• M
    qemu: Enter the namespace on relabelling · eadaa975
    Michal Privoznik 提交于
    Instead of trying to fix our security drivers, we can use a
    simple trick to relabel paths in both namespace and the host.
    I mean, if we enter the namespace some paths are still shared
    with the host so any change done to them is visible from the host
    too.
    Therefore, we can just enter the namespace and call
    SetAllLabel()/RestoreAllLabel() from there. Yes, it has slight
    overhead because we have to fork in order to enter the namespace.
    But on the other hand, no complexity is added to our code.
    Signed-off-by: NMichal Privoznik <mprivozn@redhat.com>
    eadaa975
Makefile.am 98.8 KB