apparmor: don't try to replace stale label in ptraceme check
begin_current_label_crit_section() must run in sleepable context because when label_is_stale() is true, aa_replace_current_label() runs, which uses prepare_creds(), which can sleep. Until now, the ptraceme access check (which runs with tasklist_lock held) violated this rule. Fixes: b2d09ae4 ("apparmor: move ptrace checks to using labels") Reported-by:Cyrill Gorcunov <gorcunov@gmail.com> Reported-by:
kernel test robot <rong.a.chen@intel.com> Signed-off-by:
Jann Horn <jannh@google.com> Signed-off-by:
John Johansen <john.johansen@canonical.com> Git-commit: ca3fde5214e1d24f78269b337d3f22afd6bf445e Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git Change-Id: I3d750f0e457a1755b2fa37aea14df2221c3aa2fc Signed-off-by:
Jiangjiang Shen <jiangjia@codeaurora.org>
Loading
Please register or sign in to comment