This section describes how to define the domain transition rules. In this form, you can create new domain transition rules and change the pre-defined domain transition rules. The screenshot is shown below.
If you want to add new domain transition rule, you have to select the "add new transition". If you want to change pre-defined domain transition rule, you have to select the "change transition".
The defined domain transition rules display is stratified. You can edit a transition rule by clicking a target domain name on the tree. Note that suitable one must be checked on the above radio button before clicking a domain name.
This form is displayed by selecting a domain name on the tree with "add new transition" checked. You can add a new transition rule with this form.
Specify a domain name to which source domain transits. You can't specify multiple domain names.
In this combo-box, the names of domains are listed. These domains are only the ones that are defined in the inter-configuration files. You can add the domain name to "domain name" field by selecting a domain name listed in this combo-box.
The name of the current domain is displayed here. This domain is the source domain in domain transition rule.
Specify the full-path of a program that is the trigger of domain transition. When the current domain executes this program, the domain of this program is transited to the new domain. If you specify a directory-path in this field, you can specify all programs under the directory as entry point.
By clicking this button, the new domain transition rule will be added to the inter-configuration files.
This form is displayed by selecting a domain name on the tree with "change transition" checked in the left pane. You can change pre-defined transition rules in this form. Note that you can change only the comment and the entrypoint of the domain transition rule.
The name of the domain to which the current domain transits is displayed.
In this field, the comment attached to the domain is displayed. This comment is the comment specified in Create new domain/role. You can edit this comment.
The name of the transit-from domain is displayed.
The full-path of a program that is a trigger of this domain transition is displayed. You can edit this value.
If you want to delete this domain transition rule, you should check this.
By clicking this button, the inter-configuration files are updated with the changes. If the above "delete this transition" check-box is checked, this transition rule will be deleted.