On Wed, Nov 21, 2012 at 09:36:24AM -0800, John Johansen wrote:
> On 11/21/2012 06:43 AM, Steve Beattie wrote:
> > Acked-By: Steve Beattie <[email protected]> though a comment
> > explaining why you're manipulating perms.allow might be nice.
> >
> sorry that my explanation didn't help. I'll try again
> 
> policy granted the exec so the MAY_EXEC in perms.allow is set
> however the search for a matching profile failed, and we of course
> want to reject and audit this.

Sorry, you misunderstand the gist of my remark. I got what was
happening, especially after I went and looked at the aa_audit_file()
implementation; I just wanted a comment in the code to explain it, so
that in six months (hours is probably a more accurate time estimate)
when I've forgotten the reason, an inline explanation as to the
manipulation of allows.perm would make sense.

-- 
Steve Beattie
<[email protected]>
http://NxNW.org/~steve/

Attachment: signature.asc
Description: Digital signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to