Skip to content
  • John Johansen's avatar
    apparmor: make signal label match work when matching stacked labels · 3dc6b1ce
    John Johansen authored
    
    
    Given a label with a profile stack of
        A//&B or A//&C ...
    
    A ptrace rule should be able to specify a generic trace pattern with
    a rule like
    
        signal send A//&**,
    
    however this is failing because while the correct label match routine
    is called, it is being done post label decomposition so it is always
    being done against a profile instead of the stacked label.
    
    To fix this refactor the cross check to pass the full peer label in to
    the label_match.
    
    Signed-off-by: default avatarJohn Johansen <john.johansen@canonical.com>
    3dc6b1ce