Modifying master for Tomoyo process jailing; Adding basic policies for Tomoyo environ...
[iot2.git] / localconfig / tomoyo / LabRoom.tomoyo.pol
1 <kernel> /usr/sbin/sshd /bin/bash /home/iotuser/iot2/iotjava/iotruntime/LabRoom<object-id>.sh /usr/bin/java
2 use_profile 3
3 use_group 0
4
5 misc env MAIL
6 misc env SSH_CLIENT
7 misc env USER
8 misc env SHLVL
9 misc env HOME
10 misc env OLDPWD
11 misc env LOGNAME
12 misc env _
13 misc env XDG_SESSION_ID
14 misc env PATH
15 misc env XDG_RUNTIME_DIR
16 misc env LANG
17 misc env SHELL
18 misc env PWD
19 misc env SSH_CONNECTION
20 file read /etc/ld.so.preload
21 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/jli/libjli.so
22 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/jvm.cfg
23 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/client/libjvm.so
24 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/libverify.so
25 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/libjava.so
26 network unix stream connect /var/run/nscd/socket
27 file read /etc/nsswitch.conf
28 file read /etc/passwd
29 file create /tmp/hsperfdata_iotuser/\* 0600
30 file read/write/unlink/truncate /tmp/hsperfdata_iotuser/\*
31 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/libzip.so
32 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/meta-index
33 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/rt.jar
34 file read /sys/devices/system/cpu/online
35 file read /usr/lib/locale/locale-archive
36 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/ext/meta-index
37 file write/truncate /home/iotuser/.oracle_jre_usage/81970c018e7540cf.timestamp
38 file read /usr/share/java/servlet-api-2.5.jar
39 file read /usr/share/java/asm-all-5.0.3.jar
40 file read /usr/share/java/BoofCV-WebcamCapture-0.21.jar
41 file read /usr/share/java/core-0.28.jar
42 file read /usr/share/java/jurt-4.3.3.jar
43 file read /usr/share/java/ridl-4.3.3.jar
44 file read /usr/share/java/unoloader.jar
45 file read /usr/share/java/BoofCV-xuggler-0.21-sources.jar
46 file read /usr/share/java/xpp3_min-1.1.4c.jar
47 file read /usr/share/java/simple-0.29.jar
48 file read /usr/share/java/BoofCV-recognition-0.21-sources.jar
49 file read /usr/share/java/BoofCV-feature-0.21.jar
50 file read /usr/share/java/jsp-api-2.1.jar
51 file read /usr/share/java/mysql-connector-java-5.1.39.jar
52 file read /usr/share/java/BoofCV-jcodec-0.21-sources.jar
53 file read /usr/share/java/BoofCV-visualize-0.21-sources.jar
54 file read /usr/share/java/BoofCV-WebcamCapture-0.21-sources.jar
55 file read /usr/share/java/GeoRegression-georegression-0.9-sources.jar
56 file read /usr/share/java/el-api-2.1.jar
57 file read /usr/share/java/unoil-4.3.3.jar
58 file read /usr/share/java/GeoRegression-experimental-0.9-sources.jar
59 file read /usr/share/java/xmlpull-1.1.3.1.jar
60 file read /usr/share/java/georegression-0.10.jar
61 file read /usr/share/java/BoofCV-android-0.21.jar
62 file read /usr/share/java/BoofCV-ip-0.21.jar
63 file read /usr/share/java/BoofCV-android-0.21-sources.jar
64 file read /usr/share/java/hsqldb1.8.0-1.8.0.10+dfsg.jar
65 file read /usr/share/java/BoofCV-sfm-0.21.jar
66 file read /usr/share/java/BoofCV-visualize-0.21.jar
67 file read /usr/share/java/BoofCV-geo-0.21-sources.jar
68 file read /usr/share/java/core-0.29.jar
69 file read /usr/share/java/libintl.jar
70 file read /usr/share/java/BoofCV-io-0.21-sources.jar
71 file read /usr/share/java/BoofCV-io-0.21.jar
72 file read /usr/share/java/hsqldbutil1.8.0-1.8.0.10+dfsg.jar
73 file read /usr/share/java/dense64-0.28.jar
74 file read /usr/share/java/BoofCV-xuggler-0.21.jar
75 file read /usr/share/java/BoofCV-learning-0.21.jar
76 file read /usr/share/java/BoofCV-sfm-0.21-sources.jar
77 file read /usr/share/java/zip4j_1.3.2.jar
78 file read /usr/share/java/ddogleg-0.8-SNAPSHOT.jar
79 file read /usr/share/java/BoofCV-openkinect-0.21.jar
80 file read /usr/share/java/dense64-0.29.jar
81 file read /usr/share/java/juh-4.3.3.jar
82 file read /usr/share/java/jl1.0.1.jar
83 file read /usr/share/java/BoofCV-jcodec-0.21.jar
84 file read /usr/share/java/BoofCV-ip-0.21-sources.jar
85 file read /usr/share/java/GeoRegression-experimental-0.9.jar
86 file read /usr/share/java/GeoRegression-georegression-0.9.jar
87 file read /usr/share/java/java-json.jar
88 file read /usr/share/java/ddogleg-0.9.jar
89 file read /usr/share/java/xstream-1.4.7.jar
90 file read /usr/share/java/BoofCV-geo-0.21.jar
91 file read /usr/share/java/java_uno.jar
92 file read /usr/share/java/BoofCV-calibration-0.21.jar
93 file read /usr/share/java/javac.jar
94 file read /usr/share/java/BoofCV-recognition-0.21.jar
95 file read /usr/share/java/checker.jar
96 file read /usr/share/java/BoofCV-feature-0.21-sources.jar
97 file read /usr/share/java/BoofCV-openkinect-0.21-sources.jar
98 file read /usr/share/java/equation-0.29.jar
99 file read /usr/share/java/simple-0.28.jar
100 file read /usr/share/java/BoofCV-learning-0.21-sources.jar
101 file read /usr/share/java/equation-0.28.jar
102 file read /usr/share/java/BoofCV-calibration-0.21-sources.jar
103 file read /home/iotuser/iot2/iotjava/iotruntime/slave/IoTSlave.class
104 file read /home/iotuser/iot2/iotjava/iotruntime/IoTSlave.config
105 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/arm/libnet.so
106 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/net.properties
107 network inet stream connect ::ffff:<master-ip-address> <master-com-port>
108 file read /home/iotuser/iot2/iotjava/iotruntime/master/RuntimeOutput.class
109 file read /home/iotuser/iot2/iotjava/iotruntime/messages/MessageSendFile.class
110 file read /home/iotuser/iot2/iotjava/iotruntime/messages/Message.class
111 file read /home/iotuser/iot2/iotjava/iotruntime/messages/IoTCommCode.class
112 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/security/java.security
113 file read /usr/lib/jvm/jdk-8-oracle-arm32-vfp-hflt/jre/lib/jsse.jar
114 file read /dev/random
115 file read /dev/urandom
116 file read /home/iotuser/iot2/iotjava/iotruntime/slave/IoTSlave$3.class
117 file read /home/iotuser/iot2/iotjava/iotruntime/messages/MessageSimple.class
118 file create /home/iotuser/iot2/iotjava/iotruntime/LabRoom.jar 0666
119 file read/write /home/iotuser/iot2/iotjava/iotruntime/LabRoom.jar
120 file read /home/iotuser/iot2/iotjava/iotruntime/messages/MessageCreateObject.class
121 file read /home/iotuser/iot2/iotjava/iotcode/LabRoom/LabRoom.class
122 file read /home/iotuser/iot2/iotjava/iotcode/LabRoom/Room_Skeleton.class
123 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMIComm.class
124 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMICommServer.class
125 file read /home/iotuser/iot2/iotjava/iotcode/LabRoom/Room_Skeleton$1.class
126 file read /home/iotuser/iot2/iotjava/iotruntime/slave/IoTSlave$1.class
127 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMIComm$1.class
128 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMIComm$2.class
129 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMICommServer$1.class
130 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMICommServer$2.class
131 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMICommServer$3.class
132 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMIUtil.class
133 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTRMITypes.class
134 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTSocketServer.class
135 file read /home/iotuser/iot2/iotjava/iotrmi/Java/IoTSocket.class
136 network inet stream bind/listen :: <rmi-stub-port>
137 network inet stream bind/listen :: <rmi-reg-port>
138 file ioctl socket:[family=10:type=1:protocol=6] 0x541B