Systemd components (not PID 1)
false
Allow systemd-logind to interact with the bootloader (read which one is installed on fixed disks, enumerate entries for dbus property BootLoaderEntries, etc.)
false
Allow systemd-nspawn to create a labelled namespace with the same types as parent environment
true
Enable support for systemd-tmpfiles to manage all non-security files.
Allow domain to be used as a systemd service with a unit that uses PrivateDevices=yes in section [Service].
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Create keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd hostnamed over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd logind over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send and receive messages from systemd resolved over dbus.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to enable systemd-networkd units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Transition to systemd_passwd_runtime_t when creating dirs
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to getattr on .updated file (generated by systemd-update-done
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to list dirs under /run/systemd/netif
Parameter: | Description: |
---|---|
domain |
domain permitted the access |
Allow domain to list systemd tmpfiles config directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable as an log parse environment type.
Parameter: | Description: |
---|---|
domain |
Type to be used as a log parse environment type. |
manage systemd unit dirs and the files in them
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to create/manage systemd_journal_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd_login PID pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to create/manage systemd_networkd_t unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow to domain to create systemd-passwd symlink
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage systemd_user_runtime.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to map udev hwdb file
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read udev hwdb file
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read systemd_journal_t files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read systemd_login PID files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read logind sessions files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow systemd_logind_t to read process state for cgroup file
Parameter: | Description: |
---|---|
domain |
Domain systemd_logind_t may access. |
Allow reading /run/systemd/machines
Parameter: | Description: |
---|---|
domain |
Domain that can access the machines files |
Allow domain to read files generated by systemd_networkd
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Allow domain to read systemd_networkd_t unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to read resolv.conf file generated by systemd_resolved
Parameter: | Description: |
---|---|
domain |
domain allowed access |
Relabel systemd_networkd tun socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to systemd-journald directory type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Relabel to systemd-journald file type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to relabel to systemd tmpfiles config directory
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to relabel to systemd tmpfiles config files
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read/Write from systemd_networkd netlink route socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Search keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send systemd_login a null signal.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to start power units
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Allow specified domain to start systemd-networkd units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information from systemd_login
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow specified domain to get status of systemd-networkd
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Get the system status information about power units
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for systemd tmpfiles config files.
Parameter: | Description: |
---|---|
type |
Type to be used for systemd tmpfiles config files. |
Create an object in the systemd tmpfiles config directory, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
name |
The name of the object being created. |
Allow the specified domain to create the tmpfiles config directory with the correct context.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow systemd_tmpfiles_t to manage filesystem objects
Parameter: | Description: |
---|---|
type |
type of object to manage |
class |
object class to manage |
Make the specified type usable as a systemd generator
Parameter: | Description: |
---|---|
domain |
Type to be used as a systemd generator type. |
entry_point |
Type of the program to be used as an entry point to the generator domain. |
Use inherited systemd logind file descriptors.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow domain to use systemd's Name Service Switch (NSS) module. This module provides UNIX user and group name resolution for dynamic users and groups allocated through the DynamicUser= option in systemd unit files
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Allow a systemd_passwd_agent_t process to interact with a daemon that needs a password from the sysadmin.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow systemd_passwd_agent to inherit fds
Parameter: | Description: |
---|---|
domain |
Domain that owns the fds |
Watch generic directories in logind_pids
Parameter: | Description: |
---|---|
domain |
Domain that can access the machines files |
Watch generic directories in logind_sessions_dirs
Parameter: | Description: |
---|---|
domain |
Domain that can access the machines files |
Watch generic directories in machines
Parameter: | Description: |
---|---|
domain |
Domain that can access the machines files |
Watch directories under /run/systemd/netif
Parameter: | Description: |
---|---|
domain |
Domain permitted the access |
Write keys for the all systemd --user domains.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind inhibit pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write inherited logind sessions pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow process to write to systemd_kmod_conf_t.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write systemd_login named pipe.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Template for systemd --user per-role domains.
Parameter: | Description: |
---|---|
prefix |
Prefix for generated types |
role |
The user role. |
userdomain |
The user domain for the role. |