Searched refs:unconfined (Results 1 – 14 of 14) sorted by relevance
63 struct aa_profile *unconfined; member82 #define ns_unconfined(NS) (&(NS)->unconfined->label)116 aa_get_profile(ns->unconfined); in aa_get_ns()130 aa_put_profile(ns->unconfined); in aa_put_ns()
144 #define unconfined(X) label_unconfined(X) macro
124 ns->unconfined = alloc_unconfined("unconfined"); in alloc_ns()125 if (!ns->unconfined) in alloc_ns()128 ns->unconfined->ns = ns; in alloc_ns()159 ns->unconfined->ns = NULL; in aa_free_ns()160 aa_free_profile(ns->unconfined); in aa_free_ns()418 root_ns->unconfined->ns = aa_get_ns(root_ns); in aa_alloc_root_ns()
74 if (!tracer || unconfined(tracerl)) in may_change_ptraced_domain()882 if ((bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS) && !unconfined(label) && in apparmor_bprm_creds_for_exec()920 !unconfined(label) && in apparmor_bprm_creds_for_exec()1170 if (task_no_new_privs(current) && !unconfined(label) && !ctx->nnp) in aa_change_hat()1173 if (unconfined(label)) { in aa_change_hat()1197 if (task_no_new_privs(current) && !unconfined(label) && in aa_change_hat()1218 if (task_no_new_privs(current) && !unconfined(label) && in aa_change_hat()1314 if (task_no_new_privs(current) && !unconfined(label) && !ctx->nnp) in aa_change_profile()1412 if (task_no_new_privs(current) && !unconfined(label) && in aa_change_profile()
161 if (!unconfined(label)) { in apparmor_capget()187 if (!unconfined(label)) in apparmor_capable()210 if (!unconfined(label)) in common_perm()349 if (!unconfined(label)) in apparmor_path_link()369 if (!unconfined(label)) { in apparmor_path_rename()447 if (!unconfined(label)) { in apparmor_file_open()571 if (!unconfined(label)) { in apparmor_sb_mount()596 if (!unconfined(label)) in apparmor_sb_umount()610 if (!unconfined(label)) in apparmor_sb_pivotroot()728 (unconfined(new_label))) in apparmor_bprm_committing_creds()[all …]
70 if (unconfined(label) || (labels_ns(old) != labels_ns(label))) in aa_replace_current_label()245 if (profile_unconfined(tracee) || unconfined(tracer) || in profile_tracee_perm()
154 if (ctx->label != kernel_t && !unconfined(label)) { in aa_label_sk_perm()202 label = aa_label_strn_parse(&root_ns->unconfined->label, in apparmor_secmark_init()
98 label = aa_label_strn_parse(&root_ns->unconfined->label, secdata, in apparmor_secctx_to_secid()
195 rule->label = aa_label_parse(&root_ns->unconfined->label, rulestr, in aa_audit_rule_init()
623 if (unconfined(label) || unconfined(flabel) || in aa_file_perm()
1538 if ((flags & FLAG_SHOW_MODE) && profile != profile->ns->unconfined) { in aa_profile_snxprint()1564 if (profile == profile->ns->unconfined) in label_modename()1597 profile != profile->ns->unconfined) in display_mode()1901 base != &root_ns->unconfined->label)) in aa_label_strn_parse()
445 profile = aa_get_newest_profile(ns->unconfined); in aa_lookupn_profile()476 profile = aa_get_newest_profile(ns->unconfined); in aa_fqlookupn_profile()
11 them run in an unconfined state which is equivalent to standard Linux DAC
309 unconfined856 Another feature of bringup mode is the "unconfined" option. Writing857 a label to /sys/fs/smackfs/unconfined makes subjects with that label859 all subjects. Any access that is granted because a label is unconfined