This module contains interfaces for handling multilevel security. The interfaces allow the specified subjects and objects to be allowed certain privileges in the MLS rules.
This module is required to be included in all policies.
Make specified domain MLS trusted for reading from X colormaps at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to X colormaps at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for lowering the level of databases.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from databases at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for raising the level of databases.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to databases at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for receiving dbus messages from all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for sending dbus messages to all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the file descriptors from the specified domain inheritable by all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified domain trusted to inherit and use file descriptors from all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for lowering the level of files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from files at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from files up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for relabelto to files at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for relabelto to files up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for raising the level of files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to files at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for write to files up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain trusted to be written to within its MLS range. The subject's MLS range must be a proper subset of the object's MLS range.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to keys at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to keys up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain trusted to write inbound packets regardless of the network's or node's MLS range.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain trusted to write outbound packets regardless of the network's or node's MLS range.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for receiving network data from network interfaces or hosts at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain trusted to write to network objects within its MLS range. The subject's MLS range must be a proper subset of the object's MLS range.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from processes at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from processes up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for setting the level of processes it executes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to processes at all levels.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to processes up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to do a MLS range transition that changes the current level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain a target domain for MLS range transitions that change the current level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from sockets at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from sockets at any level that is dominated by the process clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to sockets at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to sockets up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from System V IPC objects at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from System V IPC objects up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to System V IPC objects at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to System V IPC objects up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified object MLS trusted.
Make specified object MLS trusted. This allows all levels to read and write the object.
This currently only applies to filesystem objects, for example, files and directories.
Parameter: | Description: |
---|---|
domain |
The type of the object. |
Make specified socket MLS trusted.
Make specified socket MLS trusted. For sockets marked as such, this allows all levels to: * sendto to unix_dgram_sockets * connectto to unix_stream_sockets respectively.
Parameter: | Description: |
---|---|
domain |
The type of the object. |
Make specified domain MLS trusted for reading from X objects at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for reading from X objects up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for writing to X objects at any level.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make specified domain MLS trusted for write to X objects up to its clearance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |