On 08/20/2012 08:12 AM, Viktor Mihajlovski wrote:
This is a fix for the object label generation. It uses a new flag
for
virSecuritySELinuxGenNewContext that specifies whether the context is
for an object. If so the context role remains unchanged.
Without this fix it is not possible to start domains with image file or
block device backed storage when selinux is enabled.
Signed-off-by: Viktor Mihajlovski <mihajlov(a)linux.vnet.ibm.com>
---
src/security/security_selinux.c | 17 +++++++++++------
1 files changed, 11 insertions(+), 6 deletions(-)
Differs from v1 only in whitespace, and v1 had acks, so I pushed this.
--
Eric Blake eblake(a)redhat.com +1-919-301-3266
Libvirt virtualization library
http://libvirt.org