[PATCH 0/6] security_selinux: Don't store XATTRs if FS fakes SELinux

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



For full explanation see 6/6, but here's a digest:

GlusterFS via FUSE supports XATTRs but doesn't allow any SELinux label
change (which is fortunate for us because migrations work at least).
However, we need to treat this situation as "don't remember any
seclabels" because if the source sets XATTRs and the migration
destination tries to set different label this fails.

Michal Prívozník (6):
  virSecuritySELinuxGetProcessLabel: Fix comment
  virSecuritySELinuxSetFileconImpl: Drop @optional argument
  security_selinux: DropvirSecuritySELinuxSetFileconOptional()
  security_selinux: Drop @optional from _virSecuritySELinuxContextItem
  security_selinux: Drop virSecuritySELinuxSetFileconHelper
  security_selinux: Play nicely with network FS that only emulates
    SELinux

 src/security/security_selinux.c | 141 ++++++++++++++++----------------
 1 file changed, 70 insertions(+), 71 deletions(-)

-- 
2.21.0

--
libvir-list mailing list
libvir-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libvir-list




[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Fedora Tools]

  Powered by Linux