
21.8 Execute Modes
Execute modes, also named profile transitions, consist of the following modes:
Discrete profile execute mode
px
Discrete local profile execute mode
cx
Unconstrained execute mode
ux
Inherit execute mode
ix
Allow
PROT_EXEC
with
mmap(2)
calls
m
21.8.1 Discrete Profile Execute Mode (px)
This mode requires that a discrete security profile is defined for a resource executed at
an AppArmor domain transition. If there is no profile defined, the access is denied.
WARNING: Using the Discrete Profile Execute Mode
px
does not scrub the environment of variables such as
LD_PRELOAD
. As a
result, the calling domain may have an undue amount of influence over the
called item.
Incompatible with
Ux
,
ux
,
Px
, and
ix
.
21.8.2 Discrete Local Profile Execute Mode
(cx)
As
px
, but instead of searching the global profile set,
cx
only searches the local profiles
of the current profile. This profile transition provides a way for an application to have
alternate profiles for helper applications.
252
Security Guide
Summary of Contents for LINUX ENTERPRISE DESKTOP 11
Page 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Page 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Page 10: ......
Page 29: ...Part I Authentication...
Page 30: ......
Page 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Page 126: ......
Page 127: ...Part II Local Security...
Page 128: ......
Page 158: ......
Page 173: ...Part III Network Security...
Page 174: ......
Page 194: ......
Page 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Page 210: ......
Page 228: ......
Page 229: ...Part IV Confining Privileges with Novell AppArmor...
Page 230: ......
Page 274: ......
Page 300: ......
Page 328: ......
Page 340: ......
Page 342: ......
Page 386: ......
Page 387: ...Part V The Linux Audit Framework...
Page 388: ......