policy for nsplugin
false
Allow nsplugin code to execmem/execstack
true
Allow nsplugin code to connect to unreserved ports
The per role template for the nsplugin module.
Parameter: | Description: |
---|---|
user_domain |
The type of the user domain. |
The per role template for the nsplugin module.
Parameter: | Description: |
---|---|
user_domain |
The type of the user domain. |
Execute nsplugin_exec_t in the specified domain.
Execute a nsplugin_exec_t in the specified domain.
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
target_domain |
The type of the new process. |
Create, read, write, and delete nsplugin home files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage nsplugin rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete nsplugin rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read nsplugin home files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read nsplugin rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for nsplugin
Parameter: | Description: |
---|---|
userdomain_prefix |
The prefix of the user domain (e.g., user is the prefix for user_t). |
user_role |
The role associated with the user domain. |
user_domain |
The type of the user domain. |
The per role template for the nsplugin module.
This template creates a derived domains which are used for nsplugin web browser.
This template is invoked automatically for each user, and generally does not need to be invoked directly by policy writers.
Parameter: | Description: |
---|---|
userdomain_prefix |
The prefix of the user domain (e.g., user is the prefix for user_t). |
user_domain |
The type of the user domain. |
user_role |
The role associated with the user domain. |
Exec nsplugin rw files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow attempts to read and write to nsplugin named pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow read and write access to nsplugin semaphores.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to nsplugin shared memory.
Parameter: | Description: |
---|---|
domain |
The type of the process performing this action. |
Search nsplugin rw directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |