Multicategory security policy
This module is required to be included in all policies.
This domain is allowed to read files and directories regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to write files and directories regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to sigkill and sigstop all domains regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
Make specified domain MCS trusted for setting any category set for the processes it executes.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
Make specified domain MCS trusted for setting the low level of its range for the processes it executes, IE MCS will not be mandatory for it.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
This domain is allowed to ptrace all domains regardless of their MCS category set.
Parameter: | Description: |
---|---|
domain |
Domain target for user exemption. |
Make specified object MCS trusted.
Make specified object MCS trusted. This allows all levels to read and write the object.
This currently only applies to filesystem objects, for example, files and directories.
Parameter: | Description: |
---|---|
domain |
The type of the object. |