• A resource is requested by a profiled program that is not in the profile
(see
Figure 3.2, “Learning Mode Exception: Controlling Access to Spe-
cific Resources”
(page 32)). Allow or deny access to a specific resource.
• A program is executed by the profiled program and the security domain
transition has not been defined (see
Figure 3.3, “Learning Mode Exception:
Defining Execute Permissions for an Entry”
(page 33)). Define execute
permissions for an entry.
Each of these cases results in a series of questions that you must answer to
add the resource to the profile or to add the program to the profile. For an ex-
ample of each case, see
Figure 3.2, “Learning Mode Exception: Controlling
Access to Specific Resources”
(page 32) and
Figure 3.3, “Learning Mode
Exception: Defining Execute Permissions for an Entry”
(page 33). Subsequent
steps describe your options in answering these questions.
NOTE: Varying Processing Options
Depending on the type of entry processed, the available options vary.
Figure 3.2
Learning Mode Exception: Controlling Access to Specific Resources
32
Novell AppArmor Administration Guide