On Mon, Jun 22, 2015 at 11:00:01AM -0700, John Johansen wrote: > Currently rules are added to the expression tree in order, and then > tree simplification and factoring is done. This forces simplification > to "search" through the tree to find rules with the same permissions > during right factoring, which dependent on ordering of factoring may > not be able to group all rules of the same permissions. > > Instead of having tree factoring do the work to regroup rules with the > same permissions, pregroup them as part of the expr tree construction. > And only build the full tree when the dfa is constructed.
My testing of this patch did uncover one problem with incremental builds, a missing make dependency on the libapparmor_re/aare_rules.h header. Signed-off-by: Steve Beattie <[email protected]> --- parser/Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) Index: b/parser/Makefile =================================================================== --- a/parser/Makefile +++ b/parser/Makefile @@ -213,7 +213,7 @@ parser_include.o: parser_include.c parse parser_merge.o: parser_merge.c parser.h profile.h $(CXX) $(EXTRA_CFLAGS) -c -o $@ $< -parser_regex.o: parser_regex.c parser.h profile.h libapparmor_re/apparmor_re.h $(APPARMOR_H) +parser_regex.o: parser_regex.c parser.h profile.h libapparmor_re/apparmor_re.h libapparmor_re/aare_rules.h $(APPARMOR_H) $(CXX) $(EXTRA_CFLAGS) -c -o $@ $< parser_symtab.o: parser_symtab.c parser.h -- Steve Beattie <[email protected]> http://NxNW.org/~steve/
signature.asc
Description: Digital signature
-- AppArmor mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor
