diff --git a/www/api-docs/admin_acct.html b/www/api-docs/admin_acct.html index f74113de..47669791 100644 --- a/www/api-docs/admin_acct.html +++ b/www/api-docs/admin_acct.html @@ -277,6 +277,7 @@ No + diff --git a/www/api-docs/admin_consoletype.html b/www/api-docs/admin_consoletype.html index ef60f2d5..209af268 100644 --- a/www/api-docs/admin_consoletype.html +++ b/www/api-docs/admin_consoletype.html @@ -195,6 +195,7 @@ No + diff --git a/www/api-docs/admin_dmesg.html b/www/api-docs/admin_dmesg.html index c8eb76bb..9edc3439 100644 --- a/www/api-docs/admin_dmesg.html +++ b/www/api-docs/admin_dmesg.html @@ -193,6 +193,7 @@ No + diff --git a/www/api-docs/admin_firstboot.html b/www/api-docs/admin_firstboot.html index 6e5b668b..f9ec0481 100644 --- a/www/api-docs/admin_firstboot.html +++ b/www/api-docs/admin_firstboot.html @@ -149,6 +149,49 @@ No + +
+ + +
+ +firstboot_dontaudit_use_fd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to inherit a +file descriptor from firstboot. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -317,6 +360,7 @@ No +
diff --git a/www/api-docs/admin_logrotate.html b/www/api-docs/admin_logrotate.html index b0f9b858..08da1cb2 100644 --- a/www/api-docs/admin_logrotate.html +++ b/www/api-docs/admin_logrotate.html @@ -230,6 +230,48 @@ No + +
+ + +
+ +logrotate_read_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read a logrotate temporary files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process to not audit. + + +No +
+
+
+
@@ -314,6 +356,7 @@ No +
diff --git a/www/api-docs/admin_netutils.html b/www/api-docs/admin_netutils.html index 28de26b6..f26a5914 100644 --- a/www/api-docs/admin_netutils.html +++ b/www/api-docs/admin_netutils.html @@ -598,6 +598,7 @@ No + diff --git a/www/api-docs/admin_quota.html b/www/api-docs/admin_quota.html index db3a1a20..4775045d 100644 --- a/www/api-docs/admin_quota.html +++ b/www/api-docs/admin_quota.html @@ -315,6 +315,7 @@ No + diff --git a/www/api-docs/admin_rpm.html b/www/api-docs/admin_rpm.html index 83204909..a0bae7c8 100644 --- a/www/api-docs/admin_rpm.html +++ b/www/api-docs/admin_rpm.html @@ -523,6 +523,7 @@ No + diff --git a/www/api-docs/admin_su.html b/www/api-docs/admin_su.html index 3666cdf0..30884d8f 100644 --- a/www/api-docs/admin_su.html +++ b/www/api-docs/admin_su.html @@ -119,6 +119,22 @@ userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
@@ -158,6 +174,26 @@ is the prefix for user_t). No + +user_domain + + +The type of the user domain. + + +No + + + +user_role + + +The role associated with the user domain. + + +No + +
@@ -166,6 +202,7 @@ No Return + diff --git a/www/api-docs/admin_sudo.html b/www/api-docs/admin_sudo.html index b0eff4b5..be266651 100644 --- a/www/api-docs/admin_sudo.html +++ b/www/api-docs/admin_sudo.html @@ -119,6 +119,22 @@ userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
@@ -158,6 +174,26 @@ is the prefix for user_t). No + +user_domain + + +The type of the user domain. + + +No + + + +user_role + + +The role associated with the user domain. + + +No + +
@@ -166,6 +202,7 @@ No Return + diff --git a/www/api-docs/admin_tmpreaper.html b/www/api-docs/admin_tmpreaper.html index 5009cd54..2be113dc 100644 --- a/www/api-docs/admin_tmpreaper.html +++ b/www/api-docs/admin_tmpreaper.html @@ -151,6 +151,7 @@ No + diff --git a/www/api-docs/admin_updfstab.html b/www/api-docs/admin_updfstab.html index fb5556ea..3012cacc 100644 --- a/www/api-docs/admin_updfstab.html +++ b/www/api-docs/admin_updfstab.html @@ -151,6 +151,7 @@ No + diff --git a/www/api-docs/admin_usermanage.html b/www/api-docs/admin_usermanage.html index 8f124420..f856d862 100644 --- a/www/api-docs/admin_usermanage.html +++ b/www/api-docs/admin_usermanage.html @@ -635,6 +635,7 @@ No + diff --git a/www/api-docs/apps_gpg.html b/www/api-docs/apps_gpg.html index 8ae7d902..4fc64167 100644 --- a/www/api-docs/apps_gpg.html +++ b/www/api-docs/apps_gpg.html @@ -86,6 +86,22 @@ userdomain_prefix + + , + + + + userdomain_prefix + + + + , + + + + domain + + )
@@ -126,6 +142,27 @@ is the prefix for user_t). No + +userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No + + + +domain + + +The type of the process performing this action. + + +No + +
@@ -134,6 +171,7 @@ No Return + diff --git a/www/api-docs/apps_loadkeys.html b/www/api-docs/apps_loadkeys.html index 37de9b0a..fde47c41 100644 --- a/www/api-docs/apps_loadkeys.html +++ b/www/api-docs/apps_loadkeys.html @@ -238,6 +238,7 @@ No + diff --git a/www/api-docs/global_booleans.html b/www/api-docs/global_booleans.html index 40075d2b..d747b17a 100644 --- a/www/api-docs/global_booleans.html +++ b/www/api-docs/global_booleans.html @@ -103,18 +103,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -133,6 +151,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -148,6 +169,9 @@    -  sendmail
+    -  + squid
+    -  ssh
diff --git a/www/api-docs/global_tunables.html b/www/api-docs/global_tunables.html index c60ff47a..91c30477 100644 --- a/www/api-docs/global_tunables.html +++ b/www/api-docs/global_tunables.html @@ -103,18 +103,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -133,6 +151,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -148,6 +169,9 @@    -  sendmail
+    -  + squid
+    -  ssh
diff --git a/www/api-docs/index.html b/www/api-docs/index.html index 07cb0df0..a09f5630 100644 --- a/www/api-docs/index.html +++ b/www/api-docs/index.html @@ -103,18 +103,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -133,6 +151,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -148,6 +169,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -654,16 +678,41 @@ connection and disconnection of devices at runtime. bind

Berkeley internet name domain DNS server.

+ + + comsat +

Comsat, a biff server.

+ cron

Periodic execution of scheduled commands.

+ + + dbus +

Desktop messaging bus

+ + + + dhcp +

Dynamic host configuration protocol (DHCP) server

+ + + + dictd +

Dictionary daemon

+ gpm

General Purpose Mouse driver

+ + + hal +

Hardware abstraction layer

+ howl @@ -674,6 +723,11 @@ connection and disconnection of devices at runtime. inetd

Internet services daemon.

+ + + inn +

Internet News NNTP server

+ kerberos @@ -704,6 +758,11 @@ connection and disconnection of devices at runtime. nscd

Name service cache daemon

+ + + ntp +

Network time protocol daemon

+ privoxy @@ -729,6 +788,11 @@ connection and disconnection of devices at runtime. sendmail

Policy for sendmail.

+ + + squid +

Squid caching http proxy server

+ ssh diff --git a/www/api-docs/interfaces.html b/www/api-docs/interfaces.html index 4f8d87ce..f906606a 100644 --- a/www/api-docs/interfaces.html +++ b/www/api-docs/interfaces.html @@ -103,18 +103,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -133,6 +151,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -148,6 +169,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -1286,6 +1310,32 @@ Read BIND named configuration files. +
+Module: +bind

+Layer: +services

+

+ +bind_read_dnssec_keys( + + + + + domain + + + )
+
+ +
+

+Read DNSSEC keys. +

+
+ +
+
Module: bind

@@ -1565,6 +1615,33 @@ Execute bootloader in the bootloader domain.

+
+Module: +bootloader

+Layer: +kernel

+

+ +bootloader_dontaudit_getattr_boot_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get attributes +of the /boot directory. +

+
+ +
+
Module: bootloader

@@ -2600,6 +2677,41 @@ Read symbolic links in sbin directories.

+
+Module: +corecommands

+Layer: +system

+

+ +corecmd_sbin_domtrans( + + + + + domain + + + + , + + + + target_domain + + + )
+
+ +
+

+Execute a file in a sbin directory +in the specified domain. +

+
+ +
+
Module: corecommands

@@ -5244,6 +5356,32 @@ Bind TCP sockets to the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_bind_ntp_port( + + + + + domain + + + )
+
+ +
+

+Bind TCP sockets to the ntp port. +

+
+ +
+
Module: corenetwork

@@ -6440,6 +6578,32 @@ Make a TCP connection to the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_connect_ntp_port( + + + + + domain + + + )
+
+ +
+

+Make a TCP connection to the ntp port. +

+
+ +
+
Module: corenetwork

@@ -8104,6 +8268,32 @@ Send and receive TCP traffic on the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_tcp_sendrecv_ntp_port( + + + + + domain + + + )
+
+ +
+

+Send and receive TCP traffic on the ntp port. +

+
+ +
+
Module: corenetwork

@@ -9586,6 +9776,32 @@ Bind UDP sockets to the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_bind_ntp_port( + + + + + domain + + + )
+
+ +
+

+Bind UDP sockets to the ntp port. +

+
+ +
+
Module: corenetwork

@@ -11328,6 +11544,32 @@ Receive UDP traffic on the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_receive_ntp_port( + + + + + domain + + + )
+
+ +
+

+Receive UDP traffic on the ntp port. +

+
+ +
+
Module: corenetwork

@@ -13070,6 +13312,32 @@ Send UDP traffic on the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_send_ntp_port( + + + + + domain + + + )
+
+ +
+

+Send UDP traffic on the ntp port. +

+
+ +
+
Module: corenetwork

@@ -14812,6 +15080,32 @@ Send and receive UDP traffic on the nmbd port.

+
+Module: +corenetwork

+Layer: +kernel

+

+ +corenet_udp_sendrecv_ntp_port( + + + + + domain + + + )
+
+ +
+

+Send and receive UDP traffic on the ntp port. +

+
+ +
+
Module: corenetwork

@@ -15482,7 +15776,33 @@ services

-Read a cron daemon unnamed pipe +Read a cron daemon unnamed pipe. +

+
+ +
+ +
+Module: +cron

+Layer: +services

+

+ +cron_read_system_job_tmp_files( + + + + + domain + + + )
+
+ +
+

+Read temporary files from the system cron jobs.

@@ -15514,6 +15834,32 @@ Read and write the cron daemon log files.
+
+Module: +cron

+Layer: +services

+

+ +cron_rw_pipe( + + + + + domain + + + )
+
+ +
+

+Read and write a cron daemon unnamed pipe. +

+
+ +
+
Module: cron

@@ -15540,6 +15886,32 @@ Search the directory containing user cron tables.

+
+Module: +cron

+Layer: +services

+

+ +cron_sigchld( + + + + + domain + + + )
+
+ +
+

+Send a SIGCHLD signal to the cron daemon. +

+
+ +
+
Module: cron

@@ -15575,6 +15947,139 @@ from the system cron jobs.

+
+Module: +cron

+Layer: +services

+

+ +cron_use_fd( + + + + + domain + + + )
+
+ +
+

+Inherit and use a file descriptor +from the cron daemon. +

+
+ +
+ +
+Module: +cron

+Layer: +services

+

+ +cron_use_system_job_fd( + + + + + domain + + + )
+
+ +
+

+Inherit and use a file descriptor +from system cron jobs. +

+
+ +
+ +
+Module: +cron

+Layer: +services

+

+ +cron_write_system_job_pipe( + + + + + domain + + + )
+
+ +
+

+Wrate a system cron job unnamed pipe. +

+
+ +
+ +
+Module: +dbus

+Layer: +services

+

+ +dbus_connect_system_bus( + + + + + domain + + + )
+
+ +
+

+Connect to the the system DBUS +for service (acquire_svc). +

+
+ +
+ +
+Module: +dbus

+Layer: +services

+

+ +dbus_send_system_bus_msg( + + + + + domain + + + )
+
+ +
+

+Send a message on the system DBUS. +

+
+ +
+
Module: devices

@@ -17713,6 +18218,32 @@ Read and write the the power management device.

+
+Module: +devices

+Layer: +kernel

+

+ +dev_rw_printer( + + + + + domain + + + )
+
+ +
+

+Read and write the printer device. +

+
+ +
+
Module: devices

@@ -18548,6 +19079,60 @@ Write and execute raw memory devices (e.g. /dev/mem).

+
+Module: +dhcp

+Layer: +services

+

+ +dhcpd_setattr_state_files( + + + + + domain + + + )
+
+ +
+

+Set the attributes of the DCHP +server state files. +

+
+ +
+ +
+Module: +dictd

+Layer: +services

+

+ +dictd_use( + + + + + domain + + + )
+
+ +
+

+Use dictionary services by connecting +over TCP. +

+
+ +
+
Module: dmesg

@@ -20082,6 +20667,33 @@ of the /var/run directory.

+
+Module: +files

+Layer: +system

+

+ +files_dontaudit_getattr_tmp_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the +attributes of the tmp directory (/tmp). +

+
+ +
+
Module: files

@@ -20260,7 +20872,8 @@ system

-Do not audit attempts to search home directories root. +Do not audit attempts to search +home directories root (/home).

@@ -20606,6 +21219,34 @@ Summary is missing!
+
+Module: +files

+Layer: +system

+

+ +files_getattr_home_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the +attributes of the home directories root +(/home). +

+
+ +
+
Module: files

@@ -20919,6 +21560,33 @@ Summary is missing!

+
+Module: +files

+Layer: +system

+

+ +files_list_usr( + + + + + domain + + + )
+
+ +
+

+List the contents of generic +directories in /usr. +

+
+ +
+
Module: files

@@ -22362,6 +23030,33 @@ Summary is missing!

+
+Module: +files

+Layer: +system

+

+ +files_rw_etc_runtime_files( + + + + + domain + + + )
+
+ +
+

+Read and write files in /etc that are dynamically +created on boot, such as mtab. +

+
+ +
+
Module: files

@@ -22514,7 +23209,7 @@ system

-Search home directories root. +Search home directories root (/home).

@@ -22963,6 +23658,33 @@ Execute firstboot in the firstboot domain.
+
+Module: +firstboot

+Layer: +admin

+

+ +firstboot_dontaudit_use_fd( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to inherit a +file descriptor from firstboot. +

+
+ +
+
Module: firstboot

@@ -27382,7 +28104,7 @@ system

- ? + domain )
@@ -27390,7 +28112,33 @@ system

-Summary is missing! +Send init a SIGCHLD signal. +

+
+ +
+ +
+Module: +init

+Layer: +system

+

+ +init_signull( + + + + + domain + + + )
+
+ +
+

+Send init a null signal.

@@ -27587,6 +28335,216 @@ Summary is missing!
+
+Module: +inn

+Layer: +services

+

+ +inn_exec( + + + + + domain + + + )
+
+ +
+

+Allow the specified domain to execute innd +in the caller domain. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_exec_config( + + + + + domain + + + )
+
+ +
+

+Allow the specified domain to execute +inn configuration files in /etc. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_manage_log( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete the innd log. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_manage_pid( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete the innd pid files. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_read_config( + + + + + domain + + + )
+
+ +
+

+Read innd configuration files. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_read_news_lib( + + + + + domain + + + )
+
+ +
+

+Read innd news library files. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_read_news_spool( + + + + + domain + + + )
+
+ +
+

+Read innd news library files. +

+
+ +
+ +
+Module: +inn

+Layer: +services

+

+ +inn_sendto_unix_dgram_socket( + + + + + domain + + + )
+
+ +
+

+Send to a innd unix dgram socket. +

+
+ +
+
Module: ipsec

@@ -28102,6 +29060,33 @@ read system state information in proc.

+
+Module: +kernel

+Layer: +kernel

+

+ +kernel_dontaudit_search_network_state( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to search the network +state directory. +

+
+ +
+
Module: kernel

@@ -30680,6 +31665,32 @@ Execute logrotate in the caller domain.

+
+Module: +logrotate

+Layer: +admin

+

+ +logrotate_read_tmp_files( + + + + + domain + + + )
+
+ +
+

+Read a logrotate temporary files. +

+
+ +
+
Module: logrotate

@@ -31461,6 +32472,32 @@ Use file descriptors for mount.

+
+Module: +mta

+Layer: +services

+

+ +mta_append_spool( + + + + + domain + + + )
+
+ +
+

+Create, read, and write the mail spool. +

+
+ +
+
Module: mta

@@ -31566,6 +32603,88 @@ Summary is missing!

+
+Module: +mta

+Layer: +services

+

+ +mta_mailserver_delivery( + + + + + domain + + + )
+
+ +
+

+Make a type a mailserver type used +for delivering mail to local users. +

+
+ +
+ +
+Module: +mta

+Layer: +services

+

+ +mta_mailserver_sender( + + + + + domain + + + )
+
+ +
+

+Make a type a mailserver type used +for sending mail. +

+
+ +
+ +
+Module: +mta

+Layer: +services

+

+ +mta_mailserver_user_agent( + + + + + domain + + + )
+
+ +
+

+Make a type a mailserver type used +for sending mail on behalf of local +users to the local mail spool. +

+
+ +
+
Module: mta

@@ -32435,6 +33554,58 @@ a unix stream socket.

+
+Module: +ntp

+Layer: +services

+

+ +ntp_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute ntp server in the ntpd domain. +

+
+ +
+ +
+Module: +ntp

+Layer: +services

+

+ +ntp_domtrans_ntpdate( + + + + + domain + + + )
+
+ +
+

+Execute ntp server in the ntpd domain. +

+
+ +
+
Module: pcmcia

@@ -33190,6 +34361,33 @@ Allows caller to compute possible contexts for a user.

+
+Module: +selinux

+Layer: +kernel

+

+ +selinux_dontaudit_getattr_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the +attributes of the selinuxfs directory. +

+
+ +
+
Module: selinux

@@ -34435,6 +35633,111 @@ Summary is missing!

+
+Module: +squid

+Layer: +services

+

+ +squid_domtrans( + + + + + domain + + + )
+
+ +
+

+Execute squid in the squid domain. +

+
+ +
+ +
+Module: +squid

+Layer: +services

+

+ +squid_manage_logs( + + + + + domain + + + )
+
+ +
+

+Create, read, write, and delete +squid logs. +

+
+ +
+ +
+Module: +squid

+Layer: +services

+

+ +squid_read_config( + + + + + domain + + + )
+
+ +
+

+Read squid configuration file. +

+
+ +
+ +
+Module: +squid

+Layer: +services

+

+ +squid_use( + + + + + domain + + + )
+
+ +
+

+Use squid services by connecting over TCP. +

+
+ +
+
Module: ssh

@@ -35310,6 +36613,52 @@ the network config files.

+
+Module: +sysnetwork

+Layer: +system

+

+ +sysnet_create_dhcp_state( + + + + + domain + + + + , + + + + file_type + + + + , + + + + [ + + object_class + + ] + + + )
+
+ +
+

+Create DHCP state data. +

+
+ +
+
Module: sysnetwork

@@ -35440,6 +36789,32 @@ Allow network init to read network config files.

+
+Module: +sysnetwork

+Layer: +system

+

+ +sysnet_read_dhcp_config( + + + + + domain + + + )
+
+ +
+

+Read the DHCP configuration files. +

+
+ +
+
Module: sysnetwork

@@ -35562,6 +36937,32 @@ Read and write dhcp configuration files.

+
+Module: +sysnetwork

+Layer: +system

+

+ +sysnet_search_dhcp_state( + + + + + domain + + + )
+
+ +
+

+Search the DHCP state data directory. +

+
+ +
+
Module: sysnetwork

@@ -35756,6 +37157,33 @@ device nodes.

+
+Module: +terminal

+Layer: +kernel

+

+ +term_dontaudit_getattr_pty_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to get the +attributes of the /dev/pts directory. +

+
+ +
+
Module: terminal

@@ -37177,6 +38605,33 @@ with automatic file type transition.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_dontaudit_list_sysadm_home_dir( + + + + + domain + + + )
+
+ +
+

+Do not audit attempts to list the sysadm +users home directory. +

+
+ +
+
Module: userdomain

@@ -37734,6 +39189,32 @@ Execute a shell in the sysadm domain.

+
+Module: +userdomain

+Layer: +system

+

+ +userdom_sigcld_all_users( + + + + + domain + + + )
+
+ +
+

+Send a SIGCHLD signal to all user domains. +

+
+ +
+
Module: userdomain

diff --git a/www/api-docs/kernel_bootloader.html b/www/api-docs/kernel_bootloader.html index d9fd8531..ec96c97f 100644 --- a/www/api-docs/kernel_bootloader.html +++ b/www/api-docs/kernel_bootloader.html @@ -384,6 +384,49 @@ No

+ +
+ + +
+ +bootloader_dontaudit_getattr_boot_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get attributes +of the /boot directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -976,6 +1019,7 @@ No +
diff --git a/www/api-docs/kernel_corenetwork.html b/www/api-docs/kernel_corenetwork.html index 5f60547c..48cbc30b 100644 --- a/www/api-docs/kernel_corenetwork.html +++ b/www/api-docs/kernel_corenetwork.html @@ -4105,6 +4105,48 @@ Bind TCP sockets to the nmbd port.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+ + + + +
+ + +
+ +corenet_tcp_bind_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind TCP sockets to the ntp port. +

+ +
Parameters
@@ -6037,6 +6079,48 @@ Make a TCP connection to the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_connect_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a TCP connection to the ntp port. +

+ +
Parameters
@@ -8725,6 +8809,48 @@ Send and receive TCP traffic on the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_tcp_sendrecv_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive TCP traffic on the ntp port. +

+ +
Parameters
@@ -11119,6 +11245,48 @@ Bind UDP sockets to the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_bind_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Bind UDP sockets to the ntp port. +

+ +
Parameters
@@ -13933,6 +14101,48 @@ Receive UDP traffic on the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_receive_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Receive UDP traffic on the ntp port. +

+ +
Parameters
@@ -16747,6 +16957,48 @@ Send UDP traffic on the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_send_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send UDP traffic on the ntp port. +

+ +
Parameters
@@ -19561,6 +19813,48 @@ Send and receive UDP traffic on the nmbd port.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +corenet_udp_sendrecv_ntp_port( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send and receive UDP traffic on the ntp port. +

+ +
Parameters
@@ -20634,6 +20928,7 @@ No + diff --git a/www/api-docs/kernel_devices.html b/www/api-docs/kernel_devices.html index 77945a0f..2a5eab59 100644 --- a/www/api-docs/kernel_devices.html +++ b/www/api-docs/kernel_devices.html @@ -3549,6 +3549,48 @@ Read and write the the power management device.

+
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +dev_rw_printer( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write the printer device. +

+ +
Parameters
@@ -4919,6 +4961,7 @@ No + diff --git a/www/api-docs/kernel_filesystem.html b/www/api-docs/kernel_filesystem.html index 14435a53..97f8b7d4 100644 --- a/www/api-docs/kernel_filesystem.html +++ b/www/api-docs/kernel_filesystem.html @@ -4637,6 +4637,7 @@ No + diff --git a/www/api-docs/kernel_kernel.html b/www/api-docs/kernel_kernel.html index e8318854..3128cb7f 100644 --- a/www/api-docs/kernel_kernel.html +++ b/www/api-docs/kernel_kernel.html @@ -391,6 +391,49 @@ No + +
+ + +
+ +kernel_dontaudit_search_network_state( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to search the network +state directory. +

+ + +
Parameters
+
Parameter:Description:Optional:
+ + + + +
Parameter:Description:Optional:
+domain + + +The process type reading the state. + + +No +
+
+
+
@@ -2942,6 +2985,7 @@ No +
diff --git a/www/api-docs/kernel_selinux.html b/www/api-docs/kernel_selinux.html index 73b0e1ee..ee56efe6 100644 --- a/www/api-docs/kernel_selinux.html +++ b/www/api-docs/kernel_selinux.html @@ -272,6 +272,49 @@ No + +
+ + +
+ +selinux_dontaudit_getattr_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the +attributes of the selinuxfs directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain to not audit. + + +No +
+
+
+
@@ -717,6 +760,7 @@ No +
diff --git a/www/api-docs/kernel_storage.html b/www/api-docs/kernel_storage.html index a7ac52f2..dc0507f6 100644 --- a/www/api-docs/kernel_storage.html +++ b/www/api-docs/kernel_storage.html @@ -1398,6 +1398,7 @@ No + diff --git a/www/api-docs/kernel_terminal.html b/www/api-docs/kernel_terminal.html index 4fd469c1..5c8ad61a 100644 --- a/www/api-docs/kernel_terminal.html +++ b/www/api-docs/kernel_terminal.html @@ -239,6 +239,49 @@ No + +
+ + +
+ +term_dontaudit_getattr_pty_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the +attributes of the /dev/pts directory. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process to not audit. + + +No +
+
+
+
@@ -1804,6 +1847,7 @@ No +
diff --git a/www/api-docs/services.html b/www/api-docs/services.html index b87ed074..354fdaf2 100644 --- a/www/api-docs/services.html +++ b/www/api-docs/services.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -133,16 +157,41 @@ bind

Berkeley internet name domain DNS server.

+ + + comsat +

Comsat, a biff server.

+ cron

Periodic execution of scheduled commands.

+ + + dbus +

Desktop messaging bus

+ + + + dhcp +

Dynamic host configuration protocol (DHCP) server

+ + + + dictd +

Dictionary daemon

+ gpm

General Purpose Mouse driver

+ + + hal +

Hardware abstraction layer

+ howl @@ -153,6 +202,11 @@ inetd

Internet services daemon.

+ + + inn +

Internet News NNTP server

+ kerberos @@ -183,6 +237,11 @@ nscd

Name service cache daemon

+ + + ntp +

Network time protocol daemon

+ privoxy @@ -208,6 +267,11 @@ sendmail

Policy for sendmail.

+ + + squid +

Squid caching http proxy server

+ ssh diff --git a/www/api-docs/services_bind.html b/www/api-docs/services_bind.html index 53c345d8..14c1ef8f 100644 --- a/www/api-docs/services_bind.html +++ b/www/api-docs/services_bind.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -185,6 +209,48 @@ Read BIND named configuration files.

+
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+ + + + +
+ + +
+ +bind_read_dnssec_keys( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read DNSSEC keys. +

+ +
Parameters
@@ -372,6 +438,7 @@ No + diff --git a/www/api-docs/services_comsat.html b/www/api-docs/services_comsat.html new file mode 100644 index 00000000..0d8cbf1a --- /dev/null +++ b/www/api-docs/services_comsat.html @@ -0,0 +1,150 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: comsat

+ +

Description:

+ +

Comsat, a biff server.

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_cron.html b/www/api-docs/services_cron.html index e0e66a0f..120e8a5b 100644 --- a/www/api-docs/services_cron.html +++ b/www/api-docs/services_cron.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -142,7 +166,7 @@
Summary

-Read a cron daemon unnamed pipe +Read a cron daemon unnamed pipe.

@@ -154,7 +178,49 @@ Read a cron daemon unnamed pipe domain + +
Parameter:Description:Optional:
-The type of the process to performing this action. +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cron_read_system_job_tmp_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read temporary files from the system cron jobs. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. No @@ -206,6 +272,48 @@ No + +
+ + +
+ +cron_rw_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write a cron daemon unnamed pipe. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -248,6 +356,48 @@ No
+ +
+ + +
+ +cron_sigchld( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send a SIGCHLD signal to the cron daemon. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -309,6 +459,134 @@ No
+ +
+ + +
+ +cron_use_fd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Inherit and use a file descriptor +from the cron daemon. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cron_use_system_job_fd( + + + + + domain + + + )
+
+
+ +
Summary
+

+Inherit and use a file descriptor +from system cron jobs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +cron_write_system_job_pipe( + + + + + domain + + + )
+
+
+ +
Summary
+

+Wrate a system cron job unnamed pipe. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ Return @@ -381,6 +659,22 @@ No userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
@@ -420,6 +714,26 @@ is the prefix for user_t). No
+user_domain + + +The type of the user domain. + + +No +
+user_role + + +The role associated with the user domain. + + +No +
@@ -428,6 +742,7 @@ No Return + diff --git a/www/api-docs/services_dbus.html b/www/api-docs/services_dbus.html new file mode 100644 index 00000000..57f903db --- /dev/null +++ b/www/api-docs/services_dbus.html @@ -0,0 +1,402 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: dbus

+ +Interfaces +Templates + +

Description:

+ +

Desktop messaging bus

+ + + + +

Interfaces:

+ + +
+ + +
+ +dbus_connect_system_bus( + + + + + domain + + + )
+
+
+ +
Summary
+

+Connect to the the system DBUS +for service (acquire_svc). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +dbus_send_system_bus_msg( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send a message on the system DBUS. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + +

Templates:

+ + +
+ + +
+ +dbus_per_userdomain_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role + + + )
+
+
+ +
Summary
+

+The per user domain template for the dbus module. +

+ + +
Description
+

+

+This template creates a derived domain which is +used for the user dbus. +

+

+This template is invoked automatically for each user, and +generally does not need to be invoked directly +by policy writers. +

+

+ +
Parameters
+ + + + + + + + + +
Parameter:Description:Optional:
+userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+user_domain + + +The type of the user domain. + + +No +
+user_role + + +The role associated with the user domain. + + +No +
+
+
+ + +
+ + +
+ +dbus_system_bus_client_template( + + + + + domain_prefix + + + + , + + + + domain + + + )
+
+
+ +
Summary
+

+Template for creating connections to +the system DBUS. +

+ + +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain_prefix + + +The prefix of the domain (e.g., user +is the prefix for user_t). + + +No +
+domain + + +The type of the domain. + + +No +
+
+
+ + +Return + + + +
+ + diff --git a/www/api-docs/services_dhcp.html b/www/api-docs/services_dhcp.html new file mode 100644 index 00000000..46fd88ce --- /dev/null +++ b/www/api-docs/services_dhcp.html @@ -0,0 +1,197 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: dhcp

+ +

Description:

+ +

Dynamic host configuration protocol (DHCP) server

+ + + + +

Interfaces:

+ + +
+ + +
+ +dhcpd_setattr_state_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Set the attributes of the DCHP +server state files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_dictd.html b/www/api-docs/services_dictd.html new file mode 100644 index 00000000..e03fa348 --- /dev/null +++ b/www/api-docs/services_dictd.html @@ -0,0 +1,197 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: dictd

+ +

Description:

+ +

Dictionary daemon

+ + + + +

Interfaces:

+ + +
+ + +
+ +dictd_use( + + + + + domain + + + )
+
+
+ +
Summary
+

+Use dictionary services by connecting +over TCP. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_gpm.html b/www/api-docs/services_gpm.html index f4d94b8a..9ca6796f 100644 --- a/www/api-docs/services_gpm.html +++ b/www/api-docs/services_gpm.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -254,6 +278,7 @@ No + diff --git a/www/api-docs/services_hal.html b/www/api-docs/services_hal.html new file mode 100644 index 00000000..e2373490 --- /dev/null +++ b/www/api-docs/services_hal.html @@ -0,0 +1,150 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: hal

+ +

Description:

+ +

Hardware abstraction layer

+ + + + + +

No interfaces or templates.

+ + +
+ + diff --git a/www/api-docs/services_howl.html b/www/api-docs/services_howl.html index bc827ce5..a4403bc8 100644 --- a/www/api-docs/services_howl.html +++ b/www/api-docs/services_howl.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -118,6 +142,9 @@ +

No interfaces or templates.

+ + diff --git a/www/api-docs/services_inetd.html b/www/api-docs/services_inetd.html index dc5d7657..94ce0a6f 100644 --- a/www/api-docs/services_inetd.html +++ b/www/api-docs/services_inetd.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -499,6 +523,7 @@ No + diff --git a/www/api-docs/services_inn.html b/www/api-docs/services_inn.html new file mode 100644 index 00000000..5d507115 --- /dev/null +++ b/www/api-docs/services_inn.html @@ -0,0 +1,492 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: inn

+ +

Description:

+ +

Internet News NNTP server

+ + + + +

Interfaces:

+ + +
+ + +
+ +inn_exec( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow the specified domain to execute innd +in the caller domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_exec_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Allow the specified domain to execute +inn configuration files in /etc. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_manage_log( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete the innd log. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_manage_pid( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete the innd pid files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read innd configuration files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_read_news_lib( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read innd news library files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_read_news_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read innd news library files. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +inn_sendto_unix_dgram_socket( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send to a innd unix dgram socket. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_kerberos.html b/www/api-docs/services_kerberos.html index 0bc7c125..aed8b53c 100644 --- a/www/api-docs/services_kerberos.html +++ b/www/api-docs/services_kerberos.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -270,6 +294,7 @@ No + diff --git a/www/api-docs/services_ldap.html b/www/api-docs/services_ldap.html index e33a18ea..792e3326 100644 --- a/www/api-docs/services_ldap.html +++ b/www/api-docs/services_ldap.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -209,6 +233,7 @@ No + diff --git a/www/api-docs/services_mta.html b/www/api-docs/services_mta.html index 8ba217af..afe0c8f8 100644 --- a/www/api-docs/services_mta.html +++ b/www/api-docs/services_mta.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -122,6 +146,48 @@

Interfaces:

+ +
+ + +
+ +mta_append_spool( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, and write the mail spool. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -291,6 +357,136 @@ No
+ +
+ + +
+ +mta_mailserver_delivery( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a type a mailserver type used +for delivering mail to local users. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Mail server domain type used for delivering mail. + + +No +
+
+
+ + +
+ + +
+ +mta_mailserver_sender( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a type a mailserver type used +for sending mail. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Mail server domain type used for sending mail. + + +No +
+
+
+ + +
+ + +
+ +mta_mailserver_user_agent( + + + + + domain + + + )
+
+
+ +
Summary
+

+Make a type a mailserver type used +for sending mail on behalf of local +users to the local mail spool. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Mail server domain type used for sending local mail. + + +No +
+
+
+
@@ -638,7 +834,23 @@ No - ? + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role )
@@ -647,19 +859,54 @@ No
Summary

-Summary is missing! +The per user domain template for the mta module.

+
Description
+

+

+This template creates a derived domain which is +a email transfer agent, which sends mail on +behalf of the user. +

+

+This template is invoked automatically for each user, and +generally does not need to be invoked directly +by policy writers. +

+

+
Parameters
+ + + + + + + +
Parameter:Description:Optional:
-? +userdomain_prefix -Parameter descriptions are missing! +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
+user_domain + + +The type of the user domain. + + +No +
+user_role + + +The role associated with the user domain. No @@ -673,6 +920,7 @@ No Return + diff --git a/www/api-docs/services_mysql.html b/www/api-docs/services_mysql.html index 8cc11fbd..68825c19 100644 --- a/www/api-docs/services_mysql.html +++ b/www/api-docs/services_mysql.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -419,6 +443,7 @@ No + diff --git a/www/api-docs/services_nis.html b/www/api-docs/services_nis.html index 945476b0..168cae8b 100644 --- a/www/api-docs/services_nis.html +++ b/www/api-docs/services_nis.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -250,6 +274,7 @@ No + diff --git a/www/api-docs/services_nscd.html b/www/api-docs/services_nscd.html index 443f0197..219f0832 100644 --- a/www/api-docs/services_nscd.html +++ b/www/api-docs/services_nscd.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -336,6 +360,7 @@ No + diff --git a/www/api-docs/services_ntp.html b/www/api-docs/services_ntp.html new file mode 100644 index 00000000..a9f1603a --- /dev/null +++ b/www/api-docs/services_ntp.html @@ -0,0 +1,238 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: ntp

+ +

Description:

+ +

Network time protocol daemon

+ + + + +

Interfaces:

+ + +
+ + +
+ +ntp_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute ntp server in the ntpd domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +ntp_domtrans_ntpdate( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute ntp server in the ntpd domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_privoxy.html b/www/api-docs/services_privoxy.html index 672dbc97..d8f3197c 100644 --- a/www/api-docs/services_privoxy.html +++ b/www/api-docs/services_privoxy.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -118,6 +142,9 @@ +

No interfaces or templates.

+ + diff --git a/www/api-docs/services_remotelogin.html b/www/api-docs/services_remotelogin.html index c20291de..87c952a5 100644 --- a/www/api-docs/services_remotelogin.html +++ b/www/api-docs/services_remotelogin.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -166,6 +190,7 @@ No + diff --git a/www/api-docs/services_rshd.html b/www/api-docs/services_rshd.html index 2d3e2b08..455202c6 100644 --- a/www/api-docs/services_rshd.html +++ b/www/api-docs/services_rshd.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -166,6 +190,7 @@ No + diff --git a/www/api-docs/services_rsync.html b/www/api-docs/services_rsync.html index 64949647..03f24eaf 100644 --- a/www/api-docs/services_rsync.html +++ b/www/api-docs/services_rsync.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -118,6 +142,9 @@ +

No interfaces or templates.

+ + diff --git a/www/api-docs/services_sendmail.html b/www/api-docs/services_sendmail.html index 1dc83474..38374243 100644 --- a/www/api-docs/services_sendmail.html +++ b/www/api-docs/services_sendmail.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -166,6 +190,7 @@ No + diff --git a/www/api-docs/services_squid.html b/www/api-docs/services_squid.html new file mode 100644 index 00000000..9df9e4e1 --- /dev/null +++ b/www/api-docs/services_squid.html @@ -0,0 +1,323 @@ + + + + Security Enhanced Linux Reference Policy + + + + + + + +
+ +

Layer: services

+

Module: squid

+ +

Description:

+ +

Squid caching http proxy server

+ + + + +

Interfaces:

+ + +
+ + +
+ +squid_domtrans( + + + + + domain + + + )
+
+
+ +
Summary
+

+Execute squid in the squid domain. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+ + +
+ + +
+ +squid_manage_logs( + + + + + domain + + + )
+
+
+ +
Summary
+

+Create, read, write, and delete +squid logs. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +squid_read_config( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read squid configuration file. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +
+ + +
+ +squid_use( + + + + + domain + + + )
+
+
+ +
Summary
+

+Use squid services by connecting over TCP. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+ + +Return + + + + +
+ + diff --git a/www/api-docs/services_ssh.html b/www/api-docs/services_ssh.html index c7c75154..00c55365 100644 --- a/www/api-docs/services_ssh.html +++ b/www/api-docs/services_ssh.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -183,6 +207,22 @@ No userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
@@ -222,6 +262,26 @@ is the prefix for user_t). No
+user_domain + + +The type of the user domain. + + +No +
+user_role + + +The role associated with the user domain. + + +No +
@@ -284,6 +344,7 @@ No Return + diff --git a/www/api-docs/services_tcpd.html b/www/api-docs/services_tcpd.html index 9a42120b..60aab6cf 100644 --- a/www/api-docs/services_tcpd.html +++ b/www/api-docs/services_tcpd.html @@ -34,18 +34,36 @@    -  bind
+    -  + comsat
+    -  cron
+    -  + dbus
+ +    -  + dhcp
+ +    -  + dictd
+    -  gpm
+    -  + hal
+    -  howl
   -  inetd
+    -  + inn
+    -  kerberos
@@ -64,6 +82,9 @@    -  nscd
+    -  + ntp
+    -  privoxy
@@ -79,6 +100,9 @@    -  sendmail
+    -  + squid
+    -  ssh
@@ -118,6 +142,9 @@ +

No interfaces or templates.

+ + diff --git a/www/api-docs/system_authlogin.html b/www/api-docs/system_authlogin.html index 0b3dd822..67dd9794 100644 --- a/www/api-docs/system_authlogin.html +++ b/www/api-docs/system_authlogin.html @@ -1695,6 +1695,22 @@ No userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
@@ -1735,6 +1751,26 @@ is the prefix for user_t). No + +user_domain + + +The type of the user domain. + + +No + + + +user_role + + +The role associated with the user domain. + + +No + +
@@ -1743,6 +1779,7 @@ No Return + diff --git a/www/api-docs/system_clock.html b/www/api-docs/system_clock.html index 45a5b99c..27e46048 100644 --- a/www/api-docs/system_clock.html +++ b/www/api-docs/system_clock.html @@ -353,6 +353,7 @@ No + diff --git a/www/api-docs/system_corecommands.html b/www/api-docs/system_corecommands.html index 0aa14c14..ff33bb5c 100644 --- a/www/api-docs/system_corecommands.html +++ b/www/api-docs/system_corecommands.html @@ -142,6 +142,8 @@ in /bin, /sbin, /usr/bin, and /usr/sbin.

+

This module is required to be included in all policies.

+

Interfaces:

@@ -983,6 +985,87 @@ No + +
+ + +
+ +corecmd_sbin_domtrans( + + + + + domain + + + + , + + + + target_domain + + + )
+
+
+ +
Summary
+

+Execute a file in a sbin directory +in the specified domain. +

+ + +
Description
+

+

+Execute a file in a sbin directory +in the specified domain. This allows +the specified domain to execute any file +on these filesystems in the specified +domain. This is not suggested. +

+

+No interprocess communication (signals, pipes, +etc.) is provided by this interface since +the domains are not owned by this module. +

+

+This interface was added to handle +the ssh-agent policy. +

+

+ +
Parameters
+ + + + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+target_domain + + +The type of the new process. + + +No +
+
+
+
@@ -1262,6 +1345,7 @@ No +
diff --git a/www/api-docs/system_domain.html b/www/api-docs/system_domain.html index 25380ee9..fc62e908 100644 --- a/www/api-docs/system_domain.html +++ b/www/api-docs/system_domain.html @@ -1711,6 +1711,7 @@ No Return + diff --git a/www/api-docs/system_files.html b/www/api-docs/system_files.html index 7273fb67..55c6027d 100644 --- a/www/api-docs/system_files.html +++ b/www/api-docs/system_files.html @@ -1112,6 +1112,49 @@ No + +
+ + +
+ +files_dontaudit_getattr_tmp_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the +attributes of the tmp directory (/tmp). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -1386,7 +1429,8 @@ No
Summary

-Do not audit attempts to search home directories root. +Do not audit attempts to search +home directories root (/home).

@@ -1956,6 +2000,50 @@ No
+ +
+ + +
+ +files_getattr_home_dir( + + + + + domain + + + )
+
+
+ +
Summary
+

+Do not audit attempts to get the +attributes of the home directories root +(/home). +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +The type of the process performing this action. + + +No +
+
+
+
@@ -2461,6 +2549,49 @@ No
+ +
+ + +
+ +files_list_usr( + + + + + domain + + + )
+
+
+ +
Summary
+

+List the contents of generic +directories in /usr. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -4790,6 +4921,49 @@ No
+ +
+ + +
+ +files_rw_etc_runtime_files( + + + + + domain + + + )
+
+
+ +
Summary
+

+Read and write files in /etc that are dynamically +created on boot, such as mtab. +

+ + +
Parameters
+ + + + + +
Parameter:Description:Optional:
+domain + + +Domain allowed access. + + +No +
+
+
+
@@ -5022,7 +5196,7 @@ No
Summary

-Search home directories root. +Search home directories root (/home).

@@ -5722,6 +5896,7 @@ No +
diff --git a/www/api-docs/system_fstools.html b/www/api-docs/system_fstools.html index b38385fe..89b7e2d2 100644 --- a/www/api-docs/system_fstools.html +++ b/www/api-docs/system_fstools.html @@ -397,6 +397,7 @@ No + diff --git a/www/api-docs/system_getty.html b/www/api-docs/system_getty.html index a426f191..e1ff8040 100644 --- a/www/api-docs/system_getty.html +++ b/www/api-docs/system_getty.html @@ -316,6 +316,7 @@ No + diff --git a/www/api-docs/system_hostname.html b/www/api-docs/system_hostname.html index c0d4a1f3..e08d8aef 100644 --- a/www/api-docs/system_hostname.html +++ b/www/api-docs/system_hostname.html @@ -311,6 +311,7 @@ No + diff --git a/www/api-docs/system_hotplug.html b/www/api-docs/system_hotplug.html index edc33480..19b6540a 100644 --- a/www/api-docs/system_hotplug.html +++ b/www/api-docs/system_hotplug.html @@ -487,6 +487,7 @@ No + diff --git a/www/api-docs/system_init.html b/www/api-docs/system_init.html index 6c999a51..8aa8466e 100644 --- a/www/api-docs/system_init.html +++ b/www/api-docs/system_init.html @@ -1245,7 +1245,7 @@ No - ? + domain )
@@ -1254,7 +1254,7 @@ No
Summary

-Summary is missing! +Send init a SIGCHLD signal.

@@ -1263,10 +1263,52 @@ Summary is missing! Parameter:Description:Optional: -? +domain -Parameter descriptions are missing! +Domain allowed access. + + +No + + + + + + + +
+ + +
+ +init_signull( + + + + + domain + + + )
+
+
+ +
Summary
+

+Send init a null signal. +

+ + +
Parameters
+ + + + - - + + - + @@ -55,7 +57,8 @@ + untested. Need further investigations to ensure + the levels in the policy are correct. @@ -77,30 +80,32 @@ + Policy structure. Levels can be added to the labels + without changes to the policy. - + - + - + + their permissions. No planned changes. @@ -168,21 +173,17 @@ is a listing of modules which need to be converted:
  • automount
  • bluetooth
  • cdrecord
  • -
  • comsat
  • cyrus
  • -
  • dictd
  • dovecot
  • fetchmail
  • fingerd
  • ftpd
  • games
  • -
  • inn
  • irqbalance
  • ktalkd
  • kudzu
  • lockdev
  • mrtg
  • -
  • ntpd
  • portmap
  • postfix
  • prelink
  • @@ -196,7 +197,6 @@ is a listing of modules which need to be converted:
  • slrnpull
  • snmp
  • spamassassin
  • -
  • squid
  • stunnel
  • sysstat
  • telnet
  • Parameter:Description:Optional:
    +domain + + +Domain allowed access. No @@ -1605,6 +1647,7 @@ No + diff --git a/www/api-docs/system_ipsec.html b/www/api-docs/system_ipsec.html index cd7a4409..c2e783e2 100644 --- a/www/api-docs/system_ipsec.html +++ b/www/api-docs/system_ipsec.html @@ -400,6 +400,7 @@ No + diff --git a/www/api-docs/system_iptables.html b/www/api-docs/system_iptables.html index 7d646431..122ef720 100644 --- a/www/api-docs/system_iptables.html +++ b/www/api-docs/system_iptables.html @@ -311,6 +311,7 @@ No + diff --git a/www/api-docs/system_libraries.html b/www/api-docs/system_libraries.html index 75d8029c..83150d78 100644 --- a/www/api-docs/system_libraries.html +++ b/www/api-docs/system_libraries.html @@ -693,6 +693,7 @@ No + diff --git a/www/api-docs/system_locallogin.html b/www/api-docs/system_locallogin.html index 97b095ad..b2dac528 100644 --- a/www/api-docs/system_locallogin.html +++ b/www/api-docs/system_locallogin.html @@ -274,6 +274,7 @@ No + diff --git a/www/api-docs/system_logging.html b/www/api-docs/system_logging.html index fbc9875f..7fc073b9 100644 --- a/www/api-docs/system_logging.html +++ b/www/api-docs/system_logging.html @@ -738,6 +738,7 @@ No + diff --git a/www/api-docs/system_lvm.html b/www/api-docs/system_lvm.html index 421dac96..e04dfe30 100644 --- a/www/api-docs/system_lvm.html +++ b/www/api-docs/system_lvm.html @@ -310,6 +310,7 @@ No + diff --git a/www/api-docs/system_miscfiles.html b/www/api-docs/system_miscfiles.html index a671d492..58b2b0b2 100644 --- a/www/api-docs/system_miscfiles.html +++ b/www/api-docs/system_miscfiles.html @@ -443,6 +443,7 @@ No + diff --git a/www/api-docs/system_modutils.html b/www/api-docs/system_modutils.html index 5d61c097..549a2eb8 100644 --- a/www/api-docs/system_modutils.html +++ b/www/api-docs/system_modutils.html @@ -722,6 +722,7 @@ No + diff --git a/www/api-docs/system_mount.html b/www/api-docs/system_mount.html index e9cafd97..68abe9c4 100644 --- a/www/api-docs/system_mount.html +++ b/www/api-docs/system_mount.html @@ -355,6 +355,7 @@ No + diff --git a/www/api-docs/system_pcmcia.html b/www/api-docs/system_pcmcia.html index 1634927a..296a0d9d 100644 --- a/www/api-docs/system_pcmcia.html +++ b/www/api-docs/system_pcmcia.html @@ -439,6 +439,7 @@ No + diff --git a/www/api-docs/system_raid.html b/www/api-docs/system_raid.html index 6da77a00..cceeaa77 100644 --- a/www/api-docs/system_raid.html +++ b/www/api-docs/system_raid.html @@ -242,6 +242,7 @@ No + diff --git a/www/api-docs/system_selinuxutil.html b/www/api-docs/system_selinuxutil.html index 74bff535..c7abf6e4 100644 --- a/www/api-docs/system_selinuxutil.html +++ b/www/api-docs/system_selinuxutil.html @@ -1766,6 +1766,7 @@ No + diff --git a/www/api-docs/system_sysnetwork.html b/www/api-docs/system_sysnetwork.html index 41593584..0f26fb48 100644 --- a/www/api-docs/system_sysnetwork.html +++ b/www/api-docs/system_sysnetwork.html @@ -186,6 +186,100 @@ No + +
    + + +
    + +sysnet_create_dhcp_state( + + + + + domain + + + + , + + + + file_type + + + + , + + + + [ + + object_class + + ] + + + )
    +
    +
    + +
    Summary
    +

    +Create DHCP state data. +

    + + +
    Description
    +

    +

    +Create DHCP state data. +

    +

    +This is added for DHCP server, as +the server and client put their state +files in the same directory. +

    +

    + +
    Parameters
    + + + + + + + + + +
    Parameter:Description:Optional:
    +domain + + +Domain allowed access. + + +No +
    +file_type + + +The type of the object to be created + + +No +
    +object_class + + +The object class. If not specified, file is used. + + +yes +
    +
    +
    +
    @@ -396,6 +490,48 @@ No
    + +
    + + +
    + +sysnet_read_dhcp_config( + + + + + domain + + + )
    +
    +
    + +
    Summary
    +

    +Read the DHCP configuration files. +

    + + +
    Parameters
    + + + + + +
    Parameter:Description:Optional:
    +domain + + +Domain allowed access. + + +No +
    +
    +
    +
    @@ -602,6 +738,48 @@ No
    + +
    + + +
    + +sysnet_search_dhcp_state( + + + + + domain + + + )
    +
    +
    + +
    Summary
    +

    +Search the DHCP state data directory. +

    + + +
    Parameters
    + + + + + +
    Parameter:Description:Optional:
    +domain + + +Domain allowed access. + + +No +
    +
    +
    +
    @@ -775,6 +953,7 @@ No +
    diff --git a/www/api-docs/system_udev.html b/www/api-docs/system_udev.html index 51ca4edd..05fe3889 100644 --- a/www/api-docs/system_udev.html +++ b/www/api-docs/system_udev.html @@ -317,6 +317,7 @@ No + diff --git a/www/api-docs/system_unconfined.html b/www/api-docs/system_unconfined.html index 629b3e29..d3bdf9ef 100644 --- a/www/api-docs/system_unconfined.html +++ b/www/api-docs/system_unconfined.html @@ -584,6 +584,7 @@ No Return + diff --git a/www/api-docs/system_userdomain.html b/www/api-docs/system_userdomain.html index 726460b2..e378a8fb 100644 --- a/www/api-docs/system_userdomain.html +++ b/www/api-docs/system_userdomain.html @@ -255,6 +255,49 @@ No + +
    + + +
    + +userdom_dontaudit_list_sysadm_home_dir( + + + + + domain + + + )
    +
    +
    + +
    Summary
    +

    +Do not audit attempts to list the sysadm +users home directory. +

    + + +
    Parameters
    + + + + + +
    Parameter:Description:Optional:
    +domain + + +Domain to not audit. + + +No +
    +
    +
    +
    @@ -1148,6 +1191,48 @@ No
    + +
    + + +
    + +userdom_sigcld_all_users( + + + + + domain + + + )
    +
    +
    + +
    Summary
    +

    +Send a SIGCHLD signal to all user domains. +

    + + +
    Parameters
    + + + + + +
    Parameter:Description:Optional:
    +domain + + +Domain allowed access. + + +No +
    +
    +
    +
    @@ -1850,7 +1935,7 @@ No - domain + userdomain_prefix @@ -1858,7 +1943,7 @@ No - userdomain_prefix + domain )
    @@ -1887,21 +1972,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -1922,7 +2007,7 @@ No - domain + userdomain_prefix @@ -1930,7 +2015,7 @@ No - userdomain_prefix + domain )
    @@ -1961,21 +2046,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -1996,7 +2081,7 @@ No - domain + userdomain_prefix @@ -2004,7 +2089,7 @@ No - userdomain_prefix + domain )
    @@ -2035,21 +2120,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2070,7 +2155,7 @@ No - domain + userdomain_prefix @@ -2078,7 +2163,7 @@ No - userdomain_prefix + domain )
    @@ -2109,21 +2194,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2144,7 +2229,7 @@ No - domain + userdomain_prefix @@ -2152,7 +2237,7 @@ No - userdomain_prefix + domain )
    @@ -2183,21 +2268,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2218,7 +2303,7 @@ No - domain + userdomain_prefix @@ -2226,7 +2311,7 @@ No - userdomain_prefix + domain )
    @@ -2257,21 +2342,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2292,7 +2377,7 @@ No - domain + userdomain_prefix @@ -2300,7 +2385,7 @@ No - userdomain_prefix + domain )
    @@ -2331,21 +2416,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2366,7 +2451,7 @@ No - domain + userdomain_prefix @@ -2374,7 +2459,7 @@ No - userdomain_prefix + domain )
    @@ -2404,6 +2489,17 @@ be called from a per-userdomain template. + + +
    Parameter:Description:Optional:
    +userdomain_prefix + + +The prefix of the user domain (e.g., user +is the prefix for user_t). + + +No +
    domain @@ -2414,6 +2510,57 @@ The type of the process performing this action. No
    + + + + +
    + + +
    + +userdom_read_user_home_files( + + + + + userdomain_prefix + + + + , + + + + domain + + + )
    +
    +
    + +
    Summary
    +

    +Read user home files. +

    + + +
    Description
    +

    +

    +Read user home files. +

    +

    +This is a templated interface, and should only +be called from a per-userdomain template. +

    +

    + +
    Parameters
    + + + + +
    Parameter:Description:Optional:
    userdomain_prefix @@ -2425,6 +2572,16 @@ is the prefix for user_t). No
    +domain + + +The type of the process performing this action. + + +No +
    @@ -2440,7 +2597,7 @@ No - domain + userdomain_prefix @@ -2448,7 +2605,7 @@ No - userdomain_prefix + domain )
    @@ -2477,21 +2634,21 @@ be called from a per-userdomain template.
    Parameter:Description:Optional:
    -domain +userdomain_prefix -The type of the process performing this action. +The prefix of the user domain (e.g., user +is the prefix for user_t). No
    -userdomain_prefix +domain -The prefix of the user domain (e.g., user -is the prefix for user_t). +The type of the process performing this action. No @@ -2505,6 +2662,7 @@ No Return + diff --git a/www/api-docs/templates.html b/www/api-docs/templates.html index f3396298..c9bfe5e4 100644 --- a/www/api-docs/templates.html +++ b/www/api-docs/templates.html @@ -103,18 +103,36 @@    -  bind
    +    -  + comsat
    +    -  cron
    +    -  + dbus
    + +    -  + dhcp
    + +    -  + dictd
    +    -  gpm
    +    -  + hal
    +    -  howl
       -  inetd
    +    -  + inn
    +    -  kerberos
    @@ -133,6 +151,9 @@    -  nscd
    +    -  + ntp
    +    -  privoxy
    @@ -148,6 +169,9 @@    -  sendmail
    +    -  + squid
    +    -  ssh
    @@ -332,6 +356,22 @@ system

    userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
    @@ -411,6 +451,22 @@ services

    userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
    @@ -422,6 +478,83 @@ The per user domain template for the cron module. +

    +Module: +dbus

    +Layer: +services

    +

    + +dbus_per_userdomain_template( + + + + + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role + + + )
    +
    + +
    +

    +The per user domain template for the dbus module. +

    +
    + +
    + +
    +Module: +dbus

    +Layer: +services

    +

    + +dbus_system_bus_client_template( + + + + + domain_prefix + + + + , + + + + domain + + + )
    +
    + +
    +

    +Template for creating connections to +the system DBUS. +

    +
    + +
    +
    Module: domain

    @@ -489,6 +622,22 @@ apps

    userdomain_prefix + + , + + + + userdomain_prefix + + + + , + + + + domain + + )

    @@ -512,7 +661,23 @@ services

    - ? + userdomain_prefix + + + + , + + + + user_domain + + + + , + + + + user_role )
    @@ -520,7 +685,7 @@ services

    -Summary is missing! +The per user domain template for the mta module.

    @@ -541,6 +706,22 @@ services

    userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
    @@ -593,6 +774,22 @@ admin

    userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
    @@ -619,6 +816,22 @@ admin

    userdomain_prefix + + , + + + + user_domain + + + + , + + + + user_role + + )
    @@ -694,7 +907,7 @@ system

    - domain + userdomain_prefix @@ -702,7 +915,7 @@ system

    - userdomain_prefix + domain )
    @@ -728,7 +941,7 @@ system

    - domain + userdomain_prefix @@ -736,7 +949,7 @@ system

    - userdomain_prefix + domain )
    @@ -763,7 +976,7 @@ system

    - domain + userdomain_prefix @@ -771,7 +984,7 @@ system

    - userdomain_prefix + domain )
    @@ -798,7 +1011,7 @@ system

    - domain + userdomain_prefix @@ -806,7 +1019,7 @@ system

    - userdomain_prefix + domain )
    @@ -833,7 +1046,7 @@ system

    - domain + userdomain_prefix @@ -841,7 +1054,7 @@ system

    - userdomain_prefix + domain )
    @@ -868,7 +1081,7 @@ system

    - domain + userdomain_prefix @@ -876,7 +1089,7 @@ system

    - userdomain_prefix + domain )
    @@ -903,7 +1116,7 @@ system

    - domain + userdomain_prefix @@ -911,7 +1124,7 @@ system

    - userdomain_prefix + domain )
    @@ -938,7 +1151,7 @@ system

    - domain + userdomain_prefix @@ -946,7 +1159,7 @@ system

    - userdomain_prefix + domain )
    @@ -961,6 +1174,40 @@ temporary symbolic links. +

    +Module: +userdomain

    +Layer: +system

    +

    + +userdom_read_user_home_files( + + + + + userdomain_prefix + + + + , + + + + domain + + + )
    +
    + +
    +

    +Read user home files. +

    +
    + +
    +
    Module: userdomain

    @@ -973,7 +1220,7 @@ system

    - domain + userdomain_prefix @@ -981,7 +1228,7 @@ system

    - userdomain_prefix + domain )
    diff --git a/www/html/status.html b/www/html/status.html index 96c7d56d..fe997630 100644 --- a/www/html/status.html +++ b/www/html/status.html @@ -1,10 +1,10 @@

    Status

    -Current Version: 20050826 +Current Version: 20050907

    See download for download information. Details of this release are part of the changelog. - This release focused on loadable module infrastructure, and adding - more policies. Currently both strict and targeted policies can be + This release focused on addition of policies from the NSA example + policy. Currently both strict and targeted policies can be built. MLS policies can be built, but the policy has not been tested on running systems.

    @@ -36,14 +36,16 @@
    Documentation InfrastructureInterfaces completeTools to create webpages from the module interface documentation - is complete. Adding tunables to the webpages is planned.Interfaces, templates, Booleans, and tunables completeTools to create webpages from the module interface and + template documentation is complete. Global Booleans and + tunables are supported. Booleans and tunables local to + policies are planned.
    Policy Documentation OngoingMost kernel layer modules are documented.Most modules are documented.
    Unused ModulesMinor improvements MLS infrastructure added to support easy conversion between MLS and non-MLS policy. Policy is compilable, but - untested.
    Network InfrastructureLabeling Minor improvements All labeling moved to modules, consistent with Reference - Policy structure.
    Tunables Minor improvementsTunables are documented, and in the future will be included - in the webpage policy documentation.Tunables are documented and included in the webpage policy + documentation.
    Users UnchangedAssignment of users to rolesAssignment of users to roles.
    Constraints UnchangedPlan to split up into relevant modules. There are ordering - problems with source policies.Plan to split up into relevant modules when loadable modules + support this. There are ordering problems with source + policies.
    Flask Unchanged Headers for the policy, describing object classes, and - their permissions. No planned changes
    Genhomedircon