Execute Modes - Novell LINUX ENTERPRISE SERVER 11 - SECURITY Manual

Hide thumbs Also See for LINUX ENTERPRISE SERVER 11 - SECURITY:
Table of Contents

Advertisement

21.8 Execute Modes

Execute modes, also named profile transitions, consist of the following modes:
px
cx
ux
ix
m
21.8.1 Discrete Profile Execute Mode (px)
This mode requires that a discrete security profile is defined for a resource executed at
an AppArmor domain transition. If there is no profile defined, the access is denied.
WARNING: Using the Discrete Profile Execute Mode
px does not scrub the environment of variables such as LD_PRELOAD. As a
result, the calling domain may have an undue amount of influence over the
called item.
Incompatible with Ux, ux, Px, and ix.
21.8.2 Discrete Local Profile Execute Mode
As px, but instead of searching the global profile set, cx only searches the local profiles
of the current profile. This profile transition provides a way for an application to have
alternate profiles for helper applications.
252
Security Guide
Discrete profile execute mode
Discrete local profile execute mode
Unconstrained execute mode
Inherit execute mode
Allow PROT_EXEC with mmap(2) calls
(cx)

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the LINUX ENTERPRISE SERVER 11 - SECURITY and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

Suse linux enterprise server 11

Table of Contents