From abd70ac3ae35ef0425c197c619b0f319b4a7ce4d Mon Sep 17 00:00:00 2001 From: Michal Privoznik Date: Mon, 15 Apr 2019 17:16:39 +0200 Subject: [PATCH] virSecurityDACRestoreChardevLabel: Restore UNIX sockets too MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit We're setting seclabels on unix sockets but never restoring them. Surprisingly, we are doing so in SELinux driver. Signed-off-by: Michal Privoznik Reviewed-by: Ján Tomko --- src/security/security_dac.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/src/security/security_dac.c b/src/security/security_dac.c index 6f8ca8cd54..3c21dbbddb 100644 --- a/src/security/security_dac.c +++ b/src/security/security_dac.c @@ -1457,13 +1457,20 @@ virSecurityDACRestoreChardevLabel(virSecurityManagerPtr mgr, ret = 0; break; + case VIR_DOMAIN_CHR_TYPE_UNIX: + if (!dev_source->data.nix.listen && + virSecurityDACRestoreFileLabel(mgr, dev_source->data.nix.path) < 0) { + goto done; + } + ret = 0; + break; + case VIR_DOMAIN_CHR_TYPE_NULL: case VIR_DOMAIN_CHR_TYPE_VC: case VIR_DOMAIN_CHR_TYPE_PTY: case VIR_DOMAIN_CHR_TYPE_STDIO: case VIR_DOMAIN_CHR_TYPE_UDP: case VIR_DOMAIN_CHR_TYPE_TCP: - case VIR_DOMAIN_CHR_TYPE_UNIX: case VIR_DOMAIN_CHR_TYPE_SPICEVMC: case VIR_DOMAIN_CHR_TYPE_SPICEPORT: case VIR_DOMAIN_CHR_TYPE_NMDM: