[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check
authorAlex Murray <alex.murray@canonical.com>
Wed, 17 Nov 2021 04:07:39 +0000 (14:37 +1030)
committerMarkus Koschany <apo@debian.org>
Tue, 13 Jun 2023 09:28:53 +0000 (10:28 +0100)
commit7d69dced992cc409aa8ccb1e8d0ed17f9703ea90
tree9629dc6906c1e7de985750cd1aecc23500e63cd2
parent5fc6460e6f6fdf6beb5a4ea7870c999ae0df5020
[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check

Only consider snap-confine as confined by AppArmor when the AppArmor label
matches an expected path location for the snap-confine binary, rather than
just if the label is not "unconfined". This ensures snap-confine will fail
to execute if it is executed under a more permissive AppArmor profile than
expected.

Signed-off-by: Alex Murray <alex.murray@canonical.com>
Gbp-Pq: Topic cve202144730
Gbp-Pq: Name 0013-cmd-libsnap-confine-private-Tighten-AppArmor-label-c.patch
cmd/libsnap-confine-private/apparmor-support.c