On 03/17/2014 06:29 PM, [email protected] wrote:
> ptrace rules currently take the form of
>
>   ptrace [<ptrace_perms>] [<peer_profile_name>],
>   ptrace_perm := read|trace|readby|tracedby
>   ptrace_perms := ptrace_perm | '(' ptrace_perm+ ')'

I just mentioned that signal should use this:

   signal (send,receive) set=(kill) label=/profile/foo,


I think the same is true for ptrace. Ie:

  ptrace (readby) label=/profile/foo,

It is more explicit and hearkens to the peer=() syntax without adding something
meaningless and also keeps it consistent with 'signal'.

-- 
Jamie Strandboge                 http://www.ubuntu.com/

Attachment: signature.asc
Description: OpenPGP digital signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to