On Fri, Aug 12, 2016 at 11:03:33PM +0200, Christian Boltz wrote:
> This is the correct way of doing AARE matches. However, this check is
> more strict when matching against an AARE containing wildcards etc.
> (which can "by luck" match when doing str matching)
> 
> To avoid breaking DbusRule, PtraceRule and SignalRule (especially their
> tests), introduce _is_covered_aare_compat() which keeps the previous
> behaviour of doing str matching, and use it in these classes.
> 
> On the long term, _is_covered_aare_compat() needs to go away, but doing
> the changes needed in DbusRule, PtraceRule and SignalRule (or ideally
> just in AARE) are out of scope for the FileRule patch series.

(Refactorings or other cleanups that occur because adding a rule type
exposes issues with other types of rules are certainly what I would
consider in scope for a patch series.)

> [ 29-aare-covered-regex.diff ]

Acked-by: Steve Beattie <[email protected]>. Thanks!

-- 
Steve Beattie
<[email protected]>
http://NxNW.org/~steve/

Attachment: signature.asc
Description: PGP signature

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to