• M
    security_dac: Remember old labels · 1845d3ad
    Michal Privoznik 提交于
    This also requires the same DAC label to be used for shared
    paths. If a path is already in use by a domain (or domains) then
    and the domain we are starting now wants to access the path it
    has to have the same DAC label. This might look too restrictive
    as the new label can still guarantee access to already running
    domains but in reality it is very unlikely and usually an admin
    mistake.
    
    This requirement also simplifies seclabel remembering, because we
    can store only one seclabel and have a refcounter for how many
    times the path is in use. If we were to allow different labels
    and store them in some sort of array the algorithm to match
    labels to domains would be needlessly complicated.
    Signed-off-by: NMichal Privoznik <mprivozn@redhat.com>
    Reviewed-by: NJán Tomko <jtomko@redhat.com>
    1845d3ad
security_dac.c 69.1 KB