Policy for deepin_perm_control and related programs.
false
Let dpkg can upgrade package.
false
whether init process can disable security service.
true
whether init process can enable security service.
false
enable sysadm can gdb security service.
true
enable file audit.
false
enable process audit.
false
enable socket audit.
true
enable process unkillable.
false
open app networking control.
false
deepin gdb flag.
false
open developer mode of usec.
true
use failsafe context directly when root login.
allow domain to access all security resources.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow domain to access all sensitive resources.
allow $1 to access downstream network.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow domain to access all system resources.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow domain to access camera resource.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow domain to access microphone resource.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow specific domain to access network.
Parameter: | Description: |
---|---|
domain |
Domain allow access. |
allow specific domain to access security service.
Let $1 can be write.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified domain usable for the deepin_app_access_camera_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_app_access_camera_domain. |
Make the specified domain usable for the deepin_app_access_microphone_domain.
Grant the $1_t domains access camera resource by condition
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_app_access_microphone_domain. |
Make the specified domain usable for the deepin_app_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_app_domain. |
Make the specified type usable for the deepin_app_private_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_app_private_file_type. |
Make the specified type usable for the deepin_camera_resource_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_camera_resource_type. |
Make the specified type usable for the deepin_controlled_database_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_database_type. |
Make the specified type usable for the deepin_controlled_dbus_domain.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_dbus_domain. |
Make the specified type usable for the deepin_controlled_domain.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_domain. |
Make the specified type usable for the deepin_controlled_ptrace_domain.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_ptrace_domain. |
Make the specified type usable for the deepin_controlled_resource_domain.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_resource_domain. |
Make the specified type usable for the deepin_controlled_resource_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_resource_type. |
Make the specified type usable for the deepin_controlled_service.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_controlled_service. |
allow specific domain to send dbus to security enhance.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for the deepin_deletable_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_deletable_file_type. |
Make the specified type usable for the deepin_exec_controlled_resource_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_exec_controlled_resource_type. |
let exec file writable.
Let $1 be unkillable.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for the deepin_executable_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_executable_file_type. |
Make the specified type usable for the deepin_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_file_type. |
allow specific domain to manage all files which were labeled to deepin_sidtwo_type.
Allow $1 to access security service.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
allow specific domain to manage all files which were labeled to deepin_wall_paper_resource_type.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for the deepin_microphone_resource_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_microphone_resource_type. |
Make the specified domain usable for the deepin_package_manage_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_package_manage_domain. |
Execute a domain transition to run deepin permission manager.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
let domain unkillable.
Grant the $1_t domains access microphone resource by condition
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type usable for the deepin_read_controlled_resource_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_read_controlled_resource_type. |
Make the specified type usable for the deepin_readable_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_readable_file_type. |
Make the specified domain usable for the deepin_sec_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_sec_domain. |
Make the specified domain usable for the deepin_security_server_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_security_server_domain. |
Execute a domain transition to run deepin security verify.
Allow $1 to manage deepin_wall_paper_resource_type.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Make the specified type usable for the deepin_sidtwo_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_sidtwo_type. |
Make the specified domain usable for the deepin_sys_domain.
Parameter: | Description: |
---|---|
domain |
Type to be used for deepin_sys_domain. |
Make the specified type usable for the deepin_usaudit_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_usaudit_file_type. |
Make the specified type usable for the deepin_usaudit_process_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_usaudit_process_type. |
Make the specified type usable for the deepin_usaudit_socket_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_usaudit_socket_type. |
Make the specified type usable for the deepin_usaudit_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_usaudit_type. |
Make the specified type usable for the deepin_wall_paper_resource_type.
Allow $1 to manage deepin_sidtwo_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_wall_paper_resource_type. |
Make the specified type usable for the deepin_writable_file_type.
Parameter: | Description: |
---|---|
type |
Type to be used for deepin_writable_file_type. |