aboutsummaryrefslogtreecommitdiff
path: root/security/apparmor/include/apparmor.h
diff options
context:
space:
mode:
authorAndy Whitcroft <apw@canonical.com>2012-05-01 16:17:52 +0100
committerJohn Rigby <john.rigby@linaro.org>2012-06-25 12:17:17 -0600
commitf6b35ac1477136a1c2f2b4839bc4db8e8c2e539f (patch)
tree2d9356f19115b32056d5a4dd5818e224a6e44400 /security/apparmor/include/apparmor.h
parent29ae32ad16746ad037b7cd28a254227d1461abb8 (diff)
UBUNTU: ubuntu: overlayfs -- overlayfs: switch to use inode_only_permissions
When checking permissions on an overlayfs inode we do not take into account either device cgroup restrictions nor security permissions. This allows a user to mount an overlayfs layer over a restricted device directory and by pass those permissions to open otherwise restricted files. Switch over to the newly introduced inode_only_permissions. Signed-off-by: Andy Whitcroft <apw@canonical.com> Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
Diffstat (limited to 'security/apparmor/include/apparmor.h')
0 files changed, 0 insertions, 0 deletions