[CRIU] apparmor stacking c/r v4

Tycho Andersen tycho.andersen at canonical.com
Thu Oct 27 15:54:54 PDT 2016


Hi guys,

Here's a v4 of the apparmor stacking patchset, with a big bug fixed: it now
supports profiles with "/"s in the names.

Also, this feature is in development by our security team, and is not yet
posted on LKML (although it is in the ubuntu kernels today). My understanding
is that we don't want to merge stuff into CRIU whose API is not yet finalized
on LKML; the first two patches are not related to this feature (well, the first
one re-orders things so it is easier), and the last five are. So, it would be
easiest to maintain an out of tree patchset with these first two applied.

I think that the API will probably not change very much, given that the
upstream apparmor maintainer is the guy who wrote the patches, but you never
know :)

Anyway, thoughts welcome!

Tycho



More information about the CRIU mailing list