SELinux policy for systemd components
false
Allow systemd-socket-proxyd to bind any port instead of one labelled with systemd_socket_proxyd_port_t.
false
Allow systemd-socket-proxyd to connect to any port instead of labelled ones.
Allow process to create directory configured in a systemd unit as ReadWriteDirectory or ReadOnlyDirectory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to mount directory configured in a systemd unit as ReadWriteDirectory or ReadOnlyDirectory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Exchange messages with systemd resolved over dbus or varlink.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to modify the systemd configuration of all systemd services
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Configure generic unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Configure power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to modify the systemd configuration of all systemd services
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows connections to the systemd-socket-proxyd's socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd-coredump.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to list systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a directory in the /usr/lib/systemd/system directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a link in the /usr/lib/systemd/system directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd hostnamed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd localed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd logind over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd machined over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Exchange messages with systemd resolved over dbus (deprecated)
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd timedated over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete filesystem objects with systemd_delete_private_tmp attribute
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Execute a domain transition to run systemd-sysctl.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemctl in the specified domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
target_domain |
Domain to transition to. |
Dontaudit attempts to send dbus domains chat messages
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit domain to read all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit attempts to write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Execute systemd-notify in the caller domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow a domain to execute systemd-sysctl in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemctl in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content for /etc/hostname
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get attributes of generic systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr all systemd unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to delete hostname config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to manage hostname config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to read hostname config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send systemd_hostnamed a null signal.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to manage hwdb config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to mmap hwdb config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to read hwdb config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to list systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd-localed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to connect to systemd_logger with a unix socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to halt the system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to reboot the system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send systemd_login a null signal.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information from systemd_login
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to do an unknown access.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd_login PID directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd_login session directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the process state (/proc/pid) of systemd_logind_t.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-machined lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-machined lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write systemd-machined devpts character nodes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search systemd-machined lib directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to connect to systemd_machined with a unix socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd-machined PID directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd unit lnk_files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd homedir content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to systemd_passwd_agent processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd random seed file
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd unit dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd unit link files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage named sockets in userdbd runtime directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap to systemd-bootchart temporary file system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap to systemd-coredump temporary file system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap systemd_networkd_exec_t files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mmap systemd_resolved_exec_t files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mark the following type as mountable by systemd.
Parameter: | Description: |
---|---|
type |
Type to be authorized to be mounted |
Mounton inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to mount directory with inhibit pipes
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd_networkd PID directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd_notify.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Template for temporary sockets and files in /dev/.systemd/ask-password which are used by systemd-passwd-agent
Parameter: | Description: |
---|---|
userdomain_prefix |
The prefix of the domain (e.g., user is the prefix for user_t). |
Execute a domain transition to run systemd-tty-ask-password-agent.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemd-tty-ask-password-agent in the caller domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for systemd_passwd_agent
Parameter: | Description: |
---|---|
role |
Role allowed access |
domain |
User domain for the role |
Execute systemd-tty-ask-password-agent in the systemd_passwd_agent domain, and allow the specified role the systemd_passwd_agent domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
role |
The role to be allowed the systemd_passwd_agent domain. |
Watch systemd-passwd pid dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable as a systemd private tmp type.
Parameter: | Description: |
---|---|
domain |
Type to be used as a private tmp type. |
Make the specified type usable as a systemd read efivarfs type.
Parameter: | Description: |
---|---|
domain |
Type to be used as a read efivarfs type. |
Allow to domain to read systemd-passwd pipe
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
read systemd homedir content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read logind sessions files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to read all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel systemd unit directories
Parameter: | Description: |
---|---|
script_file |
Domain allowed access. |
Relabel systemd unit files
Parameter: | Description: |
---|---|
script_file |
Domain allowed access. |
Relabel systemd unit link files
Parameter: | Description: |
---|---|
script_file |
Domain allowed access. |
Relabel to user home directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create objects in /var/run/systemd/resolve with a private type using a type_transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
file_type |
Private file type. |
class |
Object classes to be created. |
name |
The name of the object being created. |
Read systemd_resolved PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch systemd_resolved PID directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write to systemd_resolved PID socket files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd_rfkill.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd rfkill dir
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton rfkill lib directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
read systemd rfkill dir
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-rfkill lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to systemd-bootchart temporary file system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to systemd-coredump temporary file system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to search systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to systemd_passwd_agent processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to start all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to start systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Status power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to status systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to stop systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a domain for processes which are started exuting systemctl.
Parameter: | Description: |
---|---|
domain_prefix |
Domain allowed access. |
Create a domain for processes which are started exuting systemctl.
Parameter: | Description: |
---|---|
domain_prefix |
Domain allowed access. |
Allow systemd_systemctl_exec_t to be an entrypoint of the specified domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd timesync dir
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mounton systemd timesync directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get timedated service status
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute a domain transition to run systemd-tmpfiles.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow a domain to execute systemd-tmpfiles in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow caller nnp_transition to systemd_tmpfiles_t
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemd-tmpfiles in the systemd_tmpfiles_t domain, and allow the specified role the systemd_tmpfiles domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
role |
The role to be allowed the systemd_tmpfiles domain. |
Create a file type used for systemd unit files.
Parameter: | Description: |
---|---|
script_file |
Type to be used for an unit file. |
Create objects in /run/systemd/generator directory with an automatic type transition to a specified private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private_type |
The type of the object to create. |
object_class |
The class of the object to be created. |
name |
The name of the object being created. |
Use and and inherited systemd logind file descriptors.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create objects in the pid directory with a private type with a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-userdbd data symlinks.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to systemd-userdbd with a unix socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write systemd inhibit pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Creates types and rules for a basic systemd domains.
Parameter: | Description: |
---|---|
prefix |
Prefix for the domain. |