On Tue, 2026-07-07 at 11:13 -0700, Ryan Lee via AppArmor wrote:
> This will be needed for introducing condref variants into
> policy.c:update_to_newest_parent.
> 

Acked-by: Georgia Garcia <[email protected]>
> Signed-off-by: Ryan Lee <[email protected]>
> ---
>  security/apparmor/include/policy.h | 23 +++++++++++++++++++++++
>  1 file changed, 23 insertions(+)
> 
> diff --git a/security/apparmor/include/policy.h 
> b/security/apparmor/include/policy.h
> index 240b2eba7687..2b210fc0dd9e 100644
> --- a/security/apparmor/include/policy.h
> +++ b/security/apparmor/include/policy.h
> @@ -324,6 +324,19 @@ static inline struct aa_profile 
> *aa_get_newest_profile(struct aa_profile *p)
>  {
>       return labels_profile(aa_get_newest_label(&p->label));
>  }
> +/**
> + * aa_get_newest_profile_condref - simple wrapper fn to wrap the label 
> version
> + * @p: profile (NOT NULL)
> + * @needput: returns whether the reference needs put
> + *
> + * Returns refcount to newest version of the profile (maybe @p)
> + *
> + * Requires: @p must be held with a valid refcount
> + */
> +static inline struct aa_profile *aa_get_newest_profile_condref(struct 
> aa_profile *p, bool *needput)
> +{
> +     return labels_profile(aa_get_newest_label_condref(&p->label, needput));
> +}
>  
>  static inline aa_state_t RULE_MEDIATES(struct aa_ruleset *rules,
>                                      unsigned char class)
> @@ -428,6 +441,16 @@ static inline void aa_put_profile(struct aa_profile *p)
>       if (p)
>               kref_put(&p->label.count.count, aa_label_kref);
>  }
> +/**
> + * aa_put_profile_condref - conditionally decrement refcount on profile @p
> + * @p: profile  (MAYBE NULL)
> + * @needput: whether to put the profile
> + */
> +static inline void aa_put_profile_condref(struct aa_profile *p, bool needput)
> +{
> +     if (unlikely(needput))
> +             aa_put_profile(p);
> +}
>  
>  static inline int AUDIT_MODE(struct aa_profile *profile)
>  {


Reply via email to