• D
    Allow for resource relabelling with static labels · 6321fd97
    Daniel P. Berrange 提交于
    Add a new attribute to the <seclabel> XML to allow resource
    relabelling to be enabled with static label usage.
    
      <seclabel model='selinux' type='static' relabel='yes'>
        <label>system_u:system_r:svirt_t:s0:c392,c662</label>
      </seclabel>
    
    * docs/schemas/domain.rng: Add relabel attribute
    * src/conf/domain_conf.c, src/conf/domain_conf.h: Parse
      the 'relabel' attribute
    * src/qemu/qemu_process.c: Unconditionally clear out the
      'imagelabel' attribute
    * src/security/security_apparmor.c: Skip based on 'relabel'
      attribute instead of label type
    * src/security/security_selinux.c: Skip based on 'relabel'
      attribute instead of label type and fill in <imagelabel>
      attribute if relabel is enabled.
    6321fd97
security_apparmor.c 22.3 KB