[apparmor] [PATCH 08/31] split routines for loading binary policy into its own file

Tyler Hicks tyhicks at canonical.com
Tue Dec 9 20:19:37 UTC 2014


On 2014-12-06 15:21:28, Christian Boltz wrote:
> Hello,
> 
> Am Freitag, 5. Dezember 2014 schrieb Tyler Hicks:
> > From: John Johansen <john.johansen at canonical.com>
> > 
> > Signed-off-by: John Johansen <john.johansen at canonical.com>
> > [tyhicks: Handle inverted return from find_subdomainfs_mountpoint()]
> 
> It would be a good idea to rename this function to something like 
> find_apparmor_mountpoint(), and also rename other occurrences of 
> "subdomain" in function names, variables etc. (as long as it doesn't 
> terribly break something, of course - but that could be worked around 
> with a wrapper function with the old name and a deprecation warning).

That function gets the axe in the following patch:

  [PATCH 29/31] parser: Finalize the aa_kernel_interface API

> 
> The "hard goal" should be not to expose something named *subdomain* in 
> libapparmor. As "soft goal", I propose to get rid of *subdomain* 
> everywhere, even if it's only used internally.

Agreed.

Tyler
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20141209/9dd7d502/attachment.pgp>


More information about the AppArmor mailing list