On Wed, Nov 21, 2012 at 09:36:24AM -0800, John Johansen wrote: > On 11/21/2012 06:43 AM, Steve Beattie wrote: > > Acked-By: Steve Beattie <[email protected]> though a comment > > explaining why you're manipulating perms.allow might be nice. > > > sorry that my explanation didn't help. I'll try again > > policy granted the exec so the MAY_EXEC in perms.allow is set > however the search for a matching profile failed, and we of course > want to reject and audit this.
Sorry, you misunderstand the gist of my remark. I got what was happening, especially after I went and looked at the aa_audit_file() implementation; I just wanted a comment in the code to explain it, so that in six months (hours is probably a more accurate time estimate) when I've forgotten the reason, an inline explanation as to the manipulation of allows.perm would make sense. -- Steve Beattie <[email protected]> http://NxNW.org/~steve/
signature.asc
Description: Digital signature
-- AppArmor mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor
