1 policy_module(sysadm, 2.2.1)
3 ########################################
10 userdom_admin_user_template(sysadm)
13 userdom_security_admin_template(sysadm_t, sysadm_r)
16 ########################################
20 kernel_read_fs_sysctls(sysadm_t)
22 corecmd_exec_shell(sysadm_t)
24 domain_dontaudit_read_all_domains_state(sysadm_t)
26 files_read_kernel_modules(sysadm_t)
28 dev_filetrans_all_named_dev(sysadm_t)
29 storage_filetrans_all_named_dev(sysadm_t)
30 term_filetrans_all_named_dev(sysadm_t)
32 mls_process_read_up(sysadm_t)
33 mls_file_read_to_clearance(sysadm_t)
34 mls_process_write_to_clearance(sysadm_t)
36 storage_setattr_fixed_disk_dev(sysadm_t)
38 ubac_process_exempt(sysadm_t)
39 ubac_file_exempt(sysadm_t)
40 ubac_fd_exempt(sysadm_t)
42 application_exec(sysadm_t)
45 init_exec_script_files(sysadm_t)
46 init_dbus_chat(sysadm_t)
47 init_script_role_transition(sysadm_r)
49 miscfiles_filetrans_named_content(sysadm_t)
50 miscfiles_read_hwdata(sysadm_t)
52 sysnet_filetrans_named_content(sysadm_t)
54 # Add/remove user home directories
55 userdom_manage_user_home_dirs(sysadm_t)
56 userdom_home_filetrans_user_home_dir(sysadm_t)
57 userdom_manage_tmp_role(sysadm_r, sysadm_t)
60 alsa_filetrans_named_content(sysadm_t)
64 ssh_filetrans_admin_home_content(sysadm_t)
67 ifdef(`direct_sysadm_daemon',`
69 init_run_daemon(sysadm_t, sysadm_r)
72 ifdef(`distro_gentoo',`
74 seutil_init_script_run_runinit(sysadm_t, sysadm_r)
80 logging_manage_audit_log(sysadm_t)
81 logging_manage_audit_config(sysadm_t)
82 logging_run_auditctl(sysadm_t, sysadm_r)
83 logging_stream_connect_syslog(sysadm_t)
86 tunable_policy(`deny_ptrace',`',`
87 domain_ptrace_all_domains(sysadm_t)
91 amanda_run_recover(sysadm_t, sysadm_r)
95 apache_run_helper(sysadm_t, sysadm_r)
96 apache_filetrans_home_content(sysadm_t)
97 #apache_run_all_scripts(sysadm_t, sysadm_r)
98 #apache_domtrans_sys_script(sysadm_t)
102 # cjp: why is this not apm_run_client
103 apm_domtrans_client(sysadm_t)
107 apt_run(sysadm_t, sysadm_r)
111 auditadm_role_change(sysadm_r)
115 backup_run(sysadm_t, sysadm_r)
119 bind_run_ndc(sysadm_t, sysadm_r)
123 bootloader_run(sysadm_t, sysadm_r)
127 certmonger_dbus_chat(sysadm_t)
131 certwatch_run(sysadm_t, sysadm_r)
135 clock_run(sysadm_t, sysadm_r)
139 clockspeed_run_cli(sysadm_t, sysadm_r)
143 cron_admin_role(sysadm_r, sysadm_t)
144 #cron_role(sysadm_r, sysadm_t)
148 consoletype_exec(sysadm_t)
152 daemonstools_run_start(sysadm_t, sysadm_r)
156 dbus_role_template(sysadm, sysadm_r, sysadm_t)
160 dcc_run_cdcc(sysadm_t, sysadm_r)
161 dcc_run_client(sysadm_t, sysadm_r)
162 dcc_run_dbclean(sysadm_t, sysadm_r)
166 ddcprobe_run(sysadm_t, sysadm_r)
170 devicekit_filetrans_named_content(sysadm_t)
178 dmidecode_run(sysadm_t, sysadm_r)
182 dpkg_run(sysadm_t, sysadm_r)
186 firstboot_run(sysadm_t, sysadm_r)
190 fstools_run(sysadm_t, sysadm_r)
194 hostname_run(sysadm_t, sysadm_r)
198 hadoop_role(sysadm_r, sysadm_t)
202 # allow system administrator to use the ipsec script to look
203 # at things (e.g., ipsec auto --status)
204 # probably should create an ipsec_admin role for this kind of thing
205 ipsec_exec_mgmt(sysadm_t)
206 ipsec_stream_connect(sysadm_t)
208 ipsec_getattr_key_sockets(sysadm_t)
209 ipsec_run_setkey(sysadm_t, sysadm_r)
210 ipsec_run_racoon(sysadm_t, sysadm_r)
211 ipsec_stream_connect_racoon(sysadm_t)
214 ipsec_mgmt_dbus_chat(sysadm_t)
219 iptables_run(sysadm_t, sysadm_r)
223 irc_role(sysadm_r, sysadm_t)
227 kerberos_exec_kadmind(sysadm_t)
228 kerberos_filetrans_named_content(sysadm_t)
232 kudzu_run(sysadm_t, sysadm_r)
236 libs_run_ldconfig(sysadm_t, sysadm_r)
240 logrotate_run(sysadm_t, sysadm_r)
244 lpd_run_checkpc(sysadm_t, sysadm_r)
245 lpd_role(sysadm_r, sysadm_t)
249 lvm_run(sysadm_t, sysadm_r)
253 modutils_run_depmod(sysadm_t, sysadm_r)
254 modutils_run_insmod(sysadm_t, sysadm_r)
255 modutils_run_update_mods(sysadm_t, sysadm_r)
256 modutils_read_module_deps(sysadm_t)
257 modules_filetrans_named_content(sysadm_t)
261 mount_run(sysadm_t, sysadm_r)
262 mount_run_showmount(sysadm_t, sysadm_r)
266 mta_role(sysadm_r, sysadm_t)
267 # this is defined in userdom_common_user_template
268 #mta_filetrans_home_content(sysadm_t)
269 mta_filetrans_admin_home_content(sysadm_t)
273 munin_stream_connect(sysadm_t)
277 mysql_stream_connect(sysadm_t)
281 ncftool_run(sysadm_t, sysadm_r)
285 netutils_run(sysadm_t, sysadm_r)
286 netutils_run_ping(sysadm_t, sysadm_r)
287 netutils_run_traceroute(sysadm_t, sysadm_r)
291 networkmanager_filetrans_named_content(sysadm_t)
296 corenet_udp_bind_ntp_port(sysadm_t)
300 nx_filetrans_named_content(sysadm_t)
304 oav_run_update(sysadm_t, sysadm_r)
308 openvpn_run(sysadm_t, sysadm_r)
312 pcmcia_run_cardctl(sysadm_t, sysadm_r)
316 polipo_role(sysadm_r, sysadm_t)
317 polipo_named_filetrans_admin_cache_home_dirs(sysadm_t)
318 polipo_named_filetrans_admin_config_home_files(sysadm_t)
322 portage_run(sysadm_t, sysadm_r)
323 portage_run_gcc_config(sysadm_t, sysadm_r)
327 portmap_run_helper(sysadm_t, sysadm_r)
331 postfix_filetrans_named_content(sysadm_t)
335 prelink_run(sysadm_t, sysadm_r)
339 puppet_run_puppetca(sysadm_t, sysadm_r)
343 quota_run(sysadm_t, sysadm_r)
347 raid_domtrans_mdadm(sysadm_t)
351 rpc_domtrans_nfsd(sysadm_t)
355 rpm_run(sysadm_t, sysadm_r)
356 rpm_dbus_chat(sysadm_t, sysadm_r)
364 samba_run_net(sysadm_t, sysadm_r)
365 samba_run_winbind_helper(sysadm_t, sysadm_r)
369 samhain_admin(sysadm_t)
373 screen_role_template(sysadm, sysadm_r, sysadm_t)
377 secadm_role_change(sysadm_r)
381 setroubleshoot_stream_connect(sysadm_t)
382 setroubleshoot_dbus_chat(sysadm_t)
383 setroubleshoot_dbus_chat_fixit(sysadm_t)
387 seutil_run_setfiles(sysadm_t, sysadm_r)
388 seutil_run_runinit(sysadm_t, sysadm_r)
392 shutdown_run(sysadm_t, sysadm_r)
396 ssh_role_template(sysadm, sysadm_r, sysadm_t)
400 staff_role_change(sysadm_r)
404 su_role_template(sysadm, sysadm_r, sysadm_t)
408 sudo_role_template(sysadm, sysadm_r, sysadm_t)
412 sysnet_run_ifconfig(sysadm_t, sysadm_r)
413 sysnet_run_dhcpc(sysadm_t, sysadm_r)
417 systemd_passwd_agent_run(sysadm_t, sysadm_r)
418 systemd_config_all_services(sysadm_t)
419 systemd_manage_all_unit_files(sysadm_t)
420 systemd_manage_all_unit_lnk_files(sysadm_t)
424 tripwire_run_siggen(sysadm_t, sysadm_r)
425 tripwire_run_tripwire(sysadm_t, sysadm_r)
426 tripwire_run_twadmin(sysadm_t, sysadm_r)
427 tripwire_run_twprint(sysadm_t, sysadm_r)
431 tzdata_domtrans(sysadm_t)
435 unconfined_domtrans(sysadm_t)
439 udev_run(sysadm_t, sysadm_r)
443 unprivuser_role_change(sysadm_r)
447 usbmodules_run(sysadm_t, sysadm_r)
451 usermanage_run_admin_passwd(sysadm_t, sysadm_r)
452 usermanage_run_groupadd(sysadm_t, sysadm_r)
453 usermanage_run_useradd(sysadm_t, sysadm_r)
457 virt_stream_connect(sysadm_t)
458 virt_filetrans_home_content(sysadm_t)
462 vlock_run(sysadm_t, sysadm_r)
466 vpn_run(sysadm_t, sysadm_r)
470 webalizer_run(sysadm_t, sysadm_r)
474 xserver_role(sysadm_r, sysadm_t)
478 yam_run(sysadm_t, sysadm_r)
482 zebra_stream_connect(sysadm_t)
485 ifndef(`distro_redhat',`
487 apache_role(sysadm_r, sysadm_t)
490 auth_role(sysadm_r, sysadm_t)
494 bluetooth_role(sysadm_r, sysadm_t)
498 cdrecord_role(sysadm_r, sysadm_t)
502 dbus_role_template(sysadm, sysadm_r, sysadm_t)
506 gnome_role(sysadm_r, sysadm_t)
507 gnome_filetrans_admin_home_content(sysadm_t)
511 gpg_role(sysadm_r, sysadm_t)
515 java_role(sysadm_r, sysadm_t)
519 lockdev_role(sysadm_r, sysadm_t)
527 mplayer_role(sysadm_r, sysadm_t)
531 pyzor_role(sysadm_r, sysadm_t)
535 razor_role(sysadm_r, sysadm_t)
539 rssh_role(sysadm_r, sysadm_t)
543 spamassassin_role(sysadm_r, sysadm_t)
547 tvtime_role(sysadm_r, sysadm_t)
551 uml_role(sysadm_r, sysadm_t)
555 userhelper_role_template(sysadm, sysadm_r, sysadm_t)
559 vmware_role(sysadm_r, sysadm_t)
563 wireshark_role(sysadm_r, sysadm_t)
567 xserver_role(sysadm_r, sysadm_t)