#DESC Admin - Domains for administrators. # ################################# # sysadm_t is the system administrator domain. type sysadm_t, domain, privlog, privowner, admin, userdomain, web_client_domain, privhome, etc_writer, privmodule, nscd_client_domain ifdef(`direct_sysadm_daemon', `, priv_system_role') ; dnl end of sysadm_t type declaration allow privhome home_root_t:dir { getattr search }; # system_r is authorized for sysadm_t for single-user mode. role system_r types sysadm_t; general_proc_read_access(sysadm_t) # sysadm_t is also granted permissions specific to administrator domains. admin_domain(sysadm) # Allow administrator domains to set the enforcing flag. can_setenforce(sysadm_t) # Allow administrator domains to set policy booleans. can_setbool(sysadm_t) # Allow administrator domains to set security parameters can_setsecparam(sysadm_t) # for su allow sysadm_t userdomain:fd use; define(`admin_tty_type', `{ sysadm_tty_device_t sysadm_devpts_t }') # Add/remove user home directories file_type_auto_trans(sysadm_t, home_root_t, user_home_dir_t, dir)