data:image/s3,"s3://crabby-images/12820/1282072ed175e49a455ff82949eafd410e1867f6" alt="Novell APPARMOR 1.2 Administration Manual Download Page 71"
Finally, you might want to grant the child process very powerful access by specifying
Unconfined. This writes
ux
into the parent profile so that when the child runs, it runs
without any Novell AppArmor profile being applied at all. This means running with
no protection and should only be used when absolutely required.
Subdomain.vim
A syntax coloring file for the vim text editor highlights various features of an Novell
AppArmor profile with colors. Using vim and the Novell AppArmor syntax mode for
vim, you can see the semantic implications of your profiles with color highlighting.
Use vim to view and edit your profile by typing vim at a terminal window.
To enable the syntax coloring when you edit a Novell AppArmor profile in vim, use
the commands
:syntax on
then
:set syntax=subdomain
. Alternatively, you
can place these lines in your
~/.vimrc
file:
syntax on
set modeline
set modelines=5
When you enable this feature, vim colors the lines of the profile for you:
Blue
#include
lines that pull in other Novell AppArmor rules and comments that
begin with
#
White
Ordinary read access lines
Brown
Capability statements and complain flags
Yellow
Lines that grant write access
Green
Lines that grant execute permission (either ix or px)
Red
Lines that grant unconfined access (ux)
Building Novell AppArmor Profiles
71
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......