Layer: system

Module: systemd

Tunables Interfaces

Description:

Systemd components (not PID 1)


Tunables:

systemd_tmpfiles_manage_all
Default value

false

Description

Enable support for systemd-tmpfiles to manage all non-security files.

Return

Interfaces:

manage_systemd_journal_files( domain )
Summary

Allow domain to create/manage systemd_journal_log_t files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_dbus_chat_logind( domain )
Summary

Send and receive messages from systemd logind over dbus.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_dontaudit_read_unit_files( domain )
Summary

Dontaudit domain to read all systemd unit files.

Parameters
Parameter:Description:
domain

Domain to not audit.

systemd_filetrans_named_content( domain )
Summary

Transition to systemd named content

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_getattr_unit_files( domain )
Summary

Allow domain to getattr all systemd unit files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_list_unit_dirs( domain )
Summary

Allow domain to list systemd unit dirs.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_log_parse_environment( domain )
Summary

Make the specified type usable as an log parse environment type.

Parameters
Parameter:Description:
domain

Type to be used as a log parse environment type.

systemd_login_halt( domain )
Summary

Tell systemd_login to halt the system.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_login_list_pid_dirs( domain )
Summary

Read systemd_login PID files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_login_reboot( domain )
Summary

Tell systemd_login to reboot the system.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_login_status( domain )
Summary

Get the system status information from systemd_login

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_login_undefined( domain )
Summary

Tell systemd_login to do an unknown access.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_login_write_pid_pipe( domain )
Summary

Write systemd_login named pipe.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_logind_read_process_state( domain )
Summary

Allow systemd_logind_t to read process state for cgroup file

Parameters
Parameter:Description:
domain

Domain systemd_logind_t may access.

systemd_manage_all_unit_files( domain )
Summary

manage all systemd unit files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_all_unit_lnk_files( domain )
Summary

manage all systemd unit lnk_files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_lnk_file_passwd_run( domain )
Summary

Allow to domain to create systemd-passwd symlink

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_logind_pid_pipes( domain )
Summary

Manage systemd_login PID pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_passwd_run( domain )
Summary

Send generic signals to systemd_passwd_agent processes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_unit_dirs( domain )
Summary

manage systemd unit dirs

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_notify_domtrans( domain )
Summary

Execute a domain transition to run systemd_notify.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_passwd_agent_dev_template( userdomain_prefix )
Summary

Template for temporary sockets and files in /dev/.systemd/ask-password which are used by systemd-passwd-agent

Parameters
Parameter:Description:
userdomain_prefix

The prefix of the domain (e.g., user is the prefix for user_t).

systemd_passwd_agent_domtrans( domain )
Summary

Execute a domain transition to run systemd-tty-ask-password-agent.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_passwd_agent_exec( domain )
Summary

Execute systemd-tty-ask-password-agent in the caller domain

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_passwd_agent_inherits_fd( domain )
Summary

allow systemd_passwd_agent to inherit fds

Parameters
Parameter:Description:
domain

Domain that owns the fds

systemd_passwd_agent_role( role , domain )
Summary

Role access for systemd_passwd_agent

Parameters
Parameter:Description:
role

Role allowed access

domain

User domain for the role

systemd_passwd_agent_run( domain , role )
Summary

Execute systemd-tty-ask-password-agent in the systemd_passwd_agent domain, and allow the specified role the systemd_passwd_agent domain.

Parameters
Parameter:Description:
domain

Domain allowed access

role

The role to be allowed the systemd_passwd_agent domain.

systemd_read_fifo_file_passwd_run( domain )
Summary

Allow to domain to read systemd-passwd pipe

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_pids( domain )
Summary

Read systemd_login PID files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_sessions_files( domain )
Summary

Read logind sessions files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_machines( domain )
Summary

Allow reading /run/systemd/machines

Parameters
Parameter:Description:
domain

Domain that can access the machines files

systemd_read_unit_files( domain )
Summary

Allow domain to read all systemd unit files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_relabelto_kmod_files( domain )
Summary

Allow process to relabel to systemd_kmod_conf_t.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_search_unit_dirs( domain )
Summary

Allow domain to search systemd unit dirs.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_signal_passwd_agent( domain )
Summary

Send generic signals to systemd_passwd_agent processes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_signull_logind( domain )
Summary

Send systemd_login a null signal.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_start_power_units( domain )
Summary

Allow specified domain to start power units

Parameters
Parameter:Description:
domain

Domain to not audit.

systemd_status_logind( domain )
Summary

Get the system status information from systemd_login

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_tmpfiles_domtrans( domain )
Summary

Execute a domain transition to run systemd-tmpfiles.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_tmpfiles_manage_object( type , class )
Summary

Allow systemd_tmpfiles_t to manage filesystem objects

Parameters
Parameter:Description:
type

type of object to manage

class

object class to manage

systemd_use_logind_fds( domain )
Summary

Use inherited systemd logind file descriptors.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_inherited_logind_sessions_pipes( domain )
Summary

Write inherited logind sessions pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_kmod_files( domain )
Summary

Allow process to write to systemd_kmod_conf_t.

Parameters
Parameter:Description:
domain

Domain allowed access.

Return