aa-logprof asks for "a" rule even if "deny w" is present

Bug #1385474 reported by Christian Boltz
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
AppArmor
Fix Released
Undecided
Unassigned
Ubuntu
Invalid
Undecided
Unassigned

Bug Description

From bug 1324608 comment 1:

Additionally problem. When there is an already existing deny rule with a "w" mask
  deny /home/*/.profile w,
the "a" mask is not recognized as being matched by it and thus aa-logprof prompts to create a new rule when the permission is already affirmatively denied.

Tags: aa-tools
Revision history for this message
Christian Boltz (cboltz) wrote :

For the records: Even after the rewrite to FileRule, this bug survived.

At least there's a TODO note for it in is_covered_localvars() ;-)

Revision history for this message
Tyler Hicks (tyhicks) wrote :

This was released in AppArmor 2.12. The upstream commit is a0d4e246ab248046e1b0b7d270733183d8a02115.

Changed in apparmor:
status: Triaged → Fix Released
Revision history for this message
Paul White (paulw2u) wrote :

Belatedly invalidating superfluous Ubuntu task.

Changed in ubuntu:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.