Novell APPARMOR Admin Manual page 60

Hide thumbs Also See for APPARMOR:
Table of Contents

Advertisement

U s e r ' s G u i d e
page 69.
• Actual Path Name: This is the literal path that the program needs
access to so that it can run properly.
6. Once you select the path name or #include, you can process it as
an entry into the Novell AppArmor profile by clicking Allow or Deny.
If you are not satisfied with the directory path entry as it is dis-
played, you can also Glob or Edit it.
The following options are available to process the learning mode
entries and to build the profile:
• Press Enter: Accepts the entry highlighted with []. Press the
Enter key if you want to allow access to the selected directory path.
• "A"llow: Select Allow if you want to grant the program access to
the specified directory path entries. Novell AppArmor suggests file
p e r mi s s i o n a c c e s s . F o r mo r e i n f o r ma t i o n o n t h i s , r e f e r t o " File Per-
mission Access Modes" o n p a g e6 9
• "D"eny: Select Deny to prevent the program from accessing the
specified directory path entries. Novell AppArmor will then move on
to the next event.
• " N " e w : Prompts you to enter your own rule for this event, allow-
ing you to specify whatever form of regular expression you want. If
the expression you enter does not actually satisfy the event that
prompted the question in the first place, Novell AppArmor will ask
you for confirmation and let you re-enter the expression.
• "G"lob: Select Glob once once to modify the directory path (by
using wildcards) to include all files in the suggested entry directory.
When you select Glob twice, access will be granted to all files and
subdirectories beneath the one shown.
F o r mo r e i n f o r ma t i o n o n g l o b b i n g s y n t a x , r e f e r t o " Path Names and
Regular Expression Matching" o n p a g e6 9 .
• G l o b w / " E " x t : When you select Glob w/Ext, the original directory
path is modified while retaining the filename extension. With one
click, /etc/apache2/file.ext becomes /etc/apache2/*.ext, adding the
wildcard (asterisk) in place of the file name. This will allow the pro-
gram to access all files in the suggested directory that end with the
".ext" extension. When you select it twice, access will be granted to
all files (with the particular extension) and subdirectories beneath
the one shown.
• "E"dit: Select Edit to edit the highlighted line. The new line will
appear at the bottom of the list.
60

Advertisement

Table of Contents
loading

Table of Contents