Libvirt virtualization API
false
Allow virt to use serial/parallell communication ports
false
Allow confined virtual guests to use executable memory and executable stack
false
Allow virt to read fuse files
false
Allow virt to manage nfs files
false
Allow virt to manage cifs files
false
Allow confined virtual guests to interact with the sanlock
false
Allow virt to manage device configuration, (pci)
true
Allow virt to use usb devices
false
Allow virtual machine to interact with the xserver
All of the rules required to administrate an virt environment
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
| role |
Role allowed access. |
Allow the specified domain to append virt log files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Allow domain to attach to virt TUN devices
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute a domain transition to run virt.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Transition to virt_bridgehelper.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Dontaudit inherited read virt lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Do not audit attempts to write virt daemon unnamed pipes.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
dontaudit domain to write virt tmp files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
Execute Sandbox Files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Getattr on virt executable.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Allow domain to read virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Make the specified type usable as a virt image
| Parameter: | Description: |
|---|---|
| type |
Type to be used as a virtual image |
Send a sigkill to virtd daemon
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send a sigkill to virtual machines
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Create, read, write, and delete svirt cache files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
manage virt config files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to manage virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Create, read, write, and delete virt lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to manage virt log files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Manage virt pid files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage Sandbox Files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Mounton Sandbox Files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to read virt blk image files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read virt config files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow domain to manage virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Allow domain to read virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Read virt lib files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Allow the specified domain to read virt's log files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read virt PID files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read virt PID lnk files.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
allow domain to read virt tmpf files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
Relabel Sandbox File systems
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute a domain transition to run virt.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
| role |
Role allowed to access. |
Allow domain to search virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Allow domain to search virt image direcories
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Search virt lib directories.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Send a signal to virtual machines
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Connect to virt over an unix domain stream socket.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Connect to virt over a unix domain stream socket.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute qemu in the svirt domain, and allow the specified role the svirt domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
| role |
The role to be allowed the svirt domain. |
Allow domain to write virt image files
| Parameter: | Description: |
|---|---|
| domain |
Domain to not audit. |
Allow domain to write virt tmp sock files
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access |
Creates types and rules for a basic qemu process domain.
| Parameter: | Description: |
|---|---|
| prefix |
Prefix for the domain. |