+
+ +
Summary
+

+Execute amrecover in the amanda_recover domain, and +allow the specified role the amanda_recover domain. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+role + + +The role to be allowed the amanda_recover domain. + + +No +
+terminal + + +The type of the terminal allow the amanda_recover domain to use. + + +No +
+
+
+ + +
+ + +
+ +amanda_search_lib( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search amanda library directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/admin_anaconda.html b/www/api-docs/admin_anaconda.html index 55b58ae0..9c552966 100644 --- a/www/api-docs/admin_anaconda.html +++ b/www/api-docs/admin_anaconda.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_consoletype.html b/www/api-docs/admin_consoletype.html index dbf7c29a..bad02cd3 100644 --- a/www/api-docs/admin_consoletype.html +++ b/www/api-docs/admin_consoletype.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_dmesg.html b/www/api-docs/admin_dmesg.html index 0da57528..40926f3a 100644 --- a/www/api-docs/admin_dmesg.html +++ b/www/api-docs/admin_dmesg.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_dmidecode.html b/www/api-docs/admin_dmidecode.html index b2cfacd9..898c5add 100644 --- a/www/api-docs/admin_dmidecode.html +++ b/www/api-docs/admin_dmidecode.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_firstboot.html b/www/api-docs/admin_firstboot.html index 93e2019e..a7b03729 100644 --- a/www/api-docs/admin_firstboot.html +++ b/www/api-docs/admin_firstboot.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_kudzu.html b/www/api-docs/admin_kudzu.html index 70fa9373..846d2c4d 100644 --- a/www/api-docs/admin_kudzu.html +++ b/www/api-docs/admin_kudzu.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_logrotate.html b/www/api-docs/admin_logrotate.html index d22f285c..04574b24 100644 --- a/www/api-docs/admin_logrotate.html +++ b/www/api-docs/admin_logrotate.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_netutils.html b/www/api-docs/admin_netutils.html index 21a44f40..09d1d90a 100644 --- a/www/api-docs/admin_netutils.html +++ b/www/api-docs/admin_netutils.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_quota.html b/www/api-docs/admin_quota.html index 863c9f7f..70d4e6c3 100644 --- a/www/api-docs/admin_quota.html +++ b/www/api-docs/admin_quota.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_rpm.html b/www/api-docs/admin_rpm.html index 928b2572..c2695b33 100644 --- a/www/api-docs/admin_rpm.html +++ b/www/api-docs/admin_rpm.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -158,6 +161,49 @@ No + +
+ + +
+ +rpm_dontaudit_manage_db( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to create, read, +write, and delete the RPM package database. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
diff --git a/www/api-docs/admin_su.html b/www/api-docs/admin_su.html index d645e0f8..30288813 100644 --- a/www/api-docs/admin_su.html +++ b/www/api-docs/admin_su.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -261,6 +264,48 @@ No
+ +
+ + +
+ +su_restricted_domain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ Return diff --git a/www/api-docs/admin_sudo.html b/www/api-docs/admin_sudo.html index 77d87d9a..83b6769b 100644 --- a/www/api-docs/admin_sudo.html +++ b/www/api-docs/admin_sudo.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_tmpreaper.html b/www/api-docs/admin_tmpreaper.html index dc8753ed..27645cfd 100644 --- a/www/api-docs/admin_tmpreaper.html +++ b/www/api-docs/admin_tmpreaper.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_updfstab.html b/www/api-docs/admin_updfstab.html index 249da55c..aa1bd3b1 100644 --- a/www/api-docs/admin_updfstab.html +++ b/www/api-docs/admin_updfstab.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/admin_usermanage.html b/www/api-docs/admin_usermanage.html index 89fa6df5..c6134251 100644 --- a/www/api-docs/admin_usermanage.html +++ b/www/api-docs/admin_usermanage.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -369,6 +372,86 @@ No + +
+ + +
+ +usermanage_run_admin_passwd( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+
+ +
Summary
+

+Execute passwd admin functions in the admin +passwd domain, and allow the specified role +the admin passwd domain. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+role + + +The role to be allowed the admin passwd domain. + + +No +
+terminal + + +The type of the terminal allow the admin passwd domain to use. + + +No +
+
+
+
diff --git a/www/api-docs/admin_vpn.html b/www/api-docs/admin_vpn.html index 5276de74..67af56e4 100644 --- a/www/api-docs/admin_vpn.html +++ b/www/api-docs/admin_vpn.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
diff --git a/www/api-docs/global_booleans.html b/www/api-docs/global_booleans.html index 3ae081e7..78bfbdc0 100644 --- a/www/api-docs/global_booleans.html +++ b/www/api-docs/global_booleans.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -88,12 +91,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -127,12 +139,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -142,9 +160,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -154,6 +181,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -169,12 +202,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -184,6 +223,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -193,6 +235,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -202,9 +247,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -214,15 +265,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -241,6 +304,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -259,9 +325,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -277,15 +352,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -379,6 +445,30 @@ Enabling secure mode disallows programs, such asnewrole, from transitioning to a
+
+
secure_mode_insmod
+
+
Default value
+

false

+ +
Description
+

+Disable transitions to insmod.

+ +
+ +
+
secure_mode_policyload
+
+
Default value
+

false

+ +
Description
+

+boolean to determine whether the system permits loading policy, settingenforcing mode, and changing boolean values. Set this to true and youhave to reboot to set it back

+ +
+ diff --git a/www/api-docs/global_tunables.html b/www/api-docs/global_tunables.html index 64e2fc36..a4184934 100644 --- a/www/api-docs/global_tunables.html +++ b/www/api-docs/global_tunables.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -88,12 +91,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -127,12 +139,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -142,9 +160,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -154,6 +181,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -169,12 +202,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -184,6 +223,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -193,6 +235,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -202,9 +247,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -214,15 +265,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -241,6 +304,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -259,9 +325,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -277,15 +352,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -427,6 +493,18 @@ Allow gpg executable stack

+
+
allow_gssd_read_tmp
+
+
Default value
+

true

+ +
Description
+

+Allow gssd to read temp directory.

+ +
+
allow_httpd_anon_write
@@ -463,6 +541,18 @@ Allow sysadm to ptrace all processes

+
+
allow_rsync_anon_write
+
+
Default value
+

false

+ +
Description
+

+Allow rsync to modify public filesused for public file transfer services.

+ +
+
allow_saslauthd_read_shadow
@@ -475,6 +565,18 @@ Allow sasl to read shadow

+
+
allow_smbd_anon_write
+
+
Default value
+

false

+ +
Description
+

+Allow samba to modify public filesused for public file transfer services.

+ +
+
allow_ssh_keysign
@@ -595,6 +697,18 @@ Allow httpd cgi support

+
+
httpd_enable_ftp_server
+
+
Default value
+

false

+ +
Description
+

+Allow httpd to act as a FTP server bylistening on the ftp port.

+ +
+
httpd_enable_homedirs
@@ -655,6 +769,30 @@ Allow BIND to write the master zone files.Generally this is used for dynamic DNS
+
+
nfs_export_all_ro
+
+
Default value
+

false

+ +
Description
+

+Allow nfs to be exported read only

+ +
+ +
+
nfs_export_all_rw
+
+
Default value
+

false

+ +
Description
+

+Allow nfs to be exported read/write.

+ +
+
pppd_can_insmod
@@ -715,6 +853,42 @@ Allow ssh to run from inetd instead of as a daemon.

+
+
samba_enable_home_dirs
+
+
Default value
+

false

+ +
Description
+

+Allow samba to export user home directories.

+ +
+ +
+
spamassasin_can_network
+
+
Default value
+

false

+ +
Description
+

+Allow spamassassin to do DNS lookups

+ +
+ +
+
spamassassin_can_network
+
+
Default value
+

false

+ +
Description
+

+Allow user spamassassin clients to use the network.

+ +
+
squid_connect_any
@@ -751,6 +925,18 @@ Allow staff_r users to search the sysadm homedir and read files (such as ~/.bash
+
+
stunnel_is_daemon
+
+
Default value
+

false

+ +
Description
+

+Configure stunnel to be a standalone daemon orinetd service.

+ +
+
use_nfs_home_dirs
@@ -831,7 +1017,7 @@ Control users use of ping and traceroute

Description

-Allow user to r/w noextattrfile (FAT, CDROM, FLOPPY)

+Allow user to r/w files on filesystemsthat do not have extended attributes (FAT, CDROM, FLOPPY)

diff --git a/www/api-docs/index.html b/www/api-docs/index.html index 81c93634..f88b88ac 100644 --- a/www/api-docs/index.html +++ b/www/api-docs/index.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -88,12 +91,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -127,12 +139,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -142,9 +160,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -154,6 +181,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -169,12 +202,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -184,6 +223,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -193,6 +235,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -202,9 +247,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -214,15 +265,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -241,6 +304,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -259,9 +325,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -277,15 +352,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -381,6 +447,11 @@ acct

Berkeley process accounting

+ + + amanda +

Automated backup program.

+ anaconda @@ -505,6 +576,14 @@ Policy for kernel threads, proc filesystem,and unlabeled processes and objects. bootloader

Policy for the kernel modules, kernel image, and bootloader.

+ + + corecommands +

+Core policy for shells, and generic programs +in /bin, /sbin, /usr/bin, and /usr/sbin. +

+ corenetwork @@ -515,6 +594,18 @@ Policy for kernel threads, proc filesystem,and unlabeled processes and objects. devices

Device nodes and interfaces for many basic system devices. +

+ + + + domain +

Core policy for domains.

+ + + + files +

+Basic filesystem types and interfaces.

@@ -636,26 +727,6 @@ Policy for kernel security interface, in particular, selinuxfs. clock

Policy for reading and setting the hardware clock.

- - - corecommands -

-Core policy for shells, and generic programs -in /bin, /sbin, /usr/bin, and /usr/sbin. -

- - - - domain -

Core policy for domains.

- - - - files -

-Basic filesystem types and interfaces. -

- fstools @@ -805,6 +876,11 @@ connection and disconnection of devices at runtime. arpwatch

Ethernet activity monitor.

+ + + avahi +

mDNS/DNS-SD daemon implementing Apple ZeroConf architecture

+ bind @@ -815,6 +891,11 @@ connection and disconnection of devices at runtime. bluetooth

Bluetooth tools and system services.

+ + + canna +

Canna - kana-kanji conversion server

+ comsat @@ -830,11 +911,26 @@ connection and disconnection of devices at runtime. cron

Periodic execution of scheduled commands.

+ + + cups +

Common UNIX printing system

+ cvs

Concurrent versions system

+ + + cyrus +

Cyrus is an IMAP service intended to be run on sealed servers

+ + + + dbskk +

Dictionary server for the SKK Japanese input method system.

+ dbus @@ -850,6 +946,16 @@ connection and disconnection of devices at runtime. dictd

Dictionary daemon

+ + + distcc +

Distributed compiler daemon

+ + + + dovecot +

Dovecot POP and IMAP mail server

+ finger @@ -875,6 +981,11 @@ connection and disconnection of devices at runtime. howl

Port of Apple Rendezvous multicast DNS

+ + + i18n_input +

IIIMF htt server

+ inetd @@ -885,6 +996,11 @@ connection and disconnection of devices at runtime. inn

Internet News NNTP server

+ + + irqbalance +

IRQ balancing daemon

+ kerberos @@ -900,6 +1016,11 @@ connection and disconnection of devices at runtime. ldap

OpenLDAP directory server

+ + + lpd +

Line printer daemon

+ mailman @@ -915,6 +1036,11 @@ connection and disconnection of devices at runtime. mysql

Policy for MySQL

+ + + networkmanager +

Manager for dynamically switching between networks.

+ nis @@ -930,11 +1056,21 @@ connection and disconnection of devices at runtime. ntp

Network time protocol daemon

+ + + pegasus +

The Open Group Pegasus CIM/WBEM Server.

+ portmap

RPC port mapping service.

+ + + postfix +

Postfix email server

+ postgresql @@ -950,11 +1086,26 @@ connection and disconnection of devices at runtime. privoxy

Privacy enhancing web proxy.

+ + + procmail +

Procmail mail delivery agent

+ + + + radius +

RADIUS authentication and accounting server.

+ radvd

IPv6 router advertisement daemon

+ + + rdisc +

Network router discovery daemon

+ remotelogin @@ -965,6 +1116,11 @@ connection and disconnection of devices at runtime. rlogin

Remote login daemon

+ + + rpc +

Remote Procedure Call Daemon for managment of network based process communication

+ rshd @@ -999,6 +1155,11 @@ from Windows NT servers. snmp

Simple network management protocol services

+ + + spamassassin +

Filter used for removing unsolicited email.

+ squid @@ -1029,11 +1190,26 @@ from Windows NT servers. tftp

Trivial file transfer protocol daemon

+ + + timidity +

MIDI to WAV converter and player configured as a service

+ uucp

Unix to Unix Copy

+ + + xdm +

X windows login display manager

+ + + + xfs +

X Windows Font Server

+ zebra diff --git a/www/api-docs/interfaces.html b/www/api-docs/interfaces.html index ea502ad5..05bc8845 100644 --- a/www/api-docs/interfaces.html +++ b/www/api-docs/interfaces.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -88,12 +91,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -127,12 +139,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -142,9 +160,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -154,6 +181,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -169,12 +202,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -184,6 +223,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -193,6 +235,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -202,9 +247,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -214,15 +265,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -241,6 +304,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -259,9 +325,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -277,15 +352,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -471,6 +537,127 @@ Create, read, write, and delete process accounting data. +
+Module: +amanda

+Layer: +admin

+

+ +amanda_domtrans_recover( + + + + + domain + + + )
+
+ +
+

+Execute amrecover in the amanda_recover domain. +

+
+ +
+ +
+Module: +amanda

+Layer: +admin

+

+ +amanda_dontaudit_read_dumpdates( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read /etc/dumpdates. +

+
+ +
+ +
+Module: +amanda

+Layer: +admin

+

+ +amanda_run_recover( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+ +
+

+Execute amrecover in the amanda_recover domain, and +allow the specified role the amanda_recover domain. +

+
+ +
+ +
+Module: +amanda

+Layer: +admin

+

+ +amanda_search_lib( + + + + + domain + + + )
+
+ +
+

+Search amanda library directories. +

+
+ +
+
Module: apache

@@ -713,6 +900,33 @@ TCP sockets.

+
+Module: +apache

+Layer: +services

+

+ +apache_dontaudit_search_modules( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to search Apache +module directories. +

+
+ +
+
Module: apache

@@ -929,6 +1143,32 @@ specified role the dmidecode domain.

+
+Module: +apache

+Layer: +services

+

+ +apache_search_sys_script_state( + + + + + domain + + + )
+
+ +
+

+Search system script state directory. +

+
+ +
+
Module: apache

@@ -1085,6 +1325,32 @@ Read and write to an apm unix stream socket.

+
+Module: +apm

+Layer: +services

+

+ +apm_stream_connect( + + + + + domain + + + )
+
+ +
+

+Connect to apmd over an unix stream socket. +

+
+ +
+
Module: apm

@@ -1190,6 +1456,32 @@ Create arpwatch data files.

+
+Module: +arpwatch

+Layer: +services

+

+ +arpwatch_manage_tmp_files( + + + + + domain + + + )
+
+ +
+

+Read and write arpwatch temporary files. +

+
+ +
+
Module: arpwatch

@@ -1563,6 +1855,32 @@ of the shadow passwords file.

+
+Module: +authlogin

+Layer: +system

+

+ +auth_dontaudit_read_pam_pid( + + + + + domain + + + )
+
+ +
+

+Do not audit attemps to read PAM pid files. +

+
+ +
+
Module: authlogin

@@ -1837,6 +2155,123 @@ Summary is missing!

+
+Module: +authlogin

+Layer: +system

+

+ +auth_read_all_dirs_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all directories on the filesystem, except +the shadow passwords and listed exceptions. +

+
+ +
+ +
+Module: +authlogin

+Layer: +system

+

+ +auth_read_all_files_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all files on the filesystem, except +the shadow passwords and listed exceptions. +

+
+ +
+ +
+Module: +authlogin

+Layer: +system

+

+ +auth_read_all_symlinks_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all symbolic links on the filesystem, except +the shadow passwords and listed exceptions. +

+
+ +
+
Module: authlogin

@@ -2006,6 +2441,33 @@ the shadow passwords and listed exceptions.

+
+Module: +authlogin

+Layer: +system

+

+ +auth_relabel_shadow( + + + + + domain + + + )
+
+ +
+

+Relabel from and to the shadow +password file type. +

+
+ +
+
Module: authlogin

@@ -2018,7 +2480,7 @@ system

- ? + domain )
@@ -2026,7 +2488,8 @@ system

-Summary is missing! +Relabel to the shadow +password file type.

@@ -2220,6 +2683,33 @@ Read and write the shadow password file (/etc/shadow).
+
+Module: +authlogin

+Layer: +system

+

+ +auth_search_pam_console_data( + + + + + domain + + + )
+
+ +
+

+Search the contents of the +pam_console data directory. +

+
+ +
+
Module: authlogin

@@ -2298,6 +2788,33 @@ Write to login records (wtmp).

+
+Module: +avahi

+Layer: +services

+

+ +avahi_dbus_chat( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +avahi over dbus. +

+
+ +
+
Module: bind

@@ -2350,6 +2867,33 @@ Execute ndc in the ndc domain.

+
+Module: +bind

+Layer: +services

+

+ +bind_manage_cache( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete +BIND cache files. +

+
+ +
+
Module: bind

@@ -2499,6 +3043,32 @@ of the BIND pid directory.

+
+Module: +bind

+Layer: +services

+

+ +bind_signal( + + + + + domain + + + )
+
+ +
+

+Send generic signals to BIND. +

+
+ +
+
Module: bind

@@ -2525,6 +3095,128 @@ Write BIND named configuration files.

+
+Module: +bluetooth

+Layer: +services

+

+ +bluetooth_dbus_chat( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +bluetooth over dbus. +

+
+ +
+ +
+Module: +bluetooth

+Layer: +services

+

+ +bluetooth_domtrans_helper( + + + + + domain + + + )
+
+ +
+

+Execute bluetooth_helper in the bluetooth_helper domain. +

+
+ +
+ +
+Module: +bluetooth

+Layer: +services

+

+ +bluetooth_dontaudit_read_helper_files( + + + + + domain + + + )
+
+ +
+

+Read bluetooth helper files. +

+
+ +
+ +
+Module: +bluetooth

+Layer: +services

+

+ +bluetooth_run_helper( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+ +
+

+Execute bluetooth_helper in the bluetooth_helper domain, and +allow the specified role the bluetooth_helper domain. +

+
+ +
+
Module: bootloader

@@ -3120,6 +3812,32 @@ Write kernel module files.

+
+Module: +canna

+Layer: +services

+

+ +canna_stream_connect( + + + + + domain + + + )
+
+ +
+

+Connect to Canna using a unix domain stream socket. +

+
+ +
+
Module: clock

@@ -3294,10 +4012,36 @@ Execute consoletype in the caller domain.

-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

+

+ +corecmd_bin_alias( + + + + + domain + + + )
+
+ +
+

+Create a aliased type to generic bin files. +

+
+ +
+ +
+Module: +corecommands

+Layer: +kernel

corecmd_bin_domtrans( @@ -3329,10 +4073,36 @@ in the specified domain.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

+

+ +corecmd_check_exec_shell( + + + + + domain + + + )
+
+ +
+

+Check if a shell is executable (DAC-wise). +

+
+ +
+ +
+Module: +corecommands

+Layer: +kernel

corecmd_dontaudit_getattr_sbin_file( @@ -3355,10 +4125,37 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

+

+ +corecmd_dontaudit_search_sbin( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to search +sbin directories. +

+
+ +
+ +
+Module: +corecommands

+Layer: +kernel

corecmd_exec_bin( @@ -3381,10 +4178,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_exec_chroot( @@ -3407,10 +4204,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_exec_ls( @@ -3433,10 +4230,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_exec_sbin( @@ -3459,10 +4256,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_exec_shell( @@ -3485,10 +4282,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_getattr_bin_file( @@ -3511,10 +4308,10 @@ Get the attributes of files in bin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_getattr_sbin_file( @@ -3537,10 +4334,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_list_bin( @@ -3563,10 +4360,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_list_sbin( @@ -3589,10 +4386,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_bin_file( @@ -3615,10 +4412,10 @@ Read files in bin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_bin_pipe( @@ -3641,10 +4438,10 @@ Read pipes in bin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_bin_socket( @@ -3667,10 +4464,10 @@ Read named sockets in bin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_bin_symlink( @@ -3693,10 +4490,10 @@ Read symbolic links in bin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_sbin_file( @@ -3719,10 +4516,10 @@ Read files in sbin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_sbin_pipe( @@ -3745,10 +4542,10 @@ Read named pipes in sbin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_sbin_socket( @@ -3771,10 +4568,10 @@ Read named sockets in sbin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_read_sbin_symlink( @@ -3797,10 +4594,10 @@ Read symbolic links in sbin directories.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_sbin_domtrans( @@ -3832,10 +4629,10 @@ in the specified domain.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_search_bin( @@ -3858,10 +4655,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_search_sbin( @@ -3884,10 +4681,10 @@ Summary is missing!
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_shell_domtrans( @@ -3918,10 +4715,10 @@ Execute a shell in the specified domain.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_shell_entry_type( @@ -3944,10 +4741,10 @@ Make the shell an entrypoint for the specified domain.
-Module: +Module: corecommands

-Layer: -system

+Layer: +kernel

corecmd_shell_spec_domtrans( @@ -4058,6 +4855,60 @@ Do not audit attempts to bind UDP sockets to all reserved ports.
+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_non_ipsec_sendrecv( + + + + + domain + + + )
+
+ +
+

+Send and receive messages on a +non-encrypted (no IPSEC) network +session. +

+
+ +
+ +
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_raw_bind_all_nodes( + + + + + domain + + + )
+
+ +
+

+Bind raw sockets to all nodes. +

+
+ +
+
Module: corenetwork

@@ -5410,6 +6261,32 @@ Bind TCP sockets to node compat_ipv4.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_comsat_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the comsat port. +

+
+ +
+
Module: corenetwork

@@ -5566,6 +6443,32 @@ Bind TCP sockets to the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_distccd_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the distccd port. +

+
+ +
+
Module: corenetwork

@@ -5670,6 +6573,32 @@ Bind TCP sockets to the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -5878,6 +6807,32 @@ Bind TCP sockets to the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -6892,6 +7847,32 @@ Bind TCP sockets to generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -7802,6 +8783,32 @@ Make a TCP connection to the clockspeed port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_comsat_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the comsat port. +

+
+ +
+
Module: corenetwork

@@ -7958,6 +8965,32 @@ Make a TCP connection to the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_distccd_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the distccd port. +

+
+ +
+
Module: corenetwork

@@ -8062,6 +9095,32 @@ Make a TCP connection to the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -8244,6 +9303,32 @@ Make a TCP connection to the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -9128,6 +10213,32 @@ Connect TCP sockets to generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -10064,6 +11175,32 @@ Send and receive TCP traffic on the compat_ipv4 node.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_comsat_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the comsat port. +

+
+ +
+
Module: corenetwork

@@ -10220,6 +11357,32 @@ Send and receive TCP traffic on the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_distccd_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the distccd port. +

+
+ +
+
Module: corenetwork

@@ -10324,6 +11487,32 @@ Send and receive TCP traffic on the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -10558,6 +11747,32 @@ Send and receive TCP traffic on the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -11572,6 +12787,32 @@ Send and receive TCP network traffic on generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -12534,6 +13775,32 @@ Bind UDP sockets to the compat_ipv4 node.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_comsat_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the comsat port. +

+
+ +
+
Module: corenetwork

@@ -12690,6 +13957,32 @@ Bind UDP sockets to the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_distccd_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the distccd port. +

+
+ +
+
Module: corenetwork

@@ -12794,6 +14087,32 @@ Bind UDP sockets to the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -13002,6 +14321,32 @@ Bind UDP sockets to the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -14016,6 +15361,32 @@ Bind UDP sockets to generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -15004,6 +16375,32 @@ Receive UDP traffic on the compat_ipv4 node.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_comsat_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the comsat port. +

+
+ +
+
Module: corenetwork

@@ -15160,6 +16557,32 @@ Receive UDP traffic on the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_distccd_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the distccd port. +

+
+ +
+
Module: corenetwork

@@ -15264,6 +16687,32 @@ Receive UDP traffic on the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -15498,6 +16947,32 @@ Receive UDP traffic on the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -16512,6 +17987,32 @@ Receive UDP network traffic on generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -17500,6 +19001,32 @@ Send UDP traffic on the compat_ipv4 node.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_comsat_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the comsat port. +

+
+ +
+
Module: corenetwork

@@ -17656,6 +19183,32 @@ Send UDP traffic on the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_distccd_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the distccd port. +

+
+ +
+
Module: corenetwork

@@ -17760,6 +19313,32 @@ Send UDP traffic on the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -17994,6 +19573,32 @@ Send UDP traffic on the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -19008,6 +20613,32 @@ Send UDP network traffic on generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -19996,6 +21627,32 @@ Send and receive UDP traffic on the compat_ipv4 node.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_comsat_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the comsat port. +

+
+ +
+
Module: corenetwork

@@ -20152,6 +21809,32 @@ Send and receive UDP traffic on the dict port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_distccd_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the distccd port. +

+
+ +
+
Module: corenetwork

@@ -20256,6 +21939,32 @@ Send and receive UDP traffic on the ftp port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_gatekeeper_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the gatekeeper port. +

+
+ +
+
Module: corenetwork

@@ -20490,6 +22199,32 @@ Send and receive UDP traffic on the http port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_i18n_input_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the i18n_input port. +

+
+ +
+
Module: corenetwork

@@ -21504,6 +23239,32 @@ Send and receive UDP network traffic on generic reserved ports.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_rlogind_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the rlogind port. +

+
+ +
+
Module: corenetwork

@@ -22158,6 +23919,85 @@ CPUcontrol stub interface. No access allowed.

+
+Module: +cron

+Layer: +services

+

+ +cron_crw_tcp_socket( + + + + + domain + + + )
+
+ +
+

+Create, read, and write a cron daemon TCP socket. +

+
+ +
+ +
+Module: +cron

+Layer: +services

+

+ +cron_domtrans_anacron_system_job( + + + + + domain + + + )
+
+ +
+

+Execute APM in the apm domain. +

+
+ +
+ +
+Module: +cron

+Layer: +services

+

+ +cron_dontaudit_append_system_job_tmp_files( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to append temporary +files from the system cron jobs. +

+
+ +
+
Module: cron

@@ -22236,6 +24076,32 @@ Read and write a cron daemon unnamed pipe.

+
+Module: +cron

+Layer: +services

+

+ +cron_rw_system_job_pipe( + + + + + domain + + + )
+
+ +
+

+Read and write a system cron job unnamed pipe. +

+
+ +
+
Module: cron

@@ -22397,7 +24263,218 @@ services

-Wrate a system cron job unnamed pipe. +Write a system cron job unnamed pipe. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_dbus_chat( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +cups over dbus. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_dbus_chat_config( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +cupsd_config over dbus. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute cups in the cups domain. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_domtrans_config( + + + + + domain + + + )
+
+ +
+

+Execute cups_config in the cups_config domain. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_read_log( + + + + + domain + + + )
+
+ +
+

+Read cups log files. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_read_rw_config( + + + + + domain + + + )
+
+ +
+

+Read cups-writable configuration files. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_signal_config( + + + + + domain + + + )
+
+ +
+

+Send generic signals to the cups +configuration daemon. +

+
+ +
+ +
+Module: +cups

+Layer: +services

+

+ +cups_stream_connect_ptal( + + + + + domain + + + )
+
+ +
+

+Connect to ptal over an unix domain stream socket.

@@ -22429,6 +24506,33 @@ Read the CVS data and metadata.
+
+Module: +cyrus

+Layer: +services

+

+ +cyrus_manage_data( + + + + + domain + + + )
+
+ +
+

+Allow caller to create, read, write, +and delete cyrus data files. +

+
+ +
+
Module: dbus

@@ -22482,6 +24586,36 @@ Send a message on the system DBUS.

+
+Module: +dbus

+Layer: +services

+

+ +dbus_stub( + + + + + [ + + domain + + ] + + + )
+
+ +
+

+DBUS stub interface. No access allowed. +

+
+ +
+
Module: dbus

@@ -22508,6 +24642,86 @@ Allow unconfined access to the system DBUS.

+
+Module: +devices

+Layer: +kernel

+

+ +dev_append_printer( + + + + + domain + + + )
+
+ +
+

+Append the printer device. +

+
+ +
+ +
+Module: +devices

+Layer: +kernel

+

+ +dev_associate_usbfs( + + + + + domain + + + )
+
+ +
+

+Mount a usbfs filesystem. +

+
+ +
+ +
+Module: +devices

+Layer: +kernel

+

+ +dev_create_cardmgr( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete +the PCMCIA card manager device +with the correct type. +

+
+ +
+
Module: devices

@@ -22892,6 +25106,33 @@ the scanner device.

+
+Module: +devices

+Layer: +kernel

+

+ +dev_dontaudit_getattr_usbfs_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the attributes +of a directory in the usb filesystem. +

+
+ +
+
Module: devices

@@ -23603,6 +25844,32 @@ Get the attributes of the mouse devices.

+
+Module: +devices

+Layer: +kernel

+

+ +dev_getattr_mtrr( + + + + + domain + + + )
+
+ +
+

+Get the attributes of the mtrr device. +

+
+ +
+
Module: devices

@@ -23915,6 +26182,33 @@ Read, write, create, and delete all character device files.

+
+Module: +devices

+Layer: +kernel

+

+ +dev_manage_cardmgr( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete +the PCMCIA card manager device. +

+
+ +
+
Module: devices

@@ -23953,33 +26247,6 @@ kernel

- domain - - - )
-

- -
-

-Allow read, write, create, and delete for generic -block files. -

-
- -
- -
-Module: -devices

-Layer: -kernel

-

- -dev_manage_generic_blk_file( - - - - domain @@ -24620,6 +26887,32 @@ Read and write the apm bios.
+
+Module: +devices

+Layer: +kernel

+

+ +dev_rw_cardmgr( + + + + + domain + + + )
+
+ +
+

+Read and write the PCMCIA card manager device. +

+
+ +
+
Module: devices

@@ -25892,10 +28185,10 @@ allow the specified role the dmidecode domain.

-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_base_type( @@ -25918,10 +28211,10 @@ Make the specified type usable as a basic domain.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_cron_exemption_source( @@ -25947,10 +28240,10 @@ constraints.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_cron_exemption_target( @@ -25976,10 +28269,63 @@ constraints.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_dgram_sockets( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the attributes +of all domains unix datagram sockets. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_domains( + + + + + domain + + + )
+
+ +
+

+Get the attributes of all domains of all domains. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

domain_dontaudit_getattr_all_key_sockets( @@ -26003,10 +28349,91 @@ all domains IPSEC key management sockets.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_packet_sockets( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get attribues of +all domains packet sockets. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_pipes( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the attributes +of all domains unnamed pipes. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_raw_sockets( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get attribues of +all domains raw sockets. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

domain_dontaudit_getattr_all_sockets( @@ -26030,10 +28457,37 @@ of all domains sockets, for all socket types.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

+

+ +domain_dontaudit_getattr_all_stream_sockets( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the attributes +of all domains unix datagram sockets. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

domain_dontaudit_getattr_all_tcp_sockets( @@ -26057,10 +28511,10 @@ of all domains TCP sockets.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_getattr_all_udp_sockets( @@ -26084,64 +28538,10 @@ of all domains UDP sockets.
-Module: +Module: domain

-Layer: -system

-

- -domain_dontaudit_getattr_all_unix_dgram_sockets( - - - - - domain - - - )
-
- -
-

-Do not audit attempts to get the attributes -of all domains unix datagram sockets. -

-
- -
- -
-Module: -domain

-Layer: -system

-

- -domain_dontaudit_getattr_all_unnamed_pipes( - - - - - domain - - - )
-
- -
-

-Do not audit attempts to get the attributes -of all domains unnamed pipes. -

-
- -
- -
-Module: -domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_getsession_all_domains( @@ -26165,10 +28565,10 @@ session ID of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_list_all_domains_proc( @@ -26192,10 +28592,10 @@ directories of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_ptrace_all_domains( @@ -26218,10 +28618,10 @@ Do not audit attempts to ptrace all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_ptrace_confined_domains( @@ -26244,10 +28644,10 @@ Do not audit attempts to ptrace confined domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_read_all_domains_state( @@ -26271,10 +28671,10 @@ state (/proc/pid) of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_rw_all_key_sockets( @@ -26298,10 +28698,10 @@ all domains key sockets.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dontaudit_rw_all_udp_sockets( @@ -26325,10 +28725,37 @@ all domains UDP sockets.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

+

+ +domain_dontaudit_search_all_domains_state( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to search the process +state directory (/proc/pid) of all domains. +

+
+ +
+ +
+Module: +domain

+Layer: +kernel

domain_dontaudit_use_wide_inherit_fd( @@ -26351,10 +28778,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_dyntrans_type( @@ -26377,10 +28804,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_entry_file( @@ -26412,10 +28839,10 @@ an entry point for the domain.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_exec_all_entry_files( @@ -26438,10 +28865,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_getattr_all_domains( @@ -26464,10 +28891,10 @@ Get the attributes of all domains of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_getattr_all_entry_files( @@ -26491,10 +28918,10 @@ files for all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_getattr_all_sockets( @@ -26518,10 +28945,10 @@ sockets, for all socket types.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_getattr_confined_domains( @@ -26544,10 +28971,10 @@ Get the attributes of all confined domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_getsession_all_domains( @@ -26570,10 +28997,10 @@ Get the session ID of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_kill_all_domains( @@ -26596,10 +29023,10 @@ Send a kill signal to all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_obj_id_change_exempt( @@ -26623,10 +29050,10 @@ changing the user identity in object contexts.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_ptrace_all_domains( @@ -26649,10 +29076,10 @@ Ptrace all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_read_all_domains_state( @@ -26675,10 +29102,10 @@ Read the process state (/proc/pid) of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_read_all_entry_files( @@ -26701,10 +29128,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_read_confined_domains_state( @@ -26727,10 +29154,10 @@ Read the process state (/proc/pid) of all confined domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_role_change_exempt( @@ -26754,10 +29181,10 @@ changing of role.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_search_all_domains_state( @@ -26780,10 +29207,10 @@ Search the process state directory (/proc/pid) of all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_setpriority_all_domains( @@ -26806,10 +29233,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_sigchld_all_domains( @@ -26832,10 +29259,10 @@ Send a child terminated signal to all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_sigchld_wide_inherit_fd( @@ -26859,10 +29286,10 @@ discriptors are widely inheritable.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_signal_all_domains( @@ -26885,10 +29312,10 @@ Send general signals to all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_signull_all_domains( @@ -26911,10 +29338,10 @@ Send a null signal to all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_sigstop_all_domains( @@ -26937,10 +29364,10 @@ Send a stop signal to all domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_subj_id_change_exempt( @@ -26964,10 +29391,10 @@ changing of user identity.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_system_change_exempt( @@ -26992,10 +29419,10 @@ identity and system role.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_type( @@ -27018,10 +29445,10 @@ Make the specified type usable as a domain.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_unconfined( @@ -27044,10 +29471,10 @@ Unconfined access to domains.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_use_wide_inherit_fd( @@ -27070,10 +29497,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_user_exemption_target( @@ -27099,10 +29526,10 @@ constraints.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_wide_inherit_fd( @@ -27125,10 +29552,36 @@ Summary is missing!
-Module: +Module: +dovecot

+Layer: +services

+

+ +dovecot_manage_spool( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete the dovecot spool files. +

+
+ +
+ +
+Module: files

-Layer: -system

+Layer: +kernel

files_associate_tmp( @@ -27153,10 +29606,37 @@ temporary directory (/tmp).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_config_file( + + + + + file_type + + + )
+
+ +
+

+Make the specified type a +configuration file. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_create_boot_flag( @@ -27179,10 +29659,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_etc_config( @@ -27205,10 +29685,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_home_dirs( @@ -27239,10 +29719,10 @@ Create home directories
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_lock( @@ -27265,10 +29745,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_pid( @@ -27291,10 +29771,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_root( @@ -27343,10 +29823,10 @@ default is file.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_tmp_files( @@ -27369,10 +29849,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_usr( @@ -27415,10 +29895,10 @@ Create objects in the /usr directory
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_var( @@ -27461,10 +29941,10 @@ Create objects in the /var directory
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_create_var_lib( @@ -27507,10 +29987,10 @@ Create objects in the /var/lib directory
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_delete_all_locks( @@ -27533,10 +30013,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_delete_all_pid_dirs( @@ -27559,10 +30039,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_delete_all_pids( @@ -27585,10 +30065,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_delete_etc_files( @@ -27611,10 +30091,10 @@ Delete system configuration files in /etc.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_delete_root_dir_entry( @@ -27637,10 +30117,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_all_dirs( @@ -27664,10 +30144,10 @@ of all directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_all_files( @@ -27691,10 +30171,10 @@ of all files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_all_pipes( @@ -27718,10 +30198,10 @@ of all named pipes.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_all_sockets( @@ -27745,10 +30225,10 @@ of all named sockets.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_all_symlinks( @@ -27772,10 +30252,10 @@ of all symbolic links.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_default_dir( @@ -27799,10 +30279,10 @@ directories with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_default_files( @@ -27826,10 +30306,10 @@ files with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_home_dir( @@ -27854,10 +30334,10 @@ attributes of the home directories root
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_blk_dev( @@ -27881,10 +30361,10 @@ of non security block devices.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_chr_dev( @@ -27908,10 +30388,10 @@ of non security character devices.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_files( @@ -27935,10 +30415,10 @@ of non security files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_pipes( @@ -27962,10 +30442,10 @@ of non security named pipes.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_sockets( @@ -27989,10 +30469,10 @@ of non security named sockets.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_non_security_symlinks( @@ -28016,10 +30496,10 @@ of non security symbolic links.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_pid_dir( @@ -28043,10 +30523,10 @@ of the /var/run directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_getattr_tmp_dir( @@ -28070,10 +30550,10 @@ attributes of the tmp directory (/tmp).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_ioctl_all_pids( @@ -28096,10 +30576,10 @@ Do not audit attempts to ioctl daemon runtime data files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_list_default( @@ -28123,10 +30603,10 @@ directories with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_list_non_security( @@ -28150,10 +30630,10 @@ non security directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_read_default_files( @@ -28177,10 +30657,10 @@ with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_read_etc_runtime_files( @@ -28205,10 +30685,10 @@ created on boot, such as mtab.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_read_root_file( @@ -28231,10 +30711,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_rw_root_chr_dev( @@ -28257,10 +30737,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_rw_root_file( @@ -28283,10 +30763,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_all_dirs( @@ -28309,10 +30789,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_home( @@ -28336,10 +30816,10 @@ home directories root (/home).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_isid_type_dir( @@ -28363,10 +30843,10 @@ that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_locks( @@ -28390,10 +30870,10 @@ locks directory (/var/lock).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_pids( @@ -28417,10 +30897,10 @@ the /var/run directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_src( @@ -28443,10 +30923,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_search_var( @@ -28470,10 +30950,10 @@ the contents of /var.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_dontaudit_write_all_pids( @@ -28496,10 +30976,10 @@ Do not audit attempts to write to daemon runtime data files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_exec_etc_files( @@ -28522,10 +31002,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_exec_usr_files( @@ -28548,10 +31028,10 @@ Execute generic programs in /usr in the caller domain.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_exec_usr_src_files( @@ -28574,10 +31054,10 @@ Execute programs in /usr/src in the caller domain.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_all_dirs( @@ -28600,10 +31080,37 @@ Get the attributes of all directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_getattr_all_file_type_sockets( + + + + + domain + + + )
+
+ +
+

+Get the attributes of all sockets +with the type of a file. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_getattr_all_files( @@ -28626,10 +31133,10 @@ Get the attributes of all files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_all_pipes( @@ -28652,10 +31159,10 @@ Get the attributes of all named pipes.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_all_sockets( @@ -28678,10 +31185,10 @@ Get the attributes of all named sockets.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_all_symlinks( @@ -28704,10 +31211,10 @@ Get the attributes of all symbolic links.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_generic_locks( @@ -28730,10 +31237,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_home_dir( @@ -28757,10 +31264,36 @@ Get the attributes of the home directories root
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_getattr_tmp_dir( + + + + + domain + + + )
+
+ +
+

+Get the attributes of the tmp directory (/tmp). +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_getattr_usr_files( @@ -28783,10 +31316,10 @@ Get the attributes of files in /usr.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_getattr_var_lib_dir( @@ -28809,13 +31342,13 @@ Get the attributes of the /var/lib directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

-files_list_all_dirs( +files_list_all( @@ -28835,10 +31368,10 @@ List the contents of all directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_all_dirs( @@ -28861,10 +31394,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_default( @@ -28887,10 +31420,10 @@ List contents of directories with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_etc( @@ -28913,10 +31446,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_home( @@ -28939,10 +31472,10 @@ Get listing of home directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_isid_type_dir( @@ -28966,10 +31499,10 @@ that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_mnt( @@ -28992,10 +31525,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_pids( @@ -29018,10 +31551,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_root( @@ -29044,10 +31577,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_spool( @@ -29070,10 +31603,36 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_list_tmp( + + + + + domain + + + )
+
+ +
+

+Read the tmp directory (/tmp). +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_list_usr( @@ -29097,10 +31656,10 @@ directories in /usr.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_var( @@ -29123,10 +31682,10 @@ List the contents of /var.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_var_lib( @@ -29149,10 +31708,10 @@ List the contents of the /var/lib directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_list_world_readable( @@ -29175,10 +31734,10 @@ List world-readable directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_lock_file( @@ -29201,10 +31760,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_all_files( @@ -29240,10 +31799,10 @@ the listed exceptions.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_etc_files( @@ -29266,10 +31825,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_etc_runtime_files( @@ -29294,10 +31853,10 @@ such as mtab.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_generic_locks( @@ -29320,10 +31879,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_generic_spool_dirs( @@ -29346,10 +31905,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_generic_spools( @@ -29372,10 +31931,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_isid_type_blk_node( @@ -29399,10 +31958,10 @@ on new filesystems that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_isid_type_chr_node( @@ -29426,10 +31985,10 @@ on new filesystems that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_isid_type_dir( @@ -29453,10 +32012,10 @@ on new filesystems that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_isid_type_file( @@ -29480,10 +32039,10 @@ on new filesystems that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_isid_type_symlink( @@ -29507,10 +32066,10 @@ on new filesystems that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_lost_found( @@ -29534,10 +32093,10 @@ lost+found directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_mnt_dirs( @@ -29560,10 +32119,10 @@ Create, read, write, and delete directories in /mnt.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_mnt_files( @@ -29586,10 +32145,10 @@ Create, read, write, and delete files in /mnt.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_mnt_symlinks( @@ -29612,10 +32171,37 @@ Create, read, write, and delete symbolic links in /mnt.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_manage_mounttab( + + + + + domain + + + )
+
+ +
+

+Allow domain to manage mount tables +necessary for rpcd, nfsd, etc. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_manage_urandom_seed( @@ -29638,10 +32224,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_var_dirs( @@ -29665,10 +32251,10 @@ in the /var directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_var_files( @@ -29691,10 +32277,10 @@ Create, read, write, and delete files in the /var directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_manage_var_symlinks( @@ -29718,10 +32304,10 @@ links in the /var directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mount_all_file_type_fs( @@ -29744,10 +32330,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mounton_all_mountpoints( @@ -29770,10 +32356,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mounton_default( @@ -29796,10 +32382,10 @@ Mount a filesystem on a directory with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mounton_isid_type_dir( @@ -29823,10 +32409,10 @@ that has not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mounton_mnt( @@ -29849,10 +32435,10 @@ Mount a filesystem on /mnt.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_mountpoint( @@ -29875,10 +32461,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_pid_file( @@ -29901,10 +32487,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_poly( @@ -29928,10 +32514,10 @@ polyinstantiated directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_poly_member( @@ -29955,10 +32541,10 @@ polyinstantiation member directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_poly_member_tmp( @@ -29990,10 +32576,10 @@ type of polyinstantiated directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_poly_parent( @@ -30017,10 +32603,10 @@ of a polyinstantiated directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_purge_tmp( @@ -30043,10 +32629,101 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_read_all_blk_nodes( + + + + + domain + + + )
+
+ +
+

+Read all block nodes with file types. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

+

+ +files_read_all_chr_nodes( + + + + + domain + + + )
+
+ +
+

+Read all character nodes with file types. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

+

+ +files_read_all_dirs_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all directories on the filesystem, except +the listed exceptions. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_read_all_files( @@ -30069,10 +32746,49 @@ Read all files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_read_all_files_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all files on the filesystem, except +the listed exceptions. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_read_all_pids( @@ -30095,10 +32811,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_all_symlinks( @@ -30121,10 +32837,49 @@ Read all symbolic links.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_read_all_symlinks_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+ +
+

+Read all symbloic links on the filesystem, except +the listed exceptions. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_read_default_files( @@ -30147,10 +32902,10 @@ Read files with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_default_pipes( @@ -30173,10 +32928,10 @@ Read named pipes with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_default_sockets( @@ -30199,10 +32954,10 @@ Read sockets with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_default_symlinks( @@ -30225,10 +32980,10 @@ Read symbolic links with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_etc_files( @@ -30251,10 +33006,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_etc_runtime_files( @@ -30278,10 +33033,10 @@ created on boot, such as mtab.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_generic_spools( @@ -30304,10 +33059,62 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_read_generic_tmp_files( + + + + + domain + + + )
+
+ +
+

+Read files in the tmp directory (/tmp). +

+
+ +
+ +
+Module: +files

+Layer: +kernel

+

+ +files_read_generic_tmp_symlinks( + + + + + domain + + + )
+
+ +
+

+Read symbolic links in the tmp directory (/tmp). +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_read_isid_type_file( @@ -30331,10 +33138,10 @@ that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_usr_files( @@ -30357,10 +33164,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_usr_src_files( @@ -30383,10 +33190,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_usr_symlinks( @@ -30409,10 +33216,10 @@ Read symbolic links in /usr.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_var_files( @@ -30435,10 +33242,10 @@ Read files in the /var directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_var_lib_files( @@ -30461,10 +33268,10 @@ Read generic files in /var/lib.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_var_lib_symlinks( @@ -30487,10 +33294,10 @@ Read generic symbolic links in /var/lib
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_var_symlink( @@ -30513,10 +33320,10 @@ Read symbolic links in the /var directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_world_readable_files( @@ -30539,10 +33346,10 @@ Read world-readable files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_world_readable_pipes( @@ -30565,10 +33372,10 @@ Read world-readable named pipes.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_world_readable_sockets( @@ -30591,10 +33398,10 @@ Read world-readable sockets.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_read_world_readable_symlinks( @@ -30617,10 +33424,10 @@ Read world-readable symbolic links.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_relabel_all_files( @@ -30656,10 +33463,36 @@ the listed exceptions.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_relabel_etc_files( + + + + + domain + + + )
+
+ +
+

+Relabel from and to generic files in /etc. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_relabelto_all_file_type_fs( @@ -30682,10 +33515,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_relabelto_usr_files( @@ -30708,10 +33541,10 @@ Relabel a file to the type used in /usr.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_rw_etc_files( @@ -30734,10 +33567,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_rw_etc_runtime_files( @@ -30761,10 +33594,10 @@ created on boot, such as mtab.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_rw_generic_pids( @@ -30787,10 +33620,36 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_rw_generic_tmp_sockets( + + + + + domain + + + )
+
+ +
+

+Read and write generic named sockets in the tmp directory (/tmp). +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_rw_isid_type_blk_node( @@ -30814,10 +33673,10 @@ that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_rw_isid_type_dir( @@ -30841,10 +33700,10 @@ that have not yet been labeled.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_rw_locks_dir( @@ -30868,10 +33727,10 @@ directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_all( @@ -30894,10 +33753,10 @@ Search all directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_all_dirs( @@ -30920,10 +33779,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_default( @@ -30946,10 +33805,10 @@ Search the contents of directories with the default file type.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_etc( @@ -30972,10 +33831,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_home( @@ -30998,10 +33857,10 @@ Search home directories root (/home).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_locks( @@ -31024,10 +33883,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_mnt( @@ -31050,10 +33909,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_pids( @@ -31076,10 +33935,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_spool( @@ -31102,10 +33961,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_tmp( @@ -31128,10 +33987,10 @@ Search the tmp directory (/tmp).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_usr( @@ -31154,10 +34013,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_var( @@ -31180,10 +34039,10 @@ Search the contents of /var.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_search_var_lib( @@ -31206,10 +34065,36 @@ Search the /var/lib directory.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

+

+ +files_search_var_lib_dir( + + + + + domain + + + )
+
+ +
+

+Search directories in /var/lib. +

+
+ +
+ +
+Module: +files

+Layer: +kernel

files_security_file( @@ -31234,10 +34119,10 @@ browsing from user domains.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_setattr_all_tmp_dirs( @@ -31260,10 +34145,10 @@ Set the attributes of all tmp directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_setattr_etc_dir( @@ -31286,10 +34171,10 @@ Set the attributes of the /etc directories.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_tmp_file( @@ -31313,10 +34198,10 @@ used for temporary files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_tmpfs_file( @@ -31340,10 +34225,10 @@ virtual memory filesystem (tmpfs).
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_type( @@ -31367,10 +34252,10 @@ in a filesystem.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_unconfined( @@ -31393,10 +34278,10 @@ Unconfined access to files.
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_unmount_all_file_type_fs( @@ -31419,10 +34304,10 @@ Summary is missing!
-Module: +Module: files

-Layer: -system

+Layer: +kernel

files_unmount_rootfs( @@ -32417,6 +35302,33 @@ attributes, such as ext3, JFS, or XFS.
+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_getattr_all_dirs( + + + + + domain + + + )
+
+ +
+

+Get the attributes of all directories +with a filesystem type. +

+
+ +
+
Module: filesystem

@@ -32766,6 +35678,32 @@ filesystem.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_getattr_rpc_dirs( + + + + + domain + + + )
+
+ +
+

+Read directories of RPC file system pipes. +

+
+ +
+
Module: filesystem

@@ -32927,6 +35865,32 @@ CIFS or SMB filesystem.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_list_noxattr_fs( + + + + + domain + + + )
+
+ +
+

+Read all noxattrfs directories. +

+
+ +
+
Module: filesystem

@@ -33790,33 +36754,6 @@ Read files on a CIFS or SMB filesystem.

-
-Module: -filesystem

-Layer: -kernel

-

- -fs_read_cifs_files( - - - - - domain - - - )
-
- -
-

-Do not audit attempts to read or -write files on a CIFS or SMB filesystems. -

-
- -
-
Module: filesystem

@@ -33895,6 +36832,162 @@ Read symbolic links on a NFS filesystem.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_noxattr_fs_files( + + + + + domain + + + )
+
+ +
+

+Read all noxattrfs files. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_noxattr_fs_symlinks( + + + + + domain + + + )
+
+ +
+

+Read all noxattrfs symbolic links. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_rpc_dirs( + + + + + domain + + + )
+
+ +
+

+Read directories of RPC file system pipes. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_rpc_files( + + + + + domain + + + )
+
+ +
+

+Read files of RPC file system pipes. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_rpc_sockets( + + + + + domain + + + )
+
+ +
+

+Read sockets of RPC file system pipes. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_read_rpc_symlinks( + + + + + domain + + + )
+
+ +
+

+Read symbolic links of RPC file system pipes. +

+
+ +
+
Module: filesystem

@@ -34387,6 +37480,84 @@ some mount options to be changed.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_rw_nfsd_fs( + + + + + domain + + + )
+
+ +
+

+Read and write NFS server files. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_rw_ramfs_pipe( + + + + + domain + + + )
+
+ +
+

+Read and write a named pipe on a ramfs filesystem. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_rw_tmpfs_file( + + + + + domain + + + )
+
+ +
+

+Read and write generic tmpfs files. +

+
+ +
+
Module: filesystem

@@ -34492,6 +37663,32 @@ Search directories on a NFS filesystem.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_search_nfsd_fs( + + + + + domain + + + )
+
+ +
+

+Search NFS server directories. +

+
+ +
+
Module: filesystem

@@ -35043,6 +38240,58 @@ Read and write character nodes on tmpfs filesystems.

+
+Module: +filesystem

+Layer: +kernel

+

+ +fs_write_nfs_files( + + + + + domain + + + )
+
+ +
+

+Read files on a NFS filesystem. +

+
+ +
+ +
+Module: +filesystem

+Layer: +kernel

+

+ +fs_write_ramfs_pipe( + + + + + domain + + + )
+
+ +
+

+Write to named pipe on a ramfs filesystem. +

+
+ +
+
Module: filesystem

@@ -35508,6 +38757,139 @@ control channel named socket.

+
+Module: +hal

+Layer: +services

+

+ +hal_dbus_chat( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +hal over dbus. +

+
+ +
+ +
+Module: +hal

+Layer: +services

+

+ +hal_dbus_send( + + + + + domain + + + )
+
+ +
+

+Send a dbus message to hal. +

+
+ +
+ +
+Module: +hal

+Layer: +services

+

+ +hal_dgram_sendto( + + + + + domain + + + )
+
+ +
+

+Send to hal over a unix domain +datagram socket. +

+
+ +
+ +
+Module: +hal

+Layer: +services

+

+ +hal_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute hal in the hal domain. +

+
+ +
+ +
+Module: +hal

+Layer: +services

+

+ +hal_stream_connect( + + + + + domain + + + )
+
+ +
+

+Send to hal over a unix domain +stream socket. +

+
+ +
+
Module: hostname

@@ -35811,6 +39193,58 @@ Summary is missing!

+
+Module: +howl

+Layer: +services

+

+ +howl_signal( + + + + + domain + + + )
+
+ +
+

+Send generic signals to howl. +

+
+ +
+ +
+Module: +i18n_input

+Layer: +services

+

+ +i18n_use( + + + + + domain + + + )
+
+ +
+

+Use i18n_input over a TCP connection. +

+
+ +
+
Module: inetd

@@ -35871,6 +39305,32 @@ Run inetd child process in the inet child domain

+
+Module: +inetd

+Layer: +services

+

+ +inetd_rw_tcp_socket( + + + + + domain + + + )
+
+ +
+

+Read and write inetd TCP sockets. +

+
+ +
+
Module: inetd

@@ -36051,6 +39511,53 @@ Inherit and use file descriptors from inetd.

+
+Module: +init

+Layer: +system

+

+ +init_create_script_tmp( + + + + + domain + + + + , + + + + file_type + + + + , + + + + [ + + object_class + + ] + + + )
+
+ +
+

+Create files in a init script +temporary data directory. +

+
+ +
+
Module: init

@@ -36086,6 +39593,33 @@ Create a domain for long running processes

+
+Module: +init

+Layer: +system

+

+ +init_dbus_chat_script( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +init scripts over dbus. +

+
+ +
+
Module: init

@@ -36341,7 +39875,7 @@ system

- ? + domain )
@@ -36349,7 +39883,8 @@ system

-Summary is missing! +Do not audit attempts to read and +write the init script pty.

@@ -36511,6 +40046,58 @@ Summary is missing!
+
+Module: +init

+Layer: +system

+

+ +init_getattr_script_entry_file( + + + + + domain + + + )
+
+ +
+

+Get the attribute of init script entrypoint files. +

+
+ +
+ +
+Module: +init

+Layer: +system

+

+ +init_getattr_script_pids( + + + + + domain + + + )
+
+ +
+

+Get the attributes of init script process id files. +

+
+ +
+
Module: init

@@ -36788,6 +40375,58 @@ Send init a SIGCHLD signal.

+
+Module: +init

+Layer: +system

+

+ +init_sigchld_script( + + + + + domain + + + )
+
+ +
+

+Send SIGCHLD signals to init scripts. +

+
+ +
+ +
+Module: +init

+Layer: +system

+

+ +init_signal_script( + + + + + domain + + + )
+
+ +
+

+Send generic signals to init scripts. +

+
+ +
+
Module: init

@@ -36814,6 +40453,32 @@ Send init a null signal.

+
+Module: +init

+Layer: +system

+

+ +init_signull_script( + + + + + domain + + + )
+
+ +
+

+Send null signals to init scripts. +

+
+ +
+
Module: init

@@ -36913,33 +40578,6 @@ system

- domain - - - )
-

- -
-

-Allow the specified domain to connect to -init scripts with a unix domain stream socket. -

-
- -
- -
-Module: -init

-Layer: -system

-

- -init_unix_connect_script( - - - - domain @@ -37085,6 +40723,32 @@ Summary is missing!
+
+Module: +init

+Layer: +system

+

+ +init_write_script_pipe( + + + + + domain + + + )
+
+ +
+

+Write an init script unnamed pipe. +

+
+ +
+
Module: inn

@@ -37810,6 +41474,221 @@ unlabeled block devices.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_getattr_unlabeled_chr_dev( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to get attributes for +unlabeled character devices. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_getattr_unlabeled_file( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to get the +attributes of an unlabeled file. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_getattr_unlabeled_pipes( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to get the +attributes of unlabeled named pipes. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_getattr_unlabeled_sockets( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to get the +attributes of unlabeled named sockets. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_getattr_unlabeled_symlinks( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to get the +attributes of unlabeled symbolic links. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_list_proc( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to list the +contents of directories in /proc. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_list_unlabeled( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to list unlabeled directories. +

+
+ +
+ +
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_read_proc_symlink( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to +read system state information in proc. +

+
+ +
+
Module: kernel

@@ -37863,6 +41742,33 @@ read system state information in proc.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_read_unlabeled_file( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts by caller to +read an unlabeled file. +

+
+ +
+
Module: kernel

@@ -38153,6 +42059,32 @@ Get the attributes of the proc filesystem.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_getattr_proc_files( + + + + + domain + + + )
+
+ +
+

+Get the attributes of files in /proc. +

+
+ +
+
Module: kernel

@@ -38624,6 +42556,32 @@ Allow caller to read the network state information.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_read_network_state_symlinks( + + + + + domain + + + )
+
+ +
+

+Allow caller to read the network state symbolic links. +

+
+ +
+
Module: kernel

@@ -38728,6 +42686,32 @@ Allow caller to read the state information for software raid.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_read_sysctl( + + + + + domain + + + )
+
+ +
+

+Allow access to read sysctl directories. +

+
+ +
+
Module: kernel

@@ -39331,18 +43315,18 @@ specified directory.

-Module: +Module: kernel

Layer: kernel

-kernel_search_from( +kernel_search_network_state( - dir_type + domain )
@@ -39350,8 +43334,7 @@ kernel

-Allow the kernel to search the -specified directory. +Allow searching of network state directory.

@@ -39409,6 +43392,32 @@ Search directories in /proc.
+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_search_vm_sysctl( + + + + + domain + + + )
+
+ +
+

+Allow caller to search virtual memory sysctls. +

+
+ +
+
Module: kernel

@@ -39446,6 +43455,33 @@ socket.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_sendrecv_unlabeled_association( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from an +unlabeled IPSEC association. +

+
+ +
+
Module: kernel

@@ -40514,6 +44550,33 @@ of shared libraries.

+
+Module: +libraries

+Layer: +system

+

+ +libs_use_lib( + + + + + domain + + + )
+
+ +
+

+Load and execute functions from generic +lib files as shared libraries. +

+
+ +
+
Module: libraries

@@ -40790,6 +44853,32 @@ Summary is missing!

+
+Module: +logging

+Layer: +system

+

+ +logging_domtrans_auditctl( + + + + + domain + + + )
+
+ +
+

+Execute auditctl in the auditctl domain. +

+
+ +
+
Module: logging

@@ -41357,6 +45446,153 @@ Inherit and use logrotate file descriptors.

+
+Module: +lpd

+Layer: +services

+

+ +lpd_domtrans_checkpc( + + + + + domain + + + )
+
+ +
+

+Execute lpd in the lpd domain. +

+
+ +
+ +
+Module: +lpd

+Layer: +services

+

+ +lpd_list_spool( + + + + + domain + + + )
+
+ +
+

+List the contents of the printer spool directories. +

+
+ +
+ +
+Module: +lpd

+Layer: +services

+

+ +lpd_manage_spool( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete printer spool files. +

+
+ +
+ +
+Module: +lpd

+Layer: +services

+

+ +lpd_read_config( + + + + + domain + + + )
+
+ +
+

+List the contents of the printer spool directories. +

+
+ +
+ +
+Module: +lpd

+Layer: +services

+

+ +lpd_run_checkpc( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+ +
+

+Execute amrecover in the lpd domain, and +allow the specified role the lpd domain. +

+
+ +
+
Module: lvm

@@ -41713,6 +45949,32 @@ Delete man pages

+
+Module: +miscfiles

+Layer: +system

+

+ +miscfiles_dontaudit_search_man_pages( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to search man pages. +

+
+ +
+
Module: miscfiles

@@ -41765,6 +46027,32 @@ Allow process to read legacy time localization info

+
+Module: +miscfiles

+Layer: +system

+

+ +miscfiles_manage_fonts( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete fonts. +

+
+ +
+
Module: miscfiles

@@ -42325,6 +46613,32 @@ Execute insmod in the insmod domain.

+
+Module: +modutils

+Layer: +system

+

+ +modutils_domtrans_insmod_uncond( + + + + + domain + + + )
+
+ +
+

+Unconditionally execute insmod in the insmod domain. +

+
+ +
+
Module: modutils

@@ -42787,6 +47101,32 @@ Create, read, and write the mail spool.

+
+Module: +mta

+Layer: +services

+

+ +mta_delete_spool( + + + + + domain + + + )
+
+ +
+

+Delete from the mail spool. +

+
+ +
+
Module: mta

@@ -42841,6 +47181,33 @@ sockets of mail delivery domains.

+
+Module: +mta

+Layer: +services

+

+ +mta_dontaudit_rw_queue( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read and +write the mail queue. +

+
+ +
+
Module: mta

@@ -43079,6 +47446,58 @@ Read mail address aliases.

+
+Module: +mta

+Layer: +services

+

+ +mta_read_config( + + + + + domain + + + )
+
+ +
+

+Read mail server configuration. +

+
+ +
+ +
+Module: +mta

+Layer: +services

+

+ +mta_read_sendmail_bin( + + + + + domain + + + )
+
+ +
+

+Read sendmail binary. +

+
+ +
+
Module: mta

@@ -43131,6 +47550,33 @@ Summary is missing!

+
+Module: +mta

+Layer: +services

+

+ +mta_rw_user_mail_stream_socket( + + + + + domain + + + )
+
+ +
+

+Read and write unix domain stream sockets +of user mail domains. +

+
+ +
+
Module: mta

@@ -43829,6 +48275,164 @@ allow the specified role the traceroute domain.

+
+Module: +networkmanager

+Layer: +services

+

+ +networkmanager_dbus_chat( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +NetworkManager over dbus. +

+
+ +
+ +
+Module: +networkmanager

+Layer: +services

+

+ +networkmanager_rw_packet_socket( + + + + + domain + + + )
+
+ +
+

+Read and write NetworkManager packet sockets. +

+
+ +
+ +
+Module: +networkmanager

+Layer: +services

+

+ +networkmanager_rw_routing_socket( + + + + + domain + + + )
+
+ +
+

+Read and write NetworkManager netlink +routing sockets. +

+
+ +
+ +
+Module: +networkmanager

+Layer: +services

+

+ +networkmanager_rw_udp_socket( + + + + + domain + + + )
+
+ +
+

+Read and write NetworkManager UDP sockets. +

+
+ +
+ +
+Module: +nis

+Layer: +services

+

+ +nis_delete_ypbind_pid( + + + + + domain + + + )
+
+ +
+

+Delete ypbind pid files. +

+
+ +
+ +
+Module: +nis

+Layer: +services

+

+ +nis_domtrans_ypbind( + + + + + domain + + + )
+
+ +
+

+Execute ypbind in the ypbind domain. +

+
+ +
+
Module: nis

@@ -43849,7 +48453,59 @@ services

-Send UDP network traffic to NIS clients. +List the contents of the NIS data directory. +

+
+ +
+ +
+Module: +nis

+Layer: +services

+

+ +nis_read_ypbind_pid( + + + + + domain + + + )
+
+ +
+

+Read ypbind pid files. +

+
+ +
+ +
+Module: +nis

+Layer: +services

+

+ +nis_read_ypserv_config( + + + + + domain + + + )
+
+ +
+

+Read ypserv configuration files.

@@ -43881,6 +48537,32 @@ Send generic signals to ypbind.
+
+Module: +nis

+Layer: +services

+

+ +nis_tcp_connect_ypbind( + + + + + domain + + + )
+
+ +
+

+Connect to ypbind over TCP. +

+
+ +
+
Module: nis

@@ -44349,6 +49031,36 @@ allow the specified role the cardmgr domain.

+
+Module: +pcmcia

+Layer: +system

+

+ +pcmcia_stub( + + + + + [ + + domain + + ] + + + )
+
+ +
+

+PCMCIA stub interface. No access allowed. +

+
+ +
+
Module: pcmcia

@@ -44445,6 +49157,58 @@ Communicate with portmap.

+
+Module: +portmap

+Layer: +services

+

+ +portmap_tcp_connect( + + + + + domain + + + )
+
+ +
+

+Connect to portmap over a TCP socket +

+
+ +
+ +
+Module: +portmap

+Layer: +services

+

+ +portmap_udp_sendrecv( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP network traffic from portmap. +

+
+ +
+
Module: portmap

@@ -44471,6 +49235,367 @@ Send UDP network traffic to portmap.

+
+Module: +postfix

+Layer: +services

+

+ +postfix_create_config( + + + + + domain + + + + , + + + + private type + + + + , + + + + [ + + object + + ] + + + )
+
+ +
+

+Create files with the specified type in +the postfix configuration directories. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_domtrans_map( + + + + + domain + + + )
+
+ +
+

+Execute postfix_map in the postfix_map domain. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_domtrans_master( + + + + + domain + + + )
+
+ +
+

+Execute the master postfix program in the +postfix_master domain. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_domtrans_user_mail_handler( + + + + + domain + + + )
+
+ +
+

+Execute postfix user mail programs +in their respective domains. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_dontaudit_rw_local_tcp_socket( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read and +write postfix local delivery +TCP sockets. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_dontaudit_use_fd( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to use +postfix master process file +file descriptors. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_exec_master( + + + + + domain + + + )
+
+ +
+

+Execute the master postfix program in the +caller domain. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_list_spool( + + + + + domain + + + )
+
+ +
+

+List postfix mail spool directories. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_read_config( + + + + + domain + + + )
+
+ +
+

+Read postfix configuration files. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_run_map( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+ +
+

+Execute postfix_map in the postfix_map domain, and +allow the specified role the postfix_map domain. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_search_spool( + + + + + domain + + + )
+
+ +
+

+Search postfix mail spool directories. +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_stub( + + + + + [ + + domain + + ] + + + )
+
+ +
+

+Postfix stub interface. No access allowed. +

+
+ +
+
Module: postgresql

@@ -44653,6 +49778,33 @@ Execute domain in the ppp domain.

+
+Module: +ppp

+Layer: +services

+

+ +ppp_dontaudit_use_fd( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to inherit +and use PPP file discriptors. +

+
+ +
+
Module: ppp

@@ -44725,7 +49877,7 @@ services

-Allow domain to send sigchld to parent of PPP domain type. +Send a SIGCHLD signal to PPP.

@@ -44751,7 +49903,7 @@ services

-Allow domain to send a signal to PPP domain type. +Send a generic signal to PPP.

@@ -44783,6 +49935,58 @@ Use PPP file discriptors.
+
+Module: +procmail

+Layer: +services

+

+ +procmail_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute procmail with a domain transition. +

+
+ +
+ +
+Module: +procmail

+Layer: +services

+

+ +procmail_exec( + + + + + domain + + + )
+
+ +
+

+Execute procmail in the caller domain. +

+
+ +
+
Module: quota

@@ -44905,6 +50109,32 @@ allow the specified role the quota domain.

+
+Module: +radius

+Layer: +services

+

+ +radius_use( + + + + + domain + + + )
+
+ +
+

+Use radius over a UDP connection. +

+
+ +
+
Module: raid

@@ -45009,6 +50239,268 @@ Execute rlogind in the rlogin domain.

+
+Module: +rpc

+Layer: +services

+

+ +rpc_domtrans_nfsd( + + + + + domain + + + )
+
+ +
+

+Execute domain in nfsd domain. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_dontaudit_getattr_exports( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the attributes +of the NFS export file. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_manage_nfs_ro_content( + + + + + domain + + + )
+
+ +
+

+Allow domain to create read and write NFS directories. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_manage_nfs_rw_content( + + + + + domain + + + )
+
+ +
+

+Allow domain to create read and write NFS directories. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_read_exports( + + + + + domain + + + )
+
+ +
+

+Allow read access to exports. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_search_nfs_state_data( + + + + + domain + + + )
+
+ +
+

+Search NFS state data in /var/lib/nfs. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_udp_rw_nfs_sockets( + + + + + domain + + + )
+
+ +
+

+Allow domain to read and write to an NFS UDP socket. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_udp_sendto( + + + + + domain + + + )
+
+ +
+

+Send UDP network traffic to rpc and recieve UDP traffic from rpc. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_udp_sendto_nfs( + + + + + domain + + + )
+
+ +
+

+Allow NFS to send UDP network traffic +the specified domain and recieve from it. +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_write_exports( + + + + + domain + + + )
+
+ +
+

+Allow write access to exports. +

+
+ +
+
Module: rpm

@@ -45035,6 +50527,33 @@ Execute rpm programs in the rpm domain.

+
+Module: +rpm

+Layer: +admin

+

+ +rpm_dontaudit_manage_db( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to create, read, +write, and delete the RPM package database. +

+
+ +
+
Module: rpm

@@ -45285,6 +50804,32 @@ Domain transition to rshd.

+
+Module: +samba

+Layer: +services

+

+ +samba_connect_winbind( + + + + + domain + + + )
+
+ +
+

+Connect to winbind. +

+
+ +
+
Module: samba

@@ -45480,32 +51025,6 @@ services

- domain - - - )
-

- -
-

-Allow the specified domain to read the winbind pid files. -

-
- -
- -
-Module: -samba

-Layer: -services

-

- -samba_read_winbind_pid( - - - - domain @@ -45659,6 +51178,60 @@ Allow the specified domain to read and write to smbmount tcp sockets.
+
+Module: +samba

+Layer: +services

+

+ +samba_rw_var_files( + + + + + domain + + + )
+
+ +
+

+Allow the specified domain to +read and write samba /var files. +

+
+ +
+ +
+Module: +samba

+Layer: +services

+

+ +samba_search_var( + + + + + domain + + + )
+
+ +
+

+Allow the specified domain to search +samba /var directories. +

+
+ +
+
Module: samba

@@ -45685,6 +51258,32 @@ Allow the specified domain to write to smbmount tcp sockets.

+
+Module: +sasl

+Layer: +services

+

+ +sasl_connect( + + + + + domain + + + )
+
+ +
+

+Connect to SASL. +

+
+ +
+
Module: selinux

@@ -45843,6 +51442,33 @@ attributes of the selinuxfs directory.

+
+Module: +selinux

+Layer: +kernel

+

+ +selinux_dontaudit_read_fs( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read +generic selinuxfs entries +

+
+ +
+
Module: selinux

@@ -45989,18 +51615,6 @@ kernel

domain - - , - - - - [ - - booltype - - ] - - )

@@ -46118,6 +51732,32 @@ Allows caller to validate security contexts.
+
+Module: +sendmail

+Layer: +services

+

+ +sendmail_create_log( + + + + + domain + + + )
+
+ +
+

+Create sendmail logs with the correct type. +

+
+ +
+
Module: sendmail

@@ -46144,6 +51784,58 @@ Domain transition to sendmail.

+
+Module: +sendmail

+Layer: +services

+

+ +sendmail_manage_log( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete sendmail logs. +

+
+ +
+ +
+Module: +sendmail

+Layer: +services

+

+ +sendmail_rw_tcp_socket( + + + + + domain + + + )
+
+ +
+

+Read and write sendmail TCP sockets. +

+
+ +
+
Module: sendmail

@@ -47170,6 +52862,112 @@ Summary is missing!

+
+Module: +snmp

+Layer: +services

+

+ +snmp_use( + + + + + domain + + + )
+
+ +
+

+Use snmp over a TCP connection. +

+
+ +
+ +
+Module: +spamassassin

+Layer: +services

+

+ +spamassassin_exec( + + + + + domain + + + )
+
+ +
+

+Execute the standalone spamassassin +program in the caller directory. +

+
+ +
+ +
+Module: +spamassassin

+Layer: +services

+

+ +spamassassin_exec_client( + + + + + domain + + + )
+
+ +
+

+Execute the spamassassin client +program in the caller directory. +

+
+ +
+ +
+Module: +squid

+Layer: +services

+

+ +squid_append_log( + + + + + domain + + + )
+
+ +
+

+Append squid logs. +

+
+ +
+
Module: squid

@@ -47249,6 +53047,32 @@ Read squid configuration file.

+
+Module: +squid

+Layer: +services

+

+ +squid_read_log( + + + + + domain + + + )
+
+ +
+

+Append squid logs. +

+
+ +
+
Module: squid

@@ -47594,33 +53418,6 @@ the generic SCSI interface device nodes.

-
-Module: -storage

-Layer: -kernel

-

- -storage_getattr_scsi_generic( - - - - - domain - - - )
-
- -
-

-Get attributes of the device nodes -for the SCSI generic inerface. -

-
- -
-
Module: storage

@@ -48276,6 +54073,33 @@ Create DHCP state data.

+
+Module: +sysnetwork

+Layer: +system

+

+ +sysnet_dbus_chat_dhcpc( + + + + + domain + + + )
+
+ +
+

+Send and receive messages from +dhcpc over dbus. +

+
+ +
+
Module: sysnetwork

@@ -48380,6 +54204,32 @@ Execute ifconfig in the ifconfig domain.

+
+Module: +sysnetwork

+Layer: +system

+

+ +sysnet_dontaudit_read_config( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read network config files. +

+
+ +
+
Module: sysnetwork

@@ -50157,6 +56007,32 @@ udev file descriptor.

+
+Module: +udev

+Layer: +system

+

+ +udev_helper_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute a udev helper in the udev domain. +

+
+ +
+
Module: udev

@@ -50235,6 +56111,58 @@ Allow process to modify list of devices.

+
+Module: +unconfined

+Layer: +system

+

+ +unconfined_alias_domain( + + + + + domain + + + )
+
+ +
+

+Add an alias type to the unconfined domain. +

+
+ +
+ +
+Module: +unconfined

+Layer: +system

+

+ +unconfined_dbus_send( + + + + + domain + + + )
+
+ +
+

+Send messages to the unconfined domain over dbus. +

+
+ +
+
Module: unconfined

@@ -50261,6 +56189,32 @@ Transition to the unconfined domain.

+
+Module: +unconfined

+Layer: +system

+

+ +unconfined_dontaudit_read_pipe( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to read unconfined domain unnamed pipes. +

+
+ +
+
Module: unconfined

@@ -50289,13 +56243,13 @@ unconfined domain tcp sockets.

-Module: +Module: unconfined

Layer: system

-unconfined_role( +unconfined_read_pipe( @@ -50308,7 +56262,7 @@ system

-Add the unconfined domain to the specified role. +Read unconfined domain unnamed pipes.

@@ -50434,6 +56388,32 @@ Send a SIGCHLD signal to the unconfined domain.
+
+Module: +unconfined

+Layer: +system

+

+ +unconfined_signal( + + + + + domain + + + )
+
+ +
+

+Send generic signals to the unconfined domain. +

+
+ +
+
Module: unconfined

@@ -50487,13 +56467,13 @@ Execute updfstab in the updfstab domain.

-Module: +Module: userdomain

Layer: system

-userdom_create_user_home( +userdom_create_generic_user_home( @@ -50526,13 +56506,13 @@ with automatic file type transition.
-Module: +Module: userdomain

Layer: system

-userdom_create_user_home_dir( +userdom_create_generic_user_home_dir( @@ -50552,6 +56532,126 @@ with automatic file type transition.
+
+Module: +userdomain

+Layer: +system

+

+ +userdom_create_sysadm_home( + + + + + domain + + + + , + + + + [ + + object_class + + ] + + + )
+
+ +
+

+Create objects in sysadm home directories +with automatic file type transition. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_dbus_send_all_users( + + + + + domain + + + )
+
+ +
+

+Send a dbus message to all user domains. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_dontaudit_getattr_sysadm_home_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the +attributes of the sysadm users +home directory. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_dontaudit_getattr_sysadm_tty( + + + + + domain + + + )
+
+ +
+

+Do not audit attepts to get the attributes +of sysadm ttys. +

+
+ +
+
Module: userdomain

@@ -50817,6 +56917,33 @@ file descriptors from all user domains.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_dontaudit_use_unpriv_user_pty( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to use unprivileged +user ptys. +

+
+ +
+
Module: userdomain

@@ -50844,6 +56971,32 @@ user ttys.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_getattr_all_userdomains( + + + + + domain + + + )
+
+ +
+

+Get the attributes of all user domains. +

+
+ +
+
Module: userdomain

@@ -50871,6 +57024,58 @@ home directory.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_list_sysadm_home_dir( + + + + + domain + + + )
+
+ +
+

+List the sysadm users home directory. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_list_unpriv_user_tmp( + + + + + domain + + + )
+
+ +
+

+Read all unprivileged users temporary directories. +

+
+ +
+
Module: userdomain

@@ -50953,13 +57158,13 @@ in all users home directories.

-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_dir( +userdom_manage_generic_user_home_dir( @@ -50980,13 +57185,13 @@ generic user home directories.
-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_dirs( +userdom_manage_generic_user_home_dirs( @@ -51008,13 +57213,13 @@ home directories.
-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_files( +userdom_manage_generic_user_home_files( @@ -51035,13 +57240,13 @@ in generic user home directories.
-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_pipes( +userdom_manage_generic_user_home_pipes( @@ -51062,13 +57267,13 @@ pipes in generic user home directories.
-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_sockets( +userdom_manage_generic_user_home_sockets( @@ -51089,13 +57294,13 @@ sockets in generic user home directories.
-Module: +Module: userdomain

Layer: system

-userdom_manage_user_home_symlinks( +userdom_manage_generic_user_home_symlinks( @@ -51115,6 +57320,33 @@ links in generic user home directories.
+
+Module: +userdomain

+Layer: +system

+

+ +userdom_priveleged_home_dir_manager( + + + + + domain + + + )
+
+ +
+

+Make the specified domain a privileged +home directory manager. +

+
+ +
+
Module: userdomain

@@ -51141,6 +57373,32 @@ Read all files in all users home directories.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_read_all_userdomains_state( + + + + + domain + + + )
+
+ +
+

+Read the process state of all user domains. +

+
+ +
+
Module: userdomain

@@ -51220,6 +57478,58 @@ files.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_read_unpriv_user_tmp_files( + + + + + domain + + + )
+
+ +
+

+Read all unprivileged users temporary files. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_read_unpriv_user_tmp_symlinks( + + + + + domain + + + )
+
+ +
+

+Read all unprivileged users temporary symbolic links. +

+
+ +
+
Module: userdomain

@@ -51272,6 +57582,32 @@ Search all users home directories.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_search_generic_user_home_dir( + + + + + domain + + + )
+
+ +
+

+Search generic user home directories. +

+
+ +
+
Module: userdomain

@@ -51324,6 +57660,32 @@ Search the sysadm users home directory.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_search_sysadm_home_subdirs( + + + + + domain + + + )
+
+ +
+

+Search the sysadm users home sub directories. +

+
+ +
+
Module: userdomain

@@ -51350,6 +57712,32 @@ Search all unprivileged users home directories.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_setattr_unpriv_user_pty( + + + + + domain + + + )
+
+ +
+

+Set the attributes of user ptys. +

+
+ +
+
Module: userdomain

@@ -51376,6 +57764,32 @@ Execute a shell in the sysadm domain.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_sigchld_all_users( + + + + + domain + + + )
+
+ +
+

+Send a SIGCHLD signal to all user domains. +

+
+ +
+
Module: userdomain

@@ -51402,32 +57816,6 @@ Send a SIGCHLD signal to sysadm users.

-
-Module: -userdomain

-Layer: -system

-

- -userdom_sigcld_all_users( - - - - - domain - - - )
-
- -
-

-Send a SIGCHLD signal to all user domains. -

-
- -
-
Module: userdomain

@@ -51692,6 +58080,32 @@ Read and write sysadm ttys.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_use_unpriv_user_pty( + + + + + domain + + + )
+
+ +
+

+Read and write unprivileged user ptys. +

+
+ +
+
Module: userdomain

@@ -51901,6 +58315,50 @@ Read the crack database.

+
+Module: +usermanage

+Layer: +admin

+

+ +usermanage_run_admin_passwd( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+ +
+

+Execute passwd admin functions in the admin +passwd domain, and allow the specified role +the admin passwd domain. +

+
+ +
+
Module: usermanage

@@ -52211,6 +58669,32 @@ allow the specified role the webalizer domain.

+
+Module: +xfs

+Layer: +services

+

+ +xfs_read_socket( + + + + + domain + + + )
+
+ +
+

+Read a X font server named socket. +

+
+ +
+
Module: zebra

diff --git a/www/api-docs/kernel.html b/www/api-docs/kernel.html index 05604c72..5667144b 100644 --- a/www/api-docs/kernel.html +++ b/www/api-docs/kernel.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -102,6 +111,14 @@ Policy for kernel threads, proc filesystem,and unlabeled processes and objects. bootloader

Policy for the kernel modules, kernel image, and bootloader.

+ + + corecommands +

+Core policy for shells, and generic programs +in /bin, /sbin, /usr/bin, and /usr/sbin. +

+ corenetwork @@ -112,6 +129,18 @@ Policy for kernel threads, proc filesystem,and unlabeled processes and objects. devices

Device nodes and interfaces for many basic system devices. +

+ + + + domain +

Core policy for domains.

+ + + + files +

+Basic filesystem types and interfaces.

diff --git a/www/api-docs/kernel_bootloader.html b/www/api-docs/kernel_bootloader.html index 34cd583b..5ec0660b 100644 --- a/www/api-docs/kernel_bootloader.html +++ b/www/api-docs/kernel_bootloader.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
diff --git a/www/api-docs/system_corecommands.html b/www/api-docs/kernel_corecommands.html similarity index 84% rename from www/api-docs/system_corecommands.html rename to www/api-docs/kernel_corecommands.html index ff33bb5c..9068d767 100644 --- a/www/api-docs/system_corecommands.html +++ b/www/api-docs/kernel_corecommands.html @@ -25,6 +25,42 @@ kernel
+    -  + bootloader
+ +    -  + corecommands
+ +    -  + corenetwork
+ +    -  + devices
+ +    -  + domain
+ +    -  + files
+ +    -  + filesystem
+ +    -  + kernel
+ +    -  + mls
+ +    -  + selinux
+ +    -  + storage
+ +    -  + terminal
+
+  @@ -37,84 +73,6 @@ system
-    -  - authlogin
- -    -  - clock
- -    -  - corecommands
- -    -  - domain
- -    -  - files
- -    -  - fstools
- -    -  - getty
- -    -  - hostname
- -    -  - hotplug
- -    -  - init
- -    -  - ipsec
- -    -  - iptables
- -    -  - libraries
- -    -  - locallogin
- -    -  - logging
- -    -  - lvm
- -    -  - miscfiles
- -    -  - modutils
- -    -  - mount
- -    -  - pcmcia
- -    -  - raid
- -    -  - selinuxutil
- -    -  - sysnetwork
- -    -  - udev
- -    -  - unconfined
- -    -  - userdomain
-

@@ -131,7 +89,7 @@

-

Layer: system

+

Layer: kernel

Module: corecommands

Description:

@@ -148,6 +106,60 @@ in /bin, /sbin, /usr/bin, and /usr/sbin.

Interfaces:

+ +
+ + +
+ +corecmd_bin_alias( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create a aliased type to generic bin files. +

+ + +
Description
+

+

+Create a aliased type to generic bin files. +

+

+This is added to support targeted policy. Its +use should be limited. It has no effect +on the strict policy. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Alias type for bin_t. + + +No +
+
+
+
@@ -209,7 +221,7 @@ the ssh-agent policy. domain -The type of the process performing this action. +Domain allowed access. No @@ -229,6 +241,48 @@ No
+ +
+ + +
+ +corecmd_check_exec_shell( + + + + + domain + + + )
+
+
+ +
Summary
+

+Check if a shell is executable (DAC-wise). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -271,6 +325,49 @@ No
+ +
+ + +
+ +corecmd_dontaudit_search_sbin( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to search +sbin directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -513,7 +610,7 @@ Get the attributes of files in bin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -681,7 +778,7 @@ Read files in bin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -723,7 +820,7 @@ Read pipes in bin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -765,7 +862,7 @@ Read named sockets in bin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -807,7 +904,7 @@ Read symbolic links in bin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -849,7 +946,7 @@ Read files in sbin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -891,7 +988,7 @@ Read named pipes in sbin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -933,7 +1030,7 @@ Read named sockets in sbin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -975,7 +1072,7 @@ Read symbolic links in sbin directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -1046,7 +1143,7 @@ the ssh-agent policy. domain -The type of the process performing this action. +Domain allowed access. No @@ -1202,7 +1299,7 @@ the domains are not owned by this module. domain -The type of the process performing this action. +Domain allowed access. No @@ -1320,7 +1417,7 @@ the domains are not owned by this module. domain -The type of the process performing this action. +Domain allowed access. No diff --git a/www/api-docs/kernel_corenetwork.html b/www/api-docs/kernel_corenetwork.html index b535756c..11e61b88 100644 --- a/www/api-docs/kernel_corenetwork.html +++ b/www/api-docs/kernel_corenetwork.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -221,6 +230,92 @@ No
+ +
+ + +
+ +corenet_non_ipsec_sendrecv( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages on a +non-encrypted (no IPSEC) network +session. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +corenet_raw_bind_all_nodes( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind raw sockets to all nodes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -2387,6 +2482,48 @@ Bind TCP sockets to node compat_ipv4.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_bind_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the comsat port. +

+ +
Parameters
@@ -2639,6 +2776,48 @@ Bind TCP sockets to the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_bind_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the distccd port. +

+ +
Parameters
@@ -2807,6 +2986,48 @@ Bind TCP sockets to the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_bind_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the gatekeeper port. +

+ +
Parameters
@@ -3143,6 +3364,48 @@ Bind TCP sockets to the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_bind_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the i18n_input port. +

+ +
Parameters
@@ -4781,6 +5044,48 @@ Bind TCP sockets to generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_bind_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the rlogind port. +

+ +
Parameters
@@ -6251,6 +6556,48 @@ Make a TCP connection to the clockspeed port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the comsat port. +

+ +
Parameters
@@ -6503,6 +6850,48 @@ Make a TCP connection to the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the distccd port. +

+ +
Parameters
@@ -6671,6 +7060,48 @@ Make a TCP connection to the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the gatekeeper port. +

+ +
Parameters
@@ -6965,6 +7396,48 @@ Make a TCP connection to the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the i18n_input port. +

+ +
Parameters
@@ -8393,6 +8866,48 @@ Connect TCP sockets to generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the rlogind port. +

+ +
Parameters
@@ -9905,6 +10420,48 @@ Send and receive TCP traffic on the compat_ipv4 node.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the comsat port. +

+ +
Parameters
@@ -10157,6 +10714,48 @@ Send and receive TCP traffic on the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the distccd port. +

+ +
Parameters
@@ -10325,6 +10924,48 @@ Send and receive TCP traffic on the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the gatekeeper port. +

+ +
Parameters
@@ -10703,6 +11344,48 @@ Send and receive TCP traffic on the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the i18n_input port. +

+ +
Parameters
@@ -12341,6 +13024,48 @@ Send and receive TCP network traffic on generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the rlogind port. +

+ +
Parameters
@@ -13895,6 +14620,48 @@ Bind UDP sockets to the compat_ipv4 node.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the comsat port. +

+ +
Parameters
@@ -14147,6 +14914,48 @@ Bind UDP sockets to the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the distccd port. +

+ +
Parameters
@@ -14315,6 +15124,48 @@ Bind UDP sockets to the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the gatekeeper port. +

+ +
Parameters
@@ -14651,6 +15502,48 @@ Bind UDP sockets to the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the i18n_input port. +

+ +
Parameters
@@ -16289,6 +17182,48 @@ Bind UDP sockets to generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the rlogind port. +

+ +
Parameters
@@ -17885,6 +18820,48 @@ Receive UDP traffic on the compat_ipv4 node.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the comsat port. +

+ +
Parameters
@@ -18137,6 +19114,48 @@ Receive UDP traffic on the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the distccd port. +

+ +
Parameters
@@ -18305,6 +19324,48 @@ Receive UDP traffic on the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the gatekeeper port. +

+ +
Parameters
@@ -18683,6 +19744,48 @@ Receive UDP traffic on the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the i18n_input port. +

+ +
Parameters
@@ -20321,6 +21424,48 @@ Receive UDP network traffic on generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the rlogind port. +

+ +
Parameters
@@ -21917,6 +23062,48 @@ Send UDP traffic on the compat_ipv4 node.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the comsat port. +

+ +
Parameters
@@ -22169,6 +23356,48 @@ Send UDP traffic on the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the distccd port. +

+ +
Parameters
@@ -22337,6 +23566,48 @@ Send UDP traffic on the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the gatekeeper port. +

+ +
Parameters
@@ -22715,6 +23986,48 @@ Send UDP traffic on the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the i18n_input port. +

+ +
Parameters
@@ -24353,6 +25666,48 @@ Send UDP network traffic on generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the rlogind port. +

+ +
Parameters
@@ -25949,6 +27304,48 @@ Send and receive UDP traffic on the compat_ipv4 node.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_comsat_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the comsat port. +

+ +
Parameters
@@ -26201,6 +27598,48 @@ Send and receive UDP traffic on the dict port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_distccd_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the distccd port. +

+ +
Parameters
@@ -26369,6 +27808,48 @@ Send and receive UDP traffic on the ftp port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_gatekeeper_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the gatekeeper port. +

+ +
Parameters
@@ -26747,6 +28228,48 @@ Send and receive UDP traffic on the http port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_i18n_input_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the i18n_input port. +

+ +
Parameters
@@ -28385,6 +29908,48 @@ Send and receive UDP network traffic on generic reserved ports.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_rlogind_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the rlogind port. +

+ +
Parameters
diff --git a/www/api-docs/kernel_devices.html b/www/api-docs/kernel_devices.html index 1e7104f6..02f90019 100644 --- a/www/api-docs/kernel_devices.html +++ b/www/api-docs/kernel_devices.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -115,6 +124,134 @@ this module.

Interfaces:

+ +
+ + +
+ +dev_append_printer( + + + + + domain + + + )
+
+
+ +
Summary
+

+Append the printer device. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +dev_associate_usbfs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Mount a usbfs filesystem. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +dev_create_cardmgr( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete +the PCMCIA card manager device +with the correct type. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -726,6 +863,49 @@ the scanner device.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +dev_dontaudit_getattr_usbfs_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the attributes +of a directory in the usb filesystem. +

+ +
Parameters
@@ -1869,6 +2049,48 @@ Get the attributes of the mouse devices.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +dev_getattr_mtrr( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of the mtrr device. +

+ +
Parameters
@@ -2391,13 +2613,13 @@ No - +
-dev_manage_dev_nodes( +dev_manage_cardmgr( @@ -2411,7 +2633,8 @@ No
Summary

-Create, delete, read, and write device nodes in device directories. +Create, read, write, and delete +the PCMCIA card manager device.

@@ -2433,13 +2656,13 @@ No
- +
-dev_manage_generic_blk_file( +dev_manage_dev_nodes( @@ -2453,8 +2676,7 @@ No
Summary

-Allow read, write, create, and delete for generic -block files. +Create, delete, read, and write device nodes in device directories.

@@ -3510,6 +3732,48 @@ Read and write the apm bios.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +dev_rw_cardmgr( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write the PCMCIA card manager device. +

+ +
Parameters
diff --git a/www/api-docs/system_domain.html b/www/api-docs/kernel_domain.html similarity index 88% rename from www/api-docs/system_domain.html rename to www/api-docs/kernel_domain.html index c4ab57dd..c72992b3 100644 --- a/www/api-docs/system_domain.html +++ b/www/api-docs/kernel_domain.html @@ -25,6 +25,42 @@ kernel
+    -  + bootloader
+ +    -  + corecommands
+ +    -  + corenetwork
+ +    -  + devices
+ +    -  + domain
+ +    -  + files
+ +    -  + filesystem
+ +    -  + kernel
+ +    -  + mls
+ +    -  + selinux
+ +    -  + storage
+ +    -  + terminal
+
+  @@ -37,84 +73,6 @@ system
-    -  - authlogin
- -    -  - clock
- -    -  - corecommands
- -    -  - domain
- -    -  - files
- -    -  - fstools
- -    -  - getty
- -    -  - hostname
- -    -  - hotplug
- -    -  - init
- -    -  - ipsec
- -    -  - iptables
- -    -  - libraries
- -    -  - locallogin
- -    -  - logging
- -    -  - lvm
- -    -  - miscfiles
- -    -  - modutils
- -    -  - mount
- -    -  - pcmcia
- -    -  - raid
- -    -  - selinuxutil
- -    -  - sysnetwork
- -    -  - udev
- -    -  - unconfined
- -    -  - userdomain
-

@@ -131,7 +89,7 @@

-

Layer: system

+

Layer: kernel

Module: domain

Interfaces @@ -324,6 +282,91 @@ No

+ +
+ + +
+ +domain_dontaudit_getattr_all_dgram_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the attributes +of all domains unix datagram sockets. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +domain_dontaudit_getattr_all_domains( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of all domains of all domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -349,6 +392,135 @@ all domains IPSEC key management sockets.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +domain_dontaudit_getattr_all_packet_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get attribues of +all domains packet sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +domain_dontaudit_getattr_all_pipes( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the attributes +of all domains unnamed pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +domain_dontaudit_getattr_all_raw_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get attribues of +all domains raw sockets. +

+ +
Parameters
@@ -422,6 +594,49 @@ No + +
+ + +
+ +domain_dontaudit_getattr_all_stream_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the attributes +of all domains unix datagram sockets. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -490,92 +705,6 @@ of all domains UDP sockets.

-
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -The type of the process performing this action. - - -No -
-
-
- - -
- - -
- -domain_dontaudit_getattr_all_unix_dgram_sockets( - - - - - domain - - - )
-
-
- -
Summary
-

-Do not audit attempts to get the attributes -of all domains unix datagram sockets. -

- - -
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -The type of the process performing this action. - - -No -
-
-
- - -
- - -
- -domain_dontaudit_getattr_all_unnamed_pipes( - - - - - domain - - - )
-
-
- -
Summary
-

-Do not audit attempts to get the attributes -of all domains unnamed pipes. -

- -
Parameters
@@ -917,6 +1046,49 @@ No + +
+ + +
+ +domain_dontaudit_search_all_domains_state( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to search the process +state directory (/proc/pid) of all domains. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
diff --git a/www/api-docs/system_files.html b/www/api-docs/kernel_files.html similarity index 90% rename from www/api-docs/system_files.html rename to www/api-docs/kernel_files.html index 75d1af16..4db3242a 100644 --- a/www/api-docs/system_files.html +++ b/www/api-docs/kernel_files.html @@ -25,6 +25,42 @@ kernel
+    -  + bootloader
+ +    -  + corecommands
+ +    -  + corenetwork
+ +    -  + devices
+ +    -  + domain
+ +    -  + files
+ +    -  + filesystem
+ +    -  + kernel
+ +    -  + mls
+ +    -  + selinux
+ +    -  + storage
+ +    -  + terminal
+
+  @@ -37,84 +73,6 @@ system
-    -  - authlogin
- -    -  - clock
- -    -  - corecommands
- -    -  - domain
- -    -  - files
- -    -  - fstools
- -    -  - getty
- -    -  - hostname
- -    -  - hotplug
- -    -  - init
- -    -  - ipsec
- -    -  - iptables
- -    -  - libraries
- -    -  - locallogin
- -    -  - logging
- -    -  - lvm
- -    -  - miscfiles
- -    -  - modutils
- -    -  - mount
- -    -  - pcmcia
- -    -  - raid
- -    -  - selinuxutil
- -    -  - sysnetwork
- -    -  - udev
- -    -  - unconfined
- -    -  - userdomain
-

@@ -131,7 +89,7 @@

-

Layer: system

+

Layer: kernel

Module: files

Description:

@@ -201,6 +159,49 @@ No
+ +
+ + +
+ +files_config_file( + + + + + file_type + + + )
+
+
+ +
Summary
+

+Make the specified type a +configuration file. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+file_type + + +Type to be used as a configuration file. + + +No +
+
+
+
@@ -2539,6 +2540,49 @@ Get the attributes of all directories.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +files_getattr_all_file_type_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of all sockets +with the type of a file. +

+ +
Parameters
@@ -2810,6 +2854,48 @@ No + +
+ + +
+ +files_getattr_tmp_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of the tmp directory (/tmp). +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -2894,13 +2980,13 @@ No
- +
-files_list_all_dirs( +files_list_all( @@ -3315,6 +3401,48 @@ No
+ +
+ + +
+ +files_list_tmp( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read the tmp directory (/tmp). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -4170,6 +4298,49 @@ Create, read, write, and delete symbolic links in /mnt.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +files_manage_mounttab( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow domain to manage mount tables +necessary for rpcd, nfsd, etc. +

+ +
Parameters
@@ -4890,6 +5061,156 @@ No + +
+ + +
+ +files_read_all_blk_nodes( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all block nodes with file types. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +files_read_all_chr_nodes( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all character nodes with file types. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +files_read_all_dirs_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all directories on the filesystem, except +the listed exceptions. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+
@@ -4932,6 +5253,72 @@ No
+ +
+ + +
+ +files_read_all_files_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all files on the filesystem, except +the listed exceptions. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+
@@ -5016,6 +5403,72 @@ No
+ +
+ + +
+ +files_read_all_symlinks_except( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all symbloic links on the filesystem, except +the listed exceptions. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+
@@ -5311,6 +5764,90 @@ No
+ +
+ + +
+ +files_read_generic_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read files in the tmp directory (/tmp). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +files_read_generic_tmp_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read symbolic links in the tmp directory (/tmp). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -5882,6 +6419,48 @@ yes
+ +
+ + +
+ +files_relabel_etc_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Relabel from and to generic files in /etc. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -6093,6 +6672,48 @@ No
+ +
+ + +
+ +files_rw_generic_tmp_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write generic named sockets in the tmp directory (/tmp). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -6750,6 +7371,48 @@ Search the /var/lib directory.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +files_search_var_lib_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search directories in /var/lib. +

+ +
Parameters
diff --git a/www/api-docs/kernel_filesystem.html b/www/api-docs/kernel_filesystem.html index 05db9d7c..081f4023 100644 --- a/www/api-docs/kernel_filesystem.html +++ b/www/api-docs/kernel_filesystem.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -1346,6 +1355,49 @@ No + +
+ + +
+ +fs_getattr_all_dirs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of all directories +with a filesystem type. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -1912,6 +1964,48 @@ No
+ +
+ + +
+ +fs_getattr_rpc_dirs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read directories of RPC file system pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain reading the symbolic links. + + +No +
+
+
+
@@ -2162,7 +2256,49 @@ CIFS or SMB filesystem. domain -The type of the domain reading the files. +Domain allowed access. + + +No + + + +
+
+ + +
+ + +
+ +fs_list_noxattr_fs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all noxattrfs directories. +

+ + +
Parameters
+ + + + - -
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -3568,50 +3704,7 @@ Read files on a CIFS or SMB filesystem. domain -The type of the domain reading the files. - - -No -
-
-
- - -
- - -
- -fs_read_cifs_files( - - - - - domain - - - )
-
-
- -
Summary
-

-Do not audit attempts to read or -write files on a CIFS or SMB filesystems. -

- - -
Parameters
- - - - + +
Parameter:Description:Optional:
-domain - - -The type of the domain to not audit. +Domain allowed access. No @@ -3695,7 +3788,7 @@ Read files on a NFS filesystem. domain -The type of the domain reading the files. +Domain allowed access. No @@ -3729,6 +3822,258 @@ Read symbolic links on a NFS filesystem.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain reading the symbolic links. + + +No +
+ + + + +
+ + +
+ +fs_read_noxattr_fs_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all noxattrfs files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +fs_read_noxattr_fs_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all noxattrfs symbolic links. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +fs_read_rpc_dirs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read directories of RPC file system pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain reading the symbolic links. + + +No +
+
+
+ + +
+ + +
+ +fs_read_rpc_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read files of RPC file system pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain reading the symbolic links. + + +No +
+
+
+ + +
+ + +
+ +fs_read_rpc_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read sockets of RPC file system pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain reading the symbolic links. + + +No +
+
+
+ + +
+ + +
+ +fs_read_rpc_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read symbolic links of RPC file system pipes. +

+ +
Parameters
@@ -4529,6 +4874,133 @@ No + +
+ + +
+ +fs_rw_nfsd_fs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write NFS server files. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain doing the +read or write on nfsd files. + + +No +
+
+
+ + +
+ + +
+ +fs_rw_ramfs_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write a named pipe on a ramfs filesystem. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +fs_rw_tmpfs_file( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write generic tmpfs files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -4646,7 +5118,7 @@ Search directories on a CIFS or SMB filesystem. domain
-The type of the domain reading the files. +Domain allowed access. No @@ -4688,7 +5160,50 @@ Search directories on a NFS filesystem. domain -The type of the domain reading the files. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +fs_search_nfsd_fs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search NFS server directories. +

+ + +
Parameters
+ + + +
Parameter:Description:Optional:
+domain + + +The type of the domain doing the +search on nfsd directories. No @@ -5585,6 +6100,90 @@ No + +
+ + +
+ +fs_write_nfs_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read files on a NFS filesystem. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +fs_write_ramfs_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Write to named pipe on a ramfs filesystem. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
diff --git a/www/api-docs/kernel_kernel.html b/www/api-docs/kernel_kernel.html index 333c2846..f1ab1807 100644 --- a/www/api-docs/kernel_kernel.html +++ b/www/api-docs/kernel_kernel.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -128,7 +137,7 @@ Change the level of kernel messages logged to the console. domain
-The type of the process performing this action. +Domain allowed access. No @@ -291,6 +300,349 @@ unlabeled block devices.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+ + + + +
+ + +
+ +kernel_dontaudit_getattr_unlabeled_chr_dev( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to get attributes for +unlabeled character devices. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_getattr_unlabeled_file( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to get the +attributes of an unlabeled file. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_getattr_unlabeled_pipes( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to get the +attributes of unlabeled named pipes. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_getattr_unlabeled_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to get the +attributes of unlabeled named sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_getattr_unlabeled_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to get the +attributes of unlabeled symbolic links. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type not to audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_list_proc( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to list the +contents of directories in /proc. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_list_unlabeled( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to list unlabeled directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +kernel_dontaudit_read_proc_symlink( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to +read system state information in proc. +

+ +
Parameters
@@ -394,6 +746,49 @@ No + +
+ + +
+ +kernel_dontaudit_read_unlabeled_file( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts by caller to +read an unlabeled file. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -842,6 +1237,48 @@ Get the attributes of the proc filesystem.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +kernel_getattr_proc_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of files in /proc. +

+ +
Parameters
@@ -892,7 +1329,7 @@ Send a kill signal to unlabeled processes. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -1145,7 +1582,7 @@ Allow caller to read all sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -1314,7 +1751,7 @@ Read filesystem sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -1356,7 +1793,7 @@ Read the hotplug sysctl. domain -The type of the process performing this action. +Domain allowed access. No @@ -1398,7 +1835,7 @@ Read IRQ sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -1440,7 +1877,7 @@ Read generic kernel sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -1525,7 +1962,7 @@ Read the modprobe sysctl. domain -The type of the process performing this action. +Domain allowed access. No @@ -1567,7 +2004,7 @@ Allow caller to read network sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -1601,6 +2038,48 @@ Allow caller to read the network state information.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The process type reading the state. + + +No +
+ + + + +
+ + +
+ +kernel_read_network_state_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow caller to read the network state symbolic links. +

+ +
Parameters
@@ -1787,6 +2266,48 @@ No + +
+ + +
+ +kernel_read_sysctl( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow access to read sysctl directories. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The process type to allow to read sysctl directories. + + +No +
+
+
+
@@ -1862,7 +2383,7 @@ socket sysctls. domain
-The type of the process performing this action. +Domain allowed access. No @@ -1904,7 +2425,7 @@ Allow caller to read virtual memory sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2073,7 +2594,7 @@ Read and write all sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2115,7 +2636,7 @@ Read and write device sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2157,7 +2678,7 @@ Read and write fileystem sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2199,7 +2720,7 @@ Read and write the hotplug sysctl. domain -The type of the process performing this action. +Domain allowed access. No @@ -2241,7 +2762,7 @@ Read and write IRQ sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2283,7 +2804,7 @@ Read and write generic kernel sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2325,7 +2846,7 @@ Read and write the modprobe sysctl. domain -The type of the process performing this action. +Domain allowed access. No @@ -2367,7 +2888,7 @@ Allow caller to modiry contents of sysctl network files. domain -The type of the process performing this action. +Domain allowed access. No @@ -2578,7 +3099,7 @@ socket sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2662,7 +3183,7 @@ Read and write virtual memory sysctls. domain -The type of the process performing this action. +Domain allowed access. No @@ -2757,18 +3278,18 @@ No - +
-kernel_search_from( +kernel_search_network_state( - dir_type + domain )
@@ -2777,8 +3298,7 @@ No
Summary

-Allow the kernel to search the -specified directory. +Allow searching of network state directory.

@@ -2787,10 +3307,10 @@ specified directory.
Parameter:Description:Optional:
-dir_type +domain -Directory type to search. +The process type reading the state. No @@ -2866,6 +3386,48 @@ Search directories in /proc.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+ + + + +
+ + +
+ +kernel_search_vm_sysctl( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow caller to search virtual memory sysctls. +

+ +
Parameters
@@ -2947,6 +3509,65 @@ No + +
+ + +
+ +kernel_sendrecv_unlabeled_association( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from an +unlabeled IPSEC association. +

+ + +
Description
+

+

+Send and receive messages from an +unlabeled IPSEC association. Network +connections that are not protected +by IPSEC have use an unlabeled +assocation. +

+

+The corenetwork interface +corenet_sendrecv_no_ipsec() should +be used instead of this one. +

+

+ +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -3234,7 +3855,7 @@ Send a child terminated signal to unlabeled processes. domain
-The type of the process performing this action. +Domain allowed access. No @@ -3318,7 +3939,7 @@ Send general signals to unlabeled processes. domain -The type of the process performing this action. +Domain allowed access. No @@ -3360,7 +3981,7 @@ Send a null signal to unlabeled processes. domain -The type of the process performing this action. +Domain allowed access. No @@ -3402,7 +4023,7 @@ Send a stop signal to unlabeled processes. domain -The type of the process performing this action. +Domain allowed access. No diff --git a/www/api-docs/kernel_mls.html b/www/api-docs/kernel_mls.html index efc603d1..c8c820bf 100644 --- a/www/api-docs/kernel_mls.html +++ b/www/api-docs/kernel_mls.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
diff --git a/www/api-docs/kernel_selinux.html b/www/api-docs/kernel_selinux.html index bfaec7c4..de51cbfd 100644 --- a/www/api-docs/kernel_selinux.html +++ b/www/api-docs/kernel_selinux.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -343,6 +352,49 @@ attributes of the selinuxfs directory.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+ + + + +
+ + +
+ +selinux_dontaudit_read_fs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read +generic selinuxfs entries +

+ +
Parameters
@@ -586,18 +638,6 @@ No domain - - , - - - - [ - - booltype - - ] - - )
@@ -635,16 +675,6 @@ The process type allowed to set the Boolean. No -
-
Parameter:Description:Optional:
-booltype - - -The type of Booleans the caller is allowed to set. - - -yes -
diff --git a/www/api-docs/kernel_storage.html b/www/api-docs/kernel_storage.html index 06855d54..0996017b 100644 --- a/www/api-docs/kernel_storage.html +++ b/www/api-docs/kernel_storage.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -545,49 +554,6 @@ the generic SCSI interface device nodes.

-
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -The type of the process performing this action. - - -No -
- - - - -
- - -
- -storage_getattr_scsi_generic( - - - - - domain - - - )
-
-
- -
Summary
-

-Get attributes of the device nodes -for the SCSI generic inerface. -

- -
Parameters
diff --git a/www/api-docs/kernel_terminal.html b/www/api-docs/kernel_terminal.html index 8cdb17d7..eb5f4fcb 100644 --- a/www/api-docs/kernel_terminal.html +++ b/www/api-docs/kernel_terminal.html @@ -28,12 +28,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -188,7 +197,7 @@ device nodes. domain + + + @@ -246,6 +314,11 @@ bluetooth + + + @@ -261,11 +334,26 @@ cron + + + + + + + + + @@ -281,6 +369,16 @@ dictd + + + + + + @@ -306,6 +404,11 @@ howl + + + @@ -316,6 +419,11 @@ inn + + + @@ -331,6 +439,11 @@ ldap + + + @@ -346,6 +459,11 @@ mysql + + + @@ -361,11 +479,21 @@ ntp + + + + + + @@ -381,11 +509,26 @@ privoxy + + + + + + + + + @@ -396,6 +539,11 @@ rlogin + + + @@ -430,6 +578,11 @@ from Windows NT servers. snmp + + + @@ -460,11 +613,26 @@ from Windows NT servers. tftp + + + + + + + + + diff --git a/www/api-docs/services_apache.html b/www/api-docs/services_apache.html index 5e06d09f..fbc55f37 100644 --- a/www/api-docs/services_apache.html +++ b/www/api-docs/services_apache.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -601,6 +664,49 @@ No + +
+ + +
+ +apache_dontaudit_search_modules( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to search Apache +module directories. +

+ + +
Parameters
+
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -232,7 +241,7 @@ device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -318,7 +327,7 @@ of all unallocated tty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -490,7 +499,7 @@ any user ttys. domain -The type of the process performing this action. +Domain allowed access. No @@ -533,7 +542,7 @@ or write to the console. domain -The type of the process performing this action. +Domain allowed access. No @@ -706,7 +715,7 @@ pty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -749,7 +758,7 @@ device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -792,7 +801,7 @@ tty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -834,7 +843,7 @@ ioctl of generic pty types. domain -The type of the process performing this action. +Domain allowed access. No @@ -877,7 +886,7 @@ list all ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1005,7 +1014,7 @@ user pty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1048,7 +1057,7 @@ user tty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1091,7 +1100,7 @@ tty type. domain -The type of the process performing this action. +Domain allowed access. No @@ -1133,7 +1142,7 @@ Relabel to all user ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1176,7 +1185,7 @@ the unallocated tty type. domain -The type of the process performing this action. +Domain allowed access. No @@ -1218,7 +1227,7 @@ Search the contents of the /dev/pts directory. domain -The type of the process performing this action. +Domain allowed access. No @@ -1261,7 +1270,7 @@ pty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1304,7 +1313,7 @@ device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1347,7 +1356,7 @@ device node. domain -The type of the process performing this action. +Domain allowed access. No @@ -1390,7 +1399,7 @@ tty device nodes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1475,7 +1484,7 @@ ttys and all ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1517,7 +1526,7 @@ Read and write all user ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1559,7 +1568,7 @@ Read and write all user to all user ttys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1601,7 +1610,7 @@ Read from and write to the console. domain -The type of the process performing this action. +Domain allowed access. No @@ -1644,7 +1653,7 @@ terminal (/dev/tty). domain -The type of the process performing this action. +Domain allowed access. No @@ -1688,7 +1697,7 @@ the targeted policy. domain -The type of the process performing this action. +Domain allowed access. No @@ -1772,7 +1781,7 @@ Read and write unallocated ttys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1877,7 +1886,7 @@ Write to all user ttys. domain -The type of the process performing this action. +Domain allowed access. No @@ -1919,7 +1928,7 @@ Write to the console. domain -The type of the process performing this action. +Domain allowed access. No @@ -1961,7 +1970,7 @@ Write to unallocated ttys. domain -The type of the process performing this action. +Domain allowed access. No diff --git a/www/api-docs/services.html b/www/api-docs/services.html index dc4fdea7..f034e1aa 100644 --- a/www/api-docs/services.html +++ b/www/api-docs/services.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -236,6 +299,11 @@ arpwatch

Ethernet activity monitor.

+ + avahi

mDNS/DNS-SD daemon implementing Apple ZeroConf architecture

bind

Bluetooth tools and system services.

+ + canna

Canna - kana-kanji conversion server

comsat

Periodic execution of scheduled commands.

+ + cups

Common UNIX printing system

cvs

Concurrent versions system

+ + cyrus

Cyrus is an IMAP service intended to be run on sealed servers

+ + dbskk

Dictionary server for the SKK Japanese input method system.

dbus

Dictionary daemon

+ + distcc

Distributed compiler daemon

+ + dovecot

Dovecot POP and IMAP mail server

finger

Port of Apple Rendezvous multicast DNS

+ + i18n_input

IIIMF htt server

inetd

Internet News NNTP server

+ + irqbalance

IRQ balancing daemon

kerberos

OpenLDAP directory server

+ + lpd

Line printer daemon

mailman

Policy for MySQL

+ + networkmanager

Manager for dynamically switching between networks.

nis

Network time protocol daemon

+ + pegasus

The Open Group Pegasus CIM/WBEM Server.

portmap

RPC port mapping service.

+ + postfix

Postfix email server

postgresql

Privacy enhancing web proxy.

+ + procmail

Procmail mail delivery agent

+ + radius

RADIUS authentication and accounting server.

radvd

IPv6 router advertisement daemon

+ + rdisc

Network router discovery daemon

remotelogin

Remote login daemon

+ + rpc

Remote Procedure Call Daemon for managment of network based process communication

rshd

Simple network management protocol services

+ + spamassassin

Filter used for removing unsolicited email.

squid

Trivial file transfer protocol daemon

+ + timidity

MIDI to WAV converter and player configured as a service

uucp

Unix to Unix Copy

+ + xdm

X windows login display manager

+ + xfs

X Windows Font Server

zebra
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -959,6 +1065,48 @@ No
+ +
+ + +
+ +apache_search_sys_script_state( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search system script state directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
diff --git a/www/api-docs/services_apm.html b/www/api-docs/services_apm.html index 2bd681f7..77943dde 100644 --- a/www/api-docs/services_apm.html +++ b/www/api-docs/services_apm.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -320,6 +383,48 @@ Read and write to an apm unix stream socket.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +apm_stream_connect( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to apmd over an unix stream socket. +

+ +
Parameters
diff --git a/www/api-docs/services_arpwatch.html b/www/api-docs/services_arpwatch.html index 6958f7ca..383ae0ce 100644 --- a/www/api-docs/services_arpwatch.html +++ b/www/api-docs/services_arpwatch.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -279,6 +342,48 @@ Create arpwatch data files.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +arpwatch_manage_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write arpwatch temporary files. +

+ +
Parameters
diff --git a/www/api-docs/services_avahi.html b/www/api-docs/services_avahi.html new file mode 100644 index 00000000..beb9fbff --- /dev/null +++ b/www/api-docs/services_avahi.html @@ -0,0 +1,329 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: avahi

+ +

Description:

+ +

mDNS/DNS-SD daemon implementing Apple ZeroConf architecture

+ + + + +

Interfaces:

+ + +
+ + +
+ +avahi_dbus_chat( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +avahi over dbus. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + + + + diff --git a/www/api-docs/services_bind.html b/www/api-docs/services_bind.html index 1459d3c8..7e4e3dc8 100644 --- a/www/api-docs/services_bind.html +++ b/www/api-docs/services_bind.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -278,6 +341,49 @@ Execute ndc in the ndc domain.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+ + + + +
+ + +
+ +bind_manage_cache( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete +BIND cache files. +

+ +
Parameters
@@ -527,6 +633,48 @@ of the BIND pid directory.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +bind_signal( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send generic signals to BIND. +

+ +
Parameters
diff --git a/www/api-docs/services_bluetooth.html b/www/api-docs/services_bluetooth.html index 6b003f04..68cb9766 100644 --- a/www/api-docs/services_bluetooth.html +++ b/www/api-docs/services_bluetooth.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -209,9 +272,219 @@ + +

Interfaces:

+ + +
+ + +
+ +bluetooth_dbus_chat( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +bluetooth over dbus. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +bluetooth_domtrans_helper( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute bluetooth_helper in the bluetooth_helper domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +bluetooth_dontaudit_read_helper_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read bluetooth helper files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +bluetooth_run_helper( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+
+ +
Summary
+

+Execute bluetooth_helper in the bluetooth_helper domain, and +allow the specified role the bluetooth_helper domain. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+role + + +The role to be allowed the bluetooth_helper domain. + + +No +
+terminal + + +The type of the terminal allow the bluetooth_helper domain to use. + + +No +
+
+
+ + +Return -

No interfaces or templates.

diff --git a/www/api-docs/services_canna.html b/www/api-docs/services_canna.html new file mode 100644 index 00000000..265c4afd --- /dev/null +++ b/www/api-docs/services_canna.html @@ -0,0 +1,328 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: canna

+ +

Description:

+ +

Canna - kana-kanji conversion server

+ + + + +

Interfaces:

+ + +
+ + +
+ +canna_stream_connect( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to Canna using a unix domain stream socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_comsat.html b/www/api-docs/services_comsat.html index 40c2848f..67bb85a2 100644 --- a/www/api-docs/services_comsat.html +++ b/www/api-docs/services_comsat.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_cpucontrol.html b/www/api-docs/services_cpucontrol.html index 7dbd1ab1..4efe63b9 100644 --- a/www/api-docs/services_cpucontrol.html +++ b/www/api-docs/services_cpucontrol.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_cron.html b/www/api-docs/services_cron.html index a8447e45..2c5558d7 100644 --- a/www/api-docs/services_cron.html +++ b/www/api-docs/services_cron.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -215,6 +278,133 @@

Interfaces:

+ +
+ + +
+ +cron_crw_tcp_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, and write a cron daemon TCP socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cron_domtrans_anacron_system_job( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute APM in the apm domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cron_dontaudit_append_system_job_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to append temporary +files from the system cron jobs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -323,6 +513,48 @@ Read and write a cron daemon unnamed pipe.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +cron_rw_system_job_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write a system cron job unnamed pipe. +

+ +
Parameters
@@ -592,7 +824,7 @@ No
Summary

-Wrate a system cron job unnamed pipe. +Write a system cron job unnamed pipe.

diff --git a/www/api-docs/services_cups.html b/www/api-docs/services_cups.html new file mode 100644 index 00000000..a05da6cb --- /dev/null +++ b/www/api-docs/services_cups.html @@ -0,0 +1,625 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: cups

+ +

Description:

+ +

Common UNIX printing system

+ + + + +

Interfaces:

+ + +
+ + +
+ +cups_dbus_chat( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +cups over dbus. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cups_dbus_chat_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +cupsd_config over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cups_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute cups in the cups domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +cups_domtrans_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute cups_config in the cups_config domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +cups_read_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read cups log files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cups_read_rw_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read cups-writable configuration files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cups_signal_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send generic signals to the cups +configuration daemon. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cups_stream_connect_ptal( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to ptal over an unix domain stream socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + + + + diff --git a/www/api-docs/services_cvs.html b/www/api-docs/services_cvs.html index a5a28d96..fced0b66 100644 --- a/www/api-docs/services_cvs.html +++ b/www/api-docs/services_cvs.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_cyrus.html b/www/api-docs/services_cyrus.html new file mode 100644 index 00000000..92eeb123 --- /dev/null +++ b/www/api-docs/services_cyrus.html @@ -0,0 +1,329 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: cyrus

+ +

Description:

+ +

Cyrus is an IMAP service intended to be run on sealed servers

+ + + + +

Interfaces:

+ + +
+ + +
+ +cyrus_manage_data( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow caller to create, read, write, +and delete cyrus data files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_dbskk.html b/www/api-docs/services_dbskk.html new file mode 100644 index 00000000..3a0af0f4 --- /dev/null +++ b/www/api-docs/services_dbskk.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: dbskk

+ +

Description:

+ +

Dictionary server for the SKK Japanese input method system.

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_dbus.html b/www/api-docs/services_dbus.html index 55874d95..fc7d2286 100644 --- a/www/api-docs/services_dbus.html +++ b/www/api-docs/services_dbus.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -300,6 +363,52 @@ No + +
+ + +
+ +dbus_stub( + + + + + [ + + domain + + ] + + + )
+
+
+ +
Summary
+

+DBUS stub interface. No access allowed. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +N/A + + +yes +
+
+
+
diff --git a/www/api-docs/services_dhcp.html b/www/api-docs/services_dhcp.html index 2f9a4fce..9779a737 100644 --- a/www/api-docs/services_dhcp.html +++ b/www/api-docs/services_dhcp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_dictd.html b/www/api-docs/services_dictd.html index 1ca1e06d..037b857f 100644 --- a/www/api-docs/services_dictd.html +++ b/www/api-docs/services_dictd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_distcc.html b/www/api-docs/services_distcc.html new file mode 100644 index 00000000..2bd0e006 --- /dev/null +++ b/www/api-docs/services_distcc.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: distcc

+ +

Description:

+ +

Distributed compiler daemon

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_dovecot.html b/www/api-docs/services_dovecot.html new file mode 100644 index 00000000..de3dd85b --- /dev/null +++ b/www/api-docs/services_dovecot.html @@ -0,0 +1,328 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: dovecot

+ +

Description:

+ +

Dovecot POP and IMAP mail server

+ + + + +

Interfaces:

+ + +
+ + +
+ +dovecot_manage_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete the dovecot spool files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_finger.html b/www/api-docs/services_finger.html index 2fbae3d7..cc8a5283 100644 --- a/www/api-docs/services_finger.html +++ b/www/api-docs/services_finger.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_ftp.html b/www/api-docs/services_ftp.html index d6f83962..a468326f 100644 --- a/www/api-docs/services_ftp.html +++ b/www/api-docs/services_ftp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -203,6 +266,9 @@

Layer: services

Module: ftp

+Interfaces +Templates +

Description:

File transfer protocol service

@@ -384,6 +450,69 @@ No Return + +

Templates:

+ + +
+ + +
+ +ftp_per_userdomain_template( + + + + + userdomain_prefix + + + )
+
+
+ +
Summary
+

+The per user domain template for the ftp module. +

+ + +
Description
+

+

+This template allows ftpd to manage files in +a user home directory, creating files with the +correct type. +

+

+This template is invoked automatically for each user, and +generally does not need to be invoked directly +by policy writers. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+
+
+ + +Return +
diff --git a/www/api-docs/services_gpm.html b/www/api-docs/services_gpm.html index 31570fb8..d858df8b 100644 --- a/www/api-docs/services_gpm.html +++ b/www/api-docs/services_gpm.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_hal.html b/www/api-docs/services_hal.html index 06979a04..29df8e31 100644 --- a/www/api-docs/services_hal.html +++ b/www/api-docs/services_hal.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -209,9 +272,226 @@ + +

Interfaces:

+ + +
+ + +
+ +hal_dbus_chat( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +hal over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +hal_dbus_send( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send a dbus message to hal. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +hal_dgram_sendto( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send to hal over a unix domain +datagram socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +hal_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute hal in the hal domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +hal_stream_connect( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send to hal over a unix domain +stream socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return -

No interfaces or templates.

diff --git a/www/api-docs/services_howl.html b/www/api-docs/services_howl.html index 9e679abd..c190610a 100644 --- a/www/api-docs/services_howl.html +++ b/www/api-docs/services_howl.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -209,9 +272,55 @@ + +

Interfaces:

+ + +
+ + +
+ +howl_signal( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send generic signals to howl. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return -

No interfaces or templates.

diff --git a/www/api-docs/services_i18n_input.html b/www/api-docs/services_i18n_input.html new file mode 100644 index 00000000..f5e836d0 --- /dev/null +++ b/www/api-docs/services_i18n_input.html @@ -0,0 +1,328 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: i18n_input

+ +

Description:

+ +

IIIMF htt server

+ + + + +

Interfaces:

+ + +
+ + +
+ +i18n_use( + + + + + domain + + + )
+
+
+ +
Summary
+

+Use i18n_input over a TCP connection. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_inetd.html b/www/api-docs/services_inetd.html index a0392db8..66dee8ca 100644 --- a/www/api-docs/services_inetd.html +++ b/www/api-docs/services_inetd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -323,6 +386,48 @@ No + +
+ + +
+ +inetd_rw_tcp_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write inetd TCP sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
diff --git a/www/api-docs/services_inn.html b/www/api-docs/services_inn.html index acfa596c..d38ac303 100644 --- a/www/api-docs/services_inn.html +++ b/www/api-docs/services_inn.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_irqbalance.html b/www/api-docs/services_irqbalance.html new file mode 100644 index 00000000..ca2a6ffb --- /dev/null +++ b/www/api-docs/services_irqbalance.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: irqbalance

+ +

Description:

+ +

IRQ balancing daemon

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_kerberos.html b/www/api-docs/services_kerberos.html index bf1a47ba..e0fac655 100644 --- a/www/api-docs/services_kerberos.html +++ b/www/api-docs/services_kerberos.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_ktalk.html b/www/api-docs/services_ktalk.html index f88e605e..c7a8ce20 100644 --- a/www/api-docs/services_ktalk.html +++ b/www/api-docs/services_ktalk.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_ldap.html b/www/api-docs/services_ldap.html index 32090364..220f195d 100644 --- a/www/api-docs/services_ldap.html +++ b/www/api-docs/services_ldap.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_lpd.html b/www/api-docs/services_lpd.html new file mode 100644 index 00000000..46f63e49 --- /dev/null +++ b/www/api-docs/services_lpd.html @@ -0,0 +1,533 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: lpd

+ +

Description:

+ +

Line printer daemon

+ + + + +

Interfaces:

+ + +
+ + +
+ +lpd_domtrans_checkpc( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute lpd in the lpd domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +lpd_list_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+List the contents of the printer spool directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +lpd_manage_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete printer spool files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +lpd_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+List the contents of the printer spool directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +lpd_run_checkpc( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+
+ +
Summary
+

+Execute amrecover in the lpd domain, and +allow the specified role the lpd domain. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+role + + +The role to be allowed the lpd domain. + + +No +
+terminal + + +The type of the terminal allow the lpd domain to use. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_mailman.html b/www/api-docs/services_mailman.html index f9b6256c..67db042a 100644 --- a/www/api-docs/services_mailman.html +++ b/www/api-docs/services_mailman.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_mta.html b/www/api-docs/services_mta.html index 3417eef7..76b24684 100644 --- a/www/api-docs/services_mta.html +++ b/www/api-docs/services_mta.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -239,6 +302,48 @@ Create, read, and write the mail spool.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +mta_delete_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Delete from the mail spool. +

+ +
Parameters
@@ -343,6 +448,49 @@ No + +
+ + +
+ +mta_dontaudit_rw_queue( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read and +write the mail queue. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -725,6 +873,90 @@ No
+ +
+ + +
+ +mta_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read mail server configuration. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +mta_read_sendmail_bin( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read sendmail binary. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -809,6 +1041,49 @@ No
+ +
+ + +
+ +mta_rw_user_mail_stream_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write unix domain stream sockets +of user mail domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -1023,6 +1298,124 @@ No

Templates:

+ +
+ + +
+ +mta_admin_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + )
+
+
+ +
Summary
+

+Provide extra permissions for admin users +mail domain. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+user_domain + + +The type of the user domain. + + +No +
+
+
+ + +
+ + +
+ +mta_base_mail_template( + + + + + domain_prefix + + + )
+
+
+ +
Summary
+

+Basic mail transfer agent domain template. +

+ + +
Description
+

+

+This template creates a derived domain which is +a email transfer agent, which sends mail on +behalf of the user. +

+

+This is the basic types and rules, common +to the system agent and user agents. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain_prefix + + +The prefix of the domain (e.g., user +is the prefix for user_t). + + +No +
+
+
+
diff --git a/www/api-docs/services_mysql.html b/www/api-docs/services_mysql.html index bb9f9f98..be814d6c 100644 --- a/www/api-docs/services_mysql.html +++ b/www/api-docs/services_mysql.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_networkmanager.html b/www/api-docs/services_networkmanager.html new file mode 100644 index 00000000..cf5fac4b --- /dev/null +++ b/www/api-docs/services_networkmanager.html @@ -0,0 +1,456 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: networkmanager

+ +

Description:

+ +

Manager for dynamically switching between networks.

+ + + + +

Interfaces:

+ + +
+ + +
+ +networkmanager_dbus_chat( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +NetworkManager over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +networkmanager_rw_packet_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write NetworkManager packet sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +networkmanager_rw_routing_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write NetworkManager netlink +routing sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +networkmanager_rw_udp_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write NetworkManager UDP sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_nis.html b/www/api-docs/services_nis.html index cf599a47..8d9caccc 100644 --- a/www/api-docs/services_nis.html +++ b/www/api-docs/services_nis.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -212,6 +275,90 @@

Interfaces:

+ +
+ + +
+ +nis_delete_ypbind_pid( + + + + + domain + + + )
+
+
+ +
Summary
+

+Delete ypbind pid files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +nis_domtrans_ypbind( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute ypbind in the ypbind domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -232,7 +379,7 @@
Summary

-Send UDP network traffic to NIS clients. +List the contents of the NIS data directory.

@@ -254,6 +401,90 @@ No
+ +
+ + +
+ +nis_read_ypbind_pid( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read ypbind pid files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +nis_read_ypserv_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read ypserv configuration files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -296,6 +527,48 @@ No
+ +
+ + +
+ +nis_tcp_connect_ypbind( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to ypbind over TCP. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
diff --git a/www/api-docs/services_nscd.html b/www/api-docs/services_nscd.html index be6ae3f1..871381ac 100644 --- a/www/api-docs/services_nscd.html +++ b/www/api-docs/services_nscd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_ntp.html b/www/api-docs/services_ntp.html index e335128e..71a41ce1 100644 --- a/www/api-docs/services_ntp.html +++ b/www/api-docs/services_ntp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_pegasus.html b/www/api-docs/services_pegasus.html new file mode 100644 index 00000000..b316f92e --- /dev/null +++ b/www/api-docs/services_pegasus.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: pegasus

+ +

Description:

+ +

The Open Group Pegasus CIM/WBEM Server.

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_portmap.html b/www/api-docs/services_portmap.html index 545536ce..81013555 100644 --- a/www/api-docs/services_portmap.html +++ b/www/api-docs/services_portmap.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -334,6 +397,90 @@ No
+ +
+ + +
+ +portmap_tcp_connect( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to portmap over a TCP socket +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +portmap_udp_sendrecv( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP network traffic from portmap. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
diff --git a/www/api-docs/services_postfix.html b/www/api-docs/services_postfix.html new file mode 100644 index 00000000..8e67eed0 --- /dev/null +++ b/www/api-docs/services_postfix.html @@ -0,0 +1,1099 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: postfix

+ +Interfaces +Templates + +

Description:

+ +

Postfix email server

+ + + + +

Interfaces:

+ + +
+ + +
+ +postfix_create_config( + + + + + domain + + + + , + + + + private type + + + + , + + + + [ + + object + + ] + + + )
+
+
+ +
Summary
+

+Create files with the specified type in +the postfix configuration directories. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+private type + + +The type of the object to be created. + + +No +
+object + + +The object class of the object being created. If +no class is specified, file will be used. + + +yes +
+
+
+ + +
+ + +
+ +postfix_domtrans_map( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute postfix_map in the postfix_map domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_domtrans_master( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute the master postfix program in the +postfix_master domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_domtrans_user_mail_handler( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute postfix user mail programs +in their respective domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_dontaudit_rw_local_tcp_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read and +write postfix local delivery +TCP sockets. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +postfix_dontaudit_use_fd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to use +postfix master process file +file descriptors. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +postfix_exec_master( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute the master postfix program in the +caller domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_list_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+List postfix mail spool directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read postfix configuration files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_run_map( + + + + + domain + + + + , + + + + role + + + + , + + + + terminal + + + )
+
+
+ +
Summary
+

+Execute postfix_map in the postfix_map domain, and +allow the specified role the postfix_map domain. +

+ + +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+role + + +The role to be allowed the postfix_map domain. + + +No +
+terminal + + +The type of the terminal allow the postfix_map domain to use. + + +No +
+
+
+ + +
+ + +
+ +postfix_search_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search postfix mail spool directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +postfix_stub( + + + + + [ + + domain + + ] + + + )
+
+
+ +
Summary
+

+Postfix stub interface. No access allowed. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +N/A + + +yes +
+
+
+ + +Return + + + +

Templates:

+ + +
+ + +
+ +postfix_domain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ + +
+ + +
+ +postfix_per_userdomain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ + +
+ + +
+ +postfix_public_domain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ + +
+ + +
+ +postfix_server_domain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ + +
+ + +
+ +postfix_user_domain_template( + + + + + ? + + + )
+
+
+ +
Summary
+

+Summary is missing! +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+? + + +Parameter descriptions are missing! + + +No +
+
+
+ + +Return + + + +
+ + diff --git a/www/api-docs/services_postgresql.html b/www/api-docs/services_postgresql.html index adfeb36f..0ffd0a95 100644 --- a/www/api-docs/services_postgresql.html +++ b/www/api-docs/services_postgresql.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_ppp.html b/www/api-docs/services_ppp.html index 0ff83348..876852e3 100644 --- a/www/api-docs/services_ppp.html +++ b/www/api-docs/services_ppp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -254,6 +317,49 @@ No
+ +
+ + +
+ +ppp_dontaudit_use_fd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to inherit +and use PPP file discriptors. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -358,7 +464,7 @@ No
Summary

-Allow domain to send sigchld to parent of PPP domain type. +Send a SIGCHLD signal to PPP.

@@ -400,7 +506,7 @@ No
Summary

-Allow domain to send a signal to PPP domain type. +Send a generic signal to PPP.

diff --git a/www/api-docs/services_privoxy.html b/www/api-docs/services_privoxy.html index 39d6e344..a0bc64da 100644 --- a/www/api-docs/services_privoxy.html +++ b/www/api-docs/services_privoxy.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_procmail.html b/www/api-docs/services_procmail.html new file mode 100644 index 00000000..25e4adad --- /dev/null +++ b/www/api-docs/services_procmail.html @@ -0,0 +1,370 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: procmail

+ +

Description:

+ +

Procmail mail delivery agent

+ + + + +

Interfaces:

+ + +
+ + +
+ +procmail_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute procmail with a domain transition. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +procmail_exec( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute procmail in the caller domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_radius.html b/www/api-docs/services_radius.html new file mode 100644 index 00000000..e3c2d6b7 --- /dev/null +++ b/www/api-docs/services_radius.html @@ -0,0 +1,328 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: radius

+ +

Description:

+ +

RADIUS authentication and accounting server.

+ + + + +

Interfaces:

+ + +
+ + +
+ +radius_use( + + + + + domain + + + )
+
+
+ +
Summary
+

+Use radius over a UDP connection. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_radvd.html b/www/api-docs/services_radvd.html index ccdb1039..41b66e66 100644 --- a/www/api-docs/services_radvd.html +++ b/www/api-docs/services_radvd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_rdisc.html b/www/api-docs/services_rdisc.html new file mode 100644 index 00000000..362bf2e9 --- /dev/null +++ b/www/api-docs/services_rdisc.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: rdisc

+ +

Description:

+ +

Network router discovery daemon

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_remotelogin.html b/www/api-docs/services_remotelogin.html index 6281f281..760c912d 100644 --- a/www/api-docs/services_remotelogin.html +++ b/www/api-docs/services_remotelogin.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_rlogin.html b/www/api-docs/services_rlogin.html index c65af2de..292758b1 100644 --- a/www/api-docs/services_rlogin.html +++ b/www/api-docs/services_rlogin.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_rpc.html b/www/api-docs/services_rpc.html new file mode 100644 index 00000000..f4550081 --- /dev/null +++ b/www/api-docs/services_rpc.html @@ -0,0 +1,767 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: rpc

+ +Interfaces +Templates + +

Description:

+ +

Remote Procedure Call Daemon for managment of network based process communication

+ + + + +

Interfaces:

+ + +
+ + +
+ +rpc_domtrans_nfsd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute domain in nfsd domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +rpc_dontaudit_getattr_exports( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the attributes +of the NFS export file. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +rpc_manage_nfs_ro_content( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow domain to create read and write NFS directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +rpc_manage_nfs_rw_content( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow domain to create read and write NFS directories. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +rpc_read_exports( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow read access to exports. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +rpc_search_nfs_state_data( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search NFS state data in /var/lib/nfs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +rpc_udp_rw_nfs_sockets( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow domain to read and write to an NFS UDP socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +rpc_udp_sendto( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP network traffic to rpc and recieve UDP traffic from rpc. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +rpc_udp_sendto_nfs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow NFS to send UDP network traffic +the specified domain and recieve from it. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the receiving domain. + + +No +
+
+
+ + +
+ + +
+ +rpc_write_exports( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow write access to exports. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +Return + + + +

Templates:

+ + +
+ + +
+ +rpc_domain_template( + + + + + userdomain_prefix + + + )
+
+
+ +
Summary
+

+The template to define a rpc domain. +

+ + +
Description
+

+

+This template creates a domain to be used for +a new rpc daemon. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The type of daemon to be used. + + +No +
+
+
+ + +Return + + + +
+ + diff --git a/www/api-docs/services_rshd.html b/www/api-docs/services_rshd.html index 8bb06e7a..949f13ce 100644 --- a/www/api-docs/services_rshd.html +++ b/www/api-docs/services_rshd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_rsync.html b/www/api-docs/services_rsync.html index 1f688558..ca7a406e 100644 --- a/www/api-docs/services_rsync.html +++ b/www/api-docs/services_rsync.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_samba.html b/www/api-docs/services_samba.html index f2e7a4f5..62b0a11e 100644 --- a/www/api-docs/services_samba.html +++ b/www/api-docs/services_samba.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -219,6 +282,48 @@ from Windows NT servers.

Interfaces:

+ +
+ + +
+ +samba_connect_winbind( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to winbind. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -525,48 +630,6 @@ No - domain - - - )
-
-
- -
Summary
-

-Allow the specified domain to read the winbind pid files. -

- - -
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -Domain allowed access. - - -No -
-
-
- - -
- - -
- -samba_read_winbind_pid( - - - - domain @@ -823,6 +886,92 @@ Allow the specified domain to read and write to smbmount tcp sockets.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +samba_rw_var_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow the specified domain to +read and write samba /var files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +samba_search_var( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow the specified domain to search +samba /var directories. +

+ +
Parameters
diff --git a/www/api-docs/services_sasl.html b/www/api-docs/services_sasl.html index 9e7df340..83a2abcf 100644 --- a/www/api-docs/services_sasl.html +++ b/www/api-docs/services_sasl.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -209,9 +272,55 @@ + +

Interfaces:

+ + +
+ + +
+ +sasl_connect( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to SASL. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return -

No interfaces or templates.

diff --git a/www/api-docs/services_sendmail.html b/www/api-docs/services_sendmail.html index ff9ef8c4..ad39a7b6 100644 --- a/www/api-docs/services_sendmail.html +++ b/www/api-docs/services_sendmail.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -212,6 +275,48 @@

Interfaces:

+ +
+ + +
+ +sendmail_create_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create sendmail logs with the correct type. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -244,7 +349,91 @@ Domain transition to sendmail. domain
-The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +sendmail_manage_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete sendmail logs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +sendmail_rw_tcp_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write sendmail TCP sockets. +

+ + +
Parameters
+ + + + - - - - - - - - - diff --git a/www/api-docs/system_authlogin.html b/www/api-docs/system_authlogin.html index 5f55eaab..8353f149 100644 --- a/www/api-docs/system_authlogin.html +++ b/www/api-docs/system_authlogin.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -651,6 +642,48 @@ of the shadow passwords file.

+
Parameters
+
Parameter:Description:Optional:
+domain + + +Domain allowed access. No diff --git a/www/api-docs/services_snmp.html b/www/api-docs/services_snmp.html index 025ce656..22cd9080 100644 --- a/www/api-docs/services_snmp.html +++ b/www/api-docs/services_snmp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -209,9 +272,55 @@ + +

Interfaces:

+ + +
+ + +
+ +snmp_use( + + + + + domain + + + )
+
+
+ +
Summary
+

+Use snmp over a TCP connection. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return -

No interfaces or templates.

diff --git a/www/api-docs/services_spamassassin.html b/www/api-docs/services_spamassassin.html new file mode 100644 index 00000000..e5ccfe84 --- /dev/null +++ b/www/api-docs/services_spamassassin.html @@ -0,0 +1,472 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: spamassassin

+ +Interfaces +Templates + +

Description:

+ +

Filter used for removing unsolicited email.

+ + + + +

Interfaces:

+ + +
+ + +
+ +spamassassin_exec( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute the standalone spamassassin +program in the caller directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +spamassassin_exec_client( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute the spamassassin client +program in the caller directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + +

Templates:

+ + +
+ + +
+ +spamassassin_per_userdomain_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role + + + )
+
+
+ +
Summary
+

+The per user domain template for the spamassassin module. +

+ + +
Description
+

+

+The per user domain template for the spamassassin module. +

+

+This template is invoked automatically for each user, and +generally does not need to be invoked directly +by policy writers. +

+

+ +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+user_domain + + +The type of the user domain. + + +No +
+user_role + + +The role associated with the user domain. + + +No +
+
+
+ + +Return + + + +
+ + diff --git a/www/api-docs/services_squid.html b/www/api-docs/services_squid.html index 1d48ff7e..574ea67b 100644 --- a/www/api-docs/services_squid.html +++ b/www/api-docs/services_squid.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -212,6 +275,48 @@

Interfaces:

+ +
+ + +
+ +squid_append_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Append squid logs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -321,6 +426,48 @@ Read squid configuration file.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +squid_read_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Append squid logs. +

+ +
Parameters
diff --git a/www/api-docs/services_ssh.html b/www/api-docs/services_ssh.html index d665fc08..788c409d 100644 --- a/www/api-docs/services_ssh.html +++ b/www/api-docs/services_ssh.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_stunnel.html b/www/api-docs/services_stunnel.html index 10e796cd..57b27b48 100644 --- a/www/api-docs/services_stunnel.html +++ b/www/api-docs/services_stunnel.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_tcpd.html b/www/api-docs/services_tcpd.html index f3b1852e..ccb75f16 100644 --- a/www/api-docs/services_tcpd.html +++ b/www/api-docs/services_tcpd.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_telnet.html b/www/api-docs/services_telnet.html index 060ba450..51bdabaf 100644 --- a/www/api-docs/services_telnet.html +++ b/www/api-docs/services_telnet.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_tftp.html b/www/api-docs/services_tftp.html index 3afbbcaf..af6d73a6 100644 --- a/www/api-docs/services_tftp.html +++ b/www/api-docs/services_tftp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_timidity.html b/www/api-docs/services_timidity.html new file mode 100644 index 00000000..1fb3ea64 --- /dev/null +++ b/www/api-docs/services_timidity.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: timidity

+ +

Description:

+ +

MIDI to WAV converter and player configured as a service

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_uucp.html b/www/api-docs/services_uucp.html index cde0bf48..0a5a55c4 100644 --- a/www/api-docs/services_uucp.html +++ b/www/api-docs/services_uucp.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/services_xdm.html b/www/api-docs/services_xdm.html new file mode 100644 index 00000000..669cdace --- /dev/null +++ b/www/api-docs/services_xdm.html @@ -0,0 +1,282 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: xdm

+ +

Description:

+ +

X windows login display manager

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_xfs.html b/www/api-docs/services_xfs.html new file mode 100644 index 00000000..eaf906a0 --- /dev/null +++ b/www/api-docs/services_xfs.html @@ -0,0 +1,328 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: xfs

+ +

Description:

+ +

X Windows Font Server

+ + + + +

Interfaces:

+ + +
+ + +
+ +xfs_read_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read a X font server named socket. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + + + + diff --git a/www/api-docs/services_zebra.html b/www/api-docs/services_zebra.html index 66bf7b72..93f3d18b 100644 --- a/www/api-docs/services_zebra.html +++ b/www/api-docs/services_zebra.html @@ -40,12 +40,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -55,9 +61,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -67,6 +82,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -82,12 +103,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -97,6 +124,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -106,6 +136,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -115,9 +148,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -127,15 +166,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -154,6 +205,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -172,9 +226,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
diff --git a/www/api-docs/system.html b/www/api-docs/system.html index 7ba1ca23..e55ad687 100644 --- a/www/api-docs/system.html +++ b/www/api-docs/system.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -164,26 +155,6 @@ clock

Policy for reading and setting the hardware clock.

- - corecommands

-Core policy for shells, and generic programs -in /bin, /sbin, /usr/bin, and /usr/sbin. -

- - domain

Core policy for domains.

- - files

-Basic filesystem types and interfaces. -

fstools
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +auth_dontaudit_read_pam_pid( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attemps to read PAM pid files. +

+ +
Parameters
@@ -1114,6 +1147,204 @@ No + +
+ + +
+ +auth_read_all_dirs_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all directories on the filesystem, except +the shadow passwords and listed exceptions. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+ + +
+ + +
+ +auth_read_all_files_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all files on the filesystem, except +the shadow passwords and listed exceptions. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+ + +
+ + +
+ +auth_read_all_symlinks_except_shadow( + + + + + domain + + + + , + + + + [ + + exception_types + + ] + + + )
+
+
+ +
Summary
+

+Read all symbolic links on the filesystem, except +the shadow passwords and listed exceptions. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the domain perfoming this action. + + +No +
+exception_types + + +The types to be excluded. Each type or attribute +must be negated by the caller. + + +yes +
+
+
+
@@ -1390,6 +1621,49 @@ yes
+ +
+ + +
+ +auth_relabel_shadow( + + + + + domain + + + )
+
+
+ +
Summary
+

+Relabel from and to the shadow +password file type. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -1401,7 +1675,7 @@ yes - ? + domain )
@@ -1410,7 +1684,8 @@ yes
Summary

-Summary is missing! +Relabel to the shadow +password file type.

@@ -1419,10 +1694,10 @@ Summary is missing!
Parameter:Description:Optional:
-? +domain -Parameter descriptions are missing! +Domain allowed access. No @@ -1738,6 +2013,49 @@ Read and write the shadow password file (/etc/shadow).

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+ + + + +
+ + +
+ +auth_search_pam_console_data( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search the contents of the +pam_console data directory. +

+ +
Parameters
diff --git a/www/api-docs/system_clock.html b/www/api-docs/system_clock.html index 71d74005..f43a44bb 100644 --- a/www/api-docs/system_clock.html +++ b/www/api-docs/system_clock.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_fstools.html b/www/api-docs/system_fstools.html index 89b7e2d2..fcf65883 100644 --- a/www/api-docs/system_fstools.html +++ b/www/api-docs/system_fstools.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_getty.html b/www/api-docs/system_getty.html index e1ff8040..3db5f53f 100644 --- a/www/api-docs/system_getty.html +++ b/www/api-docs/system_getty.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_hostname.html b/www/api-docs/system_hostname.html index 254a9547..986c052a 100644 --- a/www/api-docs/system_hostname.html +++ b/www/api-docs/system_hostname.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_hotplug.html b/www/api-docs/system_hotplug.html index 19b6540a..b07fb79a 100644 --- a/www/api-docs/system_hotplug.html +++ b/www/api-docs/system_hotplug.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_init.html b/www/api-docs/system_init.html index e2753aa2..28bd1f5a 100644 --- a/www/api-docs/system_init.html +++ b/www/api-docs/system_init.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -143,6 +134,89 @@

Interfaces:

+ +
+ + +
+ +init_create_script_tmp( + + + + + domain + + + + , + + + + file_type + + + + , + + + + [ + + object_class + + ] + + + )
+
+
+ +
Summary
+

+Create files in a init script +temporary data directory. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+file_type + + +The type of the object to be created + + +No +
+object_class + + +The object class. If not specified, file is used. + + +yes +
+
+
+
@@ -204,6 +278,49 @@ No
+ +
+ + +
+ +init_dbus_chat_script( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +init scripts over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -612,7 +729,7 @@ No - ? + domain )
@@ -621,7 +738,8 @@ No
Summary

-Summary is missing! +Do not audit attempts to read and +write the init script pty.

@@ -630,10 +748,10 @@ Summary is missing!
Parameter:Description:Optional:
-? +domain -Parameter descriptions are missing! +Domain to not audit. No @@ -895,6 +1013,90 @@ No + +
+ + +
+ +init_getattr_script_entry_file( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attribute of init script entrypoint files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +init_getattr_script_pids( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of init script process id files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -1012,7 +1214,7 @@ Read init scripts. domain
-The type of the process performing this action. +Domain allowed access. No @@ -1096,7 +1298,7 @@ Read the process state (/proc/pid) of the init scripts. domain -The type of the process performing this action. +Domain allowed access. No @@ -1163,7 +1365,7 @@ style, and do not require run_init. domain -The type of the process performing this action. +Domain allowed access. No @@ -1267,7 +1469,7 @@ Read and write init script unnamed pipes. domain -The type of the process performing this action. +Domain allowed access. No @@ -1309,7 +1511,7 @@ Read and write init script temporary data. domain -The type of the process performing this action. +Domain allowed access. No @@ -1343,6 +1545,90 @@ Send init a SIGCHLD signal.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+ + + + +
+ + +
+ +init_sigchld_script( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send SIGCHLD signals to init scripts. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +init_signal_script( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send generic signals to init scripts. +

+ +
Parameters
@@ -1385,6 +1671,48 @@ Send init a null signal.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +init_signull_script( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send null signals to init scripts. +

+ +
Parameters
@@ -1496,7 +1824,7 @@ Send UDP network traffic to init. domain
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -1530,49 +1858,6 @@ Send UDP network traffic to init scripts.

-
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -The type of the process performing this action. - - -No -
- - - - -
- - -
- -init_unix_connect_script( - - - - - domain - - - )
-
-
- -
Summary
-

-Allow the specified domain to connect to -init scripts with a unix domain stream socket. -

- -
Parameters
@@ -1803,7 +2088,7 @@ the administrator terminal. domain
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -1855,6 +2140,48 @@ No + +
+ + +
+ +init_write_script_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Write an init script unnamed pipe. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ Return diff --git a/www/api-docs/system_ipsec.html b/www/api-docs/system_ipsec.html index c2e783e2..2b72ca46 100644 --- a/www/api-docs/system_ipsec.html +++ b/www/api-docs/system_ipsec.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_iptables.html b/www/api-docs/system_iptables.html index 122ef720..c06158ec 100644 --- a/www/api-docs/system_iptables.html +++ b/www/api-docs/system_iptables.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_libraries.html b/www/api-docs/system_libraries.html index 83150d78..4240751e 100644 --- a/www/api-docs/system_libraries.html +++ b/www/api-docs/system_libraries.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -628,6 +619,49 @@ of shared libraries.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+ + + + +
+ + +
+ +libs_use_lib( + + + + + domain + + + )
+
+
+ +
Summary
+

+Load and execute functions from generic +lib files as shared libraries. +

+ +
Parameters
diff --git a/www/api-docs/system_locallogin.html b/www/api-docs/system_locallogin.html index 858f2d70..36811c3f 100644 --- a/www/api-docs/system_locallogin.html +++ b/www/api-docs/system_locallogin.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_logging.html b/www/api-docs/system_logging.html index 77f1e5c6..fb908820 100644 --- a/www/api-docs/system_logging.html +++ b/www/api-docs/system_logging.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -227,6 +218,48 @@ No + +
+ + +
+ +logging_domtrans_auditctl( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute auditctl in the auditctl domain. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
diff --git a/www/api-docs/system_lvm.html b/www/api-docs/system_lvm.html index e04dfe30..305a7dba 100644 --- a/www/api-docs/system_lvm.html +++ b/www/api-docs/system_lvm.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_miscfiles.html b/www/api-docs/system_miscfiles.html index 17e6d2ec..7606e111 100644 --- a/www/api-docs/system_miscfiles.html +++ b/www/api-docs/system_miscfiles.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -185,6 +176,48 @@ No
+ +
+ + +
+ +miscfiles_dontaudit_search_man_pages( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to search man pages. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -251,6 +284,48 @@ Allow process to read legacy time localization info

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+ + + +
+ + +
+ +miscfiles_manage_fonts( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete fonts. +

+ +
Parameters
diff --git a/www/api-docs/system_modutils.html b/www/api-docs/system_modutils.html index 44d0e72a..13115055 100644 --- a/www/api-docs/system_modutils.html +++ b/www/api-docs/system_modutils.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -209,6 +200,48 @@ Execute insmod in the insmod domain.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +modutils_domtrans_insmod_uncond( + + + + + domain + + + )
+
+
+ +
Summary
+

+Unconditionally execute insmod in the insmod domain. +

+ +
Parameters
diff --git a/www/api-docs/system_mount.html b/www/api-docs/system_mount.html index 68abe9c4..8e81b44c 100644 --- a/www/api-docs/system_mount.html +++ b/www/api-docs/system_mount.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_pcmcia.html b/www/api-docs/system_pcmcia.html index a555aa36..84ae1f40 100644 --- a/www/api-docs/system_pcmcia.html +++ b/www/api-docs/system_pcmcia.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -434,6 +425,52 @@ No + +
+ + +
+ +pcmcia_stub( + + + + + [ + + domain + + ] + + + )
+
+
+ +
Summary
+

+PCMCIA stub interface. No access allowed. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +N/A + + +yes +
+
+
+
diff --git a/www/api-docs/system_raid.html b/www/api-docs/system_raid.html index cceeaa77..fd92e07f 100644 --- a/www/api-docs/system_raid.html +++ b/www/api-docs/system_raid.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_selinuxutil.html b/www/api-docs/system_selinuxutil.html index af6d10de..40781ae6 100644 --- a/www/api-docs/system_selinuxutil.html +++ b/www/api-docs/system_selinuxutil.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
diff --git a/www/api-docs/system_sysnetwork.html b/www/api-docs/system_sysnetwork.html index 36727abf..a3379d9b 100644 --- a/www/api-docs/system_sysnetwork.html +++ b/www/api-docs/system_sysnetwork.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -280,6 +271,49 @@ yes
+ +
+ + +
+ +sysnet_dbus_chat_dhcpc( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive messages from +dhcpc over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -448,6 +482,48 @@ No
+ +
+ + +
+ +sysnet_dontaudit_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read network config files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
diff --git a/www/api-docs/system_udev.html b/www/api-docs/system_udev.html index 58b3003a..cc9f68af 100644 --- a/www/api-docs/system_udev.html +++ b/www/api-docs/system_udev.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -271,6 +262,48 @@ No
+ +
+ + +
+ +udev_helper_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute a udev helper in the udev domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
diff --git a/www/api-docs/system_unconfined.html b/www/api-docs/system_unconfined.html index d3bdf9ef..15013f1d 100644 --- a/www/api-docs/system_unconfined.html +++ b/www/api-docs/system_unconfined.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -146,6 +137,102 @@

Interfaces:

+ +
+ + +
+ +unconfined_alias_domain( + + + + + domain + + + )
+
+
+ +
Summary
+

+Add an alias type to the unconfined domain. +

+ + +
Description
+

+

+Add an alias type to the unconfined domain. +

+

+This is added to support targeted policy. Its +use should be limited. It has no effect +on the strict policy. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +New alias of the unconfined domain. + + +No +
+
+
+ + +
+ + +
+ +unconfined_dbus_send( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send messages to the unconfined domain over dbus. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -170,6 +257,48 @@ Transition to the unconfined domain.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +unconfined_dontaudit_read_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to read unconfined domain unnamed pipes. +

+ +
Parameters
@@ -243,13 +372,13 @@ No - +
-unconfined_role( +unconfined_read_pipe( @@ -263,7 +392,7 @@ No
Summary

-Add the unconfined domain to the specified role. +Read unconfined domain unnamed pipes.

@@ -471,6 +600,48 @@ Send a SIGCHLD signal to the unconfined domain.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +unconfined_signal( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send generic signals to the unconfined domain. +

+ +
Parameters
diff --git a/www/api-docs/system_userdomain.html b/www/api-docs/system_userdomain.html index 3ec650f0..7b079592 100644 --- a/www/api-docs/system_userdomain.html +++ b/www/api-docs/system_userdomain.html @@ -43,15 +43,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -146,13 +137,13 @@

Interfaces:

- +
-userdom_create_user_home( +userdom_create_generic_user_home( @@ -212,13 +203,13 @@ yes
- +
-userdom_create_user_home_dir( +userdom_create_generic_user_home_dir( @@ -237,6 +228,201 @@ with automatic file type transition.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_create_sysadm_home( + + + + + domain + + + + , + + + + [ + + object_class + + ] + + + )
+
+
+ +
Summary
+

+Create objects in sysadm home directories +with automatic file type transition. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+object_class + + +The class of the object to be created. +If not specified, file is used. + + +yes +
+
+
+ + +
+ + +
+ +userdom_dbus_send_all_users( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send a dbus message to all user domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_dontaudit_getattr_sysadm_home_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the +attributes of the sysadm users +home directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+ + +
+ + +
+ +userdom_dontaudit_getattr_sysadm_tty( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attepts to get the attributes +of sysadm ttys. +

+ +
Parameters
@@ -670,7 +856,50 @@ file descriptors from all user domains. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_dontaudit_use_unpriv_user_pty( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to use unprivileged +user ptys. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. No @@ -713,7 +942,49 @@ user ttys. domain -The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_getattr_all_userdomains( + + + + + domain + + + )
+
+
+ +
Summary
+

+Get the attributes of all user domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -756,7 +1027,91 @@ home directory. domain -Domain to not audit. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_list_sysadm_home_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+List the sysadm users home directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_list_unpriv_user_tmp( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all unprivileged users temporary directories. +

+ + +
Parameters
+ + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -799,7 +1154,7 @@ in all users home directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -842,7 +1197,7 @@ in all users home directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -885,7 +1240,7 @@ in all users home directories. domain -The type of the process performing this action. +Domain allowed access. No @@ -895,13 +1250,13 @@ No - +
-userdom_manage_user_home_dir( +userdom_manage_generic_user_home_dir( @@ -938,13 +1293,13 @@ No
- +
-userdom_manage_user_home_dirs( +userdom_manage_generic_user_home_dirs( @@ -982,13 +1337,13 @@ No
- +
-userdom_manage_user_home_files( +userdom_manage_generic_user_home_files( @@ -1025,13 +1380,13 @@ No
- +
-userdom_manage_user_home_pipes( +userdom_manage_generic_user_home_pipes( @@ -1068,13 +1423,13 @@ No
- +
-userdom_manage_user_home_sockets( +userdom_manage_generic_user_home_sockets( @@ -1111,13 +1466,13 @@ No
- +
-userdom_manage_user_home_symlinks( +userdom_manage_generic_user_home_symlinks( @@ -1136,6 +1491,60 @@ links in generic user home directories.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_priveleged_home_dir_manager( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make the specified domain a privileged +home directory manager. +

+ + +
Description
+

+

+Make the specified domain a privileged +home directory manager. This domain will be +able to manage the contents of all users +general home directory content, and create +files with the correct context. +

+

+
Parameters
@@ -1186,7 +1595,49 @@ Read all files in all users home directories. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_read_all_userdomains_state( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read the process state of all user domains. +

+ + +
Parameters
+ + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -1228,7 +1679,7 @@ Read files in the staff users home directory. domain -The type of the process performing this action. +Domain allowed access. No @@ -1270,7 +1721,7 @@ Read files in the sysadm users home directory. domain -The type of the process performing this action. +Domain allowed access. No @@ -1305,6 +1756,90 @@ files.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+ + + + +
+ + +
+ +userdom_read_unpriv_user_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all unprivileged users temporary files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_read_unpriv_user_tmp_symlinks( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read all unprivileged users temporary symbolic links. +

+ +
Parameters
@@ -1355,7 +1890,7 @@ Read and write sysadm user unnamed pipes. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -1397,7 +1932,49 @@ Search all users home directories. domain -The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_search_generic_user_home_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search generic user home directories. +

+ + +
Parameters
+ + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -1473,6 +2050,48 @@ Search the sysadm users home directory.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+ + + + +
+ + +
+ +userdom_search_sysadm_home_subdirs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Search the sysadm users home sub directories. +

+ +
Parameters
@@ -1515,6 +2134,48 @@ Search all unprivileged users home directories.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_setattr_unpriv_user_pty( + + + + + domain + + + )
+
+
+ +
Summary
+

+Set the attributes of user ptys. +

+ +
Parameters
@@ -1565,7 +2226,49 @@ Execute a shell in the sysadm domain. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_sigchld_all_users( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send a SIGCHLD signal to all user domains. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -1599,48 +2302,6 @@ Send a SIGCHLD signal to sysadm users.

-
Parameters
- - - - - -
Parameter:Description:Optional:
-domain - - -The type of the process performing this action. - - -No -
- - - - -
- - -
- -userdom_sigcld_all_users( - - - - - domain - - - )
-
-
- -
Summary
-

-Send a SIGCHLD signal to all user domains. -

- -
Parameters
@@ -1691,7 +2352,7 @@ Send general signals to all user domains. domain + +
Parameter:Description:Optional:
-The type of the process performing this action. +Domain allowed access. No @@ -1733,7 +2394,7 @@ Send general signals to unprivileged user domains. domain -The type of the process performing this action. +Domain allowed access. No @@ -1777,7 +2438,7 @@ caller to use setexeccon(). domain -The type of the process performing this action. +Domain allowed access. No @@ -1821,7 +2482,7 @@ caller to use setexeccon(). domain -The type of the process performing this action. +Domain allowed access. No @@ -1905,7 +2566,7 @@ Inherit the file descriptors from all user domains domain -The type of the process performing this action. +Domain allowed access. No @@ -1947,7 +2608,7 @@ Inherit and use sysadm file descriptors domain -The type of the process performing this action. +Domain allowed access. No @@ -1989,7 +2650,7 @@ Read and write sysadm ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -2031,7 +2692,7 @@ Read and write sysadm ttys and ptys. domain -The type of the process performing this action. +Domain allowed access. No @@ -2073,7 +2734,49 @@ Read and write sysadm ttys. domain -The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_use_unpriv_user_pty( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write unprivileged user ptys. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -2115,7 +2818,7 @@ Inherit the file descriptors from unprivileged user domains. domain -The type of the process performing this action. +Domain allowed access. No @@ -2157,7 +2860,7 @@ Write all unprivileged users files in /tmp domain -The type of the process performing this action. +Domain allowed access. No @@ -2384,6 +3087,18 @@ No ] + + , + + + + [ + + private_type + + ] + + )
@@ -2425,7 +3140,7 @@ No domain
-The type of the process performing this action. +Domain allowed access. No @@ -2442,6 +3157,18 @@ specified, file is used. yes
+private_type + + +The type of the object to create. If this is +not specified, the regular home directory +type is used. + + +yes +
@@ -2508,7 +3235,82 @@ No domain
-The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_home_file( + + + + + userdomain_prefix + + + + , + + + + type + + + )
+
+
+ +
Summary
+

+Make the specified type usable in a +user home directory. +

+ + +
Description
+

+

+Make the specified type usable in a +user home directory. +

+

+This is a templated interface, and should only +be called from a per-userdomain template. +

+

+ +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+type + + +Type to be used as a file in the +user home directory. No @@ -2582,7 +3384,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -2656,7 +3458,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -2730,7 +3532,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -2804,7 +3606,81 @@ No domain -The type of the process performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +userdom_manage_user_home_subdirs( + + + + + userdomain_prefix + + + + , + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete symbolic links +in a user home subdirectory. +

+ + +
Description
+

+

+Create, read, write, and delete symbolic links +in a user home subdirectory. +

+

+This is a templated interface, and should only +be called from a per-userdomain template. +

+

+ +
Parameters
+ + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+domain + + +Domain allowed access. No @@ -2878,7 +3754,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -2952,7 +3828,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3026,7 +3902,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3100,7 +3976,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3174,7 +4050,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3246,7 +4122,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3318,7 +4194,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No @@ -3390,7 +4266,7 @@ No domain -The type of the process performing this action. +Domain allowed access. No diff --git a/www/api-docs/templates.html b/www/api-docs/templates.html index 4a5a5144..35a8a0fc 100644 --- a/www/api-docs/templates.html +++ b/www/api-docs/templates.html @@ -16,6 +16,9 @@    -  acct
+    -  + amanda
+    -  anaconda
@@ -88,12 +91,21 @@    -  bootloader
+    -  + corecommands
+    -  corenetwork
   -  devices
+    -  + domain
+ +    -  + files
+    -  filesystem
@@ -127,12 +139,18 @@    -  arpwatch
+    -  + avahi
+    -  bind
   -  bluetooth
+    -  + canna
+    -  comsat
@@ -142,9 +160,18 @@    -  cron
+    -  + cups
+    -  cvs
+    -  + cyrus
+ +    -  + dbskk
+    -  dbus
@@ -154,6 +181,12 @@    -  dictd
+    -  + distcc
+ +    -  + dovecot
+    -  finger
@@ -169,12 +202,18 @@    -  howl
+    -  + i18n_input
+    -  inetd
   -  inn
+    -  + irqbalance
+    -  kerberos
@@ -184,6 +223,9 @@    -  ldap
+    -  + lpd
+    -  mailman
@@ -193,6 +235,9 @@    -  mysql
+    -  + networkmanager
+    -  nis
@@ -202,9 +247,15 @@    -  ntp
+    -  + pegasus
+    -  portmap
+    -  + postfix
+    -  postgresql
@@ -214,15 +265,27 @@    -  privoxy
+    -  + procmail
+ +    -  + radius
+    -  radvd
+    -  + rdisc
+    -  remotelogin
   -  rlogin
+    -  + rpc
+    -  rshd
@@ -241,6 +304,9 @@    -  snmp
+    -  + spamassassin
+    -  squid
@@ -259,9 +325,18 @@    -  tftp
+    -  + timidity
+    -  uucp
+    -  + xdm
+ +    -  + xfs
+    -  zebra
@@ -277,15 +352,6 @@    -  clock
-    -  - corecommands
- -    -  - domain
- -    -  - files
-    -  fstools
@@ -712,10 +778,10 @@ the system DBUS.
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_auto_trans( @@ -738,10 +804,10 @@ Summary is missing!
-Module: +Module: domain

-Layer: -system

+Layer: +kernel

domain_trans( @@ -763,6 +829,32 @@ Summary is missing!
+
+Module: +ftp

+Layer: +services

+

+ +ftp_per_userdomain_template( + + + + + userdomain_prefix + + + )
+
+ +
+

+The per user domain template for the ftp module. +

+
+ +
+
Module: gpg

@@ -831,6 +923,67 @@ The template to define a mailmain domain.

+
+Module: +mta

+Layer: +services

+

+ +mta_admin_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + )
+
+ +
+

+Provide extra permissions for admin users +mail domain. +

+
+ +
+ +
+Module: +mta

+Layer: +services

+

+ +mta_base_mail_template( + + + + + domain_prefix + + + )
+
+ +
+

+Basic mail transfer agent domain template. +

+
+ +
+
Module: mta

@@ -873,6 +1026,162 @@ The per user domain template for the mta module.

+
+Module: +postfix

+Layer: +services

+

+ +postfix_domain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_per_userdomain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_public_domain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_server_domain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+ +
+Module: +postfix

+Layer: +services

+

+ +postfix_user_domain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+ +
+Module: +rpc

+Layer: +services

+

+ +rpc_domain_template( + + + + + userdomain_prefix + + + )
+
+ +
+

+The template to define a rpc domain. +

+
+ +
+
Module: samba

@@ -899,6 +1208,48 @@ The per user domain template for the samba module.

+
+Module: +spamassassin

+Layer: +services

+

+ +spamassassin_per_userdomain_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role + + + )
+
+ +
+

+The per user domain template for the spamassassin module. +

+
+ +
+
Module: ssh

@@ -1009,6 +1360,32 @@ The per user domain template for the su module.

+
+Module: +su

+Layer: +admin

+

+ +su_restricted_domain_template( + + + + + ? + + + )
+
+ +
+

+Summary is missing! +

+
+ +
+
Module: sudo

@@ -1138,6 +1515,18 @@ system

] + + , + + + + [ + + private_type + + ] + + )

@@ -1183,6 +1572,41 @@ Execute user home files.
+
+Module: +userdomain

+Layer: +system

+

+ +userdom_home_file( + + + + + userdomain_prefix + + + + , + + + + type + + + )
+
+ +
+

+Make the specified type usable in a +user home directory. +

+
+ +
+
Module: userdomain

@@ -1300,6 +1724,41 @@ system

+ userdomain_prefix + + + + , + + + + domain + + + )
+

+ +
+

+Create, read, write, and delete symbolic links +in a user home subdirectory. +

+
+ +
+ +
+Module: +userdomain

+Layer: +system

+

+ +userdom_manage_user_home_subdirs( + + + + userdomain_prefix