From: Michal Privoznik Date: Mon, 15 Apr 2019 15:16:39 +0000 (+0200) Subject: virSecurityDACRestoreChardevLabel: Restore UNIX sockets too X-Git-Tag: v5.3.0-rc1~81 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=abd70ac3ae35ef0425c197c619b0f319b4a7ce4d;p=thirdparty%2Flibvirt.git virSecurityDACRestoreChardevLabel: Restore UNIX sockets too We're setting seclabels on unix sockets but never restoring them. Surprisingly, we are doing so in SELinux driver. Signed-off-by: Michal Privoznik Reviewed-by: Ján Tomko --- diff --git a/src/security/security_dac.c b/src/security/security_dac.c index 6f8ca8cd54..3c21dbbddb 100644 --- a/src/security/security_dac.c +++ b/src/security/security_dac.c @@ -1457,13 +1457,20 @@ virSecurityDACRestoreChardevLabel(virSecurityManagerPtr mgr, ret = 0; break; + case VIR_DOMAIN_CHR_TYPE_UNIX: + if (!dev_source->data.nix.listen && + virSecurityDACRestoreFileLabel(mgr, dev_source->data.nix.path) < 0) { + goto done; + } + ret = 0; + break; + case VIR_DOMAIN_CHR_TYPE_NULL: case VIR_DOMAIN_CHR_TYPE_VC: case VIR_DOMAIN_CHR_TYPE_PTY: case VIR_DOMAIN_CHR_TYPE_STDIO: case VIR_DOMAIN_CHR_TYPE_UDP: case VIR_DOMAIN_CHR_TYPE_TCP: - case VIR_DOMAIN_CHR_TYPE_UNIX: case VIR_DOMAIN_CHR_TYPE_SPICEVMC: case VIR_DOMAIN_CHR_TYPE_SPICEPORT: case VIR_DOMAIN_CHR_TYPE_NMDM: