diff options
author | John Johansen <john.johansen@canonical.com> | 2013-07-11 00:12:43 -0400 |
---|---|---|
committer | John Johansen <john.johansen@canonical.com> | 2013-08-14 14:42:07 -0400 |
commit | 038165070aa55375d4bdd2f84b34a486feca63d6 (patch) | |
tree | 327014e8b5120a0ccc66418159c72f769e9b174d /security/apparmor/policy.c | |
parent | 8651e1d6572bc2c061073f05fabcd7175789259d (diff) |
apparmor: allow setting any profile into the unconfined state
Allow emulating the default profile behavior from boot, by allowing
loading of a profile in the unconfined state into a new NS.
Signed-off-by: John Johansen <john.johansen@canonical.com>
Acked-by: Seth Arnold <seth.arnold@canonical.com>
Diffstat (limited to 'security/apparmor/policy.c')
-rw-r--r-- | security/apparmor/policy.c | 6 |
1 files changed, 4 insertions, 2 deletions
diff --git a/security/apparmor/policy.c b/security/apparmor/policy.c index 7a80b0c7e0ce..2e4e2ecb25bc 100644 --- a/security/apparmor/policy.c +++ b/security/apparmor/policy.c | |||
@@ -96,6 +96,7 @@ const char *const profile_mode_names[] = { | |||
96 | "enforce", | 96 | "enforce", |
97 | "complain", | 97 | "complain", |
98 | "kill", | 98 | "kill", |
99 | "unconfined", | ||
99 | }; | 100 | }; |
100 | 101 | ||
101 | /** | 102 | /** |
@@ -290,8 +291,9 @@ static struct aa_namespace *alloc_namespace(const char *prefix, | |||
290 | if (!ns->unconfined) | 291 | if (!ns->unconfined) |
291 | goto fail_unconfined; | 292 | goto fail_unconfined; |
292 | 293 | ||
293 | ns->unconfined->flags = PFLAG_UNCONFINED | PFLAG_IX_ON_NAME_ERROR | | 294 | ns->unconfined->flags = PFLAG_IX_ON_NAME_ERROR | |
294 | PFLAG_IMMUTABLE | PFLAG_NS_COUNT; | 295 | PFLAG_IMMUTABLE | PFLAG_NS_COUNT; |
296 | ns->unconfined->mode = APPARMOR_UNCONFINED; | ||
295 | 297 | ||
296 | /* ns and ns->unconfined share ns->unconfined refcount */ | 298 | /* ns and ns->unconfined share ns->unconfined refcount */ |
297 | ns->unconfined->ns = ns; | 299 | ns->unconfined->ns = ns; |