false
Allow users to connect to console (s390)
false
Allow making the heap executable.
false
Allow making anonymous memory executable, e.g. for runtime-code generation or executable stack.
false
Allow making a modified private file mapping executable (text relocation).
false
Allow making the stack executable via mprotect. Also requires allow_execmem.
false
Enable polyinstantiated directory support.
false
Allow system to run with NIS
false
Enable reading of urandom for all domains.
This should be enabled when all programs are compiled with ProPolice/SSP stack smashing protection. All domains will be allowed to read from /dev/urandom.
false
Allow email client to various content. nfs, samba, removable devices, user temp and untrusted content files
false
Allow nfs to be exported read only
false
Allow nfs to be exported read/write.
false
Allow reading of default_t files.
false
Allow applications to read untrusted content If this is disallowed, Internet content has to be manually relabeled for read access to be granted
false
Support NFS home directories
false
Support SAMBA home directories
false
Allow users to run TCP servers (bind to ports and accept connection from the same domain and outside users) disabling this forces FTP passive mode and may change other protocols.
false
Allow applications to write untrusted content If this is disallowed, no Internet content will be stored.
false
Allow xen to manage nfs files