Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-20 Thread Jim Fehlig
On 1/20/21 12:33 AM, Christian Ehrhardt wrote: On Tue, Jan 19, 2021 at 11:43 AM Peter Krempa wrote: On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: When adding a rule for an image file and that image file has a chain of backing files then we need to add a rule for each of

Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Christian Ehrhardt
On Tue, Jan 19, 2021 at 11:43 AM Peter Krempa wrote: > > On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: > > When adding a rule for an image file and that image file has a chain > > of backing files then we need to add a rule for each of those files. > > > > To get that iterate

Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Christian Ehrhardt
On Tue, Jan 19, 2021 at 12:28 PM Peter Krempa wrote: > > On Tue, Jan 19, 2021 at 12:15:31 +0100, Christian Ehrhardt wrote: > > On Tue, Jan 19, 2021 at 11:43 AM Peter Krempa wrote: > > > > > > On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: > > > > When adding a rule for an

Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Peter Krempa
On Tue, Jan 19, 2021 at 12:15:31 +0100, Christian Ehrhardt wrote: > On Tue, Jan 19, 2021 at 11:43 AM Peter Krempa wrote: > > > > On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: > > > When adding a rule for an image file and that image file has a chain > > > of backing files then

Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Christian Ehrhardt
On Tue, Jan 19, 2021 at 11:43 AM Peter Krempa wrote: > > On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: > > When adding a rule for an image file and that image file has a chain > > of backing files then we need to add a rule for each of those files. > > > > To get that iterate

Re: [PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Peter Krempa
On Tue, Jan 19, 2021 at 11:23:16 +0100, Christian Ehrhardt wrote: > When adding a rule for an image file and that image file has a chain > of backing files then we need to add a rule for each of those files. > > To get that iterate over the backing file chain the same way as > dac/selinux already

[PATCH] apparmor: let image label setting loop over backing files

2021-01-19 Thread Christian Ehrhardt
When adding a rule for an image file and that image file has a chain of backing files then we need to add a rule for each of those files. To get that iterate over the backing file chain the same way as dac/selinux already do and add a label for each. Fixes: