Read-only mirror. Please submit merge requests / issues to https://gitlab.com/libvirt/libvirt
Go to file
Jiri Denemark ce53382ba2 security: Skip labeling resources when seclabel defaults to none
If a domain is explicitly configured with <seclabel type="none"/> we
correctly ensure that no labeling will be done by setting
norelabel=true. However, if no seclabel element is present in domain XML
and hypervisor is configured not to confine domains by default, we only
set type to "none" without turning off relabeling. Thus if such a domain
is being started, security driver wants to relabel resources with
default label, which doesn't make any sense.

Moreover, with SELinux security driver, the generated image label lacks
"s0" sensitivity, which causes setfilecon() fail with EINVAL in
enforcing mode.
2012-07-27 18:58:48 +02:00
.gnulib@dbd914496c build: update to latest gnulib, for secure tarball 2012-07-26 07:50:59 -06:00
build-aux maint: avoid regression on copyright listings 2012-07-27 07:42:34 -06:00
daemon doc: add more description on libvirtd option timeout 2012-07-26 15:30:26 +08:00
docs docs: Add method to print warnings in docBuilder class 2012-07-27 15:47:15 +02:00
examples maint: avoid regression on copyright listings 2012-07-27 07:42:34 -06:00
gnulib build: fix fresh checkout on RHEL5 2012-04-19 17:11:43 -06:00
include lib: Revert removing of Summary and Description fields in headers 2012-07-27 15:47:16 +02:00
m4 maint: make it easier to copy FORTIFY_SOURCE snippet 2012-06-07 10:52:37 -06:00
po virsh: Split cmds in node device group from virsh.c 2012-07-26 12:00:43 +08:00
python Define public API for receiving guest memory balloon events 2012-07-14 16:02:26 +08:00
src security: Skip labeling resources when seclabel defaults to none 2012-07-27 18:58:48 +02:00
tests maint: avoid regression on copyright listings 2012-07-27 07:42:34 -06:00
tools libvirt-guests: systemd host shutdown does not work 2012-07-27 09:31:52 -06:00
.dir-locals.el maint: let emacs avoid tabs in rng files 2011-08-13 08:56:26 -06:00
.gitignore Make ESX & Hyper-V code generator safe with parallel builds 2012-07-23 15:49:15 +01:00
.gitmodules make .gnulib a submodule 2009-07-08 16:17:51 +02:00
.mailmap virsh: check if specified debug level is in range 2012-07-26 08:21:04 -06:00
AUTHORS maint: spelling correction in AUTHORS 2012-07-25 08:01:24 -06:00
autobuild.sh Switch automated builds to use Mingw64 toolchain instead of Mingw32 2012-06-25 10:41:10 +01:00
autogen.sh Allow NOCONFIGURE=1 to make autogen.sh skip ./configure 2012-06-25 10:41:10 +01:00
bootstrap maint: regenerate bootstrap 2012-07-27 09:34:04 -06:00
bootstrap.conf maint: avoid regression on copyright listings 2012-07-27 07:42:34 -06:00
cfg.mk maint: avoid regression on copyright listings 2012-07-27 07:42:34 -06:00
ChangeLog-old virterror.c: Fix several spelling mistakes 2012-02-03 11:32:51 -07:00
configure.ac Add a sheepdog backend for the storage driver 2012-07-18 20:08:27 +01:00
COPYING.LIB remove all trailing blank lines 2009-07-16 15:06:42 +02:00
HACKING docs: Improve patch submission guidelines 2012-07-16 11:05:12 +02:00
libvirt.pc.in build: silence warning from autoconf 2012-05-30 09:22:02 -06:00
libvirt.spec.in building: fix deps error when some drivers are not built 2012-07-24 20:41:05 +08:00
Makefile.am Switch automated builds to use Mingw64 toolchain instead of Mingw32 2012-06-25 10:41:10 +01:00
Makefile.nonreentrant Ban use of all inet_* functions 2010-10-22 11:59:23 +01:00
mingw-libvirt.spec.in Remove accidentally added Patch: lines from mingw-libvirt.spec.in 2012-06-27 14:31:52 +01:00
README Correct typos in the documentation (Atsushi SAKAI) 2008-01-24 10:15:13 +00:00
README-hacking maint: relax git minimum version 2010-02-24 14:29:27 -05:00
TODO Update todo list file to point at bugzilla/website 2010-10-13 16:45:26 +01:00

         LibVirt : simple API for virtualization

  Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). It is free software
available under the GNU Lesser General Public License. Virtualization of
the Linux Operating System means the ability to run multiple instances of
Operating Systems concurrently on a single hardware system where the basic
resources are driven by a Linux instance. The library aim at providing
long term stable C API initially for the Xen paravirtualization but
should be able to integrate other virtualization mechanisms if needed.

Daniel Veillard <veillard@redhat.com>