Multicategory security policy
This module is required to be included in all policies.
Constrain by category access control (MCS).
Constrain the specified type by category based access control (MCS) This prevents this domain from interacting with subjects and operating on objects that it otherwise would be able to interact with or operate on respectively.
Parameter: | Description: |
---|---|
domain |
Type to be constrained by MCS. |
This domain is allowed to read files and directories regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to write files and directories regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to sigkill and sigstop all domains regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
Make specified domain MCS trusted for setting any category set for the processes it executes.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to ptrace all domains regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |