• D
    Add support for setting socket MLS level in SELinux driver · e72cc3c1
    Daniel J Walsh 提交于
    When SELinux is running in MLS mode, libvirtd will have a
    different security level to the VMs. For libvirtd to be
    able to connect to the monitor console, the client end of
    the UNIX domain socket needs a different label. This adds
    infrastructure to set the socket label via the security
    driver framework
    
    * src/qemu/qemu_driver.c: Call out to socket label APIs in
      security driver
    * src/qemu/qemu_security_stacked.c: Wire up socket label
      drivers
    * src/security/security_driver.h: Define security driver
      entry points for socket labelling
    * src/security/security_selinux.c: Set socket label based on
      VM label
    e72cc3c1
qemu_driver.c 373.0 KB