General system administration role
Execute a generic bin program in the sysadm domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow sysadm to execute a generic bin program in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().
Allow sysadm to execute a generic bin program in a specified domain.
This is a interface to support third party modules and its use is not allowed in upstream reference policy.
Parameter: | Description: |
---|---|
domain |
Domain to execute in. |
allow create dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Execute all entrypoint files in the sysadm domain. This is an explicit transition, requiring the caller to use setexeccon().
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allow sysadm to execute all entrypoint files in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().
Allow sysadm to execute all entrypoint files in a specified domain. This is an explicit transition, requiring the caller to use setexeccon().
This is a interface to support third party modules and its use is not allowed in upstream reference policy.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow exec /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow filetrans /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow getattr /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow read dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow manage all /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow manage dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow manage /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow map /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow read /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow relabel dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Change to the system administrator role.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
Change from the system administrator role.
Change from the system administrator role to the specified role.
This is an interface to support third party modules and its use is not allowed in upstream reference policy.
Parameter: | Description: |
---|---|
role |
Role allowed access. |
allow rw dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
allow rw /root files
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Read and write sysadm user unnamed pipes.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow search dirs /root
Parameter: | Description: |
---|---|
domain |
Domain to not audit. |
Execute a shell in the sysadm domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send a SIGCHLD signal to sysadm users.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
sysadm stub interface. No access allowed.
Parameter: | Description: |
---|---|
domain |
Domain allowed access |
Inherit and use sysadm file descriptors
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Watch the directory /root
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |