提交 d73f3f58 编写于 作者: M Michal Privoznik

security_util: Introduce virSecurityMoveRememberedLabel

A simple helper function that would be used from DAC and SELinux
drivers.
Signed-off-by: NMichal Privoznik <mprivozn@redhat.com>
Reviewed-by: NCole Robinson <crobinso@redhat.com>
Reviewed-by: NDaniel P. Berrangé <berrange@redhat.com>
上级 8b74cecb
...@@ -256,3 +256,66 @@ virSecuritySetRememberedLabel(const char *name, ...@@ -256,3 +256,66 @@ virSecuritySetRememberedLabel(const char *name,
VIR_FREE(ref_name); VIR_FREE(ref_name);
return ret; return ret;
} }
int
virSecurityMoveRememberedLabel(const char *name,
const char *src,
const char *dst)
{
VIR_AUTOFREE(char *) ref_name = NULL;
VIR_AUTOFREE(char *) ref_value = NULL;
VIR_AUTOFREE(char *) attr_name = NULL;
VIR_AUTOFREE(char *) attr_value = NULL;
if (!(ref_name = virSecurityGetRefCountAttrName(name)) |
!(attr_name = virSecurityGetAttrName(name)))
return -1;
if (virFileGetXAttrQuiet(src, ref_name, &ref_value) < 0) {
if (errno == ENOSYS || errno == ENOTSUP) {
return -2;
} else if (errno != ENODATA) {
virReportSystemError(errno,
_("Unable to get XATTR %s on %s"),
ref_name, src);
return -1;
}
}
if (virFileGetXAttrQuiet(src, attr_name, &attr_value) < 0) {
if (errno == ENOSYS || errno == ENOTSUP) {
return -2;
} else if (errno != ENODATA) {
virReportSystemError(errno,
_("Unable to get XATTR %s on %s"),
attr_name, src);
return -1;
}
}
if (ref_value &&
virFileRemoveXAttr(src, ref_name) < 0) {
return -1;
}
if (attr_value &&
virFileRemoveXAttr(src, attr_name) < 0) {
return -1;
}
if (dst) {
if (ref_value &&
virFileSetXAttr(dst, ref_name, ref_value) < 0) {
return -1;
}
if (attr_value &&
virFileSetXAttr(dst, attr_name, attr_value) < 0) {
ignore_value(virFileRemoveXAttr(dst, ref_name));
return -1;
}
}
return 0;
}
...@@ -27,3 +27,8 @@ int ...@@ -27,3 +27,8 @@ int
virSecuritySetRememberedLabel(const char *name, virSecuritySetRememberedLabel(const char *name,
const char *path, const char *path,
const char *label); const char *label);
int
virSecurityMoveRememberedLabel(const char *name,
const char *src,
const char *dst);
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册