mirror of
https://gitlab.com/apparmor/apparmor
synced 2025-08-22 01:57:43 +00:00
parser: Fix special casing for detached move mounts
MR: 1561 Added the ability to specify special a keyword to allow detached mounts. Unfortunately it updated remount to use the device and devbuffer when remounts current encoding doesn't support it. This caused the mount.sh regression test to fail in the following way. ``` $ sudo bash mount.sh [sudo] password for jj: using mount rules ... Error: mount failed. Test 'MOUNT (confined cap bind mount remount rprivate conflict)' was expected to 'pass'. Reason for failure 'FAIL: mount /tmp/sdtest.358520-12403-ASaOnn/mountpoint2 on /tmp/sdtest.358520-12403-ASaOnn/mountpoint failed - Permission denied' not supported by parser - skipping mount options=(nodirsync), Error: mount failed. Test 'MOUNT (confined cap mount remount option)' was expected to 'pass'. Reason for failure 'FAIL: mount /dev/loop40 on /tmp/sdtest.358520-12403-ASaOnn/mountpoint failed - Permission denied' Error: mount failed. Test 'MOUNT (confined cap mount remount)' was expected to 'pass'. Reason for failure 'FAIL: mount /dev/loop40 on /tmp/sdtest.358520-12403-ASaOnn/mountpoint failed - Permission denied' Error: mount passed. Test 'MOUNT (confined cap mount remount deny option)' was expected to 'fail' ``` Revert the change to remount. This fixes the regression failure. fa0746f2e parser: add special casing for detached move mounts Signed-off-by: John Johansen <john.johansen@canonical.com>
This commit is contained in:
parent
37666dd736
commit
89e8fe9c1c
@ -772,17 +772,8 @@ int mnt_rule::gen_policy_remount(Profile &prof, int &count,
|
||||
goto fail;
|
||||
vec[0] = mntbuf.c_str();
|
||||
} else {
|
||||
if (device && strcmp(device, "detached") == 0) {
|
||||
/* if (features_supports_detached_mount) ...
|
||||
* not needed because this is equiv to ""
|
||||
* which was preivously supported
|
||||
*
|
||||
* match nothing
|
||||
*/
|
||||
devbuf.clear();
|
||||
} else if (!clear_and_convert_entry(devbuf, device)) {
|
||||
if (!convert_entry(mntbuf, device))
|
||||
goto fail;
|
||||
}
|
||||
vec[0] = mntbuf.c_str();
|
||||
}
|
||||
/* skip device */
|
||||
|
Loading…
x
Reference in New Issue
Block a user