Lines Matching full:profile
33 struct aa_profile *profile; member
55 * @profile: profile being tested for confinement (NOT NULL)
64 static int audit_caps(struct common_audit_data *sa, struct aa_profile *profile, in audit_caps() argument
74 if (likely((AUDIT_MODE(profile) != AUDIT_ALL) && in audit_caps()
75 !cap_raised(profile->caps.audit, cap))) in audit_caps()
78 } else if (KILL_MODE(profile) || in audit_caps()
79 cap_raised(profile->caps.kill, cap)) { in audit_caps()
81 } else if (cap_raised(profile->caps.quiet, cap) && in audit_caps()
82 AUDIT_MODE(profile) != AUDIT_NOQUIET && in audit_caps()
83 AUDIT_MODE(profile) != AUDIT_ALL) { in audit_caps()
90 if (profile == ent->profile && cap_raised(ent->caps, cap)) { in audit_caps()
92 if (COMPLAIN_MODE(profile)) in audit_caps()
96 aa_put_profile(ent->profile); in audit_caps()
97 ent->profile = aa_get_profile(profile); in audit_caps()
102 return aa_audit(type, profile, sa, audit_cb); in audit_caps()
106 * profile_capable - test if profile allows use of capability @cap
107 * @profile: profile being enforced (NOT NULL, NOT unconfined)
114 static int profile_capable(struct aa_profile *profile, int cap, in profile_capable() argument
119 if (cap_raised(profile->caps.allow, cap) && in profile_capable()
120 !cap_raised(profile->caps.denied, cap)) in profile_capable()
126 if (!COMPLAIN_MODE(profile)) in profile_capable()
134 return audit_caps(sa, profile, cap, error); in profile_capable()
143 * Look up capability in profile capability set.
149 struct aa_profile *profile; in aa_capable() local
154 error = fn_for_each_confined(label, profile, in aa_capable()
155 profile_capable(profile, cap, opts, &sa)); in aa_capable()