Changeset 78

Show
Ignore:
Timestamp:
06/01/07 11:34:47 (2 years ago)
Author:
bwhalen
Message:

Change the policy type to be strict-mcs and change the binary version to 21 so we can load on rh kernels.
This will be fixed in U1 and we can roll back to building non-mls

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/RHEL5/refpolicy/src/selinux-policy-clip/build.conf

    r11 r78  
    99# override the version.  This only has an 
    1010# effect for monolithic policies. 
    11 OUTPUT_POLICY = 18 
     11OUTPUT_POLICY = 21 
    1212 
    1313# Policy Type 
     
    1515# strict-mls, targeted-mls, 
    1616# strict-mcs, targeted-mcs 
    17 TYPE = strict 
     17TYPE = strict-mcs 
    1818 
    1919# Policy Name 
  • trunk/RHEL5/refpolicy/src/selinux-policy-clip/doc/policy.xml

    r13 r78  
    37363736<summary> 
    37373737Make general progams in sbin an entrypoint for 
    3738 the specified domain. 
     3738the specified domain.  (Deprecated) 
    37393739</summary> 
    37403740<param name="domain"> 
     
    37443744</param> 
    37453745</interface> 
    3746 <interface name="corecmd_shell_entry_type" lineno="113"> 
     3746<interface name="corecmd_shell_entry_type" lineno="110"> 
    37473747<summary> 
    37483748Make the shell an entrypoint for the specified domain. 
     
    37543754</param> 
    37553755</interface> 
    3756 <interface name="corecmd_search_bin" lineno="131"> 
     3756<interface name="corecmd_search_bin" lineno="128"> 
    37573757<summary> 
    37583758Search the contents of bin directories. 
     
    37643764</param> 
    37653765</interface> 
    3766 <interface name="corecmd_list_bin" lineno="149"> 
     3766<interface name="corecmd_dontaudit_search_bin" lineno="146"> 
     3767<summary> 
     3768Do not audit attempts to search the contents of bin directories. 
     3769</summary> 
     3770<param name="domain"> 
     3771<summary> 
     3772Domain allowed access. 
     3773</summary> 
     3774</param> 
     3775</interface> 
     3776<interface name="corecmd_list_bin" lineno="164"> 
    37673777<summary> 
    37683778List the contents of bin directories. 
     
    37743784</param> 
    37753785</interface> 
    3776 <interface name="corecmd_getattr_bin_files" lineno="167"> 
     3786<interface name="corecmd_dontaudit_write_bin_dirs" lineno="182"> 
     3787<summary> 
     3788Do not auidt attempts to write bin directories. 
     3789</summary> 
     3790<param name="domain"> 
     3791<summary> 
     3792Domain allowed access. 
     3793</summary> 
     3794</param> 
     3795</interface> 
     3796<interface name="corecmd_getattr_bin_files" lineno="200"> 
    37773797<summary> 
    37783798Get the attributes of files in bin directories. 
     
    37843804</param> 
    37853805</interface> 
    3786 <interface name="corecmd_read_bin_files" lineno="185"> 
     3806<interface name="corecmd_read_bin_files" lineno="218"> 
    37873807<summary> 
    37883808Read files in bin directories. 
     
    37943814</param> 
    37953815</interface> 
    3796 <interface name="corecmd_read_bin_symlinks" lineno="203"> 
     3816<interface name="corecmd_read_bin_symlinks" lineno="236"> 
    37973817<summary> 
    37983818Read symbolic links in bin directories. 
     
    38043824</param> 
    38053825</interface> 
    3806 <interface name="corecmd_read_bin_pipes" lineno="221"> 
     3826<interface name="corecmd_read_bin_pipes" lineno="254"> 
    38073827<summary> 
    38083828Read pipes in bin directories. 
     
    38143834</param> 
    38153835</interface> 
    3816 <interface name="corecmd_read_bin_sockets" lineno="239"> 
     3836<interface name="corecmd_read_bin_sockets" lineno="272"> 
    38173837<summary> 
    38183838Read named sockets in bin directories. 
     
    38243844</param> 
    38253845</interface> 
    3826 <interface name="corecmd_exec_bin" lineno="258"> 
     3846<interface name="corecmd_exec_bin" lineno="291"> 
    38273847<summary> 
    38283848Execute generic programs in bin directories, 
     
    38353855</param> 
    38363856</interface> 
    3837 <interface name="corecmd_manage_bin_files" lineno="278"> 
     3857<interface name="corecmd_manage_bin_files" lineno="311"> 
    38383858<summary> 
    38393859Create, read, write, and delete bin files. 
     
    38453865</param> 
    38463866</interface> 
    3847 <interface name="corecmd_relabel_bin_files" lineno="296"> 
     3867<interface name="corecmd_relabel_bin_files" lineno="329"> 
    38483868<summary> 
    38493869Relabel to and from the bin type. 
     
    38553875</param> 
    38563876</interface> 
    3857 <interface name="corecmd_mmap_bin_files" lineno="314"> 
     3877<interface name="corecmd_mmap_bin_files" lineno="347"> 
    38583878<summary> 
    38593879Mmap a bin file as executable. 
     
    38653885</param> 
    38663886</interface> 
    3867 <interface name="corecmd_bin_spec_domtrans" lineno="359"> 
     3887<interface name="corecmd_bin_spec_domtrans" lineno="392"> 
    38683888<summary> 
    38693889Execute a file in a bin directory 
     
    39013921</param> 
    39023922</interface> 
    3903 <interface name="corecmd_bin_domtrans" lineno="402"> 
     3923<interface name="corecmd_bin_domtrans" lineno="435"> 
    39043924<summary> 
    39053925Execute a file in a bin directory 
     
    39353955</param> 
    39363956</interface> 
    3937 <interface name="corecmd_search_sbin" lineno="421"> 
    3938 <summary> 
    3939 Search the contents of sbin directories. 
    3940 </summary> 
    3941 <param name="domain"> 
    3942 <summary> 
    3943 Domain allowed access. 
    3944 </summary> 
    3945 </param> 
    3946 </interface> 
    3947 <interface name="corecmd_dontaudit_search_sbin" lineno="440"> 
     3957<interface name="corecmd_search_sbin" lineno="454"> 
     3958<summary> 
     3959Search the contents of sbin directories.  (Deprecated) 
     3960</summary> 
     3961<param name="domain"> 
     3962<summary> 
     3963Domain allowed access. 
     3964</summary> 
     3965</param> 
     3966</interface> 
     3967<interface name="corecmd_dontaudit_search_sbin" lineno="470"> 
    39483968<summary> 
    39493969Do not audit attempts to search 
    3950 sbin directories. 
    3951 </summary> 
    3952 <param name="domain"> 
    3953 <summary> 
    3954 Domain to not audit. 
    3955 </summary> 
    3956 </param> 
    3957 </interface> 
    3958 <interface name="corecmd_list_sbin" lineno="458"> 
    3959 <summary> 
    3960 List the contents of sbin directories. 
    3961 </summary> 
    3962 <param name="domain"> 
    3963 <summary> 
    3964 Domain allowed access. 
    3965 </summary> 
    3966 </param> 
    3967 </interface> 
    3968 <interface name="corecmd_getattr_sbin_files" lineno="476"> 
    3969 <summary> 
    3970 Get the attributes of sbin files. 
    3971 </summary> 
    3972 <param name="domain"> 
    3973 <summary> 
    3974 Domain allowed access. 
    3975 </summary> 
    3976 </param> 
    3977 </interface> 
    3978 <interface name="corecmd_dontaudit_getattr_sbin_files" lineno="495"> 
     3970sbin directories.  (Deprecated) 
     3971</summary> 
     3972<param name="domain"> 
     3973<summary> 
     3974Domain to not audit. 
     3975</summary> 
     3976</param> 
     3977</interface> 
     3978<interface name="corecmd_list_sbin" lineno="485"> 
     3979<summary> 
     3980List the contents of sbin directories.  (Deprecated) 
     3981</summary> 
     3982<param name="domain"> 
     3983<summary> 
     3984Domain allowed access. 
     3985</summary> 
     3986</param> 
     3987</interface> 
     3988<interface name="corecmd_dontaudit_write_sbin_dirs" lineno="501"> 
     3989<summary> 
     3990Do not audit attempts to write 
     3991sbin directories.  (Deprecated) 
     3992</summary> 
     3993<param name="domain"> 
     3994<summary> 
     3995Domain to not audit. 
     3996</summary> 
     3997</param> 
     3998</interface> 
     3999<interface name="corecmd_getattr_sbin_files" lineno="516"> 
     4000<summary> 
     4001Get the attributes of sbin files.  (Deprecated) 
     4002</summary> 
     4003<param name="domain"> 
     4004<summary> 
     4005Domain allowed access. 
     4006</summary> 
     4007</param> 
     4008</interface> 
     4009<interface name="corecmd_dontaudit_getattr_sbin_files" lineno="532"> 
    39794010<summary> 
    39804011Do not audit attempts to get the attibutes 
    3981 of sbin files. 
    3982 </summary> 
    3983 <param name="domain"> 
    3984 <summary> 
    3985 Domain to not audit. 
    3986 </summary> 
    3987 </param> 
    3988 </interface> 
    3989 <interface name="corecmd_read_sbin_files" lineno="513"> 
    3990 <summary> 
    3991 Read files in sbin directories. 
    3992 </summary> 
    3993 <param name="domain"> 
    3994 <summary> 
    3995 Domain allowed access. 
    3996 </summary> 
    3997 </param> 
    3998 </interface> 
    3999 <interface name="corecmd_read_sbin_symlinks" lineno="531"> 
    4000 <summary> 
    4001 Read symbolic links in sbin directories. 
    4002 </summary> 
    4003 <param name="domain"> 
    4004 <summary> 
    4005 Domain allowed access. 
    4006 </summary> 
    4007 </param> 
    4008 </interface> 
    4009 <interface name="corecmd_read_sbin_pipes" lineno="549"> 
    4010 <summary> 
    4011 Read named pipes in sbin directories. 
    4012 </summary> 
    4013 <param name="domain"> 
    4014 <summary> 
    4015 Domain allowed access. 
    4016 </summary> 
    4017 </param> 
    4018 </interface> 
    4019 <interface name="corecmd_read_sbin_sockets" lineno="567"> 
    4020 <summary> 
    4021 Read named sockets in sbin directories. 
    4022 </summary> 
    4023 <param name="domain"> 
    4024 <summary> 
    4025 Domain allowed access. 
    4026 </summary> 
    4027 </param> 
    4028 </interface> 
    4029 <interface name="corecmd_exec_sbin" lineno="586"> 
     4012of sbin files.  (Deprecated) 
     4013</summary> 
     4014<param name="domain"> 
     4015<summary> 
     4016Domain to not audit. 
     4017</summary> 
     4018</param> 
     4019</interface> 
     4020<interface name="corecmd_read_sbin_files" lineno="547"> 
     4021<summary> 
     4022Read files in sbin directories.  (Deprecated) 
     4023</summary> 
     4024<param name="domain"> 
     4025<summary> 
     4026Domain allowed access. 
     4027</summary> 
     4028</param> 
     4029</interface> 
     4030<interface name="corecmd_read_sbin_symlinks" lineno="562"> 
     4031<summary> 
     4032Read symbolic links in sbin directories.  (Deprecated) 
     4033</summary> 
     4034<param name="domain"> 
     4035<summary> 
     4036Domain allowed access. 
     4037</summary> 
     4038</param> 
     4039</interface> 
     4040<interface name="corecmd_read_sbin_pipes" lineno="577"> 
     4041<summary> 
     4042Read named pipes in sbin directories.  (Deprecated) 
     4043</summary> 
     4044<param name="domain"> 
     4045<summary> 
     4046Domain allowed access. 
     4047</summary> 
     4048</param> 
     4049</interface> 
     4050<interface name="corecmd_read_sbin_sockets" lineno="592"> 
     4051<summary> 
     4052Read named sockets in sbin directories.  (Deprecated) 
     4053</summary> 
     4054<param name="domain"> 
     4055<summary> 
     4056Domain allowed access. 
     4057</summary> 
     4058</param> 
     4059</interface> 
     4060<interface name="corecmd_exec_sbin" lineno="608"> 
    40304061<summary> 
    40314062Execute generic programs in sbin directories, 
    4032 in the caller domain. 
    4033 </summary> 
    4034 <param name="domain"> 
    4035 <summary> 
    4036 Domain allowed access. 
    4037 </summary> 
    4038 </param> 
    4039 </interface> 
    4040 <interface name="corecmd_manage_sbin_files" lineno="607"> 
    4041 <summary> 
    4042 Create, read, write, and delete sbin files. 
    4043 </summary> 
    4044 <param name="domain"> 
    4045 <summary> 
    4046 Domain allowed access. 
    4047 </summary> 
    4048 </param> 
    4049 </interface> 
    4050 <interface name="corecmd_relabel_sbin_files" lineno="626"> 
    4051 <summary> 
    4052 Relabel to and from the sbin type. 
    4053 </summary> 
    4054 <param name="domain"> 
    4055 <summary> 
    4056 Domain allowed access. 
    4057 </summary> 
    4058 </param> 
    4059 </interface> 
    4060 <interface name="corecmd_mmap_sbin_files" lineno="645"> 
    4061 <summary> 
    4062 Mmap a sbin file as executable. 
    4063 </summary> 
    4064 <param name="domain"> 
    4065 <summary> 
    4066 Domain allowed access. 
    4067 </summary> 
    4068 </param> 
    4069 </interface> 
    4070 <interface name="corecmd_sbin_domtrans" lineno="688"> 
     4063in the caller domain.  (Deprecated) 
     4064</summary> 
     4065<param name="domain"> 
     4066<summary> 
     4067Domain allowed access. 
     4068</summary> 
     4069</param> 
     4070</interface> 
     4071<interface name="corecmd_manage_sbin_files" lineno="624"> 
     4072<summary> 
     4073Create, read, write, and delete sbin files.  (Deprecated) 
     4074</summary> 
     4075<param name="domain"> 
     4076<summary> 
     4077Domain allowed access. 
     4078</summary> 
     4079</param> 
     4080</interface> 
     4081<interface name="corecmd_relabel_sbin_files" lineno="640"> 
     4082<summary> 
     4083Relabel to and from the sbin type.  (Deprecated) 
     4084</summary> 
     4085<param name="domain"> 
     4086<summary> 
     4087Domain allowed access. 
     4088</summary> 
     4089</param> 
     4090</interface> 
     4091<interface name="corecmd_mmap_sbin_files" lineno="656"> 
     4092<summary> 
     4093Mmap a sbin file as executable.  (Deprecated) 
     4094</summary> 
     4095<param name="domain"> 
     4096<summary> 
     4097Domain allowed access. 
     4098</summary> 
     4099</param> 
     4100</interface> 
     4101<interface name="corecmd_sbin_domtrans" lineno="695"> 
    40714102<summary> 
    40724103Execute a file in a sbin directory 
    4073 in the specified domain. 
     4104in the specified domain.  (Deprecated) 
    40744105</summary> 
    40754106<desc> 
     
    40794110the specified domain to execute any file 
    40804111on these filesystems in the specified 
    4081 domain.  This is not suggested. 
     4112domain.  This is not suggested.  (Deprecated) 
    40824113</p> 
    40834114<p> 
     
    41024133</param> 
    41034134</interface> 
    4104 <interface name="corecmd_sbin_spec_domtrans" lineno="733"> 
     4135<interface name="corecmd_sbin_spec_domtrans" lineno="736"> 
    41054136<summary> 
    41064137Execute a file in a sbin directory 
    41074138in the specified domain but do not 
    41084139do it automatically. This is an explicit 
    4109 transition, requiring the caller to use setexeccon(). 
     4140transition, requiring the caller to use setexeccon().  (Deprecated) 
    41104141</summary> 
    41114142<desc> 
     
    41154146the specified domain to execute any file 
    41164147on these filesystems in the specified 
    4117 domain.  This is not suggested. 
     4148domain.  This is not suggested.  (Deprecated) 
    41184149</p> 
    41194150<p> 
     
    41384169</param> 
    41394170</interface> 
    4140 <interface name="corecmd_check_exec_shell" lineno="752"> 
     4171<interface name="corecmd_check_exec_shell" lineno="751"> 
    41414172<summary> 
    41424173Check if a shell is executable (DAC-wise). 
     
    41484179</param> 
    41494180</interface> 
    4150 <interface name="corecmd_exec_shell" lineno="772"> 
     4181<interface name="corecmd_exec_shell" lineno="771"> 
    41514182<summary> 
    41524183Execute a shell in the caller domain. 
     
    41584189</param> 
    41594190</interface> 
    4160 <interface name="corecmd_exec_ls" lineno="792"> 
    4161 <summary> 
    4162 Execute ls in the caller domain. 
    4163 </summary> 
    4164 <param name="domain"> 
    4165 <summary> 
    4166 Domain allowed access. 
    4167 </summary> 
    4168 </param> 
    4169 </interface> 
    4170 <interface name="corecmd_shell_spec_domtrans" lineno="831"> 
     4191<interface name="corecmd_exec_ls" lineno="791"> 
     4192<summary> 
     4193Execute ls in the caller domain.  (Deprecated) 
     4194</summary> 
     4195<param name="domain"> 
     4196<summary> 
     4197Domain allowed access. 
     4198</summary> 
     4199</param> 
     4200</interface> 
     4201<interface name="corecmd_shell_spec_domtrans" lineno="825"> 
    41714202<summary> 
    41724203Execute a shell in the target domain.  This 
     
    41974228</param> 
    41984229</interface> 
    4199 <interface name="corecmd_shell_domtrans" lineno="866"> 
     4230<interface name="corecmd_shell_domtrans" lineno="860"> 
    42004231<summary> 
    42014232Execute a shell in the specified domain. 
     
    42224253</param> 
    42234254</interface> 
    4224 <interface name="corecmd_exec_chroot" lineno="885"> 
     4255<interface name="corecmd_exec_chroot" lineno="879"> 
    42254256<summary> 
    42264257Execute chroot in the caller domain. 
     
    42324263</param> 
    42334264</interface> 
    4234 <interface name="corecmd_exec_all_executables" lineno="906"> 
     4265<interface name="corecmd_getattr_all_executables" lineno="900"> 
     4266<summary> 
     4267Get the attributes of all executable files. 
     4268</summary> 
     4269<param name="domain"> 
     4270<summary> 
     4271Domain allowed access. 
     4272</summary> 
     4273</param> 
     4274<rolecap/> 
     4275</interface> 
     4276<interface name="corecmd_exec_all_executables" lineno="921"> 
    42354277<summary> 
    42364278Execute all executable files. 
     
    42434285<rolecap/> 
    42444286</interface> 
    4245 <interface name="corecmd_manage_all_executables" lineno="928"> 
     4287<interface name="corecmd_manage_all_executables" lineno="943"> 
    42464288<summary> 
    42474289Create, read, write, and all executable files. 
     
    42544296<rolecap/> 
    42554297</interface> 
    4256 <interface name="corecmd_relabel_all_executables" lineno="949"> 
     4298<interface name="corecmd_relabel_all_executables" lineno="964"> 
    42574299<summary> 
    42584300Relabel to and from the bin type. 
     
    42654307<rolecap/> 
    42664308</interface> 
    4267 <interface name="corecmd_mmap_all_executables" lineno="967"> 
     4309<interface name="corecmd_mmap_all_executables" lineno="983"> 
    42684310<summary> 
    42694311Mmap all executables as executable. 
     
    4303843080</param> 
    4303943081</interface> 
    43040 <template name="clockspeed_run_cli" lineno="42"> 
     43082<interface name="clockspeed_run_cli" lineno="42"> 
    4304143083<summary> 
    4304243084Allow the specified role the clockspeed_cli domain. 
     
    4305843100</param> 
    4305943101<rolecap/> 
    43060 </template> 
     43102</interface> 
    4306143103</module> 
    4306243104<module name="comsat" filename="policy/modules/services/comsat.if"> 
     
    5402754069</param> 
    5402854070</template> 
    54029 <template name="userdom_security_admin_template" lineno="1285"> 
     54071<template name="userdom_security_admin_template" lineno="1269"> 
    5403054072<summary> 
    5403154073Allow user to run as a secadm 
     
    5406454106</param> 
    5406554107</template> 
    54066 <template name="userdom_role_change_generic_user" lineno="1371"> 
     54108<template name="userdom_role_change_generic_user" lineno="1355"> 
    5406754109<summary> 
    5406854110Change to the generic user role. 
     
    5408654128<rolecap/> 
    5408754129</template> 
    54088 <template name="userdom_role_change_from_generic_user" lineno="1402"> 
     54130<template name="userdom_role_change_from_generic_user" lineno="1386"> 
    5408954131<summary> 
    5409054132Change from the generic user role. 
     
    5410954151<rolecap/> 
    5411054152</template> 
    54111 <template name="userdom_role_change_staff" lineno="1432"> 
     54153<template name="userdom_role_change_staff" lineno="1416"> 
    5411254154<summary> 
    5411354155Change to the staff user role. 
     
    5413154173<rolecap/> 
    5413254174</template> 
    54133 <template name="userdom_role_change_from_staff" lineno="1463"> 
     54175<template name="userdom_role_change_from_staff" lineno="1447"> 
    5413454176<summary> 
    5413554177Change from the staff user role. 
     
    5415454196<rolecap/> 
    5415554197</template> 
    54156 <template name="userdom_role_change_sysadm" lineno="1493"> 
     54198<template name="userdom_role_change_sysadm" lineno="1477"> 
    5415754199<summary> 
    5415854200Change to the sysadm user role. 
     
    5417654218<rolecap/> 
    5417754219</template> 
    54178 <template name="userdom_role_change_from_sysadm" lineno="1524"> 
     54220<template name="userdom_role_change_from_sysadm" lineno="1508"> 
    5417954221<summary> 
    5418054222Change from the sysadm user role. 
     
    5419954241<rolecap/> 
    5420054242</template> 
    54201 <template name="userdom_role_change_secadm" lineno="1554"> 
     54243<template name="userdom_role_change_secadm" lineno="1538"> 
    5420254244<summary> 
    5420354245Change to the secadm user role. 
     
    5422154263<rolecap/> 
    5422254264</template> 
    54223 <template name="userdom_role_change_from_secadm" lineno="1585"> 
     54265<template name="userdom_role_change_from_secadm" lineno="1569"> 
    5422454266<summary> 
    5422554267Change from the secadm user role. 
     
    5424454286<rolecap/> 
    5424554287</template> 
    54246 <template name="userdom_role_change_auditadm" lineno="1615"> 
     54288<template name="userdom_role_change_auditadm" lineno="1599"> 
    5424754289<summary> 
    5424854290Change to the auditadm user role. 
     
    5426654308<rolecap/> 
    5426754309</template> 
    54268 <template name="userdom_role_change_from_auditadm" lineno="1646"> 
     54310<template name="userdom_role_change_from_auditadm" lineno="1630"> 
    5426954311<summary> 
    5427054312Change from the auditadm user role. 
     
    5428954331<rolecap/> 
    5429054332</template> 
    54291 <template name="userdom_user_home_content" lineno="1682"> 
     54333<template name="userdom_user_home_content" lineno="1666"> 
    5429254334<summary> 
    5429354335Make the specified type usable in a 
     
    5431754359</param> 
    5431854360</template> 
    54319 <template name="userdom_setattr_user_ptys" lineno="1716"> 
     54361<template name="userdom_setattr_user_ptys" lineno="1700"> 
    5432054362<summary> 
    5432154363Set the attributes of a user pty. 
     
    5434254384</param> 
    5434354385</template> 
    54344 <template name="userdom_create_user_pty" lineno="1751"> 
     54386<template name="userdom_create_user_pty" lineno="1735"> 
    5434554387<summary> 
    5434654388Create a user pty. 
     
    5436754409</param> 
    5436854410</template> 
    54369 <template name="userdom_search_user_home_dirs" lineno="1786"> 
     54411<template name="userdom_search_user_home_dirs" lineno="1770"> 
    5437054412<summary> 
    5437154413Search user home directories. 
     
    5439254434</param> 
    5439354435</template> 
    54394 <template name="userdom_list_user_home_dirs" lineno="1820"> 
     54436<template name="userdom_list_user_home_dirs" lineno="1804"> 
    5439554437<summary> 
    5439654438List user home directories. 
     
    5441754459</param> 
    5441854460</template> 
    54419 <template name="userdom_user_home_domtrans" lineno="1868"> 
     54461<template name="userdom_user_home_domtrans" lineno="1852"> 
    5442054462<summary> 
    5442154463Do a domain transition to the specified 
     
    5445654498</param> 
    5445754499</template> 
    54458 <template name="userdom_dontaudit_list_user_home_dirs" lineno="1903"> 
     54500<template name="userdom_dontaudit_list_user_home_dirs" lineno="1887"> 
    5445954501<summary> 
    5446054502Do not audit attempts to list user home subdirectories. 
     
    5448154523</param> 
    5448254524</template> 
    54483 <template name="userdom_manage_user_home_content_dirs" lineno="1938"> 
     54525<template name="userdom_manage_user_home_content_dirs" lineno="1922"> 
    5448454526<summary> 
    5448554527Create, read, write, and delete directories 
     
    5450854550</param> 
    5450954551</template> 
    54510 <template name="userdom_dontaudit_setattr_user_home_content_files" lineno="1974"> 
     54552<template name="userdom_dontaudit_setattr_user_home_content_files" lineno="1958"> 
    5451154553<summary> 
    5451254554Do not audit attempts to set the 
     
    5453554577</param> 
    5453654578</template> 
    54537 <template name="userdom_read_user_home_content_files" lineno="2007"> 
     54579<template name="userdom_read_user_home_content_files" lineno="1991"> 
    5453854580<summary> 
    5453954581Read user home files. 
     
    5456054602</param> 
    5456154603</template> 
    54562 <template name="userdom_dontaudit_read_user_home_content_files" lineno="2041"> 
     54604<template name="userdom_dontaudit_read_user_home_content_files" lineno="2025"> 
    5456354605<summary> 
    5456454606Do not audit attempts to read user home files. 
     
    5458554627</param> 
    5458654628</template> 
    54587 <template name="userdom_dontaudit_write_user_home_content_files" lineno="2075"> 
     54629<template name="userdom_dontaudit_write_user_home_content_files" lineno="2059"> 
    5458854630<summary> 
    5458954631Do not audit attempts to write user home files. 
     
    5461054652</param> 
    5461154653</template> 
    54612 <template name="userdom_read_user_home_content_symlinks" lineno="2108"> 
     54654<template name="userdom_read_user_home_content_symlinks" lineno="2092"> 
    5461354655<summary> 
    5461454656Read user home subdirectory symbolic links. 
     
    5463554677</param> 
    5463654678</template> 
    54637 <template name="userdom_exec_user_home_content_files" lineno="2142"> 
     54679<template name="userdom_exec_user_home_content_files" lineno="2126"> 
    5463854680<summary> 
    5463954681Execute user home files. 
     
    5466054702</param> 
    5466154703</template> 
    54662 <template name="userdom_dontaudit_exec_user_home_content_files" lineno="2176"> 
     54704<template name="userdom_dontaudit_exec_user_home_content_files" lineno="2160"> 
    5466354705<summary> 
    5466454706Do not audit attempts to execute user home files. 
     
    5468554727</param> 
    5468654728</template> 
    54687 <template name="userdom_manage_user_home_content_files" lineno="2211"> 
     54729<template name="userdom_manage_user_home_content_files" lineno="2195"> 
    5468854730<summary> 
    5468954731Create, read, write, and delete files 
     
    5471254754</param> 
    5471354755</template> 
    54714 <template name="userdom_dontaudit_manage_user_home_content_dirs" lineno="2248"> 
     54756<template name="userdom_dontaudit_manage_user_home_content_dirs" lineno="2232"> 
    5471554757<summary> 
    5471654758Do not audit attempts to create, read, write, and delete directories 
     
    5473954781</param> 
    5474054782</template> 
    54741 <template name="userdom_manage_user_home_content_symlinks" lineno="2283"> 
     54783<template name="userdom_manage_user_home_content_symlinks" lineno="2267"> 
    5474254784<summary> 
    5474354785Create, read, write, and delete symbolic links 
     
    5476654808</param> 
    5476754809</template> 
    54768 <template name="userdom_manage_user_home_content_pipes" lineno="2320"> 
     54810<template name="userdom_manage_user_home_content_pipes" lineno="2304"> 
    5476954811<summary> 
    5477054812Create, read, write, and delete named pipes 
     
    5479354835</param> 
    5479454836</template> 
    54795 <template name="userdom_manage_user_home_content_sockets" lineno="2357"> 
     54837<template name="userdom_manage_user_home_content_sockets" lineno="2341"> 
    5479654838<summary> 
    5479754839Create, read, write, and delete named sockets 
     
    5482054862</param> 
    5482154863</template> 
    54822 <template name="userdom_user_home_dir_filetrans" lineno="2407"> 
     54864<template name="userdom_user_home_dir_filetrans" lineno="2391"> 
    5482354865<summary> 
    5482454866Create objects in a user home directory 
     
    5486054902</param> 
    5486154903</template> 
    54862 <template name="userdom_user_home_content_filetrans" lineno="2456"> 
     54904<template name="userdom_user_home_content_filetrans" lineno="2440"> 
    5486354905<summary> 
    5486454906Create objects in a user home directory 
     
    5490054942</param> 
    5490154943</template> 
    54902 <template name="userdom_user_home_dir_filetrans_user_home_content" lineno="2500"> 
     54944<template name="userdom_user_home_dir_filetrans_user_home_content" lineno="2484"> 
    5490354945<summary> 
    5490454946Create objects in a user home directory 
     
    5493554977</param> 
    5493654978</template> 
    54937 <template name="userdom_write_user_tmp_sockets" lineno="2534"> 
     54979<template name="userdom_write_user_tmp_sockets" lineno="2518"> 
    5493854980<summary> 
    5493954981Write to user temporary named sockets. 
     
    5496055002</param> 
    5496155003</template> 
    54962 <template name="userdom_list_user_tmp" lineno="2568"> 
     55004<template name="userdom_list_user_tmp" lineno="2552"> 
    5496355005<summary> 
    5496455006List user temporary directories. 
     
    5498555027</param> 
    5498655028</template> 
    54987 <template name="userdom_dontaudit_list_user_tmp" lineno="2604"> 
     55029<template name="userdom_dontaudit_list_user_tmp" lineno="2588"> 
    5498855030<summary> 
    5498955031Do not audit attempts to list user 
     
    5501255054</param> 
    5501355055</template> 
    55014 <template name="userdom_dontaudit_manage_user_tmp_dirs" lineno="2639"> 
     55056<template name="userdom_dontaudit_manage_user_tmp_dirs" lineno="2623"> 
    5501555057<summary> 
    5501655058Do not audit attempts to manage users 
     
    5503955081</param> 
    5504055082</template> 
    55041 <template name="userdom_read_user_tmp_files" lineno="2672"> 
     55083<template name="userdom_read_user_tmp_files" lineno="2656"> 
    5504255084<summary> 
    5504355085Read user temporary files. 
     
    5506455106</param> 
    5506555107</template> 
    55066 <template name="userdom_dontaudit_read_user_tmp_files" lineno="2709"> 
     55108<template name="userdom_dontaudit_read_user_tmp_files" lineno="2693"> 
    5506755109<summary> 
    5506855110Do not audit attempts to read users 
     
    5509155133</param> 
    5509255134</template> 
    55093 <template name="userdom_dontaudit_append_user_tmp_files" lineno="2744"> 
     55135<template name="userdom_dontaudit_append_user_tmp_files" lineno="2728"> 
    5509455136<summary> 
    5509555137Do not audit attempts to append users 
     
    5511855160</param> 
    5511955161</template> 
    55120 <template name="userdom_rw_user_tmp_files" lineno="2777"> 
     55162<template name="userdom_rw_user_tmp_files" lineno="2761"> 
    5512155163<summary> 
    5512255164Read and write user temporary files. 
     
    5514355185</param> 
    5514455186</template> 
    55145 <template name="userdom_dontaudit_manage_user_tmp_files" lineno="2814"> 
     55187<template name="userdom_dontaudit_manage_user_tmp_files" lineno="2798"> 
    5514655188<summary> 
    5514755189Do not audit attempts to manage users 
     
    5517055212</param> 
    5517155213</template> 
    55172 <template name="userdom_read_user_tmp_symlinks" lineno="2849"> 
     55214<template name="userdom_read_user_tmp_symlinks" lineno="2833"> 
    5517355215<summary> 
    5517455216Read user 
     
    5519755239</param> 
    5519855240</template> 
    55199 <template name="userdom_manage_user_tmp_dirs" lineno="2886"> 
     55241<template name="userdom_manage_user_tmp_dirs" lineno="2870"> 
    5520055242<summary> 
    5520155243Create, read, write, and delete user 
     
    5522455266</param> 
    5522555267</template> 
    55226 <template name="userdom_manage_user_tmp_files" lineno="2922"> 
     55268<template name="userdom_manage_user_tmp_files" lineno="2906"> 
    5522755269<summary> 
    5522855270Create, read, write, and delete user 
     
    5525155293</param> 
    5525255294</template> 
    55253 <template name="userdom_manage_user_tmp_symlinks" lineno="2958"> 
     55295<template name="userdom_manage_user_tmp_symlinks" lineno="2942"> 
    5525455296<summary> 
    5525555297Create, read, write, and delete user 
     
    5527855320</param> 
    5527955321</template> 
    55280 <template name="userdom_manage_user_tmp_pipes" lineno="2994"> 
     55322<template name="userdom_manage_user_tmp_pipes" lineno="2978"> 
    5528155323<summary> 
    5528255324Create, read, write, and delete user 
     
    5530555347</param> 
    5530655348</template> 
    55307 <template name="userdom_manage_user_tmp_sockets" lineno="3030"> 
     55349<template name="userdom_manage_user_tmp_sockets" lineno="3014"> 
    5530855350<summary> 
    5530955351Create, read, write, and delete user 
     
    5533255374</param> 
    5533355375</template> 
    55334 <template name="userdom_user_tmp_filetrans" lineno="3079"> 
     55376<template name="userdom_user_tmp_filetrans" lineno="3063"> 
    5533555377<summary> 
    5533655378Create objects in a user temporary directory 
     
    5537255414</param> 
    5537355415</template> 
    55374 <template name="userdom_tmp_filetrans_user_tmp" lineno="3123"> 
     55416<template name="userdom_tmp_filetrans_user_tmp" lineno="3107"> 
    5537555417<summary> 
    5537655418Create objects in the temporary directory 
     
    5540755449</param> 
    5540855450</template> 
    55409 <template name="userdom_rw_user_tmpfs_files" lineno="3156"> 
     55451<template name="userdom_rw_user_tmpfs_files" lineno="3140"> 
    5541055452<summary> 
    5541155453Read user tmpfs files. 
     
    5543255474</param> 
    5543355475</template> 
    55434 <template name="userdom_list_user_untrusted_content" lineno="3192"> 
     55476<template name="userdom_list_user_untrusted_content" lineno="3176"> 
    5543555477<summary> 
    5543655478List users untrusted directories. 
     
    5545755499</param> 
    5545855500</template> 
    55459 <template name="userdom_dontaudit_list_user_untrusted_content" lineno="3227"> 
     55501<template name="userdom_dontaudit_list_user_untrusted_content" lineno="3211"> 
    5546055502<summary> 
    5546155503Do not audit attempts to list user 
     
    5548455526</param> 
    5548555527</template> 
    55486 <template name="userdom_read_user_untrusted_content_files" lineno="3260"> 
     55528<template name="userdom_read_user_untrusted_content_files" lineno="3244"> 
    5548755529<summary> 
    5548855530Read user untrusted files. 
     
    5550955551</param> 
    5551055552</template> 
    55511 <template name="userdom_manage_user_untrusted_content_files" lineno="3294"> 
     55553<template name="userdom_manage_user_untrusted_content_files" lineno="3278"> 
    5551255554<summary> 
    5551355555Manage user untrusted files. 
     
    5553455576</param> 
    5553555577</template> 
    55536 <template name="userdom_manage_user_untrusted_content_tmp_files" lineno="3327"> 
     55578<template name="userdom_manage_user_untrusted_content_tmp_files" lineno="3311"> 
    5553755579<summary> 
    5553855580Manage user untrusted tmp files. 
     
    5555955601</param> 
    5556055602</template> 
    55561 <template name="userdom_dontaudit_read_user_untrusted_content_files" lineno="3362"> 
     55603<template name="userdom_dontaudit_read_user_untrusted_content_files" lineno="3346"> 
    5556255604<summary> 
    5556355605Do not audit attempts to read users 
     
    5558655628</param> 
    5558755629</template> 
    55588 <template name="userdom_read_user_untrusted_content_symlinks" lineno="3395"> 
     55630<template name="userdom_read_user_untrusted_content_symlinks" lineno="3379"> 
    5558955631<summary> 
    5559055632Read user untrusted symbolic links. 
     
    5561155653</param> 
    5561255654</template> 
    55613 <template name="userdom_list_user_tmp_untrusted_content" lineno="3429"> 
     55655<template name="userdom_list_user_tmp_untrusted_content" lineno="3413"> 
    5561455656<summary> 
    5561555657List users temporary untrusted directories. 
     
    5563655678</param> 
    5563755679</template> 
    55638 <template name="userdom_dontaudit_list_user_tmp_untrusted_content" lineno="3464"> 
     55680<template name="userdom_dontaudit_list_user_tmp_untrusted_content" lineno="3448"> 
    5563955681<summary> 
    5564055682Do not audit attempts to list user 
     
    5566355705</param> 
    5566455706</template> 
    55665 <template name="userdom_read_user_tmp_untrusted_content_files" lineno="3497"> 
     55707<template name="userdom_read_user_tmp_untrusted_content_files" lineno="3481"> 
    5566655708<summary> 
    5566755709Read user temporary untrusted files. 
     
    5568855730</param> 
    5568955731</template> 
    55690 <template name="userdom_dontaudit_read_user_tmp_untrusted_content_files" lineno="3533"> 
     55732<template name="userdom_dontaudit_read_user_tmp_untrusted_content_files" lineno="3517"> 
    5569155733<summary> 
    5569255734Do not audit attempts to read users 
     
    5571555757</param> 
    5571655758</template> 
    55717 <template name="userdom_read_user_tmp_untrusted_content_symlinks" lineno="3566"> 
     55759<template name="userdom_read_user_tmp_untrusted_content_symlinks" lineno="3550"> 
    5571855760<summary> 
    5571955761Read user temporary untrusted symbolic links. 
     
    5574055782</param> 
    5574155783</template> 
    55742 <interface name="userdom_read_all_untrusted_content" lineno="3585"> 
     55784<interface name="userdom_read_all_untrusted_content" lineno="3569"> 
    5574355785<summary> 
    5574455786Read all user untrusted content files. 
     
    5575055792</param> 
    5575155793</interface> 
    55752 <interface name="userdom_read_all_tmp_untrusted_content" lineno="3605"> 
     55794<interface name="userdom_read_all_tmp_untrusted_content" lineno="3589"> 
    5575355795<summary> 
    5575455796Read all user temporary untrusted content files. 
     
    5576055802</param> 
    5576155803</interface> 
    55762 <template name="userdom_setattr_user_ttys" lineno="3640"> 
     55804<template name="userdom_setattr_user_ttys" lineno="3624"> 
    5576355805<summary> 
    5576455806Set the attributes of a user domain tty. 
     
    5578555827</param> 
    5578655828</template> 
    55787 <template name="userdom_use_user_ttys" lineno="3677"> 
     55829<template name="userdom_use_user_ttys" lineno="3661"> 
    5578855830<summary> 
    5578955831Read and write a user domain tty. 
     
    5581055852</param> 
    5581155853</template> 
    55812 <template name="userdom_use_user_terminals" lineno="3714"> 
     55854<template name="userdom_use_user_terminals" lineno="3698"> 
    5581355855<summary> 
    5581455856Read and write a user domain tty and pty. 
     
    5583555877</param> 
    5583655878</template> 
    55837 <template name="userdom_dontaudit_use_user_terminals" lineno="3756"> 
     55879<template name="userdom_dontaudit_use_user_terminals" lineno="3740"> 
    5583855880<summary> 
    5583955881Do not audit attempts to read and write 
     
    5586255904</param> 
    5586355905</template> 
    55864 <interface name="userdom_spec_domtrans_all_users" lineno="3777"> 
     55906<interface name="userdom_spec_domtrans_all_users" lineno="3761"> 
    5586555907<summary> 
    5586655908Execute a shell in all user domains.  This 
     
    5587455916</param> 
    5587555917</interface> 
    55876 <interface name="userdom_xsession_spec_domtrans_all_users" lineno="3800"> 
     55918<interface name="userdom_xsession_spec_domtrans_all_users" lineno="3784"> 
    5587755919<summary> 
    5587855920Execute an Xserver session in all unprivileged user domains.  This 
     
    5588655928</param> 
    5588755929</interface> 
    55888 <interface name="userdom_spec_domtrans_unpriv_users" lineno="3823"> 
     55930<interface name="userdom_spec_domtrans_unpriv_users" lineno="3807"> 
    5588955931<summary> 
    5589055932Execute a shell in all unprivileged user domains.  This 
     
    5589855940</param> 
    5589955941</interface> 
    55900 <interface name="userdom_xsession_spec_domtrans_unpriv_users" lineno="3846"> 
     55942<interface name="userdom_xsession_spec_domtrans_unpriv_users" lineno="3830"> 
    5590155943<summary> 
    5590255944Execute an Xserver session in all unprivileged user domains.  This 
     
    5591055952