In progress of refining the Tomoyo policies for process jailing; will define a set...
[iot2.git] / localconfig / tomoyo / AmcrestCamera.tomoyo.pol
1 <kernel> /usr/sbin/sshd /bin/bash /home/iotuser/iot2/iotjava/iotruntime/<object-name>.sh /usr/bin/java
2 use_profile 3
3 use_group 0
4
5 misc env MAIL
6 misc env SSH_CLIENT
7 misc env USER
8 misc env SHLVL
9 misc env HOME
10 misc env OLDPWD
11 misc env LOGNAME
12 misc env _
13 misc env XDG_SESSION_ID
14 misc env PATH
15 misc env XDG_RUNTIME_DIR
16 misc env LANG
17 misc env SHELL
18 misc env PWD
19 misc env SSH_CONNECTION
20 file read /etc/ld.so.preload
21 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/\*.so
22 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/\*.cfg
23 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/client/\*.so
24 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/\*
25 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/\*.jar
26 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/ext/\*
27 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/security/\*
28 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/jli/\*.so
29 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/\*.jar
30 network unix stream connect /var/run/nscd/socket
31 file read /etc/nsswitch.conf
32 file read /etc/passwd
33 file create /tmp/hsperfdata_iotuser/\* 0600
34 file read/write/unlink/truncate /tmp/hsperfdata_iotuser/\*
35 file read /sys/devices/system/cpu/online
36 file read /usr/lib/locale/locale-archive
37 file write/truncate /home/iotuser/.oracle_jre_usage/\*cf.timestamp
38 file read /usr/share/java/\*.jar
39 file read /home/iotuser/iot2/iotjava/iotruntime/slave/\*.class
40 file read /home/iotuser/iot2/iotjava/iotruntime/\*.config
41 network inet stream connect ::ffff:<master-ip-address> <master-com-port>
42 file read /home/iotuser/iot2/iotjava/iotruntime/master/\*.class
43 file read /home/iotuser/iot2/iotjava/iotruntime/messages/\*.class
44 file read /dev/random
45 file read /dev/urandom
46 file create /home/iotuser/iot2/iotjava/iotruntime/AmcrestCamera.jar 0666
47 file read/write /home/iotuser/iot2/iotjava/iotruntime/AmcrestCamera.jar
48 file read /home/iotuser/iot2/iotjava/iotrmi/Java/\*.class
49 file ioctl socket:[family=10:type=1:protocol=6] 0x541B
50 file read /home/iotuser/iot2/iotjava/iotruntime/\*.class
51 file read /usr/share/locale/en_GB/LC_MESSAGES/libc.mo
52 file create /tmp/imageio\*.tmp 0600
53 file read/write/unlink /tmp/imageio\*.tmp
54 network inet stream bind/listen :: <rmi-stub-port>
55 network inet stream bind/listen :: <rmi-reg-port>