mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-30 13:58:22 +00:00
Add cux and CUx to PROFILE_MODE_RE
cux and CUx are valid exec permissions, so they should be accepted by validate_profile_mode() ;-) Acked-by: John Johansen <john.johansen@canonical.com> for trunk and 2.9
This commit is contained in:
@@ -2422,7 +2422,7 @@ def collapse_log():
|
||||
if not is_known_rule(aa[profile][hat], 'network', NetworkRule(family, sock_type)):
|
||||
log_dict[aamode][profile][hat]['netdomain'][family][sock_type] = True
|
||||
|
||||
PROFILE_MODE_RE = re.compile('^(r|w|l|m|k|a|ix|ux|px|pux|cx|pix|cix|Ux|Px|PUx|Cx|Pix|Cix)+$')
|
||||
PROFILE_MODE_RE = re.compile('^(r|w|l|m|k|a|ix|ux|px|pux|cx|pix|cix|cux|Ux|Px|PUx|Cx|Pix|Cix|CUx)+$')
|
||||
PROFILE_MODE_DENY_RE = re.compile('^(r|w|l|m|k|a|x)+$')
|
||||
|
||||
def validate_profile_mode(mode, allow, nt_name=None):
|
||||
|
Reference in New Issue
Block a user