2 # This file is for the declaration of global tunables.
3 # To change the default value at build time, the booleans.conf
9 ## Allow sysadm to debug or ptrace all processes.
12 gen_tunable(deny_ptrace, false)
16 ## Allow unconfined executables to make their heap memory executable. Doing this is a really bad idea. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzilla
19 gen_tunable(allow_execheap,false)
23 ## Allow unconfined executables to map a memory region as both executable and writable, this is dangerous and the executable should be reported in bugzilla
26 gen_tunable(allow_execmem,false)
30 ## Allow all unconfined executables to use libraries requiring text relocation that are not labeled textrel_shlib_t
33 gen_tunable(allow_execmod,false)
37 ## Allow unconfined executables to make their stack executable. This should never, ever be necessary. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzilla
40 gen_tunable(allow_execstack,false)
44 ## Enable polyinstantiated directory support.
47 gen_tunable(allow_polyinstantiation,false)
51 ## Allow system to run with NIS
54 gen_tunable(allow_ypbind,false)
58 ## Allow logging in and using the system from /dev/console.
61 gen_tunable(console_login,true)
65 ## Enable reading of urandom for all domains.
68 ## This should be enabled when all programs
69 ## are compiled with ProPolice/SSP
70 ## stack smashing protection. All domains will
71 ## be allowed to read from /dev/urandom.
74 gen_tunable(global_ssp,false)
78 ## Allow any files/directories to be exported read/write via NFS.
81 gen_tunable(nfs_export_all_rw,false)
85 ## Allow any files/directories to be exported read/only via NFS.
88 gen_tunable(nfs_export_all_ro,false)
92 ## Support NFS home directories
95 gen_tunable(use_nfs_home_dirs,false)
99 ## Support SAMBA home directories
102 gen_tunable(use_samba_home_dirs,false)
106 ## Support fusefs home directories
109 gen_tunable(use_fusefs_home_dirs,false)
113 ## Allow users to run TCP servers (bind to ports and accept connection from
114 ## the same domain and outside users) disabling this forces FTP passive mode
115 ## and may change other protocols.
118 gen_tunable(user_tcp_server,false)
122 ## Allow direct login to the console device. Required for System 390
125 gen_tunable(allow_console_login,false)