- allow
- allowx
- auditallow
- auditallowx
- block
- blockabstract
- boolean
- booleanif
- category
- categoryalias
- categoryaliasactual
- categoryorder
- categoryset
- class
- classcommon
- classmap
- classmapping
- classorder
- classpermission
- classpermissionset
- common
- constrain
- context
- defaultrange
- defaultrole
- defaulttype
- defaultuser
- devicetreecon
- dontaudit
- dontauditx
- expandtypeattribute
- false
- filecon
- fsuse
- genfscon
- handleunknown
- ibendportcon
- ibpkeycon
- ioctl
- iomemcon
- ioportcon
- ipaddr
- level
- levelrange
- mls
- mlsconstrain
- mlsvalidatetrans
- netifcon
- neverallow
- neverallowx
- nodecon
- optional
- pcidevicecon
- perm
- permissionx
- pirqcon
- policycap
- portcon
- rangetransition
- role
- roleallow
- roleattribute
- roleattributeset
- rolebounds
- roletransition
- roletype
- selinuxuser
- selinuxuserdefault
- sensitivity
- sensitivityalias
- sensitivityaliasactual
- sensitivitycategory
- sensitivityorder
- sid
- sidcontext
- sidorder
- true
- tunable
- tunableif
- type
- typealias
- typealiasactual
- typeattribute
- typeattributeset
- typebounds
- typechange
- typemember
- typepermissive
- typetransition
- unordered
- user
- userattribute
- userattributeset
- userbounds
- userlevel
- userprefix
- userrange
- userrole
- validatetrans
- blockinherit
- call
- in
- macro
- and
- dom
- domby
- eq
- incomp
- neq
- not
- or
- range
- xor
- *
- all
- dccp
- false
- h1
- h2
- l1
- l2
- object_r
- r1
- r2
- r3
- sctp
- self
- t1
- t2
- t3
- tcp
- true
- u1
- u2
- u3
- udp