Layer: system

Module: userdomain

Description:

Policy for user domains

Interfaces:

userdom_dontaudit_use_sysadm_terms( domain )
Description

Do not audit attempts to use admin ttys and ptys.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_dontaudit_use_unpriv_user_fd( domain )
Description

Do not audit attempts to inherit the file descriptors from all user domains.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_read_all_user_data( domain )
Description

Read all files in all users home directories.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_search_all_users_home( domain )
Description

Search all users home directories.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_shell_domtrans_sysadm( domain )
Description

Execute a shell in the sysadm domain.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_signal_all_users( domain )
Description

Send general signals to all user domains.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_spec_domtrans_all_users( domain )
Description

Execute a shell in all user domains. This is an explicit transition, requiring the caller to use setexeccon().

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_use_all_user_fd( domain )
Description

Inherit the file descriptors from all user domains

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_use_sysadm_terms( domain )
Description

Read and write administrative users physical and pseudo terminals.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No
userdom_use_unpriv_users_fd( domain )
Description

Inherit the file descriptors from all user domains.

Parameters
Parameter:Description:Optional:
domain The type of the process performing this action. No