|
Karl MacMillan |
660bf7 |
<html>
|
|
Karl MacMillan |
660bf7 |
<head>
|
|
Karl MacMillan |
660bf7 |
<title>
|
|
Karl MacMillan |
660bf7 |
Security Enhanced Linux Reference Policy
|
|
Karl MacMillan |
660bf7 |
</title>
|
|
Karl MacMillan |
660bf7 |
<style type="text/css" media="all">@import "style.css";</style>
|
|
Karl MacMillan |
660bf7 |
</head>
|
|
Karl MacMillan |
660bf7 |
<body>
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
+
|
|
Karl MacMillan |
660bf7 |
admin
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
+
|
|
Chris PeBenito |
e3a8e3 |
apps
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Karl MacMillan |
660bf7 |
+
|
|
Karl MacMillan |
660bf7 |
kernel
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
885e75 |
-
|
|
Chris PeBenito |
885e75 |
corecommands
|
|
Chris PeBenito |
885e75 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
corenetwork
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
devices
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
885e75 |
-
|
|
Chris PeBenito |
885e75 |
domain
|
|
Chris PeBenito |
885e75 |
|
|
Chris PeBenito |
885e75 |
-
|
|
Chris PeBenito |
885e75 |
files
|
|
Chris PeBenito |
885e75 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
filesystem
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
kernel
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
-
|
|
Chris PeBenito |
af3dd8 |
mcs
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
862a1e |
-
|
|
Chris PeBenito |
862a1e |
mls
|
|
Chris PeBenito |
862a1e |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
selinux
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
storage
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
-
|
|
Karl MacMillan |
660bf7 |
terminal
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
+
|
|
Karl MacMillan |
660bf7 |
services
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
+
|
|
Karl MacMillan |
660bf7 |
system
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
8b1125 |
* Global Booleans
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
8b1125 |
* Global Tunables
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
* Layer Index
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
* Interface Index
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
* Template Index
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Karl MacMillan |
660bf7 |
Layer: kernel
|
|
Karl MacMillan |
660bf7 |
Module: storage
|
|
Chris PeBenito |
e3a8e3 |
|
|
Karl MacMillan |
660bf7 |
Description:
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
767266 |
Policy controlling access to storage devices
|
|
Chris PeBenito |
767266 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Karl MacMillan |
660bf7 |
Interfaces:
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_dev_filetrans_fixed_disk(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Create block devices in /dev with the fixed disk type
|
|
Chris PeBenito |
af3dd8 |
via an automatic type transition.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_getattr_fixed_disk_dev(
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
domain
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
)
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
Summary
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts made by the caller to get
|
|
Chris PeBenito |
af3dd8 |
the attributes of fixed disk device nodes.
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
Parameters
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
domain
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
No
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_getattr_removable_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Do not audit attempts made by the caller to get
|
|
Chris PeBenito |
af3dd8 |
the attributes of removable devices device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_raw_read_removable_device(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts to directly read removable devices.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Domain to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
No
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_raw_write_removable_device(
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
domain
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
)
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Summary
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts to directly write removable devices.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Parameters
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
domain
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Domain to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
storage_dontaudit_read_fixed_disk(
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
domain
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
)
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Summary
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Do not audit attempts made by the caller to read
|
|
Chris PeBenito |
44a4c2 |
fixed disk device nodes.
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Parameters
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
domain
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
44a4c2 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
No
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
storage_dontaudit_read_removable_device(
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
domain
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
)
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Summary
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Do not audit attempts made by the caller to read
|
|
Chris PeBenito |
44a4c2 |
removable devices device nodes.
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Parameters
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
domain
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
44a4c2 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
No
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
44a4c2 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_rw_scsi_generic(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts to read or write
|
|
Chris PeBenito |
af3dd8 |
SCSI generic device interfaces.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Domain to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_setattr_fixed_disk_dev(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Do not audit attempts made by the caller to set
|
|
Chris PeBenito |
af3dd8 |
the attributes of fixed disk device nodes.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_setattr_removable_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts made by the caller to set
|
|
Chris PeBenito |
af3dd8 |
the attributes of removable devices device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
The type of the process to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_dontaudit_write_fixed_disk(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Do not audit attempts made by the caller to write
|
|
Chris PeBenito |
af3dd8 |
fixed disk device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Domain to not audit.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_getattr_fixed_disk_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to get the attributes of fixed disk
|
|
Chris PeBenito |
af3dd8 |
device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_getattr_removable_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to get the attributes of removable
|
|
Chris PeBenito |
af3dd8 |
devices device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
storage_getattr_scsi_generic_dev(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to get the attributes of
|
|
Chris PeBenito |
af3dd8 |
the generic SCSI interface device nodes.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_getattr_tape_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to get the attributes
|
|
Chris PeBenito |
af3dd8 |
of device nodes of tape devices.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_manage_fixed_disk(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Create, read, write, and delete fixed disk device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_raw_read_fixed_disk(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to directly read from a fixed disk.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_raw_read_removable_device(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to directly read from
|
|
Chris PeBenito |
af3dd8 |
a removable device.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_raw_write_fixed_disk(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to directly write to a fixed disk.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
8b1125 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
storage_raw_write_removable_device(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to directly write to
|
|
Chris PeBenito |
e3a8e3 |
a removable device.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
8b1125 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
storage_read_scsi_generic(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to directly read, in a
|
|
Chris PeBenito |
e3a8e3 |
generic fashion, from any SCSI device.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_read_tape(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to directly read
|
|
Chris PeBenito |
e3a8e3 |
a tape device.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
storage_relabel_fixed_disk(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Relabel fixed disk device nodes.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
storage_setattr_fixed_disk_dev(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to set the attributes of fixed disk
|
|
Chris PeBenito |
af3dd8 |
device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_setattr_removable_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to set the attributes of removable
|
|
Chris PeBenito |
af3dd8 |
devices device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_setattr_scsi_generic_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Allow the caller to set the attributes of
|
|
Chris PeBenito |
af3dd8 |
the generic SCSI interface device nodes.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_setattr_scsi_generic_dev_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
Set attributes of the device nodes
|
|
Chris PeBenito |
af3dd8 |
for the SCSI generic inerface.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_setattr_tape_dev(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to set the attributes
|
|
Chris PeBenito |
e3a8e3 |
of device nodes of tape devices.
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
e3a8e3 |
Parameters
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
No
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
storage_swapon_fixed_disk(
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
domain
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
)
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Summary
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
Enable a fixed disk device as swap space
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
No
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
storage_tmpfs_filetrans_fixed_disk(
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
domain
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
)
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Summary
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Create block devices in on a tmpfs filesystem with the
|
|
Chris PeBenito |
af3dd8 |
fixed disk type via an automatic type transition.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Parameters
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
domain
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
af3dd8 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
8b1125 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
767266 |
storage_unconfined(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
Unconfined access to storage devices.
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
Parameters
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
Parameter:Description:Optional:
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
domain
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
767266 |
Domain allowed access.
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
No
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
8b1125 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
storage_write_scsi_generic(
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
domain
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
)
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to directly write, in a
|
|
Chris PeBenito |
e3a8e3 |
generic fashion, from any SCSI device.
|
|
Chris PeBenito |
e3a8e3 |
This is extremly dangerous as it can bypass the
|
|
Chris PeBenito |
e3a8e3 |
SELinux protections for filesystem objects, and
|
|
Chris PeBenito |
e3a8e3 |
should only be used by trusted domains.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
storage_write_tape(
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
)
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
Summary
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Allow the caller to directly read
|
|
Chris PeBenito |
e3a8e3 |
a tape device.
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
45d25f |
|
|
Chris PeBenito |
767266 |
|
|
Chris PeBenito |
45d25f |
Parameters
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
Parameter:Description:Optional:
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
domain
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
af3dd8 |
|
|
Chris PeBenito |
e3a8e3 |
The type of the process performing this action.
|
|
Chris PeBenito |
af3dd8 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
No
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e3a8e3 |
Return
|
|
Chris PeBenito |
e3a8e3 |
|
|
Chris PeBenito |
e3a8e3 |
|
|
Karl MacMillan |
660bf7 |
|
|
Chris PeBenito |
e376ad |
|
|
Karl MacMillan |
660bf7 |
|
|
Karl MacMillan |
660bf7 |
</body>
|
|
Karl MacMillan |
660bf7 |
</html>
|