Karl MacMillan 660bf7
<html>
Karl MacMillan 660bf7
<head>
Karl MacMillan 660bf7
<title>
Karl MacMillan 660bf7
 Security Enhanced Linux Reference Policy
Karl MacMillan 660bf7
 </title>
Karl MacMillan 660bf7
<style type="text/css" media="all">@import "style.css";</style>
Karl MacMillan 660bf7
</head>
Karl MacMillan 660bf7
<body>
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		admin
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		kernel
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			bootloader
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			corenetwork
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			devices
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			filesystem
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			kernel
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			selinux
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			storage
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
			   - 
Karl MacMillan 660bf7
			terminal
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		services
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		system
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	

Karl MacMillan 660bf7
	* Interface Index
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7

Layer: kernel

Karl MacMillan 660bf7

Module: storage

Karl MacMillan 660bf7

Description:

Karl MacMillan 660bf7
Karl MacMillan 660bf7

Policy controlling access to storage devices

Karl MacMillan 660bf7
Karl MacMillan 660bf7

Interfaces:

Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_create_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Create block devices in /dev with the fixed disk type.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_dontaudit_getattr_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Do not audit attempts made by the caller to get
Karl MacMillan 660bf7
	the attributes of fixed disk device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process to not audit.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_dontaudit_getattr_removable_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Do not audit attempts made by the caller to get
Karl MacMillan 660bf7
	the attributes of removable devices device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process to not audit.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_getattr_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to get the attributes of fixed disk
Karl MacMillan 660bf7
	device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_getattr_removable_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to get the attributes of removable
Karl MacMillan 660bf7
	devices device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_getattr_scsi_generic(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Get attributes of the device nodes
Karl MacMillan 660bf7
	for the SCSI generic inerface.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_getattr_tape_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to get the attributes
Karl MacMillan 660bf7
	of device nodes of tape devices.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_manage_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Create, read, write, and delete fixed disk device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_read_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read from a fixed disk.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_read_lvm_volume(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read from a logical volume.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_read_removable_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read from
Karl MacMillan 660bf7
	a removable device.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_write_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly write to a fixed disk.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_write_lvm_volume(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read from a logical volume.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_raw_write_removable_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly write to
Karl MacMillan 660bf7
	a removable device.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_read_scsi_generic(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read, in a
Karl MacMillan 660bf7
	generic fashion, from any SCSI device.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_read_tape_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read
Karl MacMillan 660bf7
	a tape device.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_setattr_fixed_disk(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to set the attributes of fixed disk
Karl MacMillan 660bf7
	device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_setattr_removable_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to set the attributes of removable
Karl MacMillan 660bf7
	devices device nodes.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_setattr_scsi_generic(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Set attributes of the device nodes
Karl MacMillan 660bf7
	for the SCSI generic inerface.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_setattr_tape_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to set the attributes
Karl MacMillan 660bf7
	of device nodes of tape devices.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_write_scsi_generic(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly write, in a
Karl MacMillan 660bf7
	generic fashion, from any SCSI device.
Karl MacMillan 660bf7
	This is extremly dangerous as it can bypass the
Karl MacMillan 660bf7
	SELinux protections for filesystem objects, and
Karl MacMillan 660bf7
	should only be used by trusted domains.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
storage_write_tape_device(
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
		domain
Karl MacMillan 660bf7
		
Karl MacMillan 660bf7
	
Karl MacMillan 660bf7
	)
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Chris PeBenito 45d25f
Description
Karl MacMillan 660bf7

Karl MacMillan 660bf7
	Allow the caller to directly read
Karl MacMillan 660bf7
	a tape device.
Chris PeBenito 45d25f

Chris PeBenito 45d25f
Chris PeBenito 45d25f
Parameters
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Parameter:Description:Optional:
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
domain
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
	The type of the process performing this action.
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
No
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
Karl MacMillan 660bf7
</body>
Karl MacMillan 660bf7
</html>