summaryrefslogtreecommitdiffstats
path: root/security/apparmor/include/policy_ns.h
diff options
context:
space:
mode:
authorJohn Johansen2017-05-09 09:08:41 +0200
committerJohn Johansen2017-06-08 21:51:49 +0200
commit5d5182cae40115c03933989473288e54afb39c7c (patch)
treead17fd4482d130039eb61b62e9c32ef3fa283d04 /security/apparmor/include/policy_ns.h
parentsecurityfs: add the ability to support symlinks (diff)
downloadkernel-qcow2-linux-5d5182cae40115c03933989473288e54afb39c7c.tar.gz
kernel-qcow2-linux-5d5182cae40115c03933989473288e54afb39c7c.tar.xz
kernel-qcow2-linux-5d5182cae40115c03933989473288e54afb39c7c.zip
apparmor: move to per loaddata files, instead of replicating in profiles
The loaddata sets cover more than just a single profile and should be tracked at the ns level. Move the load data files under the namespace and reference the files from the profiles via a symlink. Signed-off-by: John Johansen <john.johansen@canonical.com> Reviewed-by: Seth Arnold <seth.arnold@canonical.com> Reviewed-by: Kees Cook <keescook@chromium.org>
Diffstat (limited to 'security/apparmor/include/policy_ns.h')
-rw-r--r--security/apparmor/include/policy_ns.h3
1 files changed, 3 insertions, 0 deletions
diff --git a/security/apparmor/include/policy_ns.h b/security/apparmor/include/policy_ns.h
index 89cffddd7e75..d7a07ac96168 100644
--- a/security/apparmor/include/policy_ns.h
+++ b/security/apparmor/include/policy_ns.h
@@ -68,6 +68,9 @@ struct aa_ns {
atomic_t uniq_null;
long uniq_id;
int level;
+ long revision;
+
+ struct list_head rawdata_list;
struct dentry *dents[AAFS_NS_SIZEOF];
};