LWN.net Logo

The future of AppArmor

The future of AppArmor

Posted Oct 19, 2007 12:48 UTC (Fri) by t8m (guest, #31777)
In reply to: The future of AppArmor by jengelh
Parent article: The future of AppArmor

I don't think so. As there are strictly only allow rules in policy so you are only adding
actions which the restricted application can do it is unlikely. On the other hand it is one of
the reasons why writing a policy is  relatively hard and that SELinux tends to "break" apps.
But that's a price for being correct and not oversimplifying security.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds