On Fri, Aug 12, 2016 at 11:03:33PM +0200, Christian Boltz wrote: > This is the correct way of doing AARE matches. However, this check is > more strict when matching against an AARE containing wildcards etc. > (which can "by luck" match when doing str matching) > > To avoid breaking DbusRule, PtraceRule and SignalRule (especially their > tests), introduce _is_covered_aare_compat() which keeps the previous > behaviour of doing str matching, and use it in these classes. > > On the long term, _is_covered_aare_compat() needs to go away, but doing > the changes needed in DbusRule, PtraceRule and SignalRule (or ideally > just in AARE) are out of scope for the FileRule patch series.
(Refactorings or other cleanups that occur because adding a rule type exposes issues with other types of rules are certainly what I would consider in scope for a patch series.) > [ 29-aare-covered-regex.diff ] Acked-by: Steve Beattie <[email protected]>. Thanks! -- Steve Beattie <[email protected]> http://NxNW.org/~steve/
signature.asc
Description: PGP signature
-- AppArmor mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/apparmor
