Changeset 159
- Timestamp:
- 01/09/08 14:53:39 (11 months ago)
- Files:
-
- branch/refpol-merged/src/selinux-policy-refpol/build.conf (modified) (1 diff)
- branch/refpol-merged/src/selinux-policy-refpol/doc/global_booleans.xml (modified) (1 diff)
- branch/refpol-merged/src/selinux-policy-refpol/doc/policy.xml (modified) (173 diffs)
- branch/refpol-merged/src/selinux-policy-refpol/policy/booleans.conf (modified) (1 diff)
- branch/refpol-merged/src/selinux-policy-refpol/policy/modules/kernel/selinux.if (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
branch/refpol-merged/src/selinux-policy-refpol/build.conf
r153 r159 19 19 # name. Otherwise the policy type will be 20 20 # used for the name. 21 NAME = refpolicy21 NAME = clip 22 22 23 23 # Distribution branch/refpol-merged/src/selinux-policy-refpol/doc/global_booleans.xml
r153 r159 18 18 <desc> 19 19 <p> 20 boolean to determine whether the system permits loading policy ,setting21 enforcing mode , and changing boolean values. Set this to true and you20 boolean to determine whether the system permits loading policy and setting 21 enforcing mode. Set this to true and you 22 22 have to reboot to set it back 23 23 </p> 24 24 </desc> 25 25 </bool> 26 <bool name="log_all_relabels" dftval="false"> 27 <desc> 28 <p> 29 log all relabels on the system 30 </p> 31 </desc> 32 </bool> branch/refpol-merged/src/selinux-policy-refpol/doc/policy.xml
r156 r159 44613 44613 <rolecap/> 44614 44614 </interface> 44615 <interface name="selinux_load_policy" lineno="21 8">44615 <interface name="selinux_load_policy" lineno="213"> 44616 44616 <summary> 44617 44617 Allow caller to load the policy into the kernel. … … 44623 44623 </param> 44624 44624 </interface> 44625 <interface name="selinux_set_boolean" lineno="2 60">44625 <interface name="selinux_set_boolean" lineno="251"> 44626 44626 <summary> 44627 44627 Allow caller to set the state of Booleans to … … 44645 44645 <rolecap/> 44646 44646 </interface> 44647 <interface name="selinux_set_parameters" lineno="300"> 44647 <interface name="selinux_set_secure_mode" lineno="287"> 44648 <summary> 44649 Allow caller to change from secure_mode to unsecure_mode 44650 </summary> 44651 <desc> 44652 <p> 44653 Allow caller to set the state of Booleans to 44654 enable or disable conditional portions of the policy. 44655 </p> 44656 <p> 44657 Since this is a security event, this action is 44658 always audited. 44659 </p> 44660 </desc> 44661 <param name="domain"> 44662 <summary> 44663 The process type allowed to set the Boolean. 44664 </summary> 44665 </param> 44666 <rolecap/> 44667 </interface> 44668 <interface name="selinux_set_parameters" lineno="321"> 44648 44669 <summary> 44649 44670 Allow caller to set SELinux access vector cache parameters. … … 44667 44688 <rolecap/> 44668 44689 </interface> 44669 <interface name="selinux_validate_context" lineno="3 24">44690 <interface name="selinux_validate_context" lineno="345"> 44670 44691 <summary> 44671 44692 Allows caller to validate security contexts. … … 44678 44699 <rolecap/> 44679 44700 </interface> 44680 <interface name="selinux_compute_access_vector" lineno="3 45">44701 <interface name="selinux_compute_access_vector" lineno="366"> 44681 44702 <summary> 44682 44703 Allows caller to compute an access vector. … … 44689 44710 <rolecap/> 44690 44711 </interface> 44691 <interface name="selinux_compute_create_context" lineno="3 66">44712 <interface name="selinux_compute_create_context" lineno="387"> 44692 44713 <summary> 44693 44714 Calculate the default type for object creation. … … 44700 44721 <rolecap/> 44701 44722 </interface> 44702 <interface name="selinux_compute_member" lineno=" 387">44723 <interface name="selinux_compute_member" lineno="408"> 44703 44724 <summary> 44704 44725 Allows caller to compute polyinstatntiated … … 44711 44732 </param> 44712 44733 </interface> 44713 <interface name="selinux_compute_relabel_context" lineno="4 16">44734 <interface name="selinux_compute_relabel_context" lineno="437"> 44714 44735 <summary> 44715 44736 Calculate the context for relabeling objects. … … 44730 44751 </param> 44731 44752 </interface> 44732 <interface name="selinux_compute_user_contexts" lineno="4 36">44753 <interface name="selinux_compute_user_contexts" lineno="457"> 44733 44754 <summary> 44734 44755 Allows caller to compute possible contexts for a user. … … 44740 44761 </param> 44741 44762 </interface> 44742 <interface name="selinux_unconfined" lineno="4 56">44763 <interface name="selinux_unconfined" lineno="477"> 44743 44764 <summary> 44744 44765 Unconfined access to the SELinux kernel security server. … … 59243 59264 </param> 59244 59265 </template> 59245 <template name="userdom_role_change_generic_user" lineno="14 89">59266 <template name="userdom_role_change_generic_user" lineno="1490"> 59246 59267 <summary> 59247 59268 Change to the generic user role. … … 59265 59286 <rolecap/> 59266 59287 </template> 59267 <template name="userdom_role_change_from_generic_user" lineno="151 6">59288 <template name="userdom_role_change_from_generic_user" lineno="1517"> 59268 59289 <summary> 59269 59290 Change from the generic user role. … … 59288 59309 <rolecap/> 59289 59310 </template> 59290 <template name="userdom_role_change_staff" lineno="154 2">59311 <template name="userdom_role_change_staff" lineno="1543"> 59291 59312 <summary> 59292 59313 Change to the staff user role. … … 59310 59331 <rolecap/> 59311 59332 </template> 59312 <template name="userdom_role_change_from_staff" lineno="15 69">59333 <template name="userdom_role_change_from_staff" lineno="1570"> 59313 59334 <summary> 59314 59335 Change from the staff user role. … … 59333 59354 <rolecap/> 59334 59355 </template> 59335 <template name="userdom_role_change_sysadm" lineno="159 5">59356 <template name="userdom_role_change_sysadm" lineno="1596"> 59336 59357 <summary> 59337 59358 Change to the sysadm user role. … … 59355 59376 <rolecap/> 59356 59377 </template> 59357 <template name="userdom_role_change_from_sysadm" lineno="162 2">59378 <template name="userdom_role_change_from_sysadm" lineno="1623"> 59358 59379 <summary> 59359 59380 Change from the sysadm user role. … … 59378 59399 <rolecap/> 59379 59400 </template> 59380 <template name="userdom_role_change_secadm" lineno="164 8">59401 <template name="userdom_role_change_secadm" lineno="1649"> 59381 59402 <summary> 59382 59403 Change to the secadm user role. … … 59400 59421 <rolecap/> 59401 59422 </template> 59402 <template name="userdom_role_change_from_secadm" lineno="16 79">59423 <template name="userdom_role_change_from_secadm" lineno="1680"> 59403 59424 <summary> 59404 59425 Change from the secadm user role. … … 59423 59444 <rolecap/> 59424 59445 </template> 59425 <template name="userdom_role_change_auditadm" lineno="17 09">59446 <template name="userdom_role_change_auditadm" lineno="1710"> 59426 59447 <summary> 59427 59448 Change to the auditadm user role. … … 59445 59466 <rolecap/> 59446 59467 </template> 59447 <template name="userdom_role_change_from_auditadm" lineno="174 0">59468 <template name="userdom_role_change_from_auditadm" lineno="1741"> 59448 59469 <summary> 59449 59470 Change from the auditadm user role. … … 59468 59489 <rolecap/> 59469 59490 </template> 59470 <template name="userdom_user_home_content" lineno="177 6">59491 <template name="userdom_user_home_content" lineno="1777"> 59471 59492 <summary> 59472 59493 Make the specified type usable in a … … 59496 59517 </param> 59497 59518 </template> 59498 <template name="userdom_setattr_user_ptys" lineno="181 0">59519 <template name="userdom_setattr_user_ptys" lineno="1811"> 59499 59520 <summary> 59500 59521 Set the attributes of a user pty. … … 59521 59542 </param> 59522 59543 </template> 59523 <template name="userdom_create_user_pty" lineno="184 3">59544 <template name="userdom_create_user_pty" lineno="1844"> 59524 59545 <summary> 59525 59546 Create a user pty. … … 59546 59567 </param> 59547 59568 </template> 59548 <template name="userdom_search_user_home_dirs" lineno="187 6">59569 <template name="userdom_search_user_home_dirs" lineno="1877"> 59549 59570 <summary> 59550 59571 Search user home directories. … … 59571 59592 </param> 59572 59593 </template> 59573 <template name="userdom_list_user_home_dirs" lineno="191 0">59594 <template name="userdom_list_user_home_dirs" lineno="1911"> 59574 59595 <summary> 59575 59596 List user home directories. … … 59596 59617 </param> 59597 59618 </template> 59598 <template name="userdom_user_home_domtrans" lineno="195 8">59619 <template name="userdom_user_home_domtrans" lineno="1959"> 59599 59620 <summary> 59600 59621 Do a domain transition to the specified … … 59635 59656 </param> 59636 59657 </template> 59637 <template name="userdom_dontaudit_list_user_home_dirs" lineno="199 3">59658 <template name="userdom_dontaudit_list_user_home_dirs" lineno="1994"> 59638 59659 <summary> 59639 59660 Do not audit attempts to list user home subdirectories. … … 59660 59681 </param> 59661 59682 </template> 59662 <template name="userdom_manage_user_home_content_dirs" lineno="202 8">59683 <template name="userdom_manage_user_home_content_dirs" lineno="2029"> 59663 59684 <summary> 59664 59685 Create, read, write, and delete directories … … 59687 59708 </param> 59688 59709 </template> 59689 <template name="userdom_dontaudit_setattr_user_home_content_files" lineno="206 4">59710 <template name="userdom_dontaudit_setattr_user_home_content_files" lineno="2065"> 59690 59711 <summary> 59691 59712 Do not audit attempts to set the … … 59714 59735 </param> 59715 59736 </template> 59716 <template name="userdom_read_user_home_content_files" lineno="209 7">59737 <template name="userdom_read_user_home_content_files" lineno="2098"> 59717 59738 <summary> 59718 59739 Read user home files. … … 59739 59760 </param> 59740 59761 </template> 59741 <template name="userdom_dontaudit_read_user_home_content_files" lineno="213 1">59762 <template name="userdom_dontaudit_read_user_home_content_files" lineno="2132"> 59742 59763 <summary> 59743 59764 Do not audit attempts to read user home files. … … 59764 59785 </param> 59765 59786 </template> 59766 <template name="userdom_dontaudit_write_user_home_content_files" lineno="216 5">59787 <template name="userdom_dontaudit_write_user_home_content_files" lineno="2166"> 59767 59788 <summary> 59768 59789 Do not audit attempts to write user home files. … … 59789 59810 </param> 59790 59811 </template> 59791 <template name="userdom_read_user_home_content_symlinks" lineno="219 8">59812 <template name="userdom_read_user_home_content_symlinks" lineno="2199"> 59792 59813 <summary> 59793 59814 Read user home subdirectory symbolic links. … … 59814 59835 </param> 59815 59836 </template> 59816 <template name="userdom_exec_user_home_content_files" lineno="223 2">59837 <template name="userdom_exec_user_home_content_files" lineno="2233"> 59817 59838 <summary> 59818 59839 Execute user home files. … … 59839 59860 </param> 59840 59861 </template> 59841 <template name="userdom_dontaudit_exec_user_home_content_files" lineno="226 6">59862 <template name="userdom_dontaudit_exec_user_home_content_files" lineno="2267"> 59842 59863 <summary> 59843 59864 Do not audit attempts to execute user home files. … … 59864 59885 </param> 59865 59886 </template> 59866 <template name="userdom_manage_user_home_content_files" lineno="230 1">59887 <template name="userdom_manage_user_home_content_files" lineno="2302"> 59867 59888 <summary> 59868 59889 Create, read, write, and delete files … … 59891 59912 </param> 59892 59913 </template> 59893 <template name="userdom_dontaudit_manage_user_home_content_dirs" lineno="233 8">59914 <template name="userdom_dontaudit_manage_user_home_content_dirs" lineno="2339"> 59894 59915 <summary> 59895 59916 Do not audit attempts to create, read, write, and delete directories … … 59918 59939 </param> 59919 59940 </template> 59920 <template name="userdom_manage_user_home_content_symlinks" lineno="237 3">59941 <template name="userdom_manage_user_home_content_symlinks" lineno="2374"> 59921 59942 <summary> 59922 59943 Create, read, write, and delete symbolic links … … 59945 59966 </param> 59946 59967 </template> 59947 <template name="userdom_manage_user_home_content_pipes" lineno="241 0">59968 <template name="userdom_manage_user_home_content_pipes" lineno="2411"> 59948 59969 <summary> 59949 59970 Create, read, write, and delete named pipes … … 59972 59993 </param> 59973 59994 </template> 59974 <template name="userdom_manage_user_home_content_sockets" lineno="244 7">59995 <template name="userdom_manage_user_home_content_sockets" lineno="2448"> 59975 59996 <summary> 59976 59997 Create, read, write, and delete named sockets … … 59999 60020 </param> 60000 60021 </template> 60001 <template name="userdom_user_home_dir_filetrans" lineno="249 7">60022 <template name="userdom_user_home_dir_filetrans" lineno="2498"> 60002 60023 <summary> 60003 60024 Create objects in a user home directory … … 60039 60060 </param> 60040 60061 </template> 60041 <template name="userdom_user_home_content_filetrans" lineno="254 6">60062 <template name="userdom_user_home_content_filetrans" lineno="2547"> 60042 60063 <summary> 60043 60064 Create objects in a user home directory … … 60079 60100 </param> 60080 60101 </template> 60081 <template name="userdom_user_home_dir_filetrans_user_home_content" lineno="259 0">60102 <template name="userdom_user_home_dir_filetrans_user_home_content" lineno="2591"> 60082 60103 <summary> 60083 60104 Create objects in a user home directory … … 60114 60135 </param> 60115 60136 </template> 60116 <template name="userdom_write_user_tmp_sockets" lineno="262 4">60137 <template name="userdom_write_user_tmp_sockets" lineno="2625"> 60117 60138 <summary> 60118 60139 Write to user temporary named sockets. … … 60139 60160 </param> 60140 60161 </template> 60141 <template name="userdom_list_user_tmp" lineno="265 8">60162 <template name="userdom_list_user_tmp" lineno="2659"> 60142 60163 <summary> 60143 60164 List user temporary directories. … … 60164 60185 </param> 60165 60186 </template> 60166 <template name="userdom_dontaudit_list_user_tmp" lineno="269 4">60187 <template name="userdom_dontaudit_list_user_tmp" lineno="2695"> 60167 60188 <summary> 60168 60189 Do not audit attempts to list user … … 60191 60212 </param> 60192 60213 </template> 60193 <template name="userdom_dontaudit_manage_user_tmp_dirs" lineno="27 29">60214 <template name="userdom_dontaudit_manage_user_tmp_dirs" lineno="2730"> 60194 60215 <summary> 60195 60216 Do not audit attempts to manage users … … 60218 60239 </param> 60219 60240 </template> 60220 <template name="userdom_read_user_tmp_files" lineno="276 2">60241 <template name="userdom_read_user_tmp_files" lineno="2763"> 60221 60242 <summary> 60222 60243 Read user temporary files. … … 60243 60264 </param> 60244 60265 </template> 60245 <template name="userdom_dontaudit_read_user_tmp_files" lineno="2 799">60266 <template name="userdom_dontaudit_read_user_tmp_files" lineno="2800"> 60246 60267 <summary> 60247 60268 Do not audit attempts to read users … … 60270 60291 </param> 60271 60292 </template> 60272 <template name="userdom_dontaudit_append_user_tmp_files" lineno="283 4">60293 <template name="userdom_dontaudit_append_user_tmp_files" lineno="2835"> 60273 60294 <summary> 60274 60295 Do not audit attempts to append users … … 60297 60318 </param> 60298 60319 </template> 60299 <template name="userdom_rw_user_tmp_files" lineno="286 7">60320 <template name="userdom_rw_user_tmp_files" lineno="2868"> 60300 60321 <summary> 60301 60322 Read and write user temporary files. … … 60322 60343 </param> 60323 60344 </template> 60324 <template name="userdom_dontaudit_manage_user_tmp_files" lineno="290 4">60345 <template name="userdom_dontaudit_manage_user_tmp_files" lineno="2905"> 60325 60346 <summary> 60326 60347 Do not audit attempts to manage users … … 60349 60370 </param> 60350 60371 </template> 60351 <template name="userdom_read_user_tmp_symlinks" lineno="29 39">60372 <template name="userdom_read_user_tmp_symlinks" lineno="2940"> 60352 60373 <summary> 60353 60374 Read user … … 60376 60397 </param> 60377 60398 </template> 60378 <template name="userdom_manage_user_tmp_dirs" lineno="297 6">60399 <template name="userdom_manage_user_tmp_dirs" lineno="2977"> 60379 60400 <summary> 60380 60401 Create, read, write, and delete user … … 60403 60424 </param> 60404 60425 </template> 60405 <template name="userdom_manage_user_tmp_files" lineno="301 2">60426 <template name="userdom_manage_user_tmp_files" lineno="3013"> 60406 60427 <summary> 60407 60428 Create, read, write, and delete user … … 60430 60451 </param> 60431 60452 </template> 60432 <template name="userdom_manage_user_tmp_symlinks" lineno="304 8">60453 <template name="userdom_manage_user_tmp_symlinks" lineno="3049"> 60433 60454 <summary> 60434 60455 Create, read, write, and delete user … … 60457 60478 </param> 60458 60479 </template> 60459 <template name="userdom_manage_user_tmp_pipes" lineno="308 4">60480 <template name="userdom_manage_user_tmp_pipes" lineno="3085"> 60460 60481 <summary> 60461 60482 Create, read, write, and delete user … … 60484 60505 </param> 60485 60506 </template> 60486 <template name="userdom_manage_user_tmp_sockets" lineno="312 0">60507 <template name="userdom_manage_user_tmp_sockets" lineno="3121"> 60487 60508 <summary> 60488 60509 Create, read, write, and delete user … … 60511 60532 </param> 60512 60533 </template> 60513 <template name="userdom_user_tmp_filetrans" lineno="31 69">60534 <template name="userdom_user_tmp_filetrans" lineno="3170"> 60514 60535 <summary> 60515 60536 Create objects in a user temporary directory … … 60551 60572 </param> 60552 60573 </template> 60553 <template name="userdom_tmp_filetrans_user_tmp" lineno="321 3">60574 <template name="userdom_tmp_filetrans_user_tmp" lineno="3214"> 60554 60575 <summary> 60555 60576 Create objects in the temporary directory … … 60586 60607 </param> 60587 60608 </template> 60588 <template name="userdom_rw_user_tmpfs_files" lineno="324 6">60609 <template name="userdom_rw_user_tmpfs_files" lineno="3247"> 60589 60610 <summary> 60590 60611 Read user tmpfs files. … … 60611 60632 </param> 60612 60633 </template> 60613 <template name="userdom_list_user_untrusted_content" lineno="328 2">60634 <template name="userdom_list_user_untrusted_content" lineno="3283"> 60614 60635 <summary> 60615 60636 List users untrusted directories. … … 60636 60657 </param> 60637 60658 </template> 60638 <template name="userdom_dontaudit_list_user_untrusted_content" lineno="331 7">60659 <template name="userdom_dontaudit_list_user_untrusted_content" lineno="3318"> 60639 60660 <summary> 60640 60661 Do not audit attempts to list user … … 60663 60684 </param> 60664 60685 </template> 60665 <template name="userdom_read_user_untrusted_content_files" lineno="335 0">60686 <template name="userdom_read_user_untrusted_content_files" lineno="3351"> 60666 60687 <summary> 60667 60688 Read user untrusted files. … … 60688 60709 </param> 60689 60710 </template> 60690 <template name="userdom_manage_user_untrusted_content_files" lineno="338 4">60711 <template name="userdom_manage_user_untrusted_content_files" lineno="3385"> 60691 60712 <summary> 60692 60713 Manage user untrusted files. … … 60713 60734 </param> 60714 60735 </template> 60715 <template name="userdom_manage_user_untrusted_content_tmp_files" lineno="341 7">60736 <template name="userdom_manage_user_untrusted_content_tmp_files" lineno="3418"> 60716 60737 <summary> 60717 60738 Manage user untrusted tmp files. … … 60738 60759 </param> 60739 60760 </template> 60740 <template name="userdom_dontaudit_read_user_untrusted_content_files" lineno="345 2">60761 <template name="userdom_dontaudit_read_user_untrusted_content_files" lineno="3453"> 60741 60762 <summary> 60742 60763 Do not audit attempts to read users … … 60765 60786 </param> 60766 60787 </template> 60767 <template name="userdom_read_user_untrusted_content_symlinks" lineno="348 5">60788 <template name="userdom_read_user_untrusted_content_symlinks" lineno="3486"> 60768 60789 <summary> 60769 60790 Read user untrusted symbolic links. … … 60790 60811 </param> 60791 60812 </template> 60792 <template name="userdom_list_user_tmp_untrusted_content" lineno="35 19">60813 <template name="userdom_list_user_tmp_untrusted_content" lineno="3520"> 60793 60814 <summary> 60794 60815 List users temporary untrusted directories. … … 60815 60836 </param> 60816 60837 </template> 60817 <template name="userdom_dontaudit_list_user_tmp_untrusted_content" lineno="355 4">60838 <template name="userdom_dontaudit_list_user_tmp_untrusted_content" lineno="3555"> 60818 60839 <summary> 60819 60840 Do not audit attempts to list user … … 60842 60863 </param> 60843 60864 </template> 60844 <template name="userdom_read_user_tmp_untrusted_content_files" lineno="358 7">60865 <template name="userdom_read_user_tmp_untrusted_content_files" lineno="3588"> 60845 60866 <summary> 60846 60867 Read user temporary untrusted files. … … 60867 60888 </param> 60868 60889 </template> 60869 <template name="userdom_dontaudit_read_user_tmp_untrusted_content_files" lineno="362 3">60890 <template name="userdom_dontaudit_read_user_tmp_untrusted_content_files" lineno="3624"> 60870 60891 <summary> 60871 60892 Do not audit attempts to read users … … 60894 60915 </param> 60895 60916 </template> 60896 <template name="userdom_read_user_tmp_untrusted_content_symlinks" lineno="365 6">60917 <template name="userdom_read_user_tmp_untrusted_content_symlinks" lineno="3657"> 60897 60918 <summary> 60898 60919 Read user temporary untrusted symbolic links. … … 60919 60940 </param> 60920 60941 </template> 60921 <interface name="userdom_read_all_untrusted_content" lineno="367 5">60942 <interface name="userdom_read_all_untrusted_content" lineno="3676"> 60922 60943 <summary> 60923 60944 Read all user untrusted content files. … … 60929 60950 </param> 60930 60951 </interface> 60931 <interface name="userdom_read_all_tmp_untrusted_content" lineno="369 5">60952 <interface name="userdom_read_all_tmp_untrusted_content" lineno="3696"> 60932 60953 <summary> 60933 60954 Read all user temporary untrusted content files. … … 60939 60960 </param> 60940 60961 </interface> 60941 <template name="userdom_setattr_user_ttys" lineno="373 0">60962 <template name="userdom_setattr_user_ttys" lineno="3731"> 60942 60963 <summary> 60943 60964 Set the attributes of a user domain tty. … … 60964 60985 </param> 60965 60986 </template> 60966 <template name="userdom_use_user_ttys" lineno="376 3">60987 <template name="userdom_use_user_ttys" lineno="3764"> 60967 60988 <summary> 60968 60989 Read and write a user domain tty. … … 60989 61010 </param> 60990 61011 </template> 60991 <template name="userdom_use_user_terminals" lineno="379 6">61012 <template name="userdom_use_user_terminals" lineno="3797"> 60992 61013 <summary> 60993 61014 Read and write a user domain tty and pty. … … 61014 61035 </param> 61015 61036 </template> 61016 <template name="userdom_dontaudit_use_user_terminals" lineno="383 3">61037 <template name="userdom_dontaudit_use_user_terminals" lineno="3834"> 61017 61038 <summary> 61018 61039 Do not audit attempts to read and write … … 61041 61062 </param> 61042 61063 </template> 61043 <interface name="userdom_spec_domtrans_all_users" lineno="385 4">61064 <interface name="userdom_spec_domtrans_all_users" lineno="3855"> 61044 61065 <summary> 61045 61066 Execute a shell in all user domains. This … … 61053 61074 </param> 61054 61075 </interface> 61055 <interface name="userdom_xsession_spec_domtrans_all_users" lineno="387 7">61076 <interface name="userdom_xsession_spec_domtrans_all_users" lineno="3878"> 61056 61077 <summary> 61057 61078 Execute an Xserver session in all unprivileged user domains. This … … 61065 61086 </param> 61066 61087 </interface> 61067 <interface name="userdom_spec_domtrans_unpriv_users" lineno="390 0">61088 <interface name="userdom_spec_domtrans_unpriv_users" lineno="3901"> 61068 61089 <summary> 61069 61090 Execute a shell in all unprivileged user domains. This … … 61077 61098 </param> 61078 61099 </interface> 61079 <interface name="userdom_xsession_spec_domtrans_unpriv_users" lineno="392 3">61100 <interface name="userdom_xsession_spec_domtrans_unpriv_users" lineno="3924"> 61080 61101 <summary> 61081 61102 Execute an Xserver session in all unprivileged user domains. This … … 61089 61110 </param> 61090 61111 </interface> 61091 <interface name="userdom_manage_unpriv_user_semaphores" lineno="394 4">61112 <interface name="userdom_manage_unpriv_user_semaphores" lineno="3945"> 61092 61113 <summary> 61093 61114 Manage unpriviledged user SysV sempaphores. … … 61099 61120 </param> 61100 61121 </interface> 61101 <interface name="userdom_manage_unpriv_user_shared_mem" lineno="396 3">61122 <interface name="userdom_manage_unpriv_user_shared_mem" lineno="3964"> 61102 61123 <summary> 61103 61124 Manage unpriviledged user SysV shared … … 61110 61131 </param> 61111 61132 </interface> 61112 <interface name="userdom_bin_spec_domtrans_unpriv_users" lineno="398 3">61133 <interface name="userdom_bin_spec_domtrans_unpriv_users" lineno="3984"> 61113 61134 <summary> 61114 61135 Execute bin_t in the unprivileged user domains. This … … 61122 61143 </param> 61123 61144 </interface> 61124 <interface name="userdom_sbin_spec_domtrans_unpriv_users" lineno="400 6">61145 <interface name="userdom_sbin_spec_domtrans_unpriv_users" lineno="4007"> 61125 61146 <summary> 61126 61147 Execute generic sbin programs in all unprivileged user … … 61134 61155 </param> 61135 61156 </interface> 61136 <interface name="userdom_entry_spec_domtrans_unpriv_users" lineno="402 3">61157 <interface name="userdom_entry_spec_domtrans_unpriv_users" lineno="4024"> 61137 61158 <summary> 61138 61159 Execute all entrypoint files in unprivileged user … … 61146 61167 </param> 61147 61168 </interface> 61148 <interface name="userdom_shell_domtrans_sysadm" lineno="404 4">61169 <interface name="userdom_shell_domtrans_sysadm" lineno="4045"> 61149 61170 <summary> 61150 61171 Execute a shell in the sysadm domain. … … 61156 61177 </param> 61157 61178 </interface> 61158 <interface name="userdom_bin_spec_domtrans_sysadm" lineno="406 5">61179 <interface name="userdom_bin_spec_domtrans_sysadm" lineno="4066"> 61159 61180 <summary> 61160 61181 Execute a generic bin program in the sysadm domain. … … 61166 61187 </param> 61167 61188 </interface> 61168 <interface name="userdom_sbin_spec_domtrans_sysadm" lineno="408 6">61189 <interface name="userdom_sbin_spec_domtrans_sysadm" lineno="4087"> 61169 61190 <summary> 61170 61191 Execute a generic sbin program in the sysadm domain. (Deprecated) … … 61176 61197 </param> 61177 61198 </interface> 61178 <interface name="userdom_entry_spec_domtrans_sysadm" lineno="410 3">61199 <interface name="userdom_entry_spec_domtrans_sysadm" lineno="4104"> 61179 61200 <summary> 61180 61201 Execute all entrypoint files in the sysadm domain. This … … 61188 61209 </param> 61189 61210 </interface> 61190 <interface name="userdom_sysadm_bin_spec_domtrans_to" lineno="413 7">61211 <interface name="userdom_sysadm_bin_spec_domtrans_to" lineno="4138"> 61191 61212 <summary> 61192 61213 Allow sysadm to execute a generic bin program in … … 61211 61232 </param> 61212 61233 </interface> 61213 <interface name="userdom_sysadm_sbin_spec_domtrans_to" lineno="417 1">61234 <interface name="userdom_sysadm_sbin_spec_domtrans_to" lineno="4172"> 61214 61235 <summary> 61215 61236 Allow sysadm to execute a generic sbin program in … … 61234 61255 </param> 61235 61256 </interface> 61236 <interface name="userdom_sysadm_entry_spec_domtrans_to" lineno="420 0">61257 <interface name="userdom_sysadm_entry_spec_domtrans_to" lineno="4201"> 61237 61258 <summary> 61238 61259 Allow sysadm to execute all entrypoint files … … 61258 61279 </param> 61259 61280 </interface> 61260 <interface name="userdom_search_staff_home_dirs" lineno="422 1">61281 <interface name="userdom_search_staff_home_dirs" lineno="4222"> 61261 61282 <summary> 61262 61283 Search the staff users home directory. … … 61268 61289 </param> 61269 61290 </interface> 61270 <interface name="userdom_dontaudit_search_staff_home_dirs" lineno="424 1">61291 <interface name="userdom_dontaudit_search_staff_home_dirs" lineno="4242"> 61271 61292 <summary> 61272 61293 Do not audit attempts to search the staff … … 61279 61300 </param> 61280 61301 </interface> 61281 <interface name="userdom_manage_staff_home_dirs" lineno="426 0">61302 <interface name="userdom_manage_staff_home_dirs" lineno="4261"> 61282 61303 <summary> 61283 61304 Create, read, write, and delete staff … … 61290 61311 </param> 61291 61312 </interface> 61292 <interface name="userdom_relabelto_staff_home_dirs" lineno="42 79">61313 <interface name="userdom_relabelto_staff_home_dirs" lineno="4280"> 61293 61314 <summary> 61294 61315 Relabel to staff home directories. … … 61300 61321 </param> 61301 61322 </interface> 61302 <interface name="userdom_dontaudit_append_staff_home_content_files" lineno="4 299">61323 <interface name="userdom_dontaudit_append_staff_home_content_files" lineno="4300"> 61303 61324 <summary> 61304 61325 Do not audit attempts to append to the staff … … 61311 61332 </param> 61312 61333 </interface> 61313 <interface name="userdom_read_staff_home_content_files" lineno="431 7">61334 <interface name="userdom_read_staff_home_content_files" lineno="4318"> 61314 61335 <summary> 61315 61336 Read files in the staff users home directory. … … 61321 61342 </param> 61322 61343 </interface> 61323 <interface name="userdom_sigchld_sysadm" lineno="433 8">61344 <interface name="userdom_sigchld_sysadm" lineno="4339"> 61324 61345 <summary> 61325 61346 Send a SIGCHLD signal to sysadm users. … … 61331 61352 </param> 61332 61353 </interface> 61333 <interface name="userdom_dontaudit_getattr_sysadm_ttys" lineno="435 7">61354 <interface name="userdom_dontaudit_getattr_sysadm_ttys" lineno="4358"> 61334 61355 <summary> 61335 61356 Do not audit attepts to get the attributes … … 61342 61363 </param> 61343 61364 </interface> 61344 <interface name="userdom_use_sysadm_ttys" lineno="437 5">61365 <interface name="userdom_use_sysadm_ttys" lineno="4376"> 61345 61366 <summary> 61346 61367 Read and write sysadm ttys. … … 61352 61373 </param> 61353 61374 </interface> 61354 <interface name="userdom_dontaudit_use_sysadm_ttys" lineno="439 5">61375 <interface name="userdom_dontaudit_use_sysadm_ttys" lineno="4396"> 61355 61376 <summary> 61356 61377 Do not audit attempts to use sysadm ttys. … … 61362 61383 </param> 61363 61384 </interface> 61364 <interface name="userdom_use_sysadm_ptys" lineno="441 3">61385 <interface name="userdom_use_sysadm_ptys" lineno="4414"> 61365 61386 <summary> 61366 61387 Read and write sysadm ptys. … … 61372 61393 </param> 61373 61394 </interface> 61374 <interface name="userdom_dontaudit_use_sysadm_ptys" lineno="443 3">61395 <interface name="userdom_dontaudit_use_sysadm_ptys" lineno="4434"> 61375 61396 <summary> 61376 61397 Dont audit attempts to read and write sysadm ptys. … … 61382 61403 </param> 61383 61404 </interface> 61384 <interface name="userdom_use_sysadm_terms" lineno="445 1">61405 <interface name="userdom_use_sysadm_terms" lineno="4452"> 61385 61406 <summary> 61386 61407 Read and write sysadm ttys and ptys. … … 61392 61413 </param> 61393 61414 </interface> 61394 <interface name="userdom_dontaudit_use_sysadm_terms" lineno="446 6">61415 <interface name="userdom_dontaudit_use_sysadm_terms" lineno="4467"> 61395 61416 <summary> 61396 61417 Do not audit attempts to use sysadm ttys and ptys. … … 61402 61423 </param> 61403 61424 </interface> 61404 <interface name="userdom_use_sysadm_fds" lineno="448 4">61425 <interface name="userdom_use_sysadm_fds" lineno="4485"> 61405 61426 <summary> 61406 61427 Inherit and use sysadm file descriptors … … 61412 61433 </param> 61413 61434 </interface> 61414 <interface name="userdom_rw_sysadm_pipes" lineno="450 2">61435 <interface name="userdom_rw_sysadm_pipes" lineno="4503"> 61415 61436 <summary> 61416 61437 Read and write sysadm user unnamed pipes. … … 61422 61443 </param> 61423 61444 </interface> 61424 <interface name="userdom_getattr_sysadm_home_dirs" lineno="452 1">61445 <interface name="userdom_getattr_sysadm_home_dirs" lineno="4522"> 61425 61446 <summary> 61426 61447 Get the attributes of the sysadm users … … 61433 61454 </param> 61434 61455 </interface> 61435 <interface name="userdom_dontaudit_getattr_sysadm_home_dirs" lineno="454 1">61456 <interface name="userdom_dontaudit_getattr_sysadm_home_dirs" lineno="4542"> 61436 61457 <summary> 61437 61458 Do not audit attempts to get the … … 61445 61466 </param> 61446 61467 </interface> 61447 <interface name="userdom_search_sysadm_home_dirs" lineno="45 59">61468 <interface name="userdom_search_sysadm_home_dirs" lineno="4560"> 61448 61469 <summary> 61449 61470 Search the sysadm users home directory. … … 61455 61476 </param> 61456 61477 </interface> 61457 <interface name="userdom_dontaudit_search_sysadm_home_dirs" lineno="457 8">61478 <interface name="userdom_dontaudit_search_sysadm_home_dirs" lineno="4579"> 61458 61479 <summary> 61459 61480 Do not audit attempts to search the sysadm … … 61466 61487 </param> 61467 61488 </interface> 61468 <interface name="userdom_list_sysadm_home_dirs" lineno="459 6">61489 <interface name="userdom_list_sysadm_home_dirs" lineno="4597"> 61469 61490 <summary> 61470 61491 List the sysadm users home directory. … … 61476 61497 </param> 61477 61498 </interface> 61478 <interface name="userdom_dontaudit_list_sysadm_home_dirs" lineno="461 5">61499 <interface name="userdom_dontaudit_list_sysadm_home_dirs" lineno="4616"> 61479 61500 <summary> 61480 61501 Do not audit attempts to list the sysadm … … 61487 61508 </param> 61488 61509 </interface> 61489 <interface name="userdom_dontaudit_read_sysadm_home_content_files" lineno="463 4">61510 <interface name="userdom_dontaudit_read_sysadm_home_content_files" lineno="4635"> 61490 61511 <summary> 61491 61512 Do not audit attempts to search the sysadm … … 61498 61519 </param> 61499 61520 </interface> 61500 <interface name="userdom_sysadm_home_dir_filetrans" lineno="466 6">61521 <interface name="userdom_sysadm_home_dir_filetrans" lineno="4667"> 61501 61522 <summary> 61502 61523 Create objects in sysadm home directories … … 61520 61541 </param> 61521 61542 </interface> 61522 <interface name="userdom_search_sysadm_home_content_dirs" lineno="468 4">61543 <interface name="userdom_search_sysadm_home_content_dirs" lineno="4685"> 61523 61544 <summary> 61524 61545 Search the sysadm users home sub directories. … … 61530 61551 </param> 61531 61552 </interface> 61532 <interface name="userdom_read_sysadm_home_content_files" lineno="470 2">61553 <interface name="userdom_read_sysadm_home_content_files" lineno="4703"> 61533 61554 <summary> 61534 61555 Read files in the sysadm users home directory. … … 61540 61561 </param> 61541 61562 </interface> 61542 <interface name="userdom_read_sysadm_tmp_files" lineno="472 3">61563 <interface name="userdom_read_sysadm_tmp_files" lineno="4724"> 61543 61564 <summary> 61544 61565 Read sysadm temporary files. … … 61550 61571 </param> 61551 61572 </interface> 61552 <interface name="userdom_search_all_users_home_dirs" lineno="474 4">61573 <interface name="userdom_search_all_users_home_dirs" lineno="4745"> 61553 61574 <summary> 61554 61575 Search all users home directories. … … 61560 61581 </param> 61561 61582 </interface> 61562 <interface name="userdom_list_all_users_home_dirs" lineno="476 3">61583 <interface name="userdom_list_all_users_home_dirs" lineno="4764"> 61563 61584 <summary> 61564 61585 List all users home directories. … … 61570 61591 </param> 61571 61592 </interface> 61572 <interface name="userdom_search_all_users_home_content" lineno="478 2">61593 <interface name="userdom_search_all_users_home_content" lineno="4783"> 61573 61594 <summary> 61574 61595 Search all users home directories. … … 61580 61601 </param> 61581 61602 </interface> 61582 <interface name="userdom_dontaudit_search_all_users_home_content" lineno="480 1">61603 <interface name="userdom_dontaudit_search_all_users_home_content" lineno="4802"> 61583 61604 <summary> 61584 61605 Do not audit attempts to search all users home directories. … … 61590 61611 </param> 61591 61612 </interface> 61592 <interface name="userdom_read_all_users_home_content_files" lineno="48 19">61613 <interface name="userdom_read_all_users_home_content_files" lineno="4820"> 61593 61614 <summary> 61594 61615 Read all files in all users home directories. … … 61600 61621 </param> 61601 61622 </interface> 61602 <interface name="userdom_manage_all_users_home_content_dirs" lineno="484 0">61623 <interface name="userdom_manage_all_users_home_content_dirs" lineno="4841"> 61603 61624 <summary> 61604 61625 Create, read, write, and delete all directories … … 61611 61632 </param> 61612 61633 </interface> 61613 <interface name="userdom_manage_all_users_home_content_files" lineno="486 0">61634 <interface name="userdom_manage_all_users_home_content_files" lineno="4861"> 61614 61635 <summary> 61615 61636 Create, read, write, and delete all files … … 61622 61643 </param> 61623 61644 </interface> 61624 <interface name="userdom_manage_all_users_home_content_symlinks" lineno="488 0">61645 <interface name="userdom_manage_all_users_home_content_symlinks" lineno="4881"> 61625 61646 <summary> 61626 61647 Create, read, write, and delete all symlinks … … 61633 61654 </param> 61634 61655 </interface> 61635 <interface name="userdom_priveleged_home_dir_manager" lineno="49 09">61656 <interface name="userdom_priveleged_home_dir_manager" lineno="4910"> 61636 61657 <summary> 61637 61658 Make the specified domain a privileged … … 61653 61674 </param> 61654 61675 </interface> 61655 <interface name="userdom_signal_unpriv_users" lineno="492 8">61676 <interface name="userdom_signal_unpriv_users" lineno="4929"> 61656 61677 <summary> 61657 61678 Send general signals to unprivileged user domains. … … 61663 61684 </param> 61664 61685 </interface> 61665 <interface name="userdom_use_unpriv_users_fds" lineno="494 6">61686 <interface name="userdom_use_unpriv_users_fds" lineno="4947"> 61666 61687 <summary> 61667 61688 Inherit the file descriptors from unprivileged user domains. … … 61673 61694 </param> 61674 61695 </interface> 61675 <interface name="userdom_dontaudit_use_unpriv_user_fds" lineno="496 5">61696 <interface name="userdom_dontaudit_use_unpriv_user_fds" lineno="4966"> 61676 61697 <summary> 61677 61698 Do not audit attempts to inherit the
