Policy for filesystems.
This module is required to be included in all policies.
Append files on a CIFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Append files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Associate the specified file type to persistent filesystems with extended attributes. This allows a file of this type to be created on a filesystem such as ext3, JFS, and XFS.
Parameter: | Description: |
---|---|
file_type |
The type of the to be associated. |
Allow the type to associate to hugetlbfs filesystems.
Parameter: | Description: |
---|---|
type |
The type of the object to be associated. |
Associate the specified file type to filesystems which lack extended attributes support. This allows a file of this type to be created on a filesystem such as FAT32, and NFS.
Parameter: | Description: |
---|---|
file_type |
The type of the to be associated. |
Allow the type to associate to ramfs filesystems.
Parameter: | Description: |
---|---|
type |
The type of the object to be associated. |
Allow the type to associate to tmpfs filesystems.
Parameter: | Description: |
---|---|
type |
The type of the object to be associated. |
Create an object in a cgroup tmpfs filesystem, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Execute a file on a CIFS or SMB filesystem in the specified domain.
Execute a file on a CIFS or SMB filesystem in the specified domain. This allows the specified domain to execute any file on these filesystems in the specified domain. This is not suggested.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
This interface was added to handle home directories on CIFS/SMB filesystems, in particular used by the ssh-agent policy.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the new process. |
Create cgroup lnk_files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create pstore directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
create trace filesystem directories
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete the files of a pstore filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete tmpfs symbolic links.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
dontaudit Append files on a CIFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
dontaudit Append files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of all files with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of all named pipes with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of all named sockets with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of all symbolic links with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to getattr generic tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of a persistent filesystem which has extended attributes, such as ext3, JFS, or XFS.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list directories of automatically mounted filesystems.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list the contents of directories on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read dirs on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list the contents of directories on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit List inotifyfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list the contents of directories on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list all noxattrfs directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to list removable storage directories.
Parameter: | Description: |
---|---|
domain |
Domain not to audit. |
Do not audit attempts to list the contents of generic tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete directories on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete files on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete directories on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete files on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete directories on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete directories on a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to create, read, write, and delete files on a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read files on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit read symbolic links on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read all noxattrfs files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit read on a ramfs files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit read on a ramfs fifo_files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read removable storage files.
Parameter: | Description: |
---|---|
domain |
Domain not to audit. |
Do not audit attempts to read or write files on anon_inodefs file systems.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to open, get attributes, read and write cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read or write files on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read or write files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read or write generic tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit Search directories on a ramfs
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
dontaudit Read and write character nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write all filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Dont audit attempts to write to noxattrfs files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write to named pipes on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write removable storage files.
Parameter: | Description: |
---|---|
domain |
Domain not to audit. |
Do not audit attempts to write tmpfs directories
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Execute files on a CIFS or SMB network filesystem, in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute files on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute files on a filesystem that does not support extended attributes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute FUSEFS files in a specified domain.
Execute FUSEFS files in a specified domain.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
Parameter: | Description: |
---|---|
source_domain |
Domain allowed to transition. |
target_domain |
Domain to transition to. |
Make FUSEFS files an entrypoint for the specified domain.
Parameter: | Description: |
---|---|
domain |
The domain for which fusefs_t is an entrypoint. |
Get the quotas of all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the filesystem quotas of a filesystem with extended attributes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all block device nodes with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all character device nodes with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all directories with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all files with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all filesystems.
Allow the specified domain to get the attributes of all filesystems. Example attributes:
Type of the file system (e.g., ext3)
Size of the file system
Available space on the file system
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all named pipes with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all named sockets with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all symbolic links with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of all the filesystems which have extended attributes. This includes pseudo filesystems.
Allow the specified domain to get the attributes of a filesystems which have extended attributes. Example attributes:
Type of the file system (e.g., tmpfs)
Size of the file system
Available space on the file system
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of an automount pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of directories on binfmt_misc filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of binfmt_misc filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get attributes of cgroup filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get attributes of cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get attributes of directories on a dosfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a DOS filesystem, such as FAT32 or NTFS.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of efivarfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
stat a FUSE filesystem
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of an hugetlbfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of files on an iso9660 filesystem, which is usually used on CDs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of an iso9660 filesystem, which is usually used on CDs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Getattr files on an nfsd filesystem
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a NFS server pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of filesystems that do not have extended attribute support.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of an nsfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of nsfs inodes (e.g. /proc/pid/ns/uts)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of directories of a pstore filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a pstore filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a RAM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a ROM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of directories of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a RPC pipe filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a tmpfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of a trace filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get attributes of dirs on tracefs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of files on a trace filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of persistent filesystems which have extended attributes, such as ext3, JFS, or XFS.
Allow the specified domain to get the attributes of a persistent filesystems which have extended attributes, such as ext3, JFS, or XFS. Example attributes:
Type of the file system (e.g., ext3)
Size of the file system
Available space on the file system
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create an object in a hugetlbfs filesystem, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Transform specified type into a filesystem image file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Ioctl cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List all directories with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read directories of automatically mounted filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
list cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of directories on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List dirs DOS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read symbolic links on an eCryptfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List dirs in efivarfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List hugetlbfs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List inotifyfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List NFS server directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all noxattrfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the directories of a pstore filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read directories of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of generic tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete auto moutpoints.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete symbolic links on an autofs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named pipes on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named sockets on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete symbolic links on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete dirs on a configfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a configfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete dirs on a DOS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a DOS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on an eCryptfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on an eCryptfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named sockets on an eCryptfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a efivarfs filesystem. - contains Linux Kernel configuration options for UEFI systems
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage symlinks on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage hugetlbfs dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named pipes on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named sockets on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete symbolic links on a NFS network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all noxattrfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete all noxattrfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage all noxattrfs symbolic links.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on a ramfs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named pipes on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete named sockets on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write, create and delete block nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write, create and delete character nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete tmpfs directories
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write, create and delete generic files on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write, create and delete socket files on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write, create and delete symbolic links on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete directories on a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete files on a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap-read all filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and map files on a DOS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap-Read-write all filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read, map and write hugetlbfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Map files a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount an automount pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount cgroup filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a DOS filesystem, such as FAT32 or NTFS.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a FUSE filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount an iso9660 filesystem, which is usually used on CDs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a NFS server pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a RAM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a ROM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a RPC pipe filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a tmpfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a persistent filesystem which has extended attributes, such as ext3, JFS, or XFS.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton a CIFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a file on a NFS filesystem in the specified domain.
Execute a file on a NFS filesystem in the specified domain. This allows the specified domain to execute any file on a NFS filesystem in the specified domain. This is not suggested.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
This interface was added to handle home directories on NFS filesystems, in particular used by the ssh-agent policy.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the new process. |
Transform specified type into a filesystem type which does not have extended attribute support.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transform specified type into a filesystem type which is a pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all inherited filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on anon_inodefs file systems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read named pipes on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read named sockets on a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read symbolic links on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on a DOS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files in efivarfs - contains Linux Kernel configuration options for UEFI systems
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read, a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read symbolic links on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on an iso9660 filesystem, which is usually used on CDs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read named pipes on a NFS network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read named sockets on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read symbolic links on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all noxattrfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all noxattrfs symbolic links.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read nsfs inodes (e.g. /proc/pid/ns/uts)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read pstore_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read block nodes on removable filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read removable storage files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read removable storage symbolic links.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read sockets of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read symbolic links of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read generic tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read tmpfs link files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Register an interpreter for new binary file types, using the kernel binfmt_misc support.
Register an interpreter for new binary file types, using the kernel binfmt_misc support.
A common use for this is to register a JVM as an interpreter for Java byte code. Registered binaries can be directly executed on a command line without specifying the interpreter.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel cgroup symbolic links.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to/from pstore_t directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel block nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel character nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel directory on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel named pipes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel files on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabelfrom all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow changing of the label of a DOS filesystem using the context= mount option.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow changing of the label of a filesystem with iso9660 type
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel all objects from filesystems that do not support extended attributes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel from tmpfs filesystem.
Parameter: | Description: |
---|---|
type |
Domain allowed access. |
Relabel from tmpfs_t dir
Parameter: | Description: |
---|---|
type |
Domain allowed access. |
Relabelfrom socket files on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabelfrom tmpfs link files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow changing of the label of a filesystem with extended attributes using the context= mount option.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount all filesystems. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount an automount pseudo filesystem This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount cgroup filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a CIFS or SMB network filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a DOS filesystem, such as FAT32 or NTFS. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a FUSE filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount an iso9660 filesystem, which is usually used on CDs. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a NFS filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount a NFS server pseudo filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a RAM filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a ROM filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a RPC pipe filesystem. This allows some mount option to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a tmpfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount a persistent filesystem which has extended attributes, such as ext3, JFS, or XFS. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write all filesystem image files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write files on anon_inodefs file systems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write hugetlbfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write inherited hugetlbfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write NFS server files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write a named pipe on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write block nodes on removable filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write RPC pipe filesystem named pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write sockets of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write block nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write character nodes on tmpfs filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write generic tmpfs files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search all directories with a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search automount filesystem to use automatically mounted filesystems.
Allow the specified domain to search mount points that have filesystems that are mounted by the automount service. Generally this will be required for any domain that accesses objects on these filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search bpf dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search cgroup directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search directories on a CIFS or SMB filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search dosfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search directories on a FUSEFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search inotifyfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search directories on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search NFS server directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search directories on a ramfs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search removable storage directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search directories of RPC file system pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
search directories on a tracefs filesystem
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search the XENFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the quotas of all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the filesystem quotas of a filesystem with extended attributes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the attributes of tmpfs directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create an object in a tmpfs filesystem, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Transform specified type into a filesystem type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unconfined access to filesystems
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount all filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount an automount pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount cgroup filesystems.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a CIFS or SMB network filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a DOS filesystem, such as FAT32 or NTFS.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a FUSE filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount an iso9660 filesystem, which is usually used on CDs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a NFS server pseudo filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount an nsfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a RAM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a ROM filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a RPC pipe filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a tmpfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount a persistent filesystem which has extended attributes, such as ext3, JFS, or XFS.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch NFS server directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch NFS server files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch a rpc pipefs dir
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch RPC pipe filesystem directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write cgroup files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read files on a NFS filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write to named pipe on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write to named socket on a ramfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read/write trace filesystem files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transform specified type into a filesystem type which has extended attribute support.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |