]> xenbits.xensource.com Git - libvirt.git/commitdiff
security: Do not restore labels on device tree binary
authorJiri Denemark <jdenemar@redhat.com>
Fri, 15 Jan 2016 15:34:37 +0000 (16:34 +0100)
committerJiri Denemark <jdenemar@redhat.com>
Fri, 15 Jan 2016 15:34:37 +0000 (16:34 +0100)
A device tree binary file specified by /domain/os/dtb element is a
read-only resource similar to kernel and initrd files. We shouldn't
restore its label when destroying a domain to avoid breaking other
domains configure with the same device tree.

Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
src/security/security_dac.c
src/security/security_selinux.c

index 378b92210fec1a86f50adf8165e4828a6b47a7c6..a09aba5f62c66a37079d5226c44ebb5f00dd7322 100644 (file)
@@ -1128,10 +1128,6 @@ virSecurityDACRestoreAllLabel(virSecurityManagerPtr mgr,
         virSecurityDACRestoreFileLabel(priv, def->os.loader->nvram) < 0)
         rc = -1;
 
-    if (def->os.dtb &&
-        virSecurityDACRestoreFileLabel(priv, def->os.dtb) < 0)
-        rc = -1;
-
     return rc;
 }
 
index 475cdbcf91d1e534085e2c877d2e98b599bc41ef..9e986350fbb14f35845951384468cc8f49670ec7 100644 (file)
@@ -2034,10 +2034,6 @@ virSecuritySELinuxRestoreAllLabel(virSecurityManagerPtr mgr,
         virSecuritySELinuxRestoreFileLabel(mgr, def->os.loader->nvram) < 0)
         rc = -1;
 
-    if (def->os.dtb &&
-        virSecuritySELinuxRestoreFileLabel(mgr, def->os.dtb) < 0)
-        rc = -1;
-
     return rc;
 }