[apparmor] [patch] NetworkRule: allow TYPE without DOMAIN
steve at nxnw.org
Tue Jul 7 04:39:04 UTC 2015
On Thu, Jun 25, 2015 at 10:41:15PM +0200, Christian Boltz wrote:
> thanks to a bug in the apparmor.d manpage, NetworkRule rejected rules
> that contained only TYPE (for example "network stream,"). A bugreport on
> IRC and some testing with the parser showed that this is actually
> allowed, so NetworkRule should of course allow it.
> Note: not strip()ing rule_details is the easiest way to ensure we have
> whitespace in front of the TYPE in TYPE-only rules, which is needed by
> the RE_NETWORK_DETAILS regex.
> Also adjust the tests to the correct behaviour.
> [ 57-adjust-NetworkRule-to-fixed-manpage.diff ]
Acked-by: Steve Beattie <steve at nxnw.org>. Thanks.
<sbeattie at ubuntu.com>
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 819 bytes
Desc: Digital signature
More information about the AppArmor