unconfined
if (unconfined(label) || !label_mediates(label, AA_CLASS_FILE))
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
&ns->unconfined->label.count,
&ns->unconfined->label.count,
&ns->unconfined->label.count,
&ns->unconfined->label.count,
&ns->unconfined->label.count,
rule->label = aa_label_parse(&root_ns->unconfined->label, rulestr,
if (task_no_new_privs(current) && !unconfined(label) && !ctx->nnp)
if (unconfined(label)) {
if (task_no_new_privs(current) && !unconfined(label) &&
if (task_no_new_privs(current) && !unconfined(label) &&
if (task_no_new_privs(current) && !unconfined(label) && !ctx->nnp)
if (!stack && unconfined(label) &&
label == &labels_ns(label)->unconfined->label &&
if (task_no_new_privs(current) && !unconfined(label) &&
if (!tracer || unconfined(tracerl))
if ((bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS) && !unconfined(label) &&
!unconfined(label) &&
return unconfined(obj_label);
if (unconfined(label) || __file_is_delegated(flabel) ||
aa_get_profile(ns->unconfined);
aa_put_profile(ns->unconfined);
struct aa_profile *unconfined;
#define ns_unconfined(NS) (&(NS)->unconfined->label)
if ((flags & FLAG_SHOW_MODE) && profile != profile->ns->unconfined) {
if (profile == profile->ns->unconfined)
profile != profile->ns->unconfined)
base != &root_ns->unconfined->label))
if (!unconfined(label))
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label))
if (!unconfined(label))
if (!unconfined(label))
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label)) {
if (!unconfined(label))
if (!unconfined(label))
if (!unconfined(label))
(unconfined(new_label)))
if (rcu_access_pointer(ctx->label) != kernel_t && !unconfined(label)) {
label = aa_label_strn_parse(&root_ns->unconfined->label,
profile = aa_get_newest_profile(ns->unconfined);
profile = aa_get_newest_profile(ns->unconfined);
ns->unconfined = alloc_unconfined("unconfined");
if (!ns->unconfined)
ns->unconfined->ns = ns;
ns->unconfined->ns = NULL;
aa_free_profile(ns->unconfined);
root_ns->unconfined->ns = aa_get_ns(root_ns);
label = aa_label_strn_parse(&root_ns->unconfined->label, secdata,
if (profile_unconfined(tracee) || unconfined(tracer) ||
if (unconfined(label) || (labels_ns(old) != labels_ns(label)))