]> git.ipfire.org Git - thirdparty/linux.git/commit
apparmor: userns: Add support for execpath in userns
authorMaxime Bélair <maxime.belair@canonical.com>
Mon, 21 Jul 2025 14:46:44 +0000 (16:46 +0200)
committerJohn Johansen <john.johansen@canonical.com>
Thu, 29 Jan 2026 09:27:53 +0000 (01:27 -0800)
commit8d34e16f7f2b51f880957f2caadaae731ee28867
tree91ad60bf09fabbeba5d2a07e40eca78938ba18fc
parent3d28e2397af7a89ac3de33c686ed404cda59b5d5
apparmor: userns: Add support for execpath in userns

This new field allows reliable identification of the binary that
triggered a denial since the existing field (comm) only gives the name of
the binary, not its path. Thus comm doesn't work for binaries outside of
$PATH or works unreliably when two binaries have the same name.
Additionally comm can be modified by a program, for example, comm="(tor)"
or comm=4143504920506F6C6C6572 (= ACPI Poller).

Signed-off-by: Maxime Bélair <maxime.belair@canonical.com>
Signed-off-by: John Johansen <john.johansen@canonical.com>
security/apparmor/task.c