summaryrefslogtreecommitdiffstats
path: root/security/apparmor/context.c
Commit message (Collapse)AuthorAgeFilesLines
* apparmor: replace remaining BUG_ON() asserts with AA_BUG()John Johansen2017-01-161-2/+2
| | | | | | AA_BUG() uses WARN and won't break the kernel like BUG_ON(). Signed-off-by: John Johansen <john.johansen@canonical.com>
* apparmor: rename context abreviation cxt to the more standard ctxJohn Johansen2017-01-161-49/+51
| | | | Signed-off-by: John Johansen <john.johansen@canonical.com>
* apparmor: fail task profile update if current_cred isn't real_credJohn Johansen2017-01-161-0/+3
| | | | | | | | Trying to update the task cred while the task current cred is not the real cred will result in an error at the cred layer. Avoid this by failing early and delaying the update. Signed-off-by: John Johansen <john.johansen@canonical.com>
* apparmor: rename replacedby to proxyJohn Johansen2017-01-161-1/+1
| | | | | | Proxy is shorter and a better fit than replaceby, so rename it. Signed-off-by: John Johansen <john.johansen@canonical.com>
* apparmor: change how profile replacement update is doneJohn Johansen2013-08-141-11/+5
| | | | | | | | | | | remove the use of replaced by chaining and move to profile invalidation and lookup to handle task replacement. Replacement chaining can result in large chains of profiles being pinned in memory when one profile in the chain is use. With implicit labeling this will be even more of a problem, so move to a direct lookup method. Signed-off-by: John Johansen <john.johansen@canonical.com>
* apparmor: localize getting the security context to a few macrosJohn Johansen2013-04-281-5/+5
| | | | | Signed-off-by: John Johansen <john.johansen@canonical.com> Acked-by: Seth Arnold <seth.arnold@canonical.com>
* apparmor: use common fn to clear task_context for domain transitionsJohn Johansen2013-04-281-11/+6
| | | | | Signed-off-by: John Johansen <john.johansen@canonical.com> Acked-by: Steve Beattie <sbeattie@ubuntu.com>
* apparmor: add utility function to get an arbitrary tasks profile.John Johansen2013-04-281-0/+17
| | | | | Signed-off-by: John Johansen <john.johansen@canonical.com> Acked-by: Steve Beattie <sbeattie@ubuntu.com>
* AppArmor: contexts used in attaching policy to system objectsJohn Johansen2010-08-021-0/+216
AppArmor contexts attach profiles and state to tasks, files, etc. when a direct profile reference is not sufficient. Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>