| Object class | Permission | Domain | Type |
| netlink_audit_socket | nlmsg_read | domain | self |
| nlmsg_readpriv |
| Object class | Permission | Domain | Type |
| netlink_audit_socket | nlmsg_relay | domain | self |
| Object class | Permission | Domain | Type |
| netlink_audit_socket | nlmsg_write | domain | self |
| Object class | Permission | Domain | Type |
| system | syslog_console | domain | kernel_t |
| syslog_mod |
| Object class | Permission | Domain | Type |
| capability | sys_module | domain | self |
| Object class | Permission | Domain | Type |
| netlink_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_route_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| nlmsg_read | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_firewall_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_firewall_socket | nlmsg_write | domain | self |
| netlink_tcpdiag_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_tcpdiag_socket | nlmsg_read | domain | self |
| netlink_nflog_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_xfrm_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_xfrm_socket | nlmsg_read | domain | self |
| nlmsg_write | |||
| netlink_selinux_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_audit_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_dnrt_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write | |||
| netlink_kobject_uevent_socket | accept | domain | self |
| append | |||
| bind | |||
| connect | |||
| create | |||
| getattr | |||
| getopt | |||
| ioctl | |||
| listen | |||
| lock | |||
| name_bind | |||
| read | |||
| recv_msg | |||
| recvfrom | |||
| relabelfrom | |||
| relabelto | |||
| send_msg | |||
| sendto | |||
| setattr | |||
| setopt | |||
| shutdown | |||
| write |
| Object class | Permission | Domain | Type |
| blk_file | relabelfrom | domain | file_type |
| chr_file | relabelto | fs_type | |
| dir | setattr | ||
| fifo_file | |||
| file | |||
| lnk_file | |||
| sock_file |
| Object class | Permission | Domain | Type |
| blk_file | relabelfrom | domain | writable_type |
| chr_file | relabelto | ||
| dir | |||
| fifo_file | |||
| file | |||
| lnk_file | |||
| sock_file | |||
| process | setfscreate | domain | self |
| Object class | Permission | Domain | Type |
| dir | getattr | domain | security_t |
| read | |||
| search | |||
| file | getattr | domain | security_t |
| read | |||
| security | check_context | domain | security_t |
| compute_av | |||
| compute_create | |||
| compute_relabel | |||
| compute_user |
| Object class | Permission | Domain | Type |
| security | setenforce | domain | security_t |
| Object class | Permission | Domain | Type |
| security | load_policy | domain | security_t |
| Object class | Permission | Domain | Type |
| security | setsecparam | domain | security_t |
| Object class | Permission | Domain | Type |
| capability | mknod | domain | self |
| blk_file | create | domain | writable_type |
| chr_file | link | ||
| rename | |||
| unlink |
| Object class | Permission | Domain | Type |
| dir | getattr | domain | file_type |
| read | |||
| search | |||
| blk_file | getattr | domain | file_type |
| chr_file | |||
| dir | |||
| fifo_file | |||
| file | |||
| lnk_file | |||
| sock_file | |||
| lnk_file | read | domain | file_type |
| Object class | Permission | Domain | Type |
| blk_file | getattr | domain | file_type |
| chr_file | ioctl | ||
| dir | lock | ||
| fifo_file | read | ||
| file | |||
| lnk_file | |||
| sock_file |
| Object class | Permission | Domain | Type |
| blk_file | append | domain | file_type |
| chr_file | create | ||
| dir | link | ||
| fifo_file | rename | ||
| file | setattr | ||
| lnk_file | unlink | ||
| sock_file | write | ||
| dir | reparent | domain | file_type |
| rmdir |
| Object class | Permission | Domain | Type |
| capability | net_admin | domain | self |
| netlink_route_socket | nlmsg_write | domain | self |
| Object class | Permission | Domain | Type |
| capability | dac_override | domain | self |
| Object class | Permission | Domain | Type |
| capability | dac_read_search | domain | self |
| Object class | Permission | Domain | Type |
| capability | linux_immutable | domain | self |
| Object class | Permission | Domain | Type |
| file | quotaon | domain | file_type |
| filesystem | quotamod | domain | fs_type |
| Object class | Permission | Domain | Type |
| dir | mounton | domain | file_type |
| filesystem | mount | domain | fs_type |
| remount | |||
| unmount |
| Object class | Permission | Domain | Type |
| capability | sys_rawio | domain | self |
| Object class | Permission | Domain | Type |
| capability | sys_chroot | domain | self |
| Object class | Permission | Domain | Type |
| dir | add_name | domain | file_t |
| getattr | unlabeled_t | ||
| ioctl | |||
| lock | |||
| read | |||
| remove_name | |||
| reparent | |||
| rmdir | |||
| search | |||
| blk_file | append | domain | file_t |
| chr_file | create | unlabeled_t | |
| dir | getattr | ||
| fifo_file | ioctl | ||
| file | link | ||
| lnk_file | lock | ||
| sock_file | read | ||
| rename | |||
| setattr | |||
| unlink | |||
| write | |||
| file | execute | domain | file_t |
| execute_no_trans | unlabeled_t |
| Object class | Permission | Domain | Type |
| capability | sys_resource | domain | self |
| Object class | Permission | Domain | Type |
| capability | sys_admin | domain | self |
| Object class | Permission | Domain | Type |
| capability | sys_tty_config | domain | self |