Policy for the kernel modules, kernel image, and bootloader.
Create, read and write the bootloader runtime data.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute bootloader and mkinitramfs in their domains.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
Execute bootloader in the caller domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Manage the bootloader temporary files in /tmp.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read the bootloader configuration file.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Execute bootloader interactively and do a domain transition to the bootloader domain.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed to transition. |
| role |
Role allowed access. |
Read and write the bootloader configuration file.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |
Read and write the bootloader temporary files in /tmp.
| Parameter: | Description: |
|---|---|
| domain |
Domain allowed access. |