Policy for terminals.
This module is required to be included in all policies.
Append to unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create the console device (/dev/console).
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create the tty device.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create directory /dev/pts.
| Parameter: | Description: |
|---|---|
| domain |
The type of the process creating the directory. |
Create the pty multiplexor (/dev/ptmx).
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Create a pty in the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
The type of the process creating the pty. |
| pty_type |
The type of the pty. |
Do not audit attempts to get the attributes of any pty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to get the attributes of any tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to get the attributes of generic pty devices.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to get attributes on the pty multiplexor (/dev/ptmx).
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to get the attributes of the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to get the attributes of all unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to ioctl unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to create, read, write, or delete the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read from the console.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to search the contents of the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Dontaudit setting the attributes of generic pty devices.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to set the attributes of unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read or write any ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read or write any ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read from or write to the console.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Dot not audit attempts to read and write the generic pty type. This is generally only used in the targeted policy.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read and write the pty multiplexor (/dev/ptmx).
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to read or write unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Get the attributes of all pty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Get the attributes of all tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Get the attributes of generic pty devices.
| Parameter: | Description: |
|---|---|
| domain |
Domain to allow |
Get the attributes of the pty multiplexor (/dev/ptmx).
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Get the attributes of the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Get the attributes of a pty filesystem
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Get the attributes of all unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
ioctl of generic pty devices.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the /dev/pts directory to list all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Transform specified type into a pty type used by login programs, such as sshd.
| Parameter: | Description: |
|---|---|
| pty_type |
An object type that will applied to a pty. |
mount a devpts_t filesystem
| Parameter: | Description: |
|---|---|
| domain |
The type of the process to mount it |
Transform specified type into a pty type.
| Parameter: | Description: |
|---|---|
| pty_type |
An object type that will applied to a pty. |
Read from the console.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to all pty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to all tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to the console type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to pty directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to pty filesystem.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from and to the unallocated tty type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel to all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Relabel from all user tty types to the unallocated tty type.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search the contents of the /dev/pts directory.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Set the attributes of all pty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Set the attributes of all tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Set the attributes of the console device node.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Set the attributes of the tty device
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow setting the attributes of generic pty devices.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Set the attributes of all unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Setattr and unlink unallocated tty device nodes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Transform specified type into a tty type.
| Parameter: | Description: |
|---|---|
| tty_type |
An object type that will applied to a tty. |
Read and write all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write the console, all ttys and all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write all ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read from and write to the console.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write the controlling terminal (/dev/tty).
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write the generic pty type. This is generally only used in the targeted policy.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write the pty multiplexor (/dev/ptmx).
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read from and write virtio console.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Transform specified type into an user pty type. This allows it to be relabeled via type change by login programs such as ssh.
| Parameter: | Description: |
|---|---|
| userdomain |
The type of the user domain associated with this pty. |
| object_type |
An object type that will applied to a pty. |
Transform specified type into a user tty type.
| Parameter: | Description: |
|---|---|
| domain |
User domain that is related to this tty. |
| tty_type |
An object type that will applied to a tty. |
watch reads on console device
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Watch reads on unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Watch unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write to all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write the console, all ttys and all ptys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write to all ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write to the console.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Write to unallocated ttys.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |