linux/security
John Johansen 2d9da9b188 apparmor: allow restricting unprivileged change_profile
unprivileged unconfined can use change_profile to alter the confinement
set by the mac admin.

Allow restricting unprivileged unconfined by still allowing change_profile
but stacking the change against unconfined. This allows unconfined to
still apply system policy but allows the task to enter the new confinement.

If unprivileged unconfined is required a sysctl is provided to switch
to the previous behavior.

Reviewed-by: Georgia Garcia <georgia.garcia@canonical.com>
Signed-off-by: John Johansen <john.johansen@canonical.com>
2023-10-18 15:48:44 -07:00
..
2023-06-30 09:20:08 -07:00
2023-06-12 21:26:19 +02:00
2023-04-27 16:52:33 -07:00
2023-04-27 16:52:33 -07:00
2023-05-25 17:52:15 -04:00
2023-05-25 17:52:15 -04:00
2023-06-27 17:24:26 -07:00