| From 2504db207146543736e877241f3b3de005cbe056 Mon Sep 17 00:00:00 2001 |
| From: John Johansen <john.johansen@canonical.com> |
| Date: Sat, 26 Mar 2022 01:58:15 -0700 |
| Subject: apparmor: fix overlapping attachment computation |
| |
| From: John Johansen <john.johansen@canonical.com> |
| |
| commit 2504db207146543736e877241f3b3de005cbe056 upstream. |
| |
| When finding the profile via patterned attachments, the longest left |
| match is being set to the static compile time value and not using the |
| runtime computed value. |
| |
| Fix this by setting the candidate value to the greater of the |
| precomputed value or runtime computed value. |
| |
| Fixes: 21f606610502 ("apparmor: improve overlapping domain attachment resolution") |
| Signed-off-by: John Johansen <john.johansen@canonical.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| security/apparmor/domain.c | 2 +- |
| security/apparmor/include/policy.h | 2 +- |
| 2 files changed, 2 insertions(+), 2 deletions(-) |
| |
| --- a/security/apparmor/domain.c |
| +++ b/security/apparmor/domain.c |
| @@ -460,7 +460,7 @@ restart: |
| * xattrs, or a longer match |
| */ |
| candidate = profile; |
| - candidate_len = profile->xmatch_len; |
| + candidate_len = max(count, profile->xmatch_len); |
| candidate_xattrs = ret; |
| conflict = false; |
| } |
| --- a/security/apparmor/include/policy.h |
| +++ b/security/apparmor/include/policy.h |
| @@ -135,7 +135,7 @@ struct aa_profile { |
| |
| const char *attach; |
| struct aa_dfa *xmatch; |
| - int xmatch_len; |
| + unsigned int xmatch_len; |
| enum audit_mode audit; |
| long mode; |
| u32 path_flags; |