Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /usr/share/doc/selinux-policy-2.4.6/html/ drwxr-xr-x |
Viewing file: kernel_devices.html (102.49 KB) -rw-r--r-- Select action/file-type: (+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) | Security Enhanced Linux Reference Policy
+
admin
-
corecommands
+
services
- corenetwork - devices - domain - files - filesystem - kernel - mcs - mls - selinux - storage - terminal * Global Booleans * Global Tunables * Layer Index * Interface Index * Template Index Layer: kernelModule: devicesDescription:
This module creates the device node concept and provides the policy for many of the device files. Notable exceptions are the mass storage and terminal devices that are covered by other modules.
This module creates the concept of a device node. That is a char or block device file, usually in /dev. All types that are used to label device nodes should use the dev_node macro.
Additionally, this module controls access to three things:
This module is required to be included in all policies. Interfaces:
dev_append_printer(
domain
)
SummaryAppend the printer device. Parameters
dev_associate_usbfs(
file_type
)
SummaryAssociate a file to a usbfs filesystem. Parameters
dev_create_all_blk_files(
domain
)
SummaryCreate all block device files. Parameters
dev_create_all_chr_files(
domain
)
SummaryCreate all character device files. Parameters
dev_create_cardmgr_dev(
domain
)
SummaryCreate, read, write, and delete the PCMCIA card manager device with the correct type. Parameters
dev_create_generic_chr_files(
domain
)
SummaryAllow read, write, and create for generic character device files. Parameters
dev_create_generic_dirs(
domain
)
SummaryCreate a directory in the device directory. Parameters
dev_create_generic_symlinks(
domain
)
SummaryCreate symbolic links in device directories. Parameters
dev_create_null_dev(
domain
)
SummaryCreate the null device (/dev/null). Parameters
dev_create_zero_dev(
domain
)
SummaryCreate the zero device (/dev/zero). Parameters
dev_delete(
domain
)
Summarydelete entries from directories in /dev. Parameters
dev_delete_all_blk_files(
domain
)
SummaryDelete all block device files. Parameters
dev_delete_all_chr_files(
domain
)
SummaryDelete all character device files. Parameters
dev_delete_dlm_control(
domain
)
SummaryDelete the dlm control device. Parameters
dev_delete_generic_dirs(
domain
)
SummaryDelete a directory in the device directory. Parameters
dev_delete_generic_files(
domain
)
SummaryDelete generic files in /dev. Parameters
dev_delete_generic_symlinks(
domain
)
SummaryDelete symbolic links in device directories. Parameters
dev_delete_lvm_control_dev(
domain
)
SummaryDelete the lvm control device. Parameters
dev_delete_null(
domain
)
SummaryDelete the null device (/dev/null). Parameters
dev_dontaudit_getattr_all_blk_files(
domain
)
SummaryDontaudit getattr on all block file device nodes. Parameters
dev_dontaudit_getattr_all_chr_files(
domain
)
SummaryDontaudit getattr on all character file device nodes. Parameters
dev_dontaudit_getattr_apm_bios_dev(
domain
)
SummaryDo not audit attempts to get the attributes of the apm bios device node. Parameters
dev_dontaudit_getattr_autofs_dev(
domain
)
SummaryDo not audit attempts to get the attributes of the autofs device node. Parameters
dev_dontaudit_getattr_generic_blk_files(
domain
)
SummaryDontaudit getattr on generic block devices. Parameters
dev_dontaudit_getattr_generic_chr_files(
domain
)
SummaryDontaudit getattr for generic character device files. Parameters
dev_dontaudit_getattr_generic_files(
domain
)
Summarydontaudit getattr generic files in /dev. Parameters
dev_dontaudit_getattr_generic_pipes(
domain
)
SummaryDontaudit getattr on generic pipes. Parameters
dev_dontaudit_getattr_memory_dev(
domain
)
Summarydontaudit getattr raw memory devices (e.g. /dev/mem). Parameters
dev_dontaudit_getattr_misc_dev(
domain
)
SummaryDo not audit attempts to get the attributes of miscellaneous devices. Parameters
dev_dontaudit_getattr_nvram_dev(
domain
)
SummaryDo not audit attempts to get the attributes of the BIOS non-volatile RAM device. Parameters
dev_dontaudit_getattr_scanner_dev(
domain
)
SummaryDo not audit attempts to get the attributes of the scanner device. Parameters
dev_dontaudit_getattr_usbfs_dirs(
domain
)
SummaryDo not audit attempts to get the attributes of a directory in the usb filesystem. Parameters
dev_dontaudit_getattr_video_dev(
domain
)
SummaryDo not audit attempts to get the attributes of video4linux device nodes. Parameters
dev_dontaudit_list_all_dev_nodes(
domain
)
SummaryDontaudit attempts to list all device nodes. Parameters
dev_dontaudit_read_all_blk_files(
domain
)
SummaryDontaudit read on all block file device nodes. Parameters
dev_dontaudit_read_all_chr_files(
domain
)
SummaryDontaudit read on all character file device nodes. Parameters
dev_dontaudit_read_framebuffer(
domain
)
SummaryDo not audit attempts to read the framebuffer. Parameters
dev_dontaudit_read_rand(
domain
)
SummaryDo not audit attempts to read from random number generator devices (e.g., /dev/random) Parameters
dev_dontaudit_read_urand(
domain
)
SummaryDo not audit attempts to read from pseudo random devices (e.g., /dev/urandom) Parameters
dev_dontaudit_rw_cardmgr(
domain
)
SummaryDo not audit attempts to read and write the PCMCIA card manager device. Parameters
dev_dontaudit_rw_dri(
domain
)
SummaryDontaudit read and write on the dri devices. Parameters
dev_dontaudit_rw_generic_dev_nodes(
domain
)
SummaryDontaudit getattr for generic device files. Parameters
dev_dontaudit_rw_misc(
domain
)
SummaryDo not audit attempts to read and write miscellaneous devices. Parameters
dev_dontaudit_search_sysfs(
domain
)
SummaryDo not audit attempts to search sysfs. Parameters
dev_dontaudit_setattr_apm_bios_dev(
domain
)
SummaryDo not audit attempts to set the attributes of the apm bios device node. Parameters
dev_dontaudit_setattr_autofs_dev(
domain
)
SummaryDo not audit attempts to set the attributes of the autofs device node. Parameters
dev_dontaudit_setattr_framebuffer_dev(
domain
)
SummaryDot not audit attempts to set the attributes of the framebuffer device node. Parameters
dev_dontaudit_setattr_generic_blk_files(
domain
)
SummaryDontaudit setattr on generic block devices. Parameters
dev_dontaudit_setattr_generic_chr_files(
domain
)
SummaryDontaudit setattr for generic character device files. Parameters
dev_dontaudit_setattr_generic_symlinks(
domain
)
SummaryDo not audit attempts to set the attributes of symbolic links in device directories (/dev). Parameters
dev_dontaudit_setattr_misc_dev(
domain
)
SummaryDo not audit attempts to set the attributes of miscellaneous devices. Parameters
dev_dontaudit_setattr_scanner_dev(
domain
)
SummaryDo not audit attempts to set the attributes of the scanner device. Parameters
dev_dontaudit_setattr_video_dev(
domain
)
SummaryDo not audit attempts to set the attributes of video4linux device nodes. Parameters
dev_execmod_zero(
domain
)
SummaryExecmod the zero device (/dev/zero). Parameters
dev_filetrans(
domain
,
file
,
objectclass(es)
)
SummaryCreate, read, and write device nodes. The node will be transitioned to the type provided. Parameters
dev_filetrans_xen(
domain
)
SummaryAutomatic type transition to the type for xen device nodes when created in /dev. Parameters
dev_getattr_agp_dev(
domain
)
SummaryGetattr the agp devices. Parameters
dev_getattr_all_blk_files(
domain
)
SummaryGetattr on all block file device nodes. Parameters
dev_getattr_all_chr_files(
domain
)
SummaryGetattr on all character file device nodes. Parameters
dev_getattr_apm_bios_dev(
domain
)
SummaryGet the attributes of the apm bios device node. Parameters
dev_getattr_autofs_dev(
domain
)
SummaryGet the attributes of the autofs device node. Parameters
dev_getattr_cpu_dev(
domain
)
SummaryGet the attributes of the CPU microcode and id interfaces. Parameters
dev_getattr_dri_dev(
domain
)
Summarygetattr the dri devices. Parameters
dev_getattr_event_dev(
domain
)
SummaryGet the attributes of the event devices. Parameters
dev_getattr_framebuffer_dev(
domain
)
SummaryGet the attributes of the framebuffer device node. Parameters
dev_getattr_generic_blk_files(
domain
)
SummaryAllow getattr on generic block devices. Parameters
dev_getattr_generic_chr_files(
domain
)
SummaryAllow getattr for generic character device files. Parameters
dev_getattr_generic_usb_dev(
domain
)
SummaryGetattr generic the USB devices. Parameters
dev_getattr_ksm_dev(
domain
)
SummaryGet the attributes of the ksm devices. Parameters
dev_getattr_misc_dev(
domain
)
SummaryGet the attributes of miscellaneous devices. Parameters
dev_getattr_mouse_dev(
domain
)
SummaryGet the attributes of the mouse devices. Parameters
dev_getattr_mtrr_dev(
domain
)
SummaryGet the attributes of the memory type range registers (MTRR) device. Parameters
dev_getattr_power_mgmt_dev(
domain
)
SummaryGet the attributes of the the power management device. Parameters
dev_getattr_printer_dev(
domain
)
SummaryGet the attributes of the printer device nodes. Parameters
dev_getattr_scanner_dev(
domain
)
SummaryGet the attributes of the scanner device. Parameters
dev_getattr_sound_dev(
domain
)
SummaryGet the attributes of the sound devices. Parameters
dev_getattr_sysfs_dirs(
domain
)
SummaryGet the attributes of sysfs directories. Parameters
dev_getattr_usbfs_dirs(
domain
)
SummaryGet the attributes of a directory in the usb filesystem. Parameters
dev_getattr_video_dev(
domain
)
SummaryGet the attributes of video4linux devices. Parameters
dev_getattr_xserver_misc_dev(
domain
)
SummaryGet the attributes of X server miscellaneous devices. Parameters
dev_list_all_dev_nodes(
domain
)
SummaryList all of the device nodes in a device directory. Parameters
dev_list_sysfs(
domain
)
SummaryList the contents of the sysfs directories. Parameters
dev_list_usbfs(
domain
)
SummaryAllow caller to get a list of usb hardware. Parameters
dev_manage_all_blk_files(
domain
)
SummaryRead, write, create, and delete all block device files. Parameters
dev_manage_all_chr_files(
domain
)
SummaryRead, write, create, and delete all character device files. Parameters
dev_manage_all_dev_nodes(
domain
)
SummaryCreate, delete, read, and write device nodes in device directories. Parameters
dev_manage_cardmgr_dev(
domain
)
SummaryCreate, read, write, and delete the PCMCIA card manager device. Parameters
dev_manage_dri_dev(
domain
)
SummaryCreate, read, write, and delete the dri devices. Parameters
dev_manage_generic_blk_files(
domain
)
SummaryCreate, delete, read, and write block device files. Parameters
dev_manage_generic_chr_files(
domain
)
SummaryCreate, delete, read, and write character device files. Parameters
dev_manage_generic_dirs(
domain
)
SummaryManage of directories in /dev. Parameters
dev_manage_generic_files(
domain
)
SummaryCreate a file in the device directory. Parameters
dev_manage_generic_symlinks(
domain
)
SummaryCreate, delete, read, and write symbolic links in device directories. Parameters
dev_manage_xen(
domain
)
SummaryCreate, read, write, and delete Xen devices. Parameters
dev_mount_usbfs(
domain
)
SummaryMount a usbfs filesystem. Parameters
dev_node(
object_type
)
SummaryMake the passed in type a type appropriate for use on device nodes (usually files in /dev). Parameters
dev_read_cpuid(
domain
)
SummaryRead the CPU identity. Parameters
dev_read_framebuffer(
domain
)
SummaryRead the framebuffer. Parameters
dev_read_input(
domain
)
SummaryRead input event devices (/dev/input). Parameters
dev_read_ksm(
domain
)
SummaryRead the ksm devices. Parameters
dev_read_kvm(
domain
)
SummaryRead the kvm devices. Parameters
dev_read_lvm_control(
domain
)
SummaryRead the lvm comtrol device. Parameters
dev_read_misc(
domain
)
SummaryRead miscellaneous devices. Parameters
dev_read_mouse(
domain
)
SummaryRead the mouse devices. Parameters
dev_read_mtrr(
domain
)
SummaryRead the memory type range registers (MTRR). (Deprecated) Description
Read the memory type range registers (MTRR). This interface has been deprecated, dev_rw_mtrr() should be used instead.
The MTRR device ioctls can be used for reading and writing; thus, read access to the device cannot be separated from write access.
Parameters
dev_read_printk(
domain
)
SummaryRead printk devices (e.g., /dev/kmsg /dev/mcelog) Parameters
dev_read_qemu(
domain
)
SummaryRead the QEMU device Parameters
dev_read_rand(
domain
)
SummaryRead from random number generator devices (e.g., /dev/random) Parameters
dev_read_raw_memory(
domain
)
SummaryRead raw memory devices (e.g. /dev/mem). Parameters
dev_read_realtime_clock(
domain
)
SummaryRead the realtime clock (/dev/rtc). Parameters
dev_read_sound(
domain
)
SummaryRead the sound devices. Parameters
dev_read_sound_mixer(
domain
)
SummaryRead the sound mixer devices. Parameters
dev_read_sysfs(
domain
)
SummaryAllow caller to read hardware state information. Parameters
dev_read_urand(
domain
)
SummaryRead from pseudo random devices (e.g., /dev/urandom) Parameters
dev_read_usbfs(
domain
)
SummaryRead USB hardware information using the usbfs filesystem interface. Parameters
dev_read_video_dev(
domain
)
SummaryRead the video4linux devices. Parameters
dev_relabel_all_dev_nodes(
domain
)
SummaryAllow full relabeling (to and from) of all device nodes. Parameters
dev_relabel_generic_dev_dirs(
domain
)
SummaryAllow full relabeling (to and from) of directories in /dev. Parameters
dev_relabel_generic_symlinks(
domain
)
SummaryRelabel symbolic links in device directories. Parameters
dev_rename_all_blk_files(
domain
)
SummaryRename all block device files. Parameters
dev_rename_all_chr_files(
domain
)
SummaryRename all character device files. Parameters
dev_rw_agp(
domain
)
SummaryRead and write the agp devices. Parameters
dev_rw_apm_bios(
domain
)
SummaryRead and write the apm bios. Parameters
dev_rw_autofs(
domain
)
SummaryRead and write the autofs device. Parameters
dev_rw_cardmgr(
domain
)
SummaryRead and write the PCMCIA card manager device. Parameters
dev_rw_cpu_microcode(
domain
)
SummaryRead and write the the CPU microcode device. This is required to load CPU microcode. Parameters
dev_rw_crypto(
domain
)
SummaryRead and write the the hardware SSL accelerator. Parameters
dev_rw_dlm_control(
domain
)
SummaryRead and write the the dlm control device Parameters
dev_rw_dri(
domain
)
SummaryRead and write the dri devices. Parameters
dev_rw_framebuffer(
domain
)
SummaryRead and write the framebuffer. Parameters
dev_rw_generic_files(
domain
)
SummaryRead and write generic files in /dev. Parameters
dev_rw_generic_usb_dev(
domain
)
SummaryRead and write generic the USB devices. Parameters
dev_rw_generic_usb_pipes(
domain
)
SummaryRead and write generic the USB fifo files. Parameters
dev_rw_input_dev(
domain
)
SummaryRead input event devices (/dev/input). Parameters
dev_rw_ksm(
domain
)
SummaryRead and write to ksm devices. Parameters
dev_rw_kvm(
domain
)
SummaryRead and write to kvm devices. Parameters
dev_rw_lvm_control(
domain
)
SummaryRead and write the lvm control device. Parameters
dev_rw_mouse(
domain
)
SummaryRead and write to mouse devices. Parameters
dev_rw_mtrr(
domain
)
SummaryRead and write the memory type range registers (MTRR). Parameters
dev_rw_null(
domain
)
SummaryRead and write to the null device (/dev/null). Parameters
dev_rw_nvram(
domain
)
SummaryRead and write BIOS non-volatile RAM. Parameters
dev_rw_power_management(
domain
)
SummaryRead and write the the power management device. Parameters
dev_rw_printer(
domain
)
SummaryRead and write the printer device. Parameters
dev_rw_qemu(
domain
)
SummaryRead and write the the QEMU device. Parameters
dev_rw_realtime_clock(
domain
)
SummaryRead and set the realtime clock (/dev/rtc). Parameters
dev_rw_scanner(
domain
)
SummaryRead and write the scanner device. Parameters
dev_rw_sysfs(
domain
)
SummaryAllow caller to modify hardware state information. Parameters
dev_rw_usbfs(
domain
)
SummaryAllow caller to modify usb hardware configuration files. Parameters
dev_rw_userio_dev(
domain
)
SummaryRead or write userio device. Parameters
dev_rw_vmware(
domain
)
SummaryRead and write VMWare devices. Parameters
dev_rw_xen(
domain
)
SummaryRead and write Xen devices. Parameters
dev_rw_xserver_misc(
domain
)
SummaryRead and write X server miscellaneous devices. Parameters
dev_rw_zero(
domain
)
SummaryRead and write to the zero device (/dev/zero). Parameters
dev_rwx_vmware(
domain
)
SummaryRead, write, and mmap VMWare devices. Parameters
dev_rwx_zero(
domain
)
SummaryRead, write, and execute the zero device (/dev/zero). Parameters
dev_rx_raw_memory(
domain
)
SummaryRead and execute raw memory devices (e.g. /dev/mem). Parameters
dev_search_sysfs(
domain
)
SummarySearch the sysfs directories. Parameters
dev_search_usbfs(
domain
)
SummarySearch the directory containing USB hardware information. Parameters
dev_search_usbfs_dirs(
domain
)
SummaryGet the attributes of a directory in the usb filesystem. Parameters
dev_setattr_all_blk_files(
domain
)
SummarySetattr on all block file device nodes. Parameters
dev_setattr_all_chr_files(
domain
)
SummarySetattr on all character file device nodes. Parameters
dev_setattr_apm_bios_dev(
domain
)
SummarySet the attributes of the apm bios device node. Parameters
dev_setattr_autofs_dev(
domain
)
SummarySet the attributes of the autofs device node. Parameters
dev_setattr_dlm_control(
domain
)
SummarySet the attributes of the dlm control devices. Parameters
dev_setattr_dri_dev(
domain
)
SummarySetattr the dri devices. Parameters
dev_setattr_event_dev(
domain
)
SummarySet the attributes of the event devices. Parameters
dev_setattr_framebuffer_dev(
domain
)
SummarySet the attributes of the framebuffer device node. Parameters
dev_setattr_generic_dirs(
domain
)
SummarySet the attributes of /dev directories. Parameters
dev_setattr_generic_usb_dev(
domain
)
SummarySetattr generic the USB devices. Parameters
dev_setattr_ksm_dev(
domain
)
SummarySet the attributes of the ksm devices. Parameters
dev_setattr_misc_dev(
domain
)
SummarySet the attributes of miscellaneous devices. Parameters
dev_setattr_mouse_dev(
domain
)
SummarySet the attributes of the mouse devices. Parameters
dev_setattr_power_mgmt_dev(
domain
)
SummarySet the attributes of the the power management device. Parameters
dev_setattr_printer_dev(
domain
)
SummarySet the attributes of the printer device nodes. Parameters
dev_setattr_qemu_dev(
domain
)
SummarySet the attributes of the QEMU microcode and id interfaces. Parameters
dev_setattr_scanner_dev(
domain
)
SummarySet the attributes of the scanner device. Parameters
dev_setattr_sound_dev(
domain
)
SummarySet the attributes of the sound devices. Parameters
dev_setattr_usbfs_files(
domain
)
SummarySet the attributes of usbfs filesystem. Parameters
dev_setattr_video_dev(
domain
)
SummarySet the attributes of video4linux device nodes. Parameters
dev_setattr_xserver_misc_dev(
domain
)
SummarySet the attributes of X server miscellaneous devices. Parameters
dev_unconfined(
domain
)
SummaryUnconfined access to devices. Parameters
dev_write_framebuffer(
domain
)
SummaryWrite the framebuffer. Parameters
dev_write_misc(
domain
)
SummaryWrite miscellaneous devices. Parameters
dev_write_mtrr(
domain
)
SummaryWrite the memory type range registers (MTRR). (Deprecated) Description
Write the memory type range registers (MTRR). This interface has been deprecated, dev_rw_mtrr() should be used instead.
The MTRR device ioctls can be used for reading and writing; thus, write access to the device cannot be separated from read access.
Parameters
dev_write_rand(
domain
)
SummaryWrite to the random device (e.g., /dev/random). This adds entropy used to generate the random data read from the random device. Parameters
dev_write_raw_memory(
domain
)
SummaryWrite raw memory devices (e.g. /dev/mem). Parameters
dev_write_realtime_clock(
domain
)
SummarySet the realtime clock (/dev/rtc). Parameters
dev_write_sound(
domain
)
SummaryWrite the sound devices. Parameters
dev_write_sound_mixer(
domain
)
SummaryWrite the sound mixer devices. Parameters
dev_write_sysfs_dirs(
domain
)
SummaryWrite in a sysfs directories. Parameters
dev_write_urand(
domain
)
SummaryWrite to the pseudo random device (e.g., /dev/urandom). This sets the random number generator seed. Parameters
dev_write_video_dev(
domain
)
SummaryWrite the video4linux devices. Parameters
dev_write_watchdog(
domain
)
SummaryWrite to watchdog devices. Parameters
dev_wx_raw_memory(
domain
)
SummaryWrite and execute raw memory devices (e.g. /dev/mem). Parameters
|
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0115 ]-- |