|
|
404507 |
From 2661dd59c5885adddb522be5e5542461f4e8bf3c Mon Sep 17 00:00:00 2001
|
|
|
404507 |
Message-Id: <2661dd59c5885adddb522be5e5542461f4e8bf3c@dist-git>
|
|
|
404507 |
From: =?UTF-8?q?J=C3=A1n=20Tomko?= <jtomko@redhat.com>
|
|
|
404507 |
Date: Mon, 27 Nov 2017 14:21:01 +0100
|
|
|
404507 |
Subject: [PATCH] qemu: functions for dealing with input device namespaces and
|
|
|
404507 |
labels
|
|
|
404507 |
MIME-Version: 1.0
|
|
|
404507 |
Content-Type: text/plain; charset=UTF-8
|
|
|
404507 |
Content-Transfer-Encoding: 8bit
|
|
|
404507 |
|
|
|
404507 |
Introudce functions that will let us create the evdevs in namespaces
|
|
|
404507 |
and label the devices on input device hotplug/hotunplug.
|
|
|
404507 |
|
|
|
404507 |
(cherry picked from commit c4c7a18c4b8107b3521880eb20a94c928bdeacb0)
|
|
|
404507 |
|
|
|
404507 |
https://bugzilla.redhat.com/show_bug.cgi?id=1509866
|
|
|
404507 |
|
|
|
404507 |
Signed-off-by: Ján Tomko <jtomko@redhat.com>
|
|
|
404507 |
Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
|
|
|
404507 |
---
|
|
|
404507 |
src/qemu/qemu_domain.c | 72 ++++++++++++++++++++++++++++++++++++++++++++++++
|
|
|
404507 |
src/qemu/qemu_domain.h | 6 ++++
|
|
|
404507 |
src/qemu/qemu_security.c | 58 ++++++++++++++++++++++++++++++++++++++
|
|
|
404507 |
src/qemu/qemu_security.h | 6 ++++
|
|
|
404507 |
4 files changed, 142 insertions(+)
|
|
|
404507 |
|
|
|
404507 |
diff --git a/src/qemu/qemu_domain.c b/src/qemu/qemu_domain.c
|
|
|
404507 |
index dbe9ed5e98..138f773c22 100644
|
|
|
404507 |
--- a/src/qemu/qemu_domain.c
|
|
|
404507 |
+++ b/src/qemu/qemu_domain.c
|
|
|
404507 |
@@ -9997,6 +9997,78 @@ qemuDomainNamespaceTeardownRNG(virQEMUDriverPtr driver,
|
|
|
404507 |
}
|
|
|
404507 |
|
|
|
404507 |
|
|
|
404507 |
+int
|
|
|
404507 |
+qemuDomainNamespaceSetupInput(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input)
|
|
|
404507 |
+{
|
|
|
404507 |
+ qemuDomainObjPrivatePtr priv = vm->privateData;
|
|
|
404507 |
+ virQEMUDriverPtr driver = priv->driver;
|
|
|
404507 |
+ virQEMUDriverConfigPtr cfg = NULL;
|
|
|
404507 |
+ char **devMountsPath = NULL;
|
|
|
404507 |
+ size_t ndevMountsPath = 0;
|
|
|
404507 |
+ const char *path = NULL;
|
|
|
404507 |
+ int ret = -1;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (!(path = virDomainInputDefGetPath(input)))
|
|
|
404507 |
+ return 0;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (!qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT))
|
|
|
404507 |
+ return 0;
|
|
|
404507 |
+
|
|
|
404507 |
+ cfg = virQEMUDriverGetConfig(driver);
|
|
|
404507 |
+ if (qemuDomainGetPreservedMounts(cfg, vm,
|
|
|
404507 |
+ &devMountsPath, NULL,
|
|
|
404507 |
+ &ndevMountsPath) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainAttachDeviceMknod(driver, vm, path,
|
|
|
404507 |
+ devMountsPath, ndevMountsPath) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ ret = 0;
|
|
|
404507 |
+ cleanup:
|
|
|
404507 |
+ virStringListFreeCount(devMountsPath, ndevMountsPath);
|
|
|
404507 |
+ virObjectUnref(cfg);
|
|
|
404507 |
+ return ret;
|
|
|
404507 |
+}
|
|
|
404507 |
+
|
|
|
404507 |
+
|
|
|
404507 |
+int
|
|
|
404507 |
+qemuDomainNamespaceTeardownInput(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input)
|
|
|
404507 |
+{
|
|
|
404507 |
+ qemuDomainObjPrivatePtr priv = vm->privateData;
|
|
|
404507 |
+ virQEMUDriverPtr driver = priv->driver;
|
|
|
404507 |
+ virQEMUDriverConfigPtr cfg = NULL;
|
|
|
404507 |
+ char **devMountsPath = NULL;
|
|
|
404507 |
+ size_t ndevMountsPath = 0;
|
|
|
404507 |
+ const char *path = NULL;
|
|
|
404507 |
+ int ret = -1;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (!(path = virDomainInputDefGetPath(input)))
|
|
|
404507 |
+ return 0;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (!qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT))
|
|
|
404507 |
+ return 0;
|
|
|
404507 |
+
|
|
|
404507 |
+ cfg = virQEMUDriverGetConfig(driver);
|
|
|
404507 |
+ if (qemuDomainGetPreservedMounts(cfg, vm,
|
|
|
404507 |
+ &devMountsPath, NULL,
|
|
|
404507 |
+ &ndevMountsPath) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainDetachDeviceUnlink(driver, vm, path,
|
|
|
404507 |
+ devMountsPath, ndevMountsPath) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ ret = 0;
|
|
|
404507 |
+ cleanup:
|
|
|
404507 |
+ virStringListFreeCount(devMountsPath, ndevMountsPath);
|
|
|
404507 |
+ virObjectUnref(cfg);
|
|
|
404507 |
+ return ret;
|
|
|
404507 |
+}
|
|
|
404507 |
+
|
|
|
404507 |
+
|
|
|
404507 |
/**
|
|
|
404507 |
* qemuDomainDiskLookupByNodename:
|
|
|
404507 |
* @def: domain definition to look for the disk
|
|
|
404507 |
diff --git a/src/qemu/qemu_domain.h b/src/qemu/qemu_domain.h
|
|
|
404507 |
index caf583373f..1a82922415 100644
|
|
|
404507 |
--- a/src/qemu/qemu_domain.h
|
|
|
404507 |
+++ b/src/qemu/qemu_domain.h
|
|
|
404507 |
@@ -969,6 +969,12 @@ int qemuDomainNamespaceTeardownRNG(virQEMUDriverPtr driver,
|
|
|
404507 |
virDomainObjPtr vm,
|
|
|
404507 |
virDomainRNGDefPtr rng);
|
|
|
404507 |
|
|
|
404507 |
+int qemuDomainNamespaceSetupInput(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input);
|
|
|
404507 |
+
|
|
|
404507 |
+int qemuDomainNamespaceTeardownInput(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input);
|
|
|
404507 |
+
|
|
|
404507 |
virDomainDiskDefPtr qemuDomainDiskLookupByNodename(virDomainDefPtr def,
|
|
|
404507 |
const char *nodename,
|
|
|
404507 |
virStorageSourcePtr *src,
|
|
|
404507 |
diff --git a/src/qemu/qemu_security.c b/src/qemu/qemu_security.c
|
|
|
404507 |
index 6fc3b0bb6e..e7d2bbd5a3 100644
|
|
|
404507 |
--- a/src/qemu/qemu_security.c
|
|
|
404507 |
+++ b/src/qemu/qemu_security.c
|
|
|
404507 |
@@ -306,3 +306,61 @@ qemuSecurityRestoreMemoryLabel(virQEMUDriverPtr driver,
|
|
|
404507 |
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
404507 |
return ret;
|
|
|
404507 |
}
|
|
|
404507 |
+
|
|
|
404507 |
+
|
|
|
404507 |
+int
|
|
|
404507 |
+qemuSecuritySetInputLabel(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input)
|
|
|
404507 |
+{
|
|
|
404507 |
+ qemuDomainObjPrivatePtr priv = vm->privateData;
|
|
|
404507 |
+ virQEMUDriverPtr driver = priv->driver;
|
|
|
404507 |
+ int ret = -1;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
404507 |
+ virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (virSecurityManagerSetInputLabel(driver->securityManager,
|
|
|
404507 |
+ vm->def,
|
|
|
404507 |
+ input) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
404507 |
+ virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
404507 |
+ vm->pid) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ ret = 0;
|
|
|
404507 |
+ cleanup:
|
|
|
404507 |
+ virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
404507 |
+ return ret;
|
|
|
404507 |
+}
|
|
|
404507 |
+
|
|
|
404507 |
+
|
|
|
404507 |
+int
|
|
|
404507 |
+qemuSecurityRestoreInputLabel(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input)
|
|
|
404507 |
+{
|
|
|
404507 |
+ qemuDomainObjPrivatePtr priv = vm->privateData;
|
|
|
404507 |
+ virQEMUDriverPtr driver = priv->driver;
|
|
|
404507 |
+ int ret = -1;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
404507 |
+ virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (virSecurityManagerRestoreInputLabel(driver->securityManager,
|
|
|
404507 |
+ vm->def,
|
|
|
404507 |
+ input) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
404507 |
+ virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
404507 |
+ vm->pid) < 0)
|
|
|
404507 |
+ goto cleanup;
|
|
|
404507 |
+
|
|
|
404507 |
+ ret = 0;
|
|
|
404507 |
+ cleanup:
|
|
|
404507 |
+ virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
404507 |
+ return ret;
|
|
|
404507 |
+}
|
|
|
404507 |
diff --git a/src/qemu/qemu_security.h b/src/qemu/qemu_security.h
|
|
|
404507 |
index 7b25855bf9..76d63f06ec 100644
|
|
|
404507 |
--- a/src/qemu/qemu_security.h
|
|
|
404507 |
+++ b/src/qemu/qemu_security.h
|
|
|
404507 |
@@ -70,6 +70,12 @@ int qemuSecurityRestoreMemoryLabel(virQEMUDriverPtr driver,
|
|
|
404507 |
virDomainObjPtr vm,
|
|
|
404507 |
virDomainMemoryDefPtr mem);
|
|
|
404507 |
|
|
|
404507 |
+int qemuSecuritySetInputLabel(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input);
|
|
|
404507 |
+
|
|
|
404507 |
+int qemuSecurityRestoreInputLabel(virDomainObjPtr vm,
|
|
|
404507 |
+ virDomainInputDefPtr input);
|
|
|
404507 |
+
|
|
|
404507 |
/* Please note that for these APIs there is no wrapper yet. Do NOT blindly add
|
|
|
404507 |
* new APIs here. If an API can touch a /dev file add a proper wrapper instead.
|
|
|
404507 |
*/
|
|
|
404507 |
--
|
|
|
404507 |
2.15.1
|
|
|
404507 |
|