fix(aa-log): handle owner rule even if thhe log is not complete.

This commit is contained in:
Alexandre Pujol 2024-03-25 20:32:13 +00:00
parent d8d15c8a35
commit 5d40cc1166
No known key found for this signature in database
GPG Key ID: C5469996F0DF68EC

View File

@ -39,9 +39,8 @@ func NewQualifierFromLog(log map[string]string) Qualifier {
owner := false
fsuid, hasFsUID := log["fsuid"]
ouid, hasOuUID := log["ouid"]
OUID, hasOUID := log["OUID"]
isDbus := strings.Contains(log["operation"], "dbus")
if hasFsUID && hasOuUID && hasOUID && fsuid == ouid && OUID != "root" && !isDbus {
if hasFsUID && hasOuUID && fsuid == ouid && ouid != "0" && !isDbus {
owner = true
}