Layer: roles

Module: sysadm

Interfaces

Description:

General system administration role


Interfaces:

sysadm_bin_spec_domtrans( domain )
Summary

Execute a generic bin program in the sysadm domain.

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_bin_spec_domtrans_to( domain )
Summary

Allow sysadm to execute a generic bin program in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().

Description

Allow sysadm to execute a generic bin program in a specified domain.

This is a interface to support third party modules and its use is not allowed in upstream reference policy.

Parameters
Parameter:Description:
domain

Domain to execute in.

sysadm_create_dirs( domain )
Summary

allow create dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_entry_spec_domtrans( domain )
Summary

Execute all entrypoint files in the sysadm domain. This is an explicit transition, requiring the caller to use setexeccon().

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_entry_spec_domtrans_to( domain )
Summary

Allow sysadm to execute all entrypoint files in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().

Description

Allow sysadm to execute all entrypoint files in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().

This is a interface to support third party modules and its use is not allowed in upstream reference policy.

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_exec_files( domain )
Summary

allow exec /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_filetrans_files( domain )
Summary

allow filetrans /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_getattr_files( domain )
Summary

allow getattr /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_list_dirs( domain )
Summary

allow read dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_manage_all_files( domain )
Summary

allow manage all /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_manage_dirs( domain )
Summary

allow manage dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_manage_files( domain )
Summary

allow manage /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_map_files( domain )
Summary

allow map /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_read_files( domain )
Summary

allow read /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_relabel_all( domain )
Summary

allow relabel dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_role_change( role )
Summary

Change to the system administrator role.

Parameters
Parameter:Description:
role

Role allowed access.

sysadm_role_change_to( role )
Summary

Change from the system administrator role.

Description

Change from the system administrator role to the specified role.

This is an interface to support third party modules and its use is not allowed in upstream reference policy.

Parameters
Parameter:Description:
role

Role allowed access.

sysadm_rw_dirs( domain )
Summary

allow rw dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_rw_files( domain )
Summary

allow rw /root files

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_rw_pipes( domain )
Summary

Read and write sysadm user unnamed pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_search_dirs( domain )
Summary

allow search dirs /root

Parameters
Parameter:Description:
domain

Domain to not audit.

sysadm_shell_domtrans( domain )
Summary

Execute a shell in the sysadm domain.

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_sigchld( domain )
Summary

Send a SIGCHLD signal to sysadm users.

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_stub( domain )
Summary

sysadm stub interface. No access allowed.

Parameters
Parameter:Description:
domain

Domain allowed access

sysadm_use_fds( domain )
Summary

Inherit and use sysadm file descriptors

Parameters
Parameter:Description:
domain

Domain allowed access.

sysadm_watch_all( domain )
Summary

Watch the directory /root

Parameters
Parameter:Description:
domain

Domain allowed access.

Return