kernel_optimize_test/security/apparmor
John Johansen 11c236b89d apparmor: add a default null dfa
Instead of testing whether a given dfa exists in every code path, have
a default null dfa that is used when loaded policy doesn't provide a
dfa.

This will let us get rid of special casing and avoid dereference bugs
when special casing is missed.

Signed-off-by: John Johansen <john.johansen@canonical.com>
2017-01-16 01:18:34 -08:00
..
include apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
.gitignore
apparmorfs.c apparmor: prepare to support newer versions of policy 2017-01-16 01:18:32 -08:00
audit.c apparmor: split apparmor policy namespaces code into its own file 2017-01-16 00:42:15 -08:00
capability.c
context.c apparmor: rename replacedby to proxy 2017-01-16 01:18:19 -08:00
crypto.c
domain.c apparmor: name null-XXX profiles after the executable 2017-01-16 01:18:30 -08:00
file.c apparmor: use designated initializers 2017-01-15 20:00:32 -08:00
ipc.c
Kconfig apparmor: add debug assert AA_BUG and Kconfig to control debug info 2017-01-16 01:18:24 -08:00
lib.c apparmor: update policy_destroy to use new debug asserts 2017-01-16 01:18:27 -08:00
lsm.c apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
Makefile apparmor: rename sid to secid 2017-01-16 00:42:17 -08:00
match.c apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
nulldfa.in apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
path.c
policy_ns.c apparmor: pass gfp_t parameter into profile allocation 2017-01-16 01:18:29 -08:00
policy_unpack.c apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
policy.c apparmor: add a default null dfa 2017-01-16 01:18:34 -08:00
procattr.c apparmor: allow ns visibility question to consider subnses 2017-01-16 01:18:22 -08:00
resource.c
secid.c apparmor: rename sid to secid 2017-01-16 00:42:17 -08:00