One or more of the following component types can be queried. If no expressions are provided, policy
statistics will be printed.
-a [ATTR], --attribute [ATTR]
Print a list of type attributes or, if ATTR is provided, print the named attribute. With -x,
print a list of types assigned to each displayed attribute.
-b [BOOL], --bool [BOOL]
Print a list of Booleans or, if BOOL is provided, print the named boolean. With -x, print the
statement of each displayed conditional boolean.
-c [CLASS], --class [CLASS]
Print a list of object classes or, if CLASS is provided, print the named object class. With -x,
print a list of permissions for each displayed object class.
-r [ROLE], --role [ROLE]
Print a list of roles or, if NAME is provided, print the named role. With -x, print the statement
for each displayed role.
-t [TYPE], --type [TYPE]
Print a list of types or, if TYPE is provided, print the named type. With -x, print a list of
attributes which include each displayed type.
-u [USER], --user [USER]
Print a list of users or, if USER is provided, print the named user. With -x, print a list of
statement for each displayed user.
--category [CAT]
Print a list of categories or, if CAT is provided, print the named category. With -x, print a
list of sensitivities with which each displayed category may be associated.
--common [COMMON]
Print a list of common permission sets or, if COMMON is provided, print the named common. With
-x, print a list of permissions in the set.
--constrain [CLASS]
Print a list of constraints and MLS constraints statements or, if CLASS is provided, print all
constraints for the named object class. There is no expanded information for this component.
--default [CLASS]
Print a list of default_* statements or, if CLASS is provided, print all default_* statements for
the named object class. There is no expanded information for this component.
--fs_use [FS_TYPE]
Print a list of fs_use_* statements or, if FS_TYPE is provided, print the statement for the named
filesystem type. There is no expanded information for this component.
--genfscon [FS_TYPE]
Print a list of genfscon statements or, if FS_TYPE is provided, print the statement for the named
filesystem type. There is no expanded information for this component.
--ibpkeycon [PKEY[-PKEY]]
Print a list of InfiniBand parition key contexts.
--ibendportcon [NAME]
Print a list of InfiniBand endport contexts.
--initialsid [NAME]
Print a list of initial SIDs or, if NAME is provided, print the named initial SID. With -x, print
the context assigned to each displayed SID.
--netifcon [DEVICE]
Print a list of netif contexts or, if DEVICE is provided, print the named statement for the
interface. There is no expanded information for this component.
--nodecon [ADDR]
Print a list of node contexts or, if ADDR is provided, print the named statement for the node with
address. There is no expanded information for this component.
--permissive [TYPE]
Print permissive types or, if TYPE is specified, print the named statement if it is permissive.
There is no expanded information for this component.
--polcap [NAME]
Print policy capabilities or, if NAME is specified, print the named capability, if enabled. With
-x, print the statement.
--portcon [PORTNUM[-PORTNUM]]
Print a list of port contexts or, if PORT or PORT range is provided, print the named statement for
the port/port range. There is no expanded information for this component.
--sensitivity [SENS]
Print a list of sensitivities or, if SENS is provided, print the named sensitivity. With -x,
print the statement for each sensitivity.
--typebounds [BOUND_TYPE]
Print a list of typebounds statements or, if BOUND_TYPE is provided, print the statement for the
named bound type. There is no expanded information for this component.
--validatetrans [CLASS]
Print a list of validatetrans and MLS validatetrans rules or, if CLASS is provided, print all
constraints for the named object class. There is no expanded information for this component.
--all Print all components.
XenComponentQueries:
--ioportcon
Print all ioportcon statements.
--iomemcon
Print all iomemcon statements.
--pcidevicecon
Print all pcidevicecon statements.
--pirqcon
Print all pirqcon statements.
--devicetreecon
Print all devicetreecon statements.