]> git.ipfire.org Git - thirdparty/libvirt.git/commit
security: Don't add seclabel of type none if there's already a seclabel
authorMichal Privoznik <mprivozn@redhat.com>
Thu, 21 Mar 2013 15:32:07 +0000 (16:32 +0100)
committerMichal Privoznik <mprivozn@redhat.com>
Thu, 28 Mar 2013 09:01:06 +0000 (10:01 +0100)
commite4a28a328188e715de8d587b390cb44e2d6c3fb4
tree2040fb4a59a6e1a27ec71256d7e58fe98c07e953
parent6c4de1161425a610797495549349d194b90fb023
security: Don't add seclabel of type none if there's already a seclabel

https://bugzilla.redhat.com/show_bug.cgi?id=923946

The <seclabel type='none'/> should be added iff there is no other
seclabel defined within a domain. This bug can be easily reproduced:
1) configure selinux seclabel for a domain
2) disable system's selinux and restart libvirtd
3) observe <seclabel type='none'/> being appended to a domain on its
   startup
src/security/security_manager.c