X Windows Server
false
Allow regular users direct dri device access
false
Allows xdm_t to bind on vnc_port_t(5910)
false
Allow the graphical login program to execute bootloader
false
Allow the graphical login program to login directly as sysadm_r:sysadm_t
false
Allow the graphical login program to create files in HOME dirs as xdm_home_t.
false
Allows clients to write to the X server shared memory segments.
false
Allows XServer to execute writable memory
false
Support X userspace object manager
Create a Xauthority file in the admin home directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
append to .xsession-errors file
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Allow domain to append XDM unix domain stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow append the xdm tmp files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Create a named socket in a XDM temporary directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from xdm over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from xdm over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Delete X server log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute the X server in the X server domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Transition to the Xauthority domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Dontaudit append to .xsession-errors file
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Dontaudit exec of Xauthority program.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to get the attributes of xdm temporary named sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit Read XDM pid files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read xdm temporary files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write X server unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write to X server sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write XDM unnamed pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit search ssh home directory
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit attempts to connect to xserver over a unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to inherit XDM file descriptors.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to write the X server log files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Do not audit attempts to read and write xdm unix domain stream sockets.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dont audit attempts to set the attributes of XDM temporary directories.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
dontaudit access checks X keyboard extension libraries.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Domain wants to use direct io devices
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make an X executable an entrypoint for the specified domain.
Parameter: | Description: |
---|---|
domain |
The domain for which the shell is an entrypoint. |
Allow execute the X server.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute xserver files created in /var/run
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow exec of Xauthority program..
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Create xserver content in admin home directory with a named file transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to xserver .fontconfig named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to xserver named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the attributes of X server logs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Kill X servers
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage xserver configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Interface to provide X object permissions on a given X server to an X client domain. Gives the domain permission to read the virtual core keyboard and virtual core pointer devices.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage user homedir fonts.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage user fonts dir.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage all users .Xauthority.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage xdm config files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Create, read, write, and delete xdm_spool files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete xdm temporary dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete xdm temporary files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage X keyboard extension libraries.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create non-drawing client sessions on an X server.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xserver configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read user homedir fonts.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read inherited XDM var lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to read X server logs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xserver files created in /var/run
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read XDM state files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read X server temporary files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read a user Iceauthority domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all users .Xauthority.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xdm config files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Read XDM files in user home directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read XDM var lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read XDM pid files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xdm-writable configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xdm process state files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read xdm temporary files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read X keyboard extension libraries.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete xdm temporary dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Rules required for using the X Windows server and environment, for restricted users.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
Domain allowed access. |
Create sessions on the X server, with read-only access to the X server shared memory segments.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
tmpfs_type |
The type of the domain SYSV tmpfs files. |
Rules required for using the X Windows server and environment.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
domain |
Domain allowed access. |
Execute xsever in the xserver domain, and allow the specified role the xserver domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to be allowed the xserver domain. |
Execute xsever in the xserver domain, and allow the specified role the xserver domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to be allowed the xserver domain. |
Read and write the X windows console named pipe.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read/write inherited user homedir fonts.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create sessions on the X server, with read and write access to the X server shared memory segments.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
tmpfs_type |
The type of the domain SYSV tmpfs files. |
Read and write X server Sys V Shared memory segments.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage keys for xdm.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write XDM unnamed pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read write xdm temporary files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search XDM var lib dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search XDM temporary directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the attributes of the X windows console named pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set the attributes of XDM temporary directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Signal X servers
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to the X server over a unix domain stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to XDM over a unix domain stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Interface to provide X object permissions on a given X server to an X client domain. Gives the domain complete control over the display.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all users fonts, user font configurations, and manage all users font caches.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read user fonts, user font configuration, and manage the user font cache.
Read user fonts, user font configuration, and manage the user font cache.
This is a templated interface, and should only be called from a per-userdomain template.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Use file descriptors for xdm.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create full client sessions on a user X server.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
tmpfs_type |
The type of the domain SYSV tmpfs files. |
Create a Xauthority file in the user home directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write xserver files created in /var/run
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow append the xdm log files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Allow ioctl the xdm log files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit |
Manage the xdm_spool files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow read the xdm_spool files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow search the xdm_spool files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create objects in a xdm temporary directory with an automatic type transition to a specified private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private_type |
The type of the object to create. |
object_class |
The class of the object to be created. |
name |
The name of the object being created. |
Make an X session script an entrypoint for the specified domain.
Parameter: | Description: |
---|---|
domain |
The domain for which the shell is an entrypoint. |
Execute an X session in the target domain. This is an explicit transition, requiring the caller to use setexeccon().
Execute an Xsession in the target domain. This is an explicit transition, requiring the caller to use setexeccon().
No interprocess communication (signals, pipes, etc.) is provided by this interface since the domains are not owned by this module.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
target_domain |
The type of the shell process. |
Interface to provide X object permissions on a given X server to an X client domain. Provides the minimal set required by a basic X client application.
Parameter: | Description: |
---|---|
prefix |
The prefix of the X client domain (e.g., user is the prefix for user_t). |
domain |
Client domain allowed access. |
Template for creating the set of types used in an X windows domain.
Parameter: | Description: |
---|---|
prefix |
The prefix of the X client domain (e.g., user is the prefix for user_t). |
Interface to provide X object permissions on a given X server to an X client domain. Provides the minimal set required by a basic X client application.
Parameter: | Description: |
---|---|
prefix |
The prefix of the X client domain (e.g., user is the prefix for user_t). |
domain |
Client domain allowed access. |
tmpfs_type |
The type of the domain SYSV tmpfs files. |