Policy controlling access to storage devices
Allow the caller to create fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to delete fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create block devices in /dev with the fixed disk type via an automatic type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
filename |
Optional filename of the block device to be created |
Create char devices in /dev with the fixed disk type via an automatic type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
filename |
Optional filename of the char device to be created |
Do not audit attempts made by the caller to get the attributes of fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to get the attributes of removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to directly read removable devices.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to directly write removable devices.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to read fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to read removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read or write fuse device interfaces.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read or write SCSI generic device interfaces.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to set the attributes of fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to set the attributes of removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to write fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts made by the caller to write removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow the caller to get the attributes of fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to get the attributes of device nodes of fuse devices.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to get the attributes of removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to get the attributes of the generic SCSI interface device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to get the attributes of device nodes of tape devices.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly read from a fixed disk. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly read from a fixed disk if a tunable is set. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
tunable |
Tunable to depend on |
Allow the caller to directly read from a removable device. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly read and write to a fixed disk. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly write to a fixed disk. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly write to a removable device. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly read, in a generic fashion, from any SCSI device. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly read a tape device.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
read or write fuse device interfaces.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to set the attributes of fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to set the attributes of removable devices device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to set the attributes of the generic SCSI interface device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set attributes of the device nodes for the SCSI generic interface.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to set the attributes of device nodes of tape devices.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Enable a fixed disk device as swap space
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create block devices in on a tmpfs filesystem with the fixed disk type via an automatic type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Unconfined access to storage devices.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch fixed disk device nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly write, in a generic fashion, from any SCSI device. This is extremely dangerous as it can bypass the SELinux protections for filesystem objects, and should only be used by trusted domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the caller to directly write a tape device.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |