On Sat, Jul 04, 2015 at 08:46:34PM +0200, Christian Boltz wrote: > preamble: this is the 2.9 version of > 61-is_known_rule-check-directory-includes.diff. > > Since the patch "only" ignores include directories, the > 60-split-off-include_dir_filelist.diff patch is not really needed for > 2.9 - but it shouldn't hurt ;-) > > $subject ;-) > > Ignore include files that were not read before (= don't exist in > include[], which typically happens for #include <directory>) so that > the profile_known_*() functions don't crash. > > Note: Since the 2.9 code is too different, this patch only avoids the > crash, but doesn't ensure that the files in the included directory are > honored (which would need in a rewrite of the profile_known_*() > functions). > > BTW: I tested with a network log entry and hope the best for > profile_known_capability() ;-) > > References: https://bugs.launchpad.net/apparmor/+bug/1471425 > (includes reproducer) > > [ 61-2.9-profile_known_network-and-capability-fix-dir-include-crash.diff ]
Acked-by: Steve Beattie <[email protected]>. Thanks. -- Steve Beattie <[email protected]> http://NxNW.org/~steve/
signature.asc
Description: Digital signature
-- AppArmor mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor
