security_dac.c 38.8 KB
Newer Older
1
/*
2
 * Copyright (C) 2010-2014 Red Hat, Inc.
3 4 5 6 7 8 9 10 11 12 13 14
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
15
 * License along with this library.  If not, see
O
Osier Yang 已提交
16
 * <http://www.gnu.org/licenses/>.
17 18 19 20 21 22 23 24 25 26
 *
 * POSIX DAC security driver
 */

#include <config.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>

#include "security_dac.h"
27
#include "virerror.h"
28
#include "virfile.h"
29
#include "viralloc.h"
30
#include "virlog.h"
31
#include "virpci.h"
32
#include "virusb.h"
33
#include "virscsi.h"
34
#include "virstoragefile.h"
35
#include "virstring.h"
M
Martin Kletzander 已提交
36
#include "virutil.h"
37 38

#define VIR_FROM_THIS VIR_FROM_SECURITY
39 40 41

VIR_LOG_INIT("security.security_dac");

42
#define SECURITY_DAC_NAME "dac"
43 44 45 46 47 48 49

typedef struct _virSecurityDACData virSecurityDACData;
typedef virSecurityDACData *virSecurityDACDataPtr;

struct _virSecurityDACData {
    uid_t user;
    gid_t group;
50 51
    gid_t *groups;
    int ngroups;
52
    bool dynamicOwnership;
53
    char *baselabel;
54 55
};

56 57 58 59 60 61 62 63
typedef struct _virSecurityDACCallbackData virSecurityDACCallbackData;
typedef virSecurityDACCallbackData *virSecurityDACCallbackDataPtr;

struct _virSecurityDACCallbackData {
    virSecurityManagerPtr manager;
    virSecurityLabelDefPtr secdef;
};

64 65 66 67 68
/* returns -1 on error, 0 on success */
int
virSecurityDACSetUserAndGroup(virSecurityManagerPtr mgr,
                              uid_t user,
                              gid_t group)
69 70 71 72
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    priv->user = user;
    priv->group = group;
73

74
    if (virAsprintf(&priv->baselabel, "+%u:+%u",
75 76 77 78 79
                    (unsigned int) user,
                    (unsigned int) group) < 0)
        return -1;

    return 0;
80 81
}

O
Osier Yang 已提交
82 83 84
void
virSecurityDACSetDynamicOwnership(virSecurityManagerPtr mgr,
                                  bool dynamicOwnership)
85 86 87 88 89
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    priv->dynamicOwnership = dynamicOwnership;
}

90
/* returns 1 if label isn't found, 0 on success, -1 on error */
O
Osier Yang 已提交
91
static int
92
ATTRIBUTE_NONNULL(2) ATTRIBUTE_NONNULL(3)
93 94
virSecurityDACParseIds(virSecurityLabelDefPtr seclabel,
                       uid_t *uidPtr, gid_t *gidPtr)
95
{
96
    if (!seclabel || !seclabel->label)
97
        return 1;
98

99
    if (virParseOwnershipIds(seclabel->label, uidPtr, gidPtr) < 0)
100 101 102 103 104
        return -1;

    return 0;
}

O
Osier Yang 已提交
105
static int
106
ATTRIBUTE_NONNULL(3) ATTRIBUTE_NONNULL(4)
107 108
virSecurityDACGetIds(virSecurityLabelDefPtr seclabel,
                     virSecurityDACDataPtr priv,
109 110
                     uid_t *uidPtr, gid_t *gidPtr,
                     gid_t **groups, int *ngroups)
111
{
112 113
    int ret;

114 115 116 117 118
    if (groups)
        *groups = priv ? priv->groups : NULL;
    if (ngroups)
        *ngroups = priv ? priv->ngroups : 0;

119
    if ((ret = virSecurityDACParseIds(seclabel, uidPtr, gidPtr)) <= 0)
120 121 122
        return ret;

    if (!priv) {
123 124
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("DAC seclabel couldn't be determined"));
125 126 127
        return -1;
    }

128 129
    *uidPtr = priv->user;
    *gidPtr = priv->group;
130 131

    return 0;
132 133
}

134 135

/* returns 1 if label isn't found, 0 on success, -1 on error */
O
Osier Yang 已提交
136
static int
137
ATTRIBUTE_NONNULL(2) ATTRIBUTE_NONNULL(3)
138
virSecurityDACParseImageIds(virSecurityLabelDefPtr seclabel,
O
Osier Yang 已提交
139
                            uid_t *uidPtr, gid_t *gidPtr)
140
{
141
    if (!seclabel || !seclabel->imagelabel)
142
        return 1;
143

144
    if (virParseOwnershipIds(seclabel->imagelabel, uidPtr, gidPtr) < 0)
145 146 147 148 149
        return -1;

    return 0;
}

O
Osier Yang 已提交
150
static int
151
ATTRIBUTE_NONNULL(3) ATTRIBUTE_NONNULL(4)
152 153
virSecurityDACGetImageIds(virSecurityLabelDefPtr seclabel,
                          virSecurityDACDataPtr priv,
O
Osier Yang 已提交
154
                          uid_t *uidPtr, gid_t *gidPtr)
155
{
156 157
    int ret;

158
    if ((ret = virSecurityDACParseImageIds(seclabel, uidPtr, gidPtr)) <= 0)
159 160 161
        return ret;

    if (!priv) {
162 163
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("DAC imagelabel couldn't be determined"));
164
        return -1;
165
    }
166

167 168
    *uidPtr = priv->user;
    *gidPtr = priv->group;
169 170

    return 0;
171 172 173
}


174
static virSecurityDriverStatus
175
virSecurityDACProbe(const char *virtDriver ATTRIBUTE_UNUSED)
176 177 178 179 180 181 182 183 184 185 186
{
    return SECURITY_DRIVER_ENABLE;
}

static int
virSecurityDACOpen(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED)
{
    return 0;
}

static int
187
virSecurityDACClose(virSecurityManagerPtr mgr)
188
{
189 190
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    VIR_FREE(priv->groups);
191
    VIR_FREE(priv->baselabel);
192 193 194 195
    return 0;
}


O
Osier Yang 已提交
196 197
static const char *
virSecurityDACGetModel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED)
198
{
199
    return SECURITY_DAC_NAME;
200 201
}

O
Osier Yang 已提交
202 203
static const char *
virSecurityDACGetDOI(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED)
204 205 206 207
{
    return "0";
}

208 209 210 211 212 213 214 215 216 217 218 219 220 221 222
static int
virSecurityDACPreFork(virSecurityManagerPtr mgr)
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    int ngroups;

    VIR_FREE(priv->groups);
    priv->ngroups = 0;
    if ((ngroups = virGetGroupList(priv->user, priv->group,
                                   &priv->groups)) < 0)
        return -1;
    priv->ngroups = ngroups;
    return 0;
}

223
static int
224
virSecurityDACSetOwnership(const char *path, uid_t uid, gid_t gid)
225
{
226 227
    VIR_INFO("Setting DAC user and group on '%s' to '%ld:%ld'",
             path, (long) uid, (long) gid);
228 229 230 231 232 233 234 235 236 237 238 239 240

    if (chown(path, uid, gid) < 0) {
        struct stat sb;
        int chown_errno = errno;

        if (stat(path, &sb) >= 0) {
            if (sb.st_uid == uid &&
                sb.st_gid == gid) {
                /* It's alright, there's nothing to change anyway. */
                return 0;
            }
        }

241
        if (chown_errno == EOPNOTSUPP || chown_errno == EINVAL) {
242 243 244
            VIR_INFO("Setting user and group to '%ld:%ld' on '%s' not "
                     "supported by filesystem",
                     (long) uid, (long) gid, path);
245
        } else if (chown_errno == EPERM) {
246 247 248
            VIR_INFO("Setting user and group to '%ld:%ld' on '%s' not "
                     "permitted",
                     (long) uid, (long) gid, path);
249
        } else if (chown_errno == EROFS) {
250 251 252
            VIR_INFO("Setting user and group to '%ld:%ld' on '%s' not "
                     "possible on readonly filesystem",
                     (long) uid, (long) gid, path);
253 254
        } else {
            virReportSystemError(chown_errno,
255 256 257
                                 _("unable to set user and group to '%ld:%ld' "
                                   "on '%s'"),
                                 (long) uid, (long) gid, path);
258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284
            return -1;
        }
    }
    return 0;
}

static int
virSecurityDACRestoreSecurityFileLabel(const char *path)
{
    struct stat buf;
    int rc = -1;
    char *newpath = NULL;

    VIR_INFO("Restoring DAC user and group on '%s'", path);

    if (virFileResolveLink(path, &newpath) < 0) {
        virReportSystemError(errno,
                             _("cannot resolve symlink %s"), path);
        goto err;
    }

    if (stat(newpath, &buf) != 0)
        goto err;

    /* XXX record previous ownership */
    rc = virSecurityDACSetOwnership(newpath, 0, 0);

285
 err:
286 287 288 289 290 291
    VIR_FREE(newpath);
    return rc;
}


static int
292
virSecurityDACSetSecurityFileLabel(virDomainDiskDefPtr disk,
293 294 295 296
                                   const char *path,
                                   size_t depth ATTRIBUTE_UNUSED,
                                   void *opaque)
{
297 298 299
    virSecurityDACCallbackDataPtr cbdata = opaque;
    virSecurityManagerPtr mgr = cbdata->manager;
    virSecurityLabelDefPtr secdef = cbdata->secdef;
300
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
301
    virSecurityDeviceLabelDefPtr disk_seclabel;
302 303 304
    uid_t user;
    gid_t group;

305
    disk_seclabel = virStorageSourceGetSecurityLabelDef(disk->src,
306 307 308 309 310 311 312 313 314 315 316 317
                                                        SECURITY_DAC_NAME);

    if (disk_seclabel && disk_seclabel->norelabel)
        return 0;

    if (disk_seclabel && disk_seclabel->label) {
        if (virParseOwnershipIds(disk_seclabel->label, &user, &group) < 0)
            return -1;
    } else {
        if (virSecurityDACGetImageIds(secdef, priv, &user, &group))
            return -1;
    }
318

319
    return virSecurityDACSetOwnership(path, user, group);
320 321 322 323
}


static int
324 325 326
virSecurityDACSetSecurityDiskLabel(virSecurityManagerPtr mgr,
                                   virDomainDefPtr def,
                                   virDomainDiskDefPtr disk)
327 328 329

{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
330 331
    virSecurityDACCallbackData cbdata;
    virSecurityLabelDefPtr secdef;
332 333 334 335

    if (!priv->dynamicOwnership)
        return 0;

336 337
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

338 339 340
    if (secdef && secdef->norelabel)
        return 0;

341 342
    cbdata.manager = mgr;
    cbdata.secdef = secdef;
343 344 345
    return virDomainDiskDefForeachPath(disk,
                                       false,
                                       virSecurityDACSetSecurityFileLabel,
346
                                       &cbdata);
347 348 349 350 351
}


static int
virSecurityDACRestoreSecurityImageLabelInt(virSecurityManagerPtr mgr,
352
                                           virDomainDefPtr def,
353
                                           virStorageSourcePtr src,
354
                                           bool migrated)
355 356
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
357 358
    virSecurityLabelDefPtr secdef;
    virSecurityDeviceLabelDefPtr disk_seclabel;
359 360 361 362

    if (!priv->dynamicOwnership)
        return 0;

363
    if (!src->path || !virStorageSourceIsLocalStorage(src))
364 365
        return 0;

366 367 368 369 370 371 372
    /* Don't restore labels on readoly/shared disks, because other VMs may
     * still be accessing these. Alternatively we could iterate over all
     * running domains and try to figure out if it is in use, but this would
     * not work for clustered filesystems, since we can't see running VMs using
     * the file on other nodes. Safest bet is thus to skip the restore step. */
    if (src->readonly || src->shared)
        return 0;
373

374
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);
375 376 377
    if (secdef && secdef->norelabel)
        return 0;

378
    disk_seclabel = virStorageSourceGetSecurityLabelDef(src,
379 380 381 382
                                                        SECURITY_DAC_NAME);
    if (disk_seclabel && disk_seclabel->norelabel)
        return 0;

383 384 385
    /* If we have a shared FS and are doing migration, we must not change
     * ownership, because that kills access on the destination host which is
     * sub-optimal for the guest VM's I/O attempts :-) */
386
    if (migrated) {
387
        int rc = virFileIsSharedFS(src->path);
388 389 390 391
        if (rc < 0)
            return -1;
        if (rc == 1) {
            VIR_DEBUG("Skipping image label restore on %s because FS is shared",
392
                      src->path);
393 394 395 396
            return 0;
        }
    }

397 398 399 400 401 402 403 404 405 406
    return virSecurityDACRestoreSecurityFileLabel(src->path);
}


static int
virSecurityDACRestoreSecurityImageLabel(virSecurityManagerPtr mgr,
                                        virDomainDefPtr def,
                                        virStorageSourcePtr src)
{
    return virSecurityDACRestoreSecurityImageLabelInt(mgr, def, src, false);
407 408 409 410
}


static int
411 412 413
virSecurityDACRestoreSecurityDiskLabel(virSecurityManagerPtr mgr,
                                       virDomainDefPtr def,
                                       virDomainDiskDefPtr disk)
414
{
415
    return virSecurityDACRestoreSecurityImageLabelInt(mgr, def, disk->src, false);
416 417 418 419
}


static int
420 421
virSecurityDACSetSecurityHostdevLabelHelper(const char *file,
                                            void *opaque)
422
{
423 424 425
    virSecurityDACCallbackDataPtr cbdata = opaque;
    virSecurityManagerPtr mgr = cbdata->manager;
    virSecurityLabelDefPtr secdef = cbdata->secdef;
426
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
427 428
    uid_t user;
    gid_t group;
429

430
    if (virSecurityDACGetIds(secdef, priv, &user, &group, NULL, NULL))
431 432 433
        return -1;

    return virSecurityDACSetOwnership(file, user, group);
434 435 436
}


437 438 439 440 441 442 443 444 445
static int
virSecurityDACSetSecurityPCILabel(virPCIDevicePtr dev ATTRIBUTE_UNUSED,
                                  const char *file,
                                  void *opaque)
{
    return virSecurityDACSetSecurityHostdevLabelHelper(file, opaque);
}


446
static int
447
virSecurityDACSetSecurityUSBLabel(virUSBDevicePtr dev ATTRIBUTE_UNUSED,
448 449 450
                                  const char *file,
                                  void *opaque)
{
451 452
    return virSecurityDACSetSecurityHostdevLabelHelper(file, opaque);
}
453

454

455 456 457 458 459 460
static int
virSecurityDACSetSecuritySCSILabel(virSCSIDevicePtr dev ATTRIBUTE_UNUSED,
                                   const char *file,
                                   void *opaque)
{
    return virSecurityDACSetSecurityHostdevLabelHelper(file, opaque);
461 462 463 464 465
}


static int
virSecurityDACSetSecurityHostdevLabel(virSecurityManagerPtr mgr,
466
                                      virDomainDefPtr def,
467 468
                                      virDomainHostdevDefPtr dev,
                                      const char *vroot)
469 470
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
471
    virSecurityDACCallbackData cbdata;
472 473 474 475 476 477 478 479
    int ret = -1;

    if (!priv->dynamicOwnership)
        return 0;

    if (dev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS)
        return 0;

480 481 482
    cbdata.manager = mgr;
    cbdata.secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

483 484 485
    if (cbdata.secdef && cbdata.secdef->norelabel)
        return 0;

486
    switch ((virDomainHostdevSubsysType) dev->source.subsys.type) {
487
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB: {
488
        virUSBDevicePtr usb;
489

490 491 492
        if (dev->missing)
            return 0;

493 494 495
        usb = virUSBDeviceNew(dev->source.subsys.u.usb.bus,
                              dev->source.subsys.u.usb.device,
                              vroot);
496 497 498
        if (!usb)
            goto done;

499 500 501
        ret = virUSBDeviceFileIterate(usb,
                                      virSecurityDACSetSecurityUSBLabel,
                                      &cbdata);
502
        virUSBDeviceFree(usb);
503 504 505 506
        break;
    }

    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI: {
507
        virPCIDevicePtr pci =
508 509 510 511
            virPCIDeviceNew(dev->source.subsys.u.pci.addr.domain,
                            dev->source.subsys.u.pci.addr.bus,
                            dev->source.subsys.u.pci.addr.slot,
                            dev->source.subsys.u.pci.addr.function);
512 513 514 515

        if (!pci)
            goto done;

516
        if (dev->source.subsys.u.pci.backend
517
            == VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) {
518
            char *vfioGroupDev = virPCIDeviceGetIOMMUGroupDev(pci);
519

520 521
            if (!vfioGroupDev) {
                virPCIDeviceFree(pci);
522
                goto done;
523
            }
524
            ret = virSecurityDACSetSecurityPCILabel(pci, vfioGroupDev, &cbdata);
525 526
            VIR_FREE(vfioGroupDev);
        } else {
527 528 529
            ret = virPCIDeviceFileIterate(pci,
                                          virSecurityDACSetSecurityPCILabel,
                                          &cbdata);
530 531
        }

532
        virPCIDeviceFree(pci);
533 534 535
        break;
    }

536 537
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_SCSI: {
        virSCSIDevicePtr scsi =
538 539
            virSCSIDeviceNew(NULL,
                             dev->source.subsys.u.scsi.adapter,
540 541 542
                             dev->source.subsys.u.scsi.bus,
                             dev->source.subsys.u.scsi.target,
                             dev->source.subsys.u.scsi.unit,
543 544
                             dev->readonly,
                             dev->shareable);
545 546 547 548

        if (!scsi)
            goto done;

549 550 551
        ret = virSCSIDeviceFileIterate(scsi,
                                       virSecurityDACSetSecuritySCSILabel,
                                       &cbdata);
552 553 554 555 556
        virSCSIDeviceFree(scsi);

        break;
    }

557
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_LAST:
558 559 560 561
        ret = 0;
        break;
    }

562
 done:
563 564 565 566 567
    return ret;
}


static int
568
virSecurityDACRestoreSecurityPCILabel(virPCIDevicePtr dev ATTRIBUTE_UNUSED,
569 570 571 572 573 574 575 576
                                      const char *file,
                                      void *opaque ATTRIBUTE_UNUSED)
{
    return virSecurityDACRestoreSecurityFileLabel(file);
}


static int
577 578 579
virSecurityDACRestoreSecurityUSBLabel(virUSBDevicePtr dev ATTRIBUTE_UNUSED,
                                      const char *file,
                                      void *opaque ATTRIBUTE_UNUSED)
580 581 582 583 584
{
    return virSecurityDACRestoreSecurityFileLabel(file);
}


585 586 587 588 589 590 591 592 593
static int
virSecurityDACRestoreSecuritySCSILabel(virSCSIDevicePtr dev ATTRIBUTE_UNUSED,
                                       const char *file,
                                       void *opaque ATTRIBUTE_UNUSED)
{
    return virSecurityDACRestoreSecurityFileLabel(file);
}


594 595
static int
virSecurityDACRestoreSecurityHostdevLabel(virSecurityManagerPtr mgr,
596
                                          virDomainDefPtr def,
597 598
                                          virDomainHostdevDefPtr dev,
                                          const char *vroot)
599 600 601

{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
602
    virSecurityLabelDefPtr secdef;
603 604
    int ret = -1;

605 606 607
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

    if (!priv->dynamicOwnership || (secdef && secdef->norelabel))
608 609 610 611 612
        return 0;

    if (dev->mode != VIR_DOMAIN_HOSTDEV_MODE_SUBSYS)
        return 0;

613
    switch ((virDomainHostdevSubsysType) dev->source.subsys.type) {
614
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_USB: {
615
        virUSBDevicePtr usb;
616 617 618

        if (dev->missing)
            return 0;
619

620 621 622
        usb = virUSBDeviceNew(dev->source.subsys.u.usb.bus,
                              dev->source.subsys.u.usb.device,
                              vroot);
623 624 625
        if (!usb)
            goto done;

626 627
        ret = virUSBDeviceFileIterate(usb, virSecurityDACRestoreSecurityUSBLabel, mgr);
        virUSBDeviceFree(usb);
628 629 630 631 632

        break;
    }

    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_PCI: {
633
        virPCIDevicePtr pci =
634 635 636 637
            virPCIDeviceNew(dev->source.subsys.u.pci.addr.domain,
                            dev->source.subsys.u.pci.addr.bus,
                            dev->source.subsys.u.pci.addr.slot,
                            dev->source.subsys.u.pci.addr.function);
638 639 640 641

        if (!pci)
            goto done;

642
        if (dev->source.subsys.u.pci.backend
643
            == VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) {
644
            char *vfioGroupDev = virPCIDeviceGetIOMMUGroupDev(pci);
645

646 647
            if (!vfioGroupDev) {
                virPCIDeviceFree(pci);
648
                goto done;
649
            }
650 651 652 653 654
            ret = virSecurityDACRestoreSecurityPCILabel(pci, vfioGroupDev, mgr);
            VIR_FREE(vfioGroupDev);
        } else {
            ret = virPCIDeviceFileIterate(pci, virSecurityDACRestoreSecurityPCILabel, mgr);
        }
655
        virPCIDeviceFree(pci);
656 657 658
        break;
    }

659 660
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_SCSI: {
        virSCSIDevicePtr scsi =
661 662
            virSCSIDeviceNew(NULL,
                             dev->source.subsys.u.scsi.adapter,
663 664 665
                             dev->source.subsys.u.scsi.bus,
                             dev->source.subsys.u.scsi.target,
                             dev->source.subsys.u.scsi.unit,
666 667
                             dev->readonly,
                             dev->shareable);
668 669 670 671 672 673 674 675 676 677

        if (!scsi)
            goto done;

        ret = virSCSIDeviceFileIterate(scsi, virSecurityDACRestoreSecuritySCSILabel, mgr);
        virSCSIDeviceFree(scsi);

        break;
    }

678
    case VIR_DOMAIN_HOSTDEV_SUBSYS_TYPE_LAST:
679 680 681 682
        ret = 0;
        break;
    }

683
 done:
684 685 686 687 688 689
    return ret;
}


static int
virSecurityDACSetChardevLabel(virSecurityManagerPtr mgr,
690
                              virDomainDefPtr def,
691 692
                              virDomainChrDefPtr dev,
                              virDomainChrSourceDefPtr dev_source)
693 694 695

{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
696
    virSecurityLabelDefPtr seclabel;
697
    virSecurityDeviceLabelDefPtr chr_seclabel = NULL;
698 699
    char *in = NULL, *out = NULL;
    int ret = -1;
700 701 702
    uid_t user;
    gid_t group;

703 704
    seclabel = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

705 706 707 708 709 710 711 712 713 714 715 716 717 718
    if (dev)
        chr_seclabel = virDomainChrDefGetSecurityLabelDef(dev,
                                                          SECURITY_DAC_NAME);

    if (chr_seclabel && chr_seclabel->norelabel)
        return 0;

    if (chr_seclabel && chr_seclabel->label) {
        if (virParseOwnershipIds(chr_seclabel->label, &user, &group) < 0)
            return -1;
    } else {
        if (virSecurityDACGetIds(seclabel, priv, &user, &group, NULL, NULL) < 0)
            return -1;
    }
719

720
    switch ((virDomainChrType) dev_source->type) {
721 722
    case VIR_DOMAIN_CHR_TYPE_DEV:
    case VIR_DOMAIN_CHR_TYPE_FILE:
723 724
        ret = virSecurityDACSetOwnership(dev_source->data.file.path,
                                         user, group);
725 726 727
        break;

    case VIR_DOMAIN_CHR_TYPE_PIPE:
728 729
        if ((virAsprintf(&in, "%s.in", dev_source->data.file.path) < 0) ||
            (virAsprintf(&out, "%s.out", dev_source->data.file.path) < 0))
730 731
            goto done;
        if (virFileExists(in) && virFileExists(out)) {
732 733
            if ((virSecurityDACSetOwnership(in, user, group) < 0) ||
                (virSecurityDACSetOwnership(out, user, group) < 0)) {
734
                goto done;
735
            }
736
        } else if (virSecurityDACSetOwnership(dev_source->data.file.path,
737
                                              user, group) < 0) {
738
            goto done;
739 740 741 742
        }
        ret = 0;
        break;

743 744 745 746 747 748 749 750 751 752 753
    case VIR_DOMAIN_CHR_TYPE_SPICEPORT:
    case VIR_DOMAIN_CHR_TYPE_NULL:
    case VIR_DOMAIN_CHR_TYPE_VC:
    case VIR_DOMAIN_CHR_TYPE_PTY:
    case VIR_DOMAIN_CHR_TYPE_STDIO:
    case VIR_DOMAIN_CHR_TYPE_UDP:
    case VIR_DOMAIN_CHR_TYPE_TCP:
    case VIR_DOMAIN_CHR_TYPE_UNIX:
    case VIR_DOMAIN_CHR_TYPE_SPICEVMC:
    case VIR_DOMAIN_CHR_TYPE_NMDM:
    case VIR_DOMAIN_CHR_TYPE_LAST:
754 755 756 757
        ret = 0;
        break;
    }

758
 done:
759 760 761 762 763 764 765
    VIR_FREE(in);
    VIR_FREE(out);
    return ret;
}

static int
virSecurityDACRestoreChardevLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
766
                                  virDomainDefPtr def ATTRIBUTE_UNUSED,
767 768
                                  virDomainChrDefPtr dev,
                                  virDomainChrSourceDefPtr dev_source)
769
{
770
    virSecurityDeviceLabelDefPtr chr_seclabel = NULL;
771 772 773
    char *in = NULL, *out = NULL;
    int ret = -1;

774 775 776 777
    if (dev)
        chr_seclabel = virDomainChrDefGetSecurityLabelDef(dev,
                                                          SECURITY_DAC_NAME);

778
    if (chr_seclabel && chr_seclabel->norelabel)
779 780
        return 0;

781
    switch ((virDomainChrType) dev_source->type) {
782 783
    case VIR_DOMAIN_CHR_TYPE_DEV:
    case VIR_DOMAIN_CHR_TYPE_FILE:
784
        ret = virSecurityDACRestoreSecurityFileLabel(dev_source->data.file.path);
785 786 787
        break;

    case VIR_DOMAIN_CHR_TYPE_PIPE:
788 789
        if ((virAsprintf(&out, "%s.out", dev_source->data.file.path) < 0) ||
            (virAsprintf(&in, "%s.in", dev_source->data.file.path) < 0))
790
            goto done;
791 792 793
        if (virFileExists(in) && virFileExists(out)) {
            if ((virSecurityDACRestoreSecurityFileLabel(out) < 0) ||
                (virSecurityDACRestoreSecurityFileLabel(in) < 0)) {
J
Jim Fehlig 已提交
794
                goto done;
795
            }
796
        } else if (virSecurityDACRestoreSecurityFileLabel(dev_source->data.file.path) < 0) {
797 798
            goto done;
        }
799 800 801
        ret = 0;
        break;

802 803 804 805 806 807 808 809 810 811 812
    case VIR_DOMAIN_CHR_TYPE_NULL:
    case VIR_DOMAIN_CHR_TYPE_VC:
    case VIR_DOMAIN_CHR_TYPE_PTY:
    case VIR_DOMAIN_CHR_TYPE_STDIO:
    case VIR_DOMAIN_CHR_TYPE_UDP:
    case VIR_DOMAIN_CHR_TYPE_TCP:
    case VIR_DOMAIN_CHR_TYPE_UNIX:
    case VIR_DOMAIN_CHR_TYPE_SPICEVMC:
    case VIR_DOMAIN_CHR_TYPE_SPICEPORT:
    case VIR_DOMAIN_CHR_TYPE_NMDM:
    case VIR_DOMAIN_CHR_TYPE_LAST:
813 814 815 816
        ret = 0;
        break;
    }

817
 done:
818 819 820 821 822 823 824
    VIR_FREE(in);
    VIR_FREE(out);
    return ret;
}


static int
825
virSecurityDACRestoreChardevCallback(virDomainDefPtr def,
826 827 828 829 830
                                     virDomainChrDefPtr dev,
                                     void *opaque)
{
    virSecurityManagerPtr mgr = opaque;

831
    return virSecurityDACRestoreChardevLabel(mgr, def, dev, &dev->source);
832 833 834
}


835 836 837 838 839 840 841 842 843
static int
virSecurityDACSetSecurityTPMFileLabel(virSecurityManagerPtr mgr,
                                      virDomainDefPtr def,
                                      virDomainTPMDefPtr tpm)
{
    int ret = 0;

    switch (tpm->type) {
    case VIR_DOMAIN_TPM_TYPE_PASSTHROUGH:
844
        ret = virSecurityDACSetChardevLabel(mgr, def, NULL,
845 846 847 848 849 850 851 852 853 854 855
                                            &tpm->data.passthrough.source);
        break;
    case VIR_DOMAIN_TPM_TYPE_LAST:
        break;
    }

    return ret;
}


static int
O
Osier Yang 已提交
856
virSecurityDACRestoreSecurityTPMFileLabel(virSecurityManagerPtr mgr,
857
                                          virDomainDefPtr def,
O
Osier Yang 已提交
858
                                          virDomainTPMDefPtr tpm)
859 860 861 862 863
{
    int ret = 0;

    switch (tpm->type) {
    case VIR_DOMAIN_TPM_TYPE_PASSTHROUGH:
864
        ret = virSecurityDACRestoreChardevLabel(mgr, def, NULL,
865 866 867 868 869 870 871 872 873 874
                                          &tpm->data.passthrough.source);
        break;
    case VIR_DOMAIN_TPM_TYPE_LAST:
        break;
    }

    return ret;
}


875 876
static int
virSecurityDACRestoreSecurityAllLabel(virSecurityManagerPtr mgr,
877
                                      virDomainDefPtr def,
878
                                      bool migrated)
879 880
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
881
    virSecurityLabelDefPtr secdef;
882
    size_t i;
883 884
    int rc = 0;

885
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);
886

887 888
    if (!priv->dynamicOwnership || (secdef && secdef->norelabel))
        return 0;
889 890

    VIR_DEBUG("Restoring security label on %s migrated=%d",
891
              def->name, migrated);
892

893
    for (i = 0; i < def->nhostdevs; i++) {
894
        if (virSecurityDACRestoreSecurityHostdevLabel(mgr,
895
                                                      def,
896 897
                                                      def->hostdevs[i],
                                                      NULL) < 0)
898 899
            rc = -1;
    }
900
    for (i = 0; i < def->ndisks; i++) {
901
        if (virSecurityDACRestoreSecurityImageLabelInt(mgr,
902
                                                       def,
903
                                                       def->disks[i]->src,
904 905 906 907
                                                       migrated) < 0)
            rc = -1;
    }

908
    if (virDomainChrDefForeach(def,
909 910
                               false,
                               virSecurityDACRestoreChardevCallback,
911
                               mgr) < 0)
912 913
        rc = -1;

914 915
    if (def->tpm) {
        if (virSecurityDACRestoreSecurityTPMFileLabel(mgr,
916
                                                      def,
917 918 919 920
                                                      def->tpm) < 0)
            rc = -1;
    }

921 922
    if (def->os.kernel &&
        virSecurityDACRestoreSecurityFileLabel(def->os.kernel) < 0)
923 924
        rc = -1;

925 926
    if (def->os.initrd &&
        virSecurityDACRestoreSecurityFileLabel(def->os.initrd) < 0)
927 928
        rc = -1;

O
Olivia Yin 已提交
929 930 931 932
    if (def->os.dtb &&
        virSecurityDACRestoreSecurityFileLabel(def->os.dtb) < 0)
        rc = -1;

933 934 935 936 937
    return rc;
}


static int
938
virSecurityDACSetChardevCallback(virDomainDefPtr def,
939 940 941 942 943
                                 virDomainChrDefPtr dev,
                                 void *opaque)
{
    virSecurityManagerPtr mgr = opaque;

944
    return virSecurityDACSetChardevLabel(mgr, def, dev, &dev->source);
945 946 947 948 949
}


static int
virSecurityDACSetSecurityAllLabel(virSecurityManagerPtr mgr,
950
                                  virDomainDefPtr def,
951 952 953
                                  const char *stdin_path ATTRIBUTE_UNUSED)
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
954
    virSecurityLabelDefPtr secdef;
955
    size_t i;
956 957
    uid_t user;
    gid_t group;
958

959 960
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

961 962 963
    if (!priv->dynamicOwnership || (secdef && secdef->norelabel))
        return 0;

964
    for (i = 0; i < def->ndisks; i++) {
965
        /* XXX fixme - we need to recursively label the entire tree :-( */
E
Eric Blake 已提交
966
        if (virDomainDiskGetType(def->disks[i]) == VIR_STORAGE_TYPE_DIR)
967
            continue;
968 969 970
        if (virSecurityDACSetSecurityDiskLabel(mgr,
                                               def,
                                               def->disks[i]) < 0)
971 972
            return -1;
    }
973
    for (i = 0; i < def->nhostdevs; i++) {
974
        if (virSecurityDACSetSecurityHostdevLabel(mgr,
975
                                                  def,
976 977
                                                  def->hostdevs[i],
                                                  NULL) < 0)
978 979 980
            return -1;
    }

981
    if (virDomainChrDefForeach(def,
982 983
                               true,
                               virSecurityDACSetChardevCallback,
984
                               mgr) < 0)
985 986
        return -1;

987 988 989 990 991 992 993
    if (def->tpm) {
        if (virSecurityDACSetSecurityTPMFileLabel(mgr,
                                                  def,
                                                  def->tpm) < 0)
            return -1;
    }

994
    if (virSecurityDACGetImageIds(secdef, priv, &user, &group))
995 996
        return -1;

997
    if (def->os.kernel &&
998
        virSecurityDACSetOwnership(def->os.kernel, user, group) < 0)
999 1000
        return -1;

1001
    if (def->os.initrd &&
1002
        virSecurityDACSetOwnership(def->os.initrd, user, group) < 0)
1003 1004
        return -1;

O
Olivia Yin 已提交
1005 1006 1007 1008
    if (def->os.dtb &&
        virSecurityDACSetOwnership(def->os.dtb, user, group) < 0)
        return -1;

1009 1010 1011 1012 1013 1014
    return 0;
}


static int
virSecurityDACSetSavedStateLabel(virSecurityManagerPtr mgr,
1015
                                 virDomainDefPtr def,
1016 1017
                                 const char *savefile)
{
1018 1019
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    virSecurityLabelDefPtr secdef;
1020 1021
    uid_t user;
    gid_t group;
1022

1023 1024 1025
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

    if (virSecurityDACGetImageIds(secdef, priv, &user, &group) < 0)
1026 1027 1028
        return -1;

    return virSecurityDACSetOwnership(savefile, user, group);
1029 1030 1031 1032 1033
}


static int
virSecurityDACRestoreSavedStateLabel(virSecurityManagerPtr mgr,
1034
                                     virDomainDefPtr def ATTRIBUTE_UNUSED,
1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047
                                     const char *savefile)
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);

    if (!priv->dynamicOwnership)
        return 0;

    return virSecurityDACRestoreSecurityFileLabel(savefile);
}


static int
virSecurityDACSetProcessLabel(virSecurityManagerPtr mgr,
1048
                              virDomainDefPtr def)
1049
{
1050 1051
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    virSecurityLabelDefPtr secdef;
1052 1053
    uid_t user;
    gid_t group;
1054 1055
    gid_t *groups;
    int ngroups;
1056

1057 1058 1059
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

    if (virSecurityDACGetIds(secdef, priv, &user, &group, &groups, &ngroups) < 0)
1060
        return -1;
1061

1062 1063
    VIR_DEBUG("Dropping privileges of DEF to %u:%u, %d supplemental groups",
              (unsigned int) user, (unsigned int) group, ngroups);
1064

1065
    if (virSetUIDGID(user, group, groups, ngroups) < 0)
1066 1067 1068
        return -1;

    return 0;
1069 1070 1071
}


1072 1073
static int
virSecurityDACSetChildProcessLabel(virSecurityManagerPtr mgr,
1074
                                   virDomainDefPtr def,
1075 1076
                                   virCommandPtr cmd)
{
1077 1078
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    virSecurityLabelDefPtr secdef;
1079 1080 1081
    uid_t user;
    gid_t group;

1082 1083 1084
    secdef = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

    if (virSecurityDACGetIds(secdef, priv, &user, &group, NULL, NULL))
1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095
        return -1;

    VIR_DEBUG("Setting child to drop privileges of DEF to %u:%u",
              (unsigned int) user, (unsigned int) group);

    virCommandSetUID(cmd, user);
    virCommandSetGID(cmd, group);
    return 0;
}


1096 1097 1098 1099 1100 1101 1102 1103
static int
virSecurityDACVerify(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
                     virDomainDefPtr def ATTRIBUTE_UNUSED)
{
    return 0;
}

static int
1104 1105
virSecurityDACGenLabel(virSecurityManagerPtr mgr,
                       virDomainDefPtr def)
1106
{
1107 1108 1109 1110 1111
    int rc = -1;
    virSecurityLabelDefPtr seclabel;
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);

    seclabel = virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);
1112
    if (seclabel == NULL)
1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130
        return rc;

    if (seclabel->imagelabel) {
        virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                       _("security image label already "
                         "defined for VM"));
        return rc;
    }

    if (seclabel->model
        && STRNEQ(seclabel->model, SECURITY_DAC_NAME)) {
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("security label model %s is not supported "
                         "with selinux"),
                       seclabel->model);
            return rc;
    }

1131
    switch ((virDomainSeclabelType) seclabel->type) {
1132 1133 1134 1135 1136 1137 1138 1139 1140
    case VIR_DOMAIN_SECLABEL_STATIC:
        if (seclabel->label == NULL) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("missing label for static security "
                             "driver in domain %s"), def->name);
            return rc;
        }
        break;
    case VIR_DOMAIN_SECLABEL_DYNAMIC:
1141
        if (virAsprintf(&seclabel->label, "+%u:+%u",
1142
                        (unsigned int) priv->user,
1143
                        (unsigned int) priv->group) < 0)
1144 1145 1146 1147 1148 1149 1150 1151 1152 1153
            return rc;
        if (seclabel->label == NULL) {
            virReportError(VIR_ERR_INTERNAL_ERROR,
                           _("cannot generate dac user and group id "
                             "for domain %s"), def->name);
            return rc;
        }
        break;
    case VIR_DOMAIN_SECLABEL_NONE:
        /* no op */
1154
        return 0;
1155 1156
    case VIR_DOMAIN_SECLABEL_DEFAULT:
    case VIR_DOMAIN_SECLABEL_LAST:
1157 1158 1159 1160 1161 1162
        virReportError(VIR_ERR_INTERNAL_ERROR,
                       _("unexpected security label type '%s'"),
                       virDomainSeclabelTypeToString(seclabel->type));
        return rc;
    }

1163 1164 1165 1166
    if (!seclabel->norelabel && !seclabel->imagelabel &&
        VIR_STRDUP(seclabel->imagelabel, seclabel->label) < 0) {
        VIR_FREE(seclabel->label);
        return rc;
1167 1168
    }

1169 1170 1171 1172 1173
    return 0;
}

static int
virSecurityDACReleaseLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1174
                           virDomainDefPtr def ATTRIBUTE_UNUSED)
1175 1176 1177 1178 1179 1180
{
    return 0;
}

static int
virSecurityDACReserveLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1181 1182
                           virDomainDefPtr def ATTRIBUTE_UNUSED,
                           pid_t pid ATTRIBUTE_UNUSED)
1183 1184 1185 1186 1187 1188
{
    return 0;
}

static int
virSecurityDACGetProcessLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1189
                              virDomainDefPtr def,
1190
                              pid_t pid ATTRIBUTE_UNUSED,
1191
                              virSecurityLabelPtr seclabel)
1192
{
1193 1194 1195 1196 1197 1198 1199
    virSecurityLabelDefPtr secdef =
        virDomainDefGetSecurityLabelDef(def, SECURITY_DAC_NAME);

    if (!secdef || !seclabel)
        return -1;

    if (secdef->label)
1200 1201
        ignore_value(virStrcpy(seclabel->label, secdef->label,
                               VIR_SECURITY_LABEL_BUFLEN));
1202

1203 1204 1205 1206
    return 0;
}

static int
1207
virSecurityDACSetDaemonSocketLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1208
                                   virDomainDefPtr vm ATTRIBUTE_UNUSED)
1209 1210 1211 1212 1213
{
    return 0;
}


1214 1215
static int
virSecurityDACSetSocketLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1216
                             virDomainDefPtr def ATTRIBUTE_UNUSED)
1217 1218 1219 1220 1221
{
    return 0;
}


1222 1223
static int
virSecurityDACClearSocketLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1224
                               virDomainDefPtr def ATTRIBUTE_UNUSED)
1225 1226 1227 1228
{
    return 0;
}

1229
static int
1230
virSecurityDACSetImageFDLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
1231
                              virDomainDefPtr def ATTRIBUTE_UNUSED,
1232
                              int fd ATTRIBUTE_UNUSED)
1233 1234 1235 1236
{
    return 0;
}

1237 1238 1239 1240 1241 1242 1243 1244
static int
virSecurityDACSetTapFDLabel(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
                            virDomainDefPtr def ATTRIBUTE_UNUSED,
                            int fd ATTRIBUTE_UNUSED)
{
    return 0;
}

O
Osier Yang 已提交
1245 1246 1247 1248
static char *
virSecurityDACGetMountOptions(virSecurityManagerPtr mgr ATTRIBUTE_UNUSED,
                              virDomainDefPtr vm ATTRIBUTE_UNUSED)
{
1249 1250 1251
    return NULL;
}

1252 1253 1254 1255 1256 1257 1258 1259
static const char *
virSecurityDACGetBaseLabel(virSecurityManagerPtr mgr,
                           int virt ATTRIBUTE_UNUSED)
{
    virSecurityDACDataPtr priv = virSecurityManagerGetPrivateData(mgr);
    return priv->baselabel;
}

1260
virSecurityDriver virSecurityDriverDAC = {
1261
    .privateDataLen                     = sizeof(virSecurityDACData),
1262
    .name                               = SECURITY_DAC_NAME,
1263 1264 1265
    .probe                              = virSecurityDACProbe,
    .open                               = virSecurityDACOpen,
    .close                              = virSecurityDACClose,
1266

1267 1268
    .getModel                           = virSecurityDACGetModel,
    .getDOI                             = virSecurityDACGetDOI,
1269

1270 1271
    .preFork                            = virSecurityDACPreFork,

1272
    .domainSecurityVerify               = virSecurityDACVerify,
1273

1274
    .domainSetSecurityDiskLabel         = virSecurityDACSetSecurityDiskLabel,
1275
    .domainRestoreSecurityDiskLabel     = virSecurityDACRestoreSecurityDiskLabel,
1276

1277 1278
    .domainRestoreSecurityImageLabel    = virSecurityDACRestoreSecurityImageLabel,

1279 1280 1281
    .domainSetSecurityDaemonSocketLabel = virSecurityDACSetDaemonSocketLabel,
    .domainSetSecuritySocketLabel       = virSecurityDACSetSocketLabel,
    .domainClearSecuritySocketLabel     = virSecurityDACClearSocketLabel,
1282

1283 1284 1285
    .domainGenSecurityLabel             = virSecurityDACGenLabel,
    .domainReserveSecurityLabel         = virSecurityDACReserveLabel,
    .domainReleaseSecurityLabel         = virSecurityDACReleaseLabel,
1286

1287 1288
    .domainGetSecurityProcessLabel      = virSecurityDACGetProcessLabel,
    .domainSetSecurityProcessLabel      = virSecurityDACSetProcessLabel,
1289
    .domainSetSecurityChildProcessLabel = virSecurityDACSetChildProcessLabel,
1290

1291 1292
    .domainSetSecurityAllLabel          = virSecurityDACSetSecurityAllLabel,
    .domainRestoreSecurityAllLabel      = virSecurityDACRestoreSecurityAllLabel,
1293

1294 1295
    .domainSetSecurityHostdevLabel      = virSecurityDACSetSecurityHostdevLabel,
    .domainRestoreSecurityHostdevLabel  = virSecurityDACRestoreSecurityHostdevLabel,
1296

1297 1298
    .domainSetSavedStateLabel           = virSecurityDACSetSavedStateLabel,
    .domainRestoreSavedStateLabel       = virSecurityDACRestoreSavedStateLabel,
1299

1300
    .domainSetSecurityImageFDLabel      = virSecurityDACSetImageFDLabel,
1301
    .domainSetSecurityTapFDLabel        = virSecurityDACSetTapFDLabel,
1302

1303
    .domainGetSecurityMountOptions      = virSecurityDACGetMountOptions,
1304 1305

    .getBaseLabel                       = virSecurityDACGetBaseLabel,
1306
};