
link /etc/sysconfig/foo -> /etc/foo.conf,
❼
/bin/mount
ux,
/dev/{,u}
❽
random
r,
/etc/ld.so.cache
r,
/etc/foo/*
r,
/lib/ld-*.so*
mr,
/lib/lib*.so*
mr,
/proc/[0-9]**
r,
/usr/lib/**
mr,
/tmp/
❾
r,
/tmp/foo.pid
wr,
/tmp/foo.*
lrw,
/@{HOME}
❿
/.foo_file
rw,
/@{HOME}/.foo_lock
kw,
owner
11
/shared/foo/** rw,
/usr/bin/foobar
cx,
12
/bin/**
px -> bin_generic,
13
# a comment about foo's local (children)profile for /usr/bin/foobar.
profile /usr/bin/foobar
14
{
/bin/bash
rmix,
/bin/cat
rmix,
/bin/more
rmix,
/var/log/foobar*
rwl,
/etc/foobar
r,
}
# foo's hat, bar.
^bar
15
{
/lib/ld-*.so*
mr,
/usr/bin/bar
px,
/var/spool/*
rwl,
}
}
❶
This loads a file containing variable definitions.
❷
The normalized path to the program that is confined.
❸
The curly braces (
{}
) serve as a container for include statements, subprofiles,
path entries, capability entries, and network entries.
❹
This directive pulls in components of AppArmor profiles to simplify profiles.
❺
Capability entry statements enable each of the 29 POSIX.1e draft capabilities.
❻
A directive determining the kind of network access allowed to the application.
For details, refer to
Section 21.5, “Network Access Control”
(page 245).
Profile Components and Syntax
239
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......