Core policy for domains.
This module is required to be included in all policies.
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Do not audit attempts to get the attributes of all domains sockets, for all socket types.
Do not audit attempts to get the attributes of all domains sockets, for all socket types.
This interface was added for PCMCIA cardmgr and is probably excessive.
Parameter: | Description: | Optional: |
---|---|---|
domain | Domain to not audit. | No |
Do not audit attempts to get the attributes of all domains TCP sockets.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to get the attributes of all domains UDP sockets.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to get the attributes of all domains unix datagram sockets.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to get the attributes of all domains unnamed pipes.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to get the session ID of all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to read the process state directories of all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to read the process state (/proc/pid) of all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to read or write all domains key sockets.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Do not audit attempts to read or write all domains UDP sockets.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Get the attributes of all domains sockets, for all socket types.
Get the attributes of all domains sockets, for all socket types.
This is commonly used for domains that can use lsof on all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | Domain allowed access. | No |
Get the session ID of all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Send a kill signal to all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Makes caller an exception to the constraint preventing changing the user identity in object contexts.
Parameter: | Description: | Optional: |
---|---|---|
domain | The process type to make an exception to the constraint. | No |
Read the process state (/proc/pid) of all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Makes caller an exception to the constraint preventing changing of role.
Parameter: | Description: | Optional: |
---|---|---|
domain | The process type to make an exception to the constraint. | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Send a child terminated signal to all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Send a SIGCHLD signal to domains whose file discriptors are widely inheritable.
Parameter: | Description: | Optional: |
---|---|---|
domain | Domain allowed access. | No |
Send general signals to all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Send a null signal to all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Send a stop signal to all domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Makes caller an exception to the constraint preventing changing of user identity.
Parameter: | Description: | Optional: |
---|---|---|
domain | The process type to make an exception to the constraint. | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Unconfined access to domains.
Parameter: | Description: | Optional: |
---|---|---|
domain | The type of the process performing this action. | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |
Summary is missing!
Parameter: | Description: | Optional: |
---|---|---|
? | Parameter descriptions are missing! | No |