c313de
From 86f741bf77f39d4af3698b71797e430c2a6989c3 Mon Sep 17 00:00:00 2001
c313de
Message-Id: <86f741bf77f39d4af3698b71797e430c2a6989c3@dist-git>
c313de
From: Michal Privoznik <mprivozn@redhat.com>
c313de
Date: Thu, 3 Jan 2019 10:03:44 +0100
c313de
Subject: [PATCH] qemu_security: Fully implement qemuSecurityDomainSetPathLabel
c313de
c313de
Even though the current use of the function does not require full
c313de
implementation with transactions (none of the callers pass a path
c313de
somewhere under /dev), it doesn't hurt either. Moreover, in
c313de
future patches the paradigm is going to shift so that any API
c313de
that touches a file is required to use transactions.
c313de
c313de
Signed-off-by: Michal Privoznik <mprivozn@redhat.com>
c313de
Reviewed-by: John Ferlan <jferlan@redhat.com>
c313de
(cherry picked from commit da24db2d30352c094f76dffb523e7f344ff8e30d)
c313de
c313de
https://bugzilla.redhat.com/show_bug.cgi?id=1658112
c313de
c313de
Signed-off-by: Erik Skultety <eskultet@redhat.com>
c313de
Message-Id: <4de2beabd9868259f1856f7eafcc835b5b2a3d6b.1546506016.git.eskultet@redhat.com>
c313de
Reviewed-by: Jiri Denemark <jdenemar@redhat.com>
c313de
---
c313de
 src/qemu/qemu_domain.c   |  3 +--
c313de
 src/qemu/qemu_process.c  | 15 ++++++---------
c313de
 src/qemu/qemu_security.c | 30 ++++++++++++++++++++++++++++++
c313de
 src/qemu/qemu_security.h |  6 +++++-
c313de
 4 files changed, 42 insertions(+), 12 deletions(-)
c313de
c313de
diff --git a/src/qemu/qemu_domain.c b/src/qemu/qemu_domain.c
c313de
index 95b84af78a..c9899b9e6d 100644
c313de
--- a/src/qemu/qemu_domain.c
c313de
+++ b/src/qemu/qemu_domain.c
c313de
@@ -801,8 +801,7 @@ qemuDomainWriteMasterKeyFile(virQEMUDriverPtr driver,
c313de
         goto cleanup;
c313de
     }
c313de
 
c313de
-    if (qemuSecurityDomainSetPathLabel(driver->securityManager,
c313de
-                                       vm->def, path, false) < 0)
c313de
+    if (qemuSecurityDomainSetPathLabel(driver, vm, path, false) < 0)
c313de
         goto cleanup;
c313de
 
c313de
     ret = 0;
c313de
diff --git a/src/qemu/qemu_process.c b/src/qemu/qemu_process.c
c313de
index 34aac69afc..c0f95dd5f1 100644
c313de
--- a/src/qemu/qemu_process.c
c313de
+++ b/src/qemu/qemu_process.c
c313de
@@ -2778,8 +2778,7 @@ qemuProcessStartManagedPRDaemon(virDomainObjPtr vm)
c313de
         virCgroupAddMachineTask(priv->cgroup, cpid) < 0)
c313de
         goto cleanup;
c313de
 
c313de
-    if (qemuSecurityDomainSetPathLabel(driver->securityManager,
c313de
-                                       vm->def, socketPath, true) < 0)
c313de
+    if (qemuSecurityDomainSetPathLabel(driver, vm, socketPath, true) < 0)
c313de
         goto cleanup;
c313de
 
c313de
     priv->prDaemonRunning = true;
c313de
@@ -3656,7 +3655,7 @@ qemuProcessNeedMemoryBackingPath(virDomainDefPtr def,
c313de
 
c313de
 static int
c313de
 qemuProcessBuildDestroyMemoryPathsImpl(virQEMUDriverPtr driver,
c313de
-                                       virDomainDefPtr def,
c313de
+                                       virDomainObjPtr vm,
c313de
                                        const char *path,
c313de
                                        bool build)
c313de
 {
c313de
@@ -3671,8 +3670,7 @@ qemuProcessBuildDestroyMemoryPathsImpl(virQEMUDriverPtr driver,
c313de
             return -1;
c313de
         }
c313de
 
c313de
-        if (qemuSecurityDomainSetPathLabel(driver->securityManager,
c313de
-                                           def, path, true) < 0)
c313de
+        if (qemuSecurityDomainSetPathLabel(driver, vm, path, true) < 0)
c313de
             return -1;
c313de
     } else {
c313de
         if (virFileDeleteTree(path) < 0)
c313de
@@ -3708,7 +3706,7 @@ qemuProcessBuildDestroyMemoryPaths(virQEMUDriverPtr driver,
c313de
             if (!path)
c313de
                 goto cleanup;
c313de
 
c313de
-            if (qemuProcessBuildDestroyMemoryPathsImpl(driver, vm->def,
c313de
+            if (qemuProcessBuildDestroyMemoryPathsImpl(driver, vm,
c313de
                                                        path, build) < 0)
c313de
                 goto cleanup;
c313de
 
c313de
@@ -3720,7 +3718,7 @@ qemuProcessBuildDestroyMemoryPaths(virQEMUDriverPtr driver,
c313de
         if (qemuGetMemoryBackingDomainPath(vm->def, cfg, &path) < 0)
c313de
             goto cleanup;
c313de
 
c313de
-        if (qemuProcessBuildDestroyMemoryPathsImpl(driver, vm->def,
c313de
+        if (qemuProcessBuildDestroyMemoryPathsImpl(driver, vm,
c313de
                                                    path, build) < 0)
c313de
             goto cleanup;
c313de
 
c313de
@@ -4904,8 +4902,7 @@ qemuProcessMakeDir(virQEMUDriverPtr driver,
c313de
         goto cleanup;
c313de
     }
c313de
 
c313de
-    if (qemuSecurityDomainSetPathLabel(driver->securityManager,
c313de
-                                       vm->def, path, true) < 0)
c313de
+    if (qemuSecurityDomainSetPathLabel(driver, vm, path, true) < 0)
c313de
         goto cleanup;
c313de
 
c313de
     ret = 0;
c313de
diff --git a/src/qemu/qemu_security.c b/src/qemu/qemu_security.c
c313de
index af3be42854..268def309a 100644
c313de
--- a/src/qemu/qemu_security.c
c313de
+++ b/src/qemu/qemu_security.c
c313de
@@ -493,3 +493,33 @@ qemuSecurityCleanupTPMEmulator(virQEMUDriverPtr driver,
c313de
 {
c313de
     virSecurityManagerRestoreTPMLabels(driver->securityManager, def);
c313de
 }
c313de
+
c313de
+
c313de
+int
c313de
+qemuSecurityDomainSetPathLabel(virQEMUDriverPtr driver,
c313de
+                               virDomainObjPtr vm,
c313de
+                               const char *path,
c313de
+                               bool allowSubtree)
c313de
+{
c313de
+    int ret = -1;
c313de
+
c313de
+    if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
c313de
+        virSecurityManagerTransactionStart(driver->securityManager) < 0)
c313de
+        goto cleanup;
c313de
+
c313de
+    if (virSecurityManagerDomainSetPathLabel(driver->securityManager,
c313de
+                                             vm->def,
c313de
+                                             path,
c313de
+                                             allowSubtree) < 0)
c313de
+        goto cleanup;
c313de
+
c313de
+    if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
c313de
+        virSecurityManagerTransactionCommit(driver->securityManager,
c313de
+                                            vm->pid) < 0)
c313de
+        goto cleanup;
c313de
+
c313de
+    ret = 0;
c313de
+ cleanup:
c313de
+    virSecurityManagerTransactionAbort(driver->securityManager);
c313de
+    return ret;
c313de
+}
c313de
diff --git a/src/qemu/qemu_security.h b/src/qemu/qemu_security.h
c313de
index a189b63828..fd11fbdd9d 100644
c313de
--- a/src/qemu/qemu_security.h
c313de
+++ b/src/qemu/qemu_security.h
c313de
@@ -95,12 +95,16 @@ int qemuSecurityStartTPMEmulator(virQEMUDriverPtr driver,
c313de
 void qemuSecurityCleanupTPMEmulator(virQEMUDriverPtr driver,
c313de
                                     virDomainDefPtr def);
c313de
 
c313de
+int qemuSecurityDomainSetPathLabel(virQEMUDriverPtr driver,
c313de
+                                   virDomainObjPtr vm,
c313de
+                                   const char *path,
c313de
+                                   bool allowSubtree);
c313de
+
c313de
 /* Please note that for these APIs there is no wrapper yet. Do NOT blindly add
c313de
  * new APIs here. If an API can touch a /dev file add a proper wrapper instead.
c313de
  */
c313de
 # define qemuSecurityCheckAllLabel virSecurityManagerCheckAllLabel
c313de
 # define qemuSecurityClearSocketLabel virSecurityManagerClearSocketLabel
c313de
-# define qemuSecurityDomainSetPathLabel virSecurityManagerDomainSetPathLabel
c313de
 # define qemuSecurityGenLabel virSecurityManagerGenLabel
c313de
 # define qemuSecurityGetBaseLabel virSecurityManagerGetBaseLabel
c313de
 # define qemuSecurityGetDOI virSecurityManagerGetDOI
c313de
-- 
c313de
2.22.0
c313de