Layer: system

Module: systemd

Tunables Interfaces Templates

Description:

Systemd components (not PID 1)


Tunables:

systemd_logind_get_bootloader
Default value

false

Description

Allow systemd-logind to interact with the bootloader (read which one is installed on fixed disks, enumerate entries for dbus property BootLoaderEntries, etc.)

systemd_nspawn_labeled_namespace
Default value

false

Description

Allow systemd-nspawn to create a labelled namespace with the same types as parent environment

systemd_tmpfiles_manage_all
Default value

false

Description

Enable support for systemd-tmpfiles to manage all non-security files.

Return

Interfaces:

systemd_PrivateDevices( domain )
Summary

Allow domain to be used as a systemd service with a unit that uses PrivateDevices=yes in section [Service].

Parameters
Parameter:Description:
domain

Domain allowed access

systemd_create_all_user_keys( domain )
Summary

Create keys for the all systemd --user domains.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_dbus_chat_hostnamed( domain )
Summary

Send and receive messages from systemd hostnamed over dbus.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_dbus_chat_logind( domain )
Summary

Send and receive messages from systemd logind over dbus.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_dbus_chat_resolved( domain )
Summary

Send and receive messages from systemd resolved over dbus.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_domtrans_sysusers( domain )
Summary

Execute systemd-sysusers in the systemd sysusers domain.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_enabledisable_networkd( domain )
Summary

Allow specified domain to enable systemd-networkd units

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_filetrans_passwd_runtime_dirs( domain )
Summary

Transition to systemd_passwd_runtime_t when creating dirs

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_getattr_updated_runtime( domain )
Summary

Allow domain to getattr on .updated file (generated by systemd-update-done

Parameters
Parameter:Description:
domain

domain allowed access

systemd_list_networkd_runtime( domain )
Summary

Allow domain to list dirs under /run/systemd/netif

Parameters
Parameter:Description:
domain

domain permitted the access

systemd_list_tmpfiles_conf( domain )
Summary

Allow domain to list systemd tmpfiles config directory

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_log_parse_environment( domain )
Summary

Make the specified type usable as an log parse environment type.

Parameters
Parameter:Description:
domain

Type to be used as a log parse environment type.

systemd_manage_all_units( domain )
Summary

manage systemd unit dirs and the files in them (Deprecated)

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_journal_files( domain )
Summary

Allow domain to create/manage systemd_journal_t files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_logind_pid_pipes( domain )
Summary

Manage systemd_login PID pipes. (Deprecated)

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_logind_runtime_pipes( domain )
Summary

Manage systemd-logind runtime pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_networkd_units( domain )
Summary

Allow domain to create/manage systemd_networkd_t unit files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_manage_passwd_runtime_symlinks( domain )
Summary

Allow to domain to create systemd-passwd symlink

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_map_hwdb( domain )
Summary

Allow domain to map udev hwdb file

Parameters
Parameter:Description:
domain

domain allowed access

systemd_read_hwdb( domain )
Summary

Allow domain to read udev hwdb file

Parameters
Parameter:Description:
domain

domain allowed access

systemd_read_journal_files( domain )
Summary

Allow domain to read systemd_journal_t files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_pids( domain )
Summary

Read systemd_login PID files. (Deprecated)

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_runtime_files( domain )
Summary

Read systemd-logind runtime files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_sessions_files( domain )
Summary

Read logind sessions files.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_logind_state( domain )
Summary

Allow systemd_logind_t to read process state for cgroup file

Parameters
Parameter:Description:
domain

Domain systemd_logind_t may access.

systemd_read_machines( domain )
Summary

Allow reading /run/systemd/machines

Parameters
Parameter:Description:
domain

Domain that can access the machines files

systemd_read_networkd_runtime( domain )
Summary

Allow domain to read files generated by systemd_networkd

Parameters
Parameter:Description:
domain

domain allowed access

systemd_read_networkd_units( domain )
Summary

Allow domain to read systemd_networkd_t unit files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_read_resolved_runtime( domain )
Summary

Allow domain to read resolv.conf file generated by systemd_resolved

Parameters
Parameter:Description:
domain

domain allowed access

systemd_relabelfrom_networkd_tun_sockets( domain )
Summary

Relabel systemd_networkd tun socket.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_relabelto_journal_dirs( domain )
Summary

Relabel to systemd-journald directory type.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_relabelto_journal_files( domain )
Summary

Relabel to systemd-journald file type.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_relabelto_tmpfiles_conf_dirs( domain )
Summary

Allow domain to relabel to systemd tmpfiles config directory

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_relabelto_tmpfiles_conf_files( domain )
Summary

Allow domain to relabel to systemd tmpfiles config files

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_run_sysusers( domain , role )
Summary

Run systemd-sysusers with a domain transition.

Parameters
Parameter:Description:
domain

Domain allowed access.

role

Role allowed access.

systemd_rw_networkd_netlink_route_sockets( domain )
Summary

Read/Write from systemd_networkd netlink route socket.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_search_all_user_keys( domain )
Summary

Search keys for the all systemd --user domains.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_signull_logind( domain )
Summary

Send systemd_login a null signal.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_start_power_units( domain )
Summary

Allow specified domain to start power units

Parameters
Parameter:Description:
domain

Domain to not audit.

systemd_startstop_networkd( domain )
Summary

Allow specified domain to start systemd-networkd units

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_status_logind( domain )
Summary

Get the system status information from systemd_login

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_status_networkd( domain )
Summary

Allow specified domain to get status of systemd-networkd

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_status_power_units( domain )
Summary

Get the system status information about power units

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_tmpfiles_conf_file( type )
Summary

Make the specified type usable for systemd tmpfiles config files.

Parameters
Parameter:Description:
type

Type to be used for systemd tmpfiles config files.

systemd_tmpfiles_conf_filetrans( domain , private type , object , name )
Summary

Create an object in the systemd tmpfiles config directory, with a private type using a type transition.

Parameters
Parameter:Description:
domain

Domain allowed access.

private type

The type of the object to be created.

object

The object class of the object being created.

name

The name of the object being created.

systemd_tmpfiles_creator( domain )
Summary

Allow the specified domain to create the tmpfiles config directory with the correct context.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_tmpfilesd_managed( type , class )
Summary

Allow systemd_tmpfiles_t to manage filesystem objects

Parameters
Parameter:Description:
type

type of object to manage

class

object class to manage

systemd_use_logind_fds( domain )
Summary

Use inherited systemd logind file descriptors.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_use_nss( domain )
Summary

Allow domain to use systemd's Name Service Switch (NSS) module. This module provides UNIX user and group name resolution for dynamic users and groups allocated through the DynamicUser= option in systemd unit files

Parameters
Parameter:Description:
domain

Domain allowed access

systemd_use_passwd_agent( domain )
Summary

Allow a systemd_passwd_agent_t process to interact with a daemon that needs a password from the sysadmin.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_use_passwd_agent_fds( domain )
Summary

allow systemd_passwd_agent to inherit fds

Parameters
Parameter:Description:
domain

Domain that owns the fds

systemd_watch_networkd_runtime_dirs( domain )
Summary

Watch directories under /run/systemd/netif

Parameters
Parameter:Description:
domain

Domain permitted the access

systemd_write_all_user_keys( domain )
Summary

Write keys for the all systemd --user domains.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_inherited_logind_inhibit_pipes( domain )
Summary

Write inherited logind inhibit pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_inherited_logind_sessions_pipes( domain )
Summary

Write inherited logind sessions pipes.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_kmod_files( domain )
Summary

Allow process to write to systemd_kmod_conf_t.

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_logind_pid_pipes( domain )
Summary

Write systemd_login named pipe. (Deprecated)

Parameters
Parameter:Description:
domain

Domain allowed access.

systemd_write_logind_runtime_pipes( domain )
Summary

Write systemd-logind runtime named pipe.

Parameters
Parameter:Description:
domain

Domain allowed access.

Return

Templates:

systemd_role_template( prefix , role , userdomain )
Summary

Template for systemd --user per-role domains.

Parameters
Parameter:Description:
prefix

Prefix for generated types

role

The user role.

userdomain

The user domain for the role.

Return