[apparmor] [PATCH 2/3] Fix permission mapping for change_profile onexec

2012-03-22 Thread John Johansen
The kernel has an extended test for change_profile when used with onexec, that allows it to only work against set executables. The parser is not correctly mapping change_profile for this test update the mapping so change_onexec will work when confined. Note: the parser does not currently support

Re: [apparmor] [PATCH 2/3] Fix permission mapping for change_profile onexec

2012-03-22 Thread John Johansen
On 03/22/2012 12:46 PM, Steve Beattie wrote: On Thu, Mar 22, 2012 at 11:44:54AM -0700, John Johansen wrote: The kernel has an extended test for change_profile when used with onexec, that allows it to only work against set executables. The parser is not correctly mapping change_profile for

Re: [apparmor] [PATCH 2/3] Fix permission mapping for change_profile onexec

2012-03-22 Thread John Johansen
...@canonical.com Sender: apparmor-boun...@lists.ubuntu.com Date: Thu, 22 Mar 2012 11:44:54 To: apparmor@lists.ubuntu.com Subject: [apparmor] [PATCH 2/3] Fix permission mapping for change_profile onexec The kernel has an extended test for change_profile when used with onexec, that allows