Policy for kernel security interface, in particular, selinuxfs.
This module is required to be included in all policies.
false
Boolean to determine whether the system permits loading policy, and setting enforcing mode. Set this to true and you have to reboot to set it back.
false
Boolean to determine whether the system permits setting Booelan values.
Allows caller to compute an access vector.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Calculate the default type for object creation.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows caller to compute polyinstatntiated directory members.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Calculate the context for relabeling objects.
Calculate the context for relabeling objects. This is determined by using the type_change rules in the policy, and is generally used for determining the context for relabeling a terminal when a user logs in.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows caller to compute possible contexts for a user.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to get the mountpoint of the selinuxfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the selinuxfs directory.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the selinuxfs filesystem
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read generic selinuxfs entries
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to search selinuxfs.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to validate security contexts.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow caller to get the state of all Booleans to view conditional portions of the policy.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows the caller to get the mode of policy enforcement (enforcing or permissive mode).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the mountpoint of the selinuxfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of the selinuxfs filesystem
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type used for labeling SELinux Booleans. This interface is only usable in the base module.
Make the specified type used for labeling SELinux Booleans.
This makes use of genfscon statements, which are only available in the base module. Thus any module which calls this interface must be included in the base module.
Parameter: | Description: |
---|---|
type |
Type used for labeling a Boolean. |
boolean |
Name of the Boolean. |
Allow caller to load the policy into the kernel.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount the selinuxfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mount on the selinuxfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller to read the policy from the kernel.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Remount the selinuxfs filesystem. This allows some mount options to be changed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search selinuxfs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller to set the state of all Booleans to enable or disable conditional portions of the policy.
Allow caller to set the state of all Booleans to enable or disable conditional portions of the policy.
Since this is a security event, this action is always audited.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller to set the mode of policy enforcement (enforcing or permissive mode).
Allow caller to set the mode of policy enforcement (enforcing or permissive mode).
Since this is a security event, this action is always audited.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller to set the state of generic Booleans to enable or disable conditional portions of the policy.
Allow caller to set the state of generic Booleans to enable or disable conditional portions of the policy.
Since this is a security event, this action is always audited.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller to set SELinux access vector cache parameters.
Allow caller to set SELinux access vector cache parameters. The allows the domain to set performance related parameters of the AVC, such as cache threshold.
Since this is a security event, this action is always audited.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unconfined access to the SELinux kernel security server.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unmount the selinuxfs filesystem.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows the caller to use the SELinux status page.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows caller to validate security contexts.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |