diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c index 7eca391..c264adc 100644 --- a/security/apparmor/lsm.c +++ b/security/apparmor/lsm.c @@ -128,7 +128,7 @@ static int apparmor_capget(struct task_struct *target, kernel_cap_t *effective, *inheritable = cred->cap_inheritable; *permitted = cred->cap_permitted; - if (!unconfined(profile)) { + if (!unconfined(profile) && !COMPLAIN_MODE(profile)) { *effective = cap_intersect(*effective, profile->caps.allow); *permitted = cap_intersect(*permitted, profile->caps.allow); }