Re: [apparmor] [RFC] Apparmor: Add support for attaching profiles via xattr presence and value

2017-12-08 Thread Matthew Garrett
On Fri, Dec 8, 2017 at 2:06 PM, Matthew Garrett wrote: > On Tue, Nov 28, 2017 at 5:45 PM, Seth Arnold > wrote: >> Hello Matthew, thanks for this; I'll let John comment on the larger design >> of the patch, I'll just nitpick one little piece: >> >> On Tue, Nov 28, 2017 at 04:08:15PM -0800, Matthe

Re: [apparmor] [RFC] Apparmor: Add support for attaching profiles via xattr presence and value

2017-12-08 Thread Matthew Garrett
On Tue, Nov 28, 2017 at 5:45 PM, Seth Arnold wrote: > Hello Matthew, thanks for this; I'll let John comment on the larger design > of the patch, I'll just nitpick one little piece: > > On Tue, Nov 28, 2017 at 04:08:15PM -0800, Matthew Garrett wrote: >> + kzfree(profile->xattrs); >> + kzfre

Re: [apparmor] IPC and sockets

2017-12-08 Thread John Johansen
On 12/08/2017 08:20 AM, Viacheslav Salnikov wrote: > Hello, > > First of all, I googled and experimented. Didn't work out so well. > > I want to ensure that communication through unix socket is monitored by > apparmor. > What should I do to make this happen? > As Seth mentioned you will need a

Re: [apparmor] IPC and sockets

2017-12-08 Thread Seth Arnold
On Fri, Dec 08, 2017 at 06:20:01PM +0200, Viacheslav Salnikov wrote: > I want to ensure that communication through unix socket is monitored by > apparmor. > What should I do to make this happen? Hello Viacheslav, This is actually slightly complicated to answer: - Different kernels will have diff

[apparmor] IPC and sockets

2017-12-08 Thread Viacheslav Salnikov
Hello, First of all, I googled and experimented. Didn't work out so well. I want to ensure that communication through unix socket is monitored by apparmor. What should I do to make this happen? Hope you will help me with that. Thanks. -- AppArmor mailing list AppArmor@lists.ubuntu.com Modify s