Compare commits
137 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| afdaf5d354 | |||
| 26bba5aea9 | |||
| 1a4185bdcc | |||
| 6a73119e65 | |||
| 1e2f9fce0a | |||
| f5edf79c95 | |||
| b59e64bf44 | |||
| a09fc2658a | |||
| a008fcf27e | |||
| 511f6cd625 | |||
| 48b90fefc1 | |||
| bc4bbabdf6 | |||
| 905627c8fd | |||
| a16d752c10 | |||
| 29b1292019 | |||
| f3546be64b | |||
| fb9044931e | |||
| 03c5fec4d2 | |||
| ce373a25b6 | |||
| 996d0e4709 | |||
| 8c01426c44 | |||
| e859f7e59e | |||
| 25ea2f59bd | |||
| c80b7f0d5a | |||
| 958f1c3dff | |||
| 4a8ca1017f | |||
| 1e122ee5dc | |||
| 6a6307bcdc | |||
| 6e8332946a | |||
| 982683e56f | |||
| 7244d1a339 | |||
| 2a3935580c | |||
| 28f7f11450 | |||
| ca07bc4597 | |||
| 8e23194a2b | |||
| fe09090e2d | |||
| b5868cf8cf | |||
| f294b40ba5 | |||
| c0c1a7bb79 | |||
| 1b864048bd | |||
| 072c9c45ab | |||
| af111679c3 | |||
| dd9f21eaa2 | |||
| f0e356df98 | |||
| 140bcf9ffc | |||
| af69660412 | |||
| 6dc94c6252 | |||
| eb34165670 | |||
| 7ce08f2148 | |||
| 049a8c79d9 | |||
| f7a6d90012 | |||
| 67a2f29a89 | |||
| 82422fa1ff | |||
| a73cf1d010 | |||
| 481419ebb6 | |||
| 1e65165c3a | |||
| bca27d9111 | |||
| 08b9144b41 | |||
| 2063007248 | |||
| 81e46cb6da | |||
| 263e2f2021 | |||
| 2b9efc3de2 | |||
| 69f6239766 | |||
| bf744f9872 | |||
| 45b0b2bfa6 | |||
| f29ea218b7 | |||
| 7d193b7810 | |||
| 3182a4df5a | |||
| 4f667910e9 | |||
| b395a39f7b | |||
| fdd7e87fe3 | |||
| f06c387ab5 | |||
| 5ad8bc8190 | |||
| 31802de821 | |||
| cc39758e17 | |||
| 55fabd69c0 | |||
| b2a1a0e9ba | |||
| cbe377ed29 | |||
| 06a21e388f | |||
| d1a886ab31 | |||
| c70baa5133 | |||
| 52b4d91272 | |||
| 338630edc8 | |||
| a05e64b718 | |||
| c003690dfc | |||
| 2cac8ea133 | |||
| deefad73a9 | |||
| f6cef943a9 | |||
| 7a6f0752c1 | |||
| 36d558635e | |||
| 98bceee6b1 | |||
| 4e70e5049f | |||
| e66ceb7f97 | |||
| 23d5b99123 | |||
| df8a62cdc8 | |||
| 8e36286f00 | |||
| cd0f44cfff | |||
| dcd808aefc | |||
| 8713d4b7ef | |||
| 68efefa919 | |||
| 1c5afbb774 | |||
| e61694fd1d | |||
| 608f915ea7 | |||
| b28edd6eab | |||
| 327fe785ba | |||
| 5c1d884231 | |||
| 54c7c9997c | |||
| dec47cc4eb | |||
| ecaf0eb615 | |||
| ea6b32b5e4 | |||
| 313e00f3ac | |||
| b3a53e18a9 | |||
| 24467d1235 | |||
| fdaa69f5e3 | |||
| cf2cd869d9 | |||
| f2572ab2b4 | |||
| 90a17a6e65 | |||
| 9f2e4f2b21 | |||
| bc485ef21f | |||
| 0d3a7da407 | |||
| f68d725fc4 | |||
| 044e9b5c7b | |||
| 96a9b8bc2e | |||
| 66a051f485 | |||
| 609ab7cda8 | |||
| 0caeb23111 | |||
| 7599107322 | |||
| 861e11f3e4 | |||
| 2ea97c32dc | |||
| cb54686f58 | |||
| bd474aff47 | |||
| d55c7f267b | |||
| f04b8ffc70 | |||
| ba3d2d023f | |||
| 4cb72ce395 | |||
| 8537c4e603 | |||
| f3f2891946 |
+9
-1
@@ -1 +1,9 @@
|
||||
libvirt-0.0.3.tar.gz
|
||||
.build*.log
|
||||
*.rpm
|
||||
i686
|
||||
x86_64
|
||||
libvirt-*.tar.gz
|
||||
libvirt-0.6.0.tar.gz
|
||||
libvirt-0.6.1.tar.gz
|
||||
libvirt-0.6.2.tar.gz
|
||||
libvirt-0.6.3.tar.gz
|
||||
|
||||
@@ -3,4 +3,19 @@
|
||||
NAME := libvirt
|
||||
SPECFILE = $(firstword $(wildcard *.spec))
|
||||
|
||||
include ../common/Makefile.common
|
||||
define find-makefile-common
|
||||
for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done
|
||||
endef
|
||||
|
||||
MAKEFILE_COMMON := $(shell $(find-makefile-common))
|
||||
|
||||
ifeq ($(MAKEFILE_COMMON),)
|
||||
# attempt a checkout
|
||||
define checkout-makefile-common
|
||||
test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2
|
||||
endef
|
||||
|
||||
MAKEFILE_COMMON := $(shell $(checkout-makefile-common))
|
||||
endif
|
||||
|
||||
include $(MAKEFILE_COMMON)
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
diff -rup libvirt-0.6.2/src/security_selinux.c libvirt-0.6.2.new/src/security_selinux.c
|
||||
--- libvirt-0.6.2/src/security_selinux.c 2009-04-03 15:36:56.000000000 +0100
|
||||
+++ libvirt-0.6.2.new/src/security_selinux.c 2009-05-05 13:39:42.000000000 +0100
|
||||
@@ -24,11 +24,12 @@
|
||||
#include "virterror_internal.h"
|
||||
#include "util.h"
|
||||
#include "memory.h"
|
||||
-
|
||||
+#include "logging.h"
|
||||
|
||||
#define VIR_FROM_THIS VIR_FROM_SECURITY
|
||||
|
||||
static char default_domain_context[1024];
|
||||
+static char default_content_context[1024];
|
||||
static char default_image_context[1024];
|
||||
#define SECURITY_SELINUX_VOID_DOI "0"
|
||||
#define SECURITY_SELINUX_NAME "selinux"
|
||||
@@ -148,8 +149,13 @@ SELinuxInitialize(virConnectPtr conn)
|
||||
close(fd);
|
||||
|
||||
ptr = strchrnul(default_image_context, '\n');
|
||||
- *ptr = '\0';
|
||||
-
|
||||
+ if (*ptr == '\n') {
|
||||
+ *ptr = '\0';
|
||||
+ strcpy(default_content_context, ptr+1);
|
||||
+ ptr = strchrnul(default_content_context, '\n');
|
||||
+ if (*ptr == '\n')
|
||||
+ *ptr = '\0';
|
||||
+ }
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -275,6 +281,8 @@ SELinuxSetFilecon(virConnectPtr conn, co
|
||||
{
|
||||
char ebuf[1024];
|
||||
|
||||
+ VIR_INFO("Setting SELinux context on '%s' to '%s'", path, tcon);
|
||||
+
|
||||
if(setfilecon(path, tcon) < 0) {
|
||||
virSecurityReportError(conn, VIR_ERR_ERROR,
|
||||
_("%s: unable to set security context "
|
||||
@@ -299,6 +307,8 @@ SELinuxRestoreSecurityImageLabel(virConn
|
||||
char *newpath = NULL;
|
||||
const char *path = disk->src;
|
||||
|
||||
+ /* Don't restore labels on readoly/shared disks, because
|
||||
+ * other VMs may still be accessing these */
|
||||
if (disk->readonly || disk->shared)
|
||||
return 0;
|
||||
|
||||
@@ -328,8 +338,13 @@ SELinuxSetSecurityImageLabel(virConnectP
|
||||
{
|
||||
const virSecurityLabelDefPtr secdef = &vm->def->seclabel;
|
||||
|
||||
- if (secdef->imagelabel)
|
||||
+ if (disk->shared) {
|
||||
+ return SELinuxSetFilecon(conn, disk->src, default_image_context);
|
||||
+ } else if (disk->readonly) {
|
||||
+ return SELinuxSetFilecon(conn, disk->src, default_content_context);
|
||||
+ } else if (secdef->imagelabel) {
|
||||
return SELinuxSetFilecon(conn, disk->src, secdef->imagelabel);
|
||||
+ }
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -403,9 +418,6 @@ SELinuxSetSecurityLabel(virConnectPtr co
|
||||
|
||||
if (secdef->imagelabel) {
|
||||
for (i = 0 ; i < vm->def->ndisks ; i++) {
|
||||
- if (vm->def->disks[i]->readonly ||
|
||||
- vm->def->disks[i]->shared) continue;
|
||||
-
|
||||
if (SELinuxSetSecurityImageLabel(conn, vm, vm->def->disks[i]) < 0)
|
||||
return -1;
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
--- src/qemu_conf.c.orig 2009-04-02 11:50:10.000000000 +0200
|
||||
+++ src/qemu_conf.c 2009-04-03 17:46:59.000000000 +0200
|
||||
@@ -779,6 +779,20 @@ int qemudBuildCommandLine(virConnectPtr
|
||||
char domid[50];
|
||||
char *pidfile;
|
||||
const char *cpu = NULL;
|
||||
+ int skipSound = 0;
|
||||
+
|
||||
+ if (driver->securityDriver &&
|
||||
+ driver->securityDriver->name &&
|
||||
+ STREQ(driver->securityDriver->name, "selinux") &&
|
||||
+ getuid() == 0) {
|
||||
+ static int soundWarned = 0;
|
||||
+ skipSound = 1;
|
||||
+ if (def->nsounds &&
|
||||
+ !soundWarned) {
|
||||
+ soundWarned = 1;
|
||||
+ VIR_WARN0("Sound cards for VMs are disabled while SELinux security model is active");
|
||||
+ }
|
||||
+ }
|
||||
|
||||
uname_normalize(&ut);
|
||||
|
||||
@@ -1425,7 +1439,8 @@ int qemudBuildCommandLine(virConnectPtr
|
||||
}
|
||||
|
||||
/* Add sound hardware */
|
||||
- if (def->nsounds) {
|
||||
+ if (def->nsounds &&
|
||||
+ !skipSound) {
|
||||
int size = 100;
|
||||
char *modstr;
|
||||
if (VIR_ALLOC_N(modstr, size+1) < 0)
|
||||
+918
-25
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user