[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check
authorAlex Murray <alex.murray@canonical.com>
Wed, 17 Nov 2021 04:07:39 +0000 (14:37 +1030)
committerMichael Vogt <mvo@debian.org>
Thu, 17 Feb 2022 15:29:46 +0000 (15:29 +0000)
commit4bc615762fa4dbc024c45ea0663e6e95897f9ca6
tree113ee09a03a131ac86e10bbc7c80f0c7f8c5490e
parent43e2f7c9c63daa4ae436b068e89c48b5d0944f02
[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check

Only consider snap-confine as confined by AppArmor when the AppArmor label
matches an expected path location for the snap-confine binary, rather than
just if the label is not "unconfined". This ensures snap-confine will fail
to execute if it is executed under a more permissive AppArmor profile than
expected.

Signed-off-by: Alex Murray <alex.murray@canonical.com>
Gbp-Pq: Topic cve202144730
Gbp-Pq: Name 0013-cmd-libsnap-confine-private-Tighten-AppArmor-label-c.patch
cmd/libsnap-confine-private/apparmor-support.c