• D
    Add support for sVirt in the LXC driver · 0f01192e
    Daniel P. Berrange 提交于
    For the sake of backwards compat, LXC guests are *not*
    confined by default. This is because it is not practical
    to dynamically relabel containers using large filesystem
    trees. Applications can create confined containers though,
    by giving suitable XML configs
    
    * src/Makefile.am: Link libvirt_lxc to security drivers
    * src/lxc/libvirtd_lxc.aug, src/lxc/lxc_conf.h,
      src/lxc/lxc_conf.c, src/lxc/lxc.conf,
      src/lxc/test_libvirtd_lxc.aug: Config file handling for
      security driver
    * src/lxc/lxc_driver.c: Wire up security driver functions
    * src/lxc/lxc_controller.c: Add a '--security' flag to
      specify which security driver to activate
    * src/lxc/lxc_container.c, src/lxc/lxc_container.h: Set
      the process label just before exec'ing init.
    0f01192e
lxc_conf.h 2.4 KB