[apparmor] PATCH [2/2] force update of stale cache

Kees Cook kees.cook at canonical.com
Tue Sep 14 19:15:52 BST 2010


On Tue, Sep 14, 2010 at 03:53:06AM -0700, John Johansen wrote:
> This patch forces a cache update in the case that There is a cache file
> that is present and invalid, and the features of the kernel and cache match.  This is done even if the-W flag is not specified.

NAK on this; I feel strongly that cache writing should only happen when the
tool is explicitly directed to write them out. (This is supported by the
caching test which fails when this patch is applied.)

-- 
Kees Cook
Ubuntu Security Team



More information about the AppArmor mailing list