SELinux policy for systemd components
Allow process to mount directory configured in a systemd unit as ReadWriteDirectory or ReadOnlyDirectory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to modify the systemd configuration of all systemd services
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Configure generic unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Configure power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to modify the systemd configuration of all systemd services
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd-coredump.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to list systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a directory in the /usr/lib/systemd/system directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a link in the /usr/lib/systemd/system directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd hostnamed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd localed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd logind over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd machined over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd timedated over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd-sysctl.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Dontaudit attempts to send dbus domains chat messages
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit domain to read all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Dontaudit attempts to write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow a domain to execute systemd-sysctl in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemctl in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd named content for /etc/hostname
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr all systemd unit directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to manage hostname config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to read hostname config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to manage hwdb config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to read hwdb config file.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to list systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run systemd-localed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to connect to systemd_logger with a unix socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to halt the system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to reboot the system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send systemd_login a null signal.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information from systemd_login
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Tell systemd_login to do an unknown access.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-machined lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-machined lib files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd-machined PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search systemd-machined lib directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd unit lnk_files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd homedir content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to systemd_passwd_agent processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage all systemd random seed file
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd unit dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
manage systemd unit link files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Mark the following type as mountable by systemd.
Parameter: | Description: |
---|---|
type |
Type to be authorized to be mounted |
Execute a domain transition to run systemd_notify.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Template for temporary sockets and files in /dev/.systemd/ask-password which are used by systemd-passwd-agent
Parameter: | Description: |
---|---|
userdomain_prefix |
The prefix of the domain (e.g., user is the prefix for user_t). |
Execute a domain transition to run systemd-tty-ask-password-agent.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemd-tty-ask-password-agent in the caller domain
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Role access for systemd_passwd_agent
Parameter: | Description: |
---|---|
role |
Role allowed access |
domain |
User domain for the role |
Execute systemd-tty-ask-password-agent in the systemd_passwd_agent domain, and allow the specified role the systemd_passwd_agent domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
role |
The role to be allowed the systemd_passwd_agent domain. |
Allow to domain to read systemd-passwd pipe
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
read systemd homedir content
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read logind sessions files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to read all systemd unit files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel systemd unit directories
Parameter: | Description: |
---|---|
script_file |
Domain allowed access. |
Relabel systemd unit files
Parameter: | Description: |
---|---|
script_file |
Domain allowed access. |
Relabel to user home directories.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to reload all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write to systemd-coredump temporary file system.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to search systemd unit dirs.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send generic signals to systemd_passwd_agent processes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow the specified domain to start all systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Allow the specified domain to start systemd services.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Start power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Status power unit files domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Create a domain for processes which are started exuting systemctl.
Parameter: | Description: |
---|---|
domain_prefix |
Domain allowed access. |
Create a domain for processes which are started exuting systemctl.
Parameter: | Description: |
---|---|
domain_prefix |
Domain allowed access. |
Execute a domain transition to run systemd-tmpfiles.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute systemd-tmpfiles in the systemd_tmpfiles_t domain, and allow the specified role the systemd_tmpfiles domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
role |
The role to be allowed the systemd_tmpfiles domain. |
Create a file type used for systemd unit files.
Parameter: | Description: |
---|---|
script_file |
Type to be used for an unit file. |
Create objects in /run/systemd/generator directory with an automatic type transition to a specified private type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private_type |
The type of the object to create. |
object_class |
The class of the object to be created. |
name |
The name of the object being created. |
Use and and inherited systemd logind file descriptors.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write systemd inhibit pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Creates types and rules for a basic systemd domains.
Parameter: | Description: |
---|---|
prefix |
Prefix for the domain. |