Systemd components (not PID 1)
false
Allow systemd-logind to interact with the bootloader (read which one is installed on fixed disks, enumerate entries for dbus property BootLoaderEntries, etc.)
false
Allow systemd-networkd to run its DHCPd server component
false
Allow systemd-nspawn to create a labelled namespace with the same types as parent environment
false
Allow systemd-socket-proxyd to bind any port instead of one labelled with systemd_socket_proxyd_port_t.
false
Allow systemd-socket-proxyd to connect to any port instead of labelled ones.
false
Enable support for systemd-tmpfiles to manage all non-security files.
Allow domain to be used as a systemd service with a unit that uses PrivateDevices=yes in section [Service].
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Allow connecting to /run/systemd/userdb/io.systemd.Machine socket
Parameter: | Description: |
---|---|
domain |
Domain that can access the socket |
Create keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to create the systemd-logind linger directory with the correct context.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd hostnamed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd localed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd logind over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd machined over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd networkd over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd resolved over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
send datagrams to systemd_nspawn_t
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemd-sysusers in the systemd sysusers domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
dontaudit connecting to /run/systemd/userdb/io.systemd.Machine socket
Parameter: | Description: |
---|---|
domain |
Domain that can access the socket |
Allow specified domain to enable systemd-networkd units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute the systemctl program.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd_passwd_runtime_t when creating dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd_userdbd_runtime_t when creating the userdb directory inside an init runtime directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the status of systemd user manager units (systemd --user).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to get the status of systemd user runtime units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to get the status of systemd user transient units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr on .updated file (generated by systemd-update-done
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to list the contents of systemd_journal_t dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to list dirs under /run/systemd/netif
Parameter: | Description: |
---|---|
domain |
domain permitted the access |
Allow domain to list systemd tmpfiles config directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list the contents of systemd user runtime unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to list the contents of systemd user transient unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of systemd userdb runtime directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable as an log parse environment type.
Parameter: | Description: |
---|---|
domain |
Type to be used as a log parse environment type. |
Allow the specified domain to manage systemd config home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to manage systemd data home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to create/manage systemd_journal_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-logind runtime pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to create/manage systemd_networkd_t unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow to domain to create systemd-passwd symlink
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd userdb runtime directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage socket files under /run/systemd/userdb .
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to map udev hwdb file
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read udev hwdb file
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read systemd_journal_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-logind runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read logind sessions files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow systemd_logind_t to read process state for cgroup file
Parameter: | Description: |
---|---|
domain |
Domain systemd_logind_t may access. |
Allow reading /run/systemd/machines
Parameter: | Description: |
---|---|
domain |
Domain that can access the machines files |
Allow domain to read files generated by systemd_networkd
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read systemd_networkd_t unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to read resolv.conf file generated by systemd_resolved
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow the specified domain to read systemd user runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read systemd user runtime lnk files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read systemd user runtime unit files. (Deprecated)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read systemd user runtime unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read systemd user transient unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read system-wide systemd user unit files. (Deprecated)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to read system-wide systemd user unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd userdb runtime files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to relabel systemd config home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to relabel systemd data home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel from systemd-journald file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel systemd_networkd tun socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to systemd-journald directory type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to systemd-journald file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to relabel to systemd tmpfiles config directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to relabel to systemd tmpfiles config files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload systemd user manager units (systemd --user).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload systemd user runtime units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload systemd user transient units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
run systemd-nspawn in systemd_nspawn_t domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role of the object to create. |
allow systemd_passwd_agent to be run by admin
Parameter: | Description: |
---|---|
domain |
Domain that runs it |
role |
role that it runs in |
Run systemd-sysusers with a domain transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
Role allowed access. |
Read and write systemd-homework semaphores.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Read/Write from systemd_networkd netlink route socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search systemd config home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search systemd data home content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search systemd user runtime content.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search systemd user runtime unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to search systemd user transient unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send systemd_login a null signal.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to start power units
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow the specified domain to start systemd user manager units (systemd --user).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to start systemd user runtime units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to start systemd user transient units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to start systemd-networkd units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information from systemd_login
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to get status of systemd-networkd
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information about power units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to get the status of systemd user runtime units. (Deprecated)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to stop systemd user manager units (systemd --user).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to stop systemd user runtime units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to stop systemd user transient units.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to systemd resolved over /run/systemd/resolve/io.systemd.Resolve .
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows connections to the systemd-socket-proxyd's socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to /run/systemd/userdb/io.systemd.DynamicUser .
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for systemd tmpfiles config files.
Parameter: | Description: |
---|---|
type |
Type to be used for systemd tmpfiles config files. |
Create an object in the systemd tmpfiles config directory, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Allow the specified domain to create the tmpfiles config directory with the correct context.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow systemd_tmpfiles_t to manage filesystem objects
Parameter: | Description: |
---|---|
type |
Type of object to manage |
receive and use a systemd_machined_devpts_t file handle
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use inherited systemd logind file descriptors.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to use systemd's Name Service Switch (NSS) module. This module provides UNIX user and group name resolution for dynamic users and groups allocated through the DynamicUser= option in systemd unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Allow a systemd_passwd_agent_t process to interact with a daemon that needs a password from the sysadmin.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow systemd_passwd_agent to inherit fds
Parameter: | Description: |
---|---|
domain |
Domain that owns the fds |
Associate the specified file type to be a type whose sock files can be managed by systemd user instances for socket activation.
Parameter: | Description: |
---|---|
file_type |
File type to be associated. |
Associate the specified domain to be a domain whose unix stream sockets and sock files can be managed by systemd user instances for socket activation.
Parameter: | Description: |
---|---|
domain |
Domain to be associated. |
sock_file_type |
File type of the domain's sock files to be associated. |
Allow domain to add a watch on systemd_journal_t directories
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd-logind runtime dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch logind sessions dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow watching /run/systemd/machines
Parameter: | Description: |
---|---|
domain |
Domain that can watch the machines files |
Watch directories under /run/systemd/netif
Parameter: | Description: |
---|---|
domain |
Domain permitted the access |
Allow a domain to watch systemd-passwd runtime dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind inhibit pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write systemd-logind runtime named pipe.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to write to the systemd user runtime named socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state (/proc/pid) of the specified systemd user instance.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain allowed access. |
Template for systemd --user per-role domains.
Parameter: | Description: |
---|---|
prefix |
Prefix for generated types |
role |
The user role. |
userdomain |
The user domain for the role. |
Allow the target domain to be monitored and have its output captured by the specified systemd user instance domain.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain to allow the systemd user instance to monitor. |
Allow the specified domain to be started as a daemon by the specified systemd user instance.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
entry_point |
Entry point file type for the domain. |
domain |
Domain to allow the systemd user domain to run. |
Send and receive messages from the specified systemd user instance over dbus.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain allowed access. |
Send a start request to the specified systemd user instance system object.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain allowed access. |
Get the status of the specified systemd user instance system object.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain allowed access. |
Send a stop request to the specified systemd user instance system object.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain allowed access. |
Allow the target domain the permissions necessary to use systemd notify when started by the specified systemd user instance.
Parameter: | Description: |
---|---|
prefix |
Prefix for the user domain. |
domain |
Domain to be allowed systemd notify permissions. |