Appendix B. SELinux Operations
Table B-1 summarizes SELinux
operations, identifying their related object classes and giving an
approximate description of them. In future SELinux releases, SELinux
developers may change the roster of operations, associate operations
with object classes differently, or modify the function performed by
an operation. The table is sorted alphabetically by the name of the
operation. The SELinux file
src/policy/flask/access_vectors shows the
relationship between object classes and operations and is sorted by
object class.
Table B-1. SELinux operations
|
Operation |
Object classes |
Description |
|---|---|---|
|
|
|
Accept a connection. |
|
|
|
Accept connection from client socket. |
|
|
|
Add a name. |
|
|
|
Write or append file or socket contents. |
|
|
|
Associate a file or key with a filesystem, queue, semaphore set, or memory segment. |
|
|
|
Toggle between permissive and enforcing modes. |
|
|
|
Control the buffer-dirty-flush daemon. |
|
|
|
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access