2
0
mirror of https://gitlab.com/apparmor/apparmor synced 2025-08-30 13:58:22 +00:00
Georgia Garcia dc48e1417d parser: don't add mediation classes to unconfined profiles
Adding mediation classes in unconfined profiles caused nested profiles
to be mediated, inside a container for example.

As a first step, skip the addition of mediation classes into the dfa.
The creation of unprivileged user namespaces is an exception, where we
always want to mediate it.

Fixes: https://bugs.launchpad.net/apparmor/+bug/2067900

Signed-off-by: Georgia Garcia <georgia.garcia@canonical.com>
2024-06-13 15:22:31 -03:00
..
2024-04-15 16:32:16 -03:00
2023-07-10 20:04:53 -07:00
2024-03-29 10:52:25 +01:00
2024-03-29 10:57:33 +01:00
2023-07-10 20:04:53 -07:00
2023-03-29 10:45:44 -07:00
2021-12-05 18:16:53 +01:00
2024-04-15 16:32:16 -03:00
2023-07-07 17:38:47 -07:00
2024-04-15 16:32:16 -03:00
2020-10-11 12:22:23 +02:00
2024-04-15 16:32:16 -03:00
2024-04-15 16:32:16 -03:00
2023-07-10 20:04:53 -07:00
2013-09-27 16:16:37 -07:00
2023-07-10 18:01:32 -03:00

The apparmor_parser allows you to add, replace, and remove AppArmor
policy through the use of command line options. The default is to add.
`apparmor_parser --help` shows what the command line options are.

You can also find more information at https://wiki.apparmor.net

-- The AppArmor development team