On Sat, Jul 04, 2015 at 08:46:34PM +0200, Christian Boltz wrote:
> preamble: this is the 2.9 version of 
> 61-is_known_rule-check-directory-includes.diff.
> 
> Since the patch "only" ignores include directories, the 
> 60-split-off-include_dir_filelist.diff patch is not really needed for 
> 2.9 - but it shouldn't hurt ;-)
> 
> $subject ;-)
> 
> Ignore include files that were not read before (= don't exist in
> include[], which typically happens for #include <directory>) so that
> the profile_known_*() functions don't crash.
> 
> Note: Since the 2.9 code is too different, this patch only avoids the
> crash, but doesn't ensure that the files in the included directory are
> honored (which would need in a rewrite of the profile_known_*()
> functions).
> 
> BTW: I tested with a network log entry and hope the best for
> profile_known_capability() ;-)
> 
> References: https://bugs.launchpad.net/apparmor/+bug/1471425
> (includes reproducer)
> 
> [ 61-2.9-profile_known_network-and-capability-fix-dir-include-crash.diff ]

Acked-by: Steve Beattie <[email protected]>. Thanks.

-- 
Steve Beattie
<[email protected]>
http://NxNW.org/~steve/

Attachment: signature.asc
Description: Digital signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to