• G
    capabilities: add baselabel per sec driver/virt type to secmodel · b51038a4
    Giuseppe Scrivano 提交于
    Expand the "secmodel" XML fragment of "host" with a sequence of
    baselabel's which describe the default security context used by
    libvirt with a specific security model and virtualization type:
    
    <secmodel>
      <model>selinux</model>
      <doi>0</doi>
      <baselabel type='kvm'>system_u:system_r:svirt_t:s0</baselabel>
      <baselabel type='qemu'>system_u:system_r:svirt_tcg_t:s0</baselabel>
    </secmodel>
    <secmodel>
      <model>dac</model>
      <doi>0</doi>
      <baselabel type='kvm'>107:107</baselabel>
      <baselabel type='qemu'>107:107</baselabel>
    </secmodel>
    
    "baselabel" is driver-specific information, e.g. in the DAC security
    model, it indicates USER_ID:GROUP_ID.
    Signed-off-by: NGiuseppe Scrivano <gscrivan@redhat.com>
    Signed-off-by: NEric Blake <eblake@redhat.com>
    b51038a4
capabilities.c 30.0 KB