]> git.ipfire.org Git - thirdparty/lxc.git/commitdiff
apparmor: support lxc.aa_profile = unchanged
authorSerge Hallyn <serge.hallyn@ubuntu.com>
Wed, 25 Nov 2015 20:45:08 +0000 (20:45 +0000)
committerStéphane Graber <stgraber@ubuntu.com>
Thu, 3 Dec 2015 06:14:37 +0000 (01:14 -0500)
In which case lxc will not update the apparmor profile at all.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
src/lxc/lsm/apparmor.c

index 88ea5a3153fa2fef55643f583ad7e6c74f1806cc..d78bd7a02dd9dc706f3eaa18adabbbb989f297ac 100644 (file)
@@ -42,6 +42,7 @@ static int mount_features_enabled = 0;
 #define AA_DEF_PROFILE "lxc-container-default"
 #define AA_MOUNT_RESTR "/sys/kernel/security/apparmor/features/mount/mask"
 #define AA_ENABLED_FILE "/sys/module/apparmor/parameters/enabled"
+#define AA_UNCHANGED "unchanged"
 
 static bool check_mount_feature_enabled(void)
 {
@@ -156,6 +157,12 @@ static int apparmor_process_label_set(const char *inlabel, struct lxc_conf *conf
        if (!aa_enabled)
                return 0;
 
+       /* user may request that we just ignore apparmor */
+       if (label && strcmp(label, AA_UNCHANGED) == 0) {
+               INFO("apparmor profile unchanged per user request");
+               return 0;
+       }
+
        if (!label) {
                if (use_default)
                        label = AA_DEF_PROFILE;