Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Skip to content
Commit c29bceb3 authored by John Johansen's avatar John Johansen Committed by James Morris
Browse files

Fix execve behavior apparmor for PR_{GET,SET}_NO_NEW_PRIVS



Add support for AppArmor to explicitly fail requested domain transitions
if NO_NEW_PRIVS is set and the task is not unconfined.

Transitions from unconfined are still allowed because this always results
in a reduction of privileges.

Acked-by: default avatarEric Paris <eparis@redhat.com>
Signed-off-by: default avatarWill Drewry <wad@chromium.org>
Signed-off-by: default avatarJohn Johansen <john.johansen@canonical.com>
Signed-off-by: default avatarAndy Lutomirski <luto@amacapital.net>

v18: new acked-by, new description
Signed-off-by: default avatarJames Morris <james.l.morris@oracle.com>
parent 259e5e6c
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment