mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 16:35:02 +01:00

The old out of tree patchseries has been completely dropped. v4.13 has most of the newer apparmor 3.x code in it. v4.14 has the rest except the af_unix mediation which is included as the last patch
32 lines
1.3 KiB
Diff
32 lines
1.3 KiB
Diff
From 9934296cba701d429a0fc0cf071a40c8c3a1587e Mon Sep 17 00:00:00 2001
|
|
From: Christos Gkekas <chris.gekas@gmail.com>
|
|
Date: Sat, 8 Jul 2017 20:50:21 +0100
|
|
Subject: [PATCH 03/17] apparmor: Fix logical error in verify_header()
|
|
|
|
verify_header() is currently checking whether interface version is less
|
|
than 5 *and* greater than 7, which always evaluates to false. Instead it
|
|
should check whether it is less than 5 *or* greater than 7.
|
|
|
|
Signed-off-by: Christos Gkekas <chris.gekas@gmail.com>
|
|
Signed-off-by: John Johansen <john.johansen@canonical.com>
|
|
(cherry picked from commit c54a2175e3a6bf6c697d249bba1aa729e06c7ba8)
|
|
---
|
|
security/apparmor/policy_unpack.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/security/apparmor/policy_unpack.c b/security/apparmor/policy_unpack.c
|
|
index 2d5a1a007b06..bda0dce3b582 100644
|
|
--- a/security/apparmor/policy_unpack.c
|
|
+++ b/security/apparmor/policy_unpack.c
|
|
@@ -832,7 +832,7 @@ static int verify_header(struct aa_ext *e, int required, const char **ns)
|
|
* if not specified use previous version
|
|
* Mask off everything that is not kernel abi version
|
|
*/
|
|
- if (VERSION_LT(e->version, v5) && VERSION_GT(e->version, v7)) {
|
|
+ if (VERSION_LT(e->version, v5) || VERSION_GT(e->version, v7)) {
|
|
audit_iface(NULL, NULL, NULL, "unsupported interface version",
|
|
e, error);
|
|
return error;
|
|
--
|
|
2.11.0
|
|
|