/* TODO: extend resource control to handle other (non current) *profiles.AppArmorrulescurrentlyhavetheimplicitassumption *thatthetaskissettingtheresourceofataskconfinedwith *thesameprofileorthatthetasksettingtheresourceofanother *taskhasCAP_SYS_RESOURCE.
*/
old = labels_profile(old_l); new = labels_profile(new_l);
/* for any rlimits the profile controlled, reset the soft limit *tothelesserofthetaskshardlimitandtheinittaskssoftlimit
*/
label_for_each_confined(i, old_l, old) { struct aa_ruleset *rules = old->label.rules[0]; if (rules->rlimits.mask) { int j;
/* set any new hard limits as dictated by the new profile */
label_for_each_confined(i, new_l, new) { struct aa_ruleset *rules = new->label.rules[0]; int j;
if (!rules->rlimits.mask) continue; for (j = 0, mask = 1; j < RLIM_NLIMITS; j++, mask <<= 1) { if (!(rules->rlimits.mask & mask)) continue;
rlim = current->signal->rlim + j;
rlim->rlim_max = min(rlim->rlim_max,
rules->rlimits.limits[j].rlim_max); /* soft limit should not exceed hard limit */
rlim->rlim_cur = min(rlim->rlim_cur, rlim->rlim_max);
}
}
}
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.9 Sekunden
(vorverarbeitet am 2026-09-29)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.