On Wed, Sep 18, 2013 at 10:46:26PM -0700, Steve Beattie wrote:
> In this case, the behavior with capabilities is mimicking the already
> accepted behavior for file rules, which is that deny rules override
> allow rules (even ones without the 'allow' keyword).

Excellent, thanks for the description and examples. It might still be
confusing but at least it is consistently confusing. :)

> Here's v3 of the patch. I've added some behavioral tests around
> overlapping the allow and deny keywords to the capabilities.sh tests.

Zounds, generating that must have been a royal headache. :) But it looked
good, at least for as long as I could focus on it.

> Subject: add optional allow prefix to the language
> From: John Johansen <[email protected]>

Acked-by: Seth Arnold <[email protected]>

Thanks!

Attachment: signature.asc
Description: Digital signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to