Karl MacMillan 660bf7
<html>
Karl MacMillan 660bf7
<head>
Karl MacMillan 660bf7
<title>
Karl MacMillan 660bf7
 Security Enhanced Linux Reference Policy
Karl MacMillan 660bf7
 </title>
Karl MacMillan 660bf7
<style type="text/css" media="all">@import "style.css";</style>
Karl MacMillan 660bf7
</head>
Karl MacMillan 660bf7
<body>
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		admin
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		apps
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
		
Chris PeBenito e3a8e3
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		kernel
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			bootloader
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			corenetwork
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			devices
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			filesystem
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			kernel
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			selinux
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			storage
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			terminal
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		services
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		system
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	

Karl MacMillan 660bf7
	* Interface Index
Chris PeBenito e3a8e3
	

Chris PeBenito e3a8e3
	* Template Index
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
Karl MacMillan 660bf7

Layer: kernel

Karl MacMillan 660bf7

Module: selinux

Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Karl MacMillan 660bf7

Description:

Karl MacMillan 660bf7
Chris PeBenito 767266

Karl MacMillan 660bf7
Policy for kernel security interface, in particular, selinuxfs.
Chris PeBenito 767266

Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266

This module is required to be included in all policies.

Karl MacMillan 660bf7
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Karl MacMillan 660bf7

Interfaces:

Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_compute_access_vector(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allows caller to compute an access vector.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type allowed to compute an access vector.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_compute_create_context(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_compute_relabel_context(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type to
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_compute_user_contexts(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allows caller to compute possible contexts for a user.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type allowed to compute user contexts.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_get_enforce_mode(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allows the caller to get the mode of policy enforcement
Chris PeBenito e3a8e3
(enforcing or permissive mode).
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type to allow to get the enforcing mode.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_get_fs_mount(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Gets the caller the mountpoint of the selinuxfs filesystem.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type requesting the selinuxfs mountpoint.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_load_policy(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allow caller to load the policy into the kernel.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type that will load the policy.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_set_boolean(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			,
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			[
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		booltype
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			]
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allow caller to set the state of Booleans to
Chris PeBenito e3a8e3
enable or disable conditional portions of the policy.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type allowed to set the Boolean.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
booltype
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The type of Booleans the caller is allowed to set.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
yes
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_set_enforce_mode(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allow caller to set the mode of policy enforcement
Chris PeBenito e3a8e3
(enforcing or permissive mode).
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type to allow to set the enforcement mode.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
selinux_set_parameters(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allow caller to set selinux security parameters.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type to allow to set security parameters.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 767266
selinux_unconfined(
Chris PeBenito 767266
	
Chris PeBenito 767266
		
Chris PeBenito 767266
		
Chris PeBenito 767266
		
Chris PeBenito 767266
		domain
Chris PeBenito 767266
		
Chris PeBenito 767266
	
Chris PeBenito 767266
	)
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Description
Chris PeBenito 767266

Chris PeBenito 767266
Unconfined access to the SELinux security server.
Chris PeBenito 767266

Chris PeBenito 767266
Chris PeBenito 767266
Parameters
Chris PeBenito 767266
Chris PeBenito 767266
Parameter:Description:Optional:
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
domain
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Domain allowed access.
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
No
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Chris PeBenito 767266
Karl MacMillan 660bf7
selinux_validate_context(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Chris PeBenito e3a8e3
Allows caller to validate security contexts.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
The process type permitted to validate contexts.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito e3a8e3
Return
Chris PeBenito e3a8e3
Chris PeBenito e3a8e3
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
</body>
Karl MacMillan 660bf7
</html>