[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check
authorAlex Murray <alex.murray@canonical.com>
Wed, 17 Nov 2021 04:07:39 +0000 (14:37 +1030)
committerAlex Murray <alex.murray@canonical.com>
Tue, 29 Nov 2022 12:01:21 +0000 (12:01 +0000)
commit5b0f02be13c9bd2297b15bb9666b94e18f36277b
tree5c9e763b3ec0fca4ef01b4da6ded968cfefbf391
parent0da27d688d9fd9a8a2b4396b06e8e00f034b8715
[PATCH 13/36] cmd/libsnap-confine-private: Tighten AppArmor label check

Only consider snap-confine as confined by AppArmor when the AppArmor label
matches an expected path location for the snap-confine binary, rather than
just if the label is not "unconfined". This ensures snap-confine will fail
to execute if it is executed under a more permissive AppArmor profile than
expected.

Signed-off-by: Alex Murray <alex.murray@canonical.com>
Gbp-Pq: Topic cve202144730
Gbp-Pq: Name 0013-cmd-libsnap-confine-private-Tighten-AppArmor-label-c.patch
cmd/libsnap-confine-private/apparmor-support.c