2016-11-23 10:52:57 +00:00
|
|
|
/*
|
|
|
|
* qemu_security.c: QEMU security management
|
|
|
|
*
|
|
|
|
* Copyright (C) 2016 Red Hat, Inc.
|
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU Lesser General Public
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 2.1 of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This library is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
* Lesser General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Lesser General Public
|
|
|
|
* License along with this library. If not, see
|
|
|
|
* <http://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
* Authors:
|
|
|
|
* Michal Privoznik <mprivozn@redhat.com>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
|
|
|
#include "qemu_domain.h"
|
|
|
|
#include "qemu_security.h"
|
|
|
|
#include "virlog.h"
|
|
|
|
|
|
|
|
#define VIR_FROM_THIS VIR_FROM_QEMU
|
|
|
|
|
|
|
|
VIR_LOG_INIT("qemu.qemu_process");
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecuritySetAllLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
const char *stdin_path)
|
|
|
|
{
|
2016-12-15 15:47:15 +00:00
|
|
|
int ret = -1;
|
2017-05-29 12:27:51 +00:00
|
|
|
qemuDomainObjPrivatePtr priv = vm->privateData;
|
2016-12-15 15:47:15 +00:00
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerSetAllLabel(driver->securityManager,
|
|
|
|
vm->def,
|
2017-05-29 12:27:51 +00:00
|
|
|
stdin_path,
|
|
|
|
priv->chardevStdioLogd) < 0)
|
2016-12-15 15:47:15 +00:00
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
2016-11-23 10:52:57 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
void
|
|
|
|
qemuSecurityRestoreAllLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
bool migrated)
|
|
|
|
{
|
2017-05-29 12:27:51 +00:00
|
|
|
qemuDomainObjPrivatePtr priv = vm->privateData;
|
|
|
|
|
2017-01-20 09:06:39 +00:00
|
|
|
/* In contrast to qemuSecuritySetAllLabel, do not use
|
|
|
|
* secdriver transactions here. This function is called from
|
|
|
|
* qemuProcessStop() which is meant to do cleanup after qemu
|
|
|
|
* process died. If it did do, the namespace is gone as qemu
|
|
|
|
* was the only process running there. We would not succeed
|
|
|
|
* in entering the namespace then. */
|
|
|
|
virSecurityManagerRestoreAllLabel(driver->securityManager,
|
|
|
|
vm->def,
|
2017-05-29 12:27:51 +00:00
|
|
|
migrated,
|
|
|
|
priv->chardevStdioLogd);
|
2016-11-23 10:52:57 +00:00
|
|
|
}
|
2016-11-15 15:53:04 +00:00
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecuritySetDiskLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainDiskDefPtr disk)
|
|
|
|
{
|
2017-01-18 08:50:14 +00:00
|
|
|
int ret = -1;
|
2016-11-15 15:53:04 +00:00
|
|
|
|
2017-01-18 08:50:14 +00:00
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerSetDiskLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
disk) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
2016-11-15 15:53:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecurityRestoreDiskLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainDiskDefPtr disk)
|
|
|
|
{
|
2017-01-18 08:50:14 +00:00
|
|
|
int ret = -1;
|
2016-11-15 15:53:04 +00:00
|
|
|
|
2017-01-18 08:50:14 +00:00
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerRestoreDiskLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
disk) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
2017-02-03 16:09:33 +00:00
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecuritySetImageLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virStorageSourcePtr src)
|
|
|
|
{
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerSetImageLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
src) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecurityRestoreImageLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virStorageSourcePtr src)
|
|
|
|
{
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerRestoreImageLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
src) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
2017-01-18 08:50:14 +00:00
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
2016-11-15 15:53:04 +00:00
|
|
|
}
|
2016-11-16 14:27:47 +00:00
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecuritySetHostdevLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainHostdevDefPtr hostdev)
|
|
|
|
{
|
2017-01-18 08:50:14 +00:00
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerSetHostdevLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
hostdev,
|
|
|
|
NULL) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
2016-11-16 14:27:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecurityRestoreHostdevLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainHostdevDefPtr hostdev)
|
|
|
|
{
|
2017-01-18 08:50:14 +00:00
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerRestoreHostdevLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
hostdev,
|
|
|
|
NULL) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
2016-11-16 14:27:47 +00:00
|
|
|
}
|
2016-08-04 13:26:09 +00:00
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecuritySetMemoryLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainMemoryDefPtr mem)
|
|
|
|
{
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerSetMemoryLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
mem) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
qemuSecurityRestoreMemoryLabel(virQEMUDriverPtr driver,
|
|
|
|
virDomainObjPtr vm,
|
|
|
|
virDomainMemoryDefPtr mem)
|
|
|
|
{
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionStart(driver->securityManager) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (virSecurityManagerRestoreMemoryLabel(driver->securityManager,
|
|
|
|
vm->def,
|
|
|
|
mem) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
if (qemuDomainNamespaceEnabled(vm, QEMU_DOMAIN_NS_MOUNT) &&
|
|
|
|
virSecurityManagerTransactionCommit(driver->securityManager,
|
|
|
|
vm->pid) < 0)
|
|
|
|
goto cleanup;
|
|
|
|
|
|
|
|
ret = 0;
|
|
|
|
cleanup:
|
|
|
|
virSecurityManagerTransactionAbort(driver->securityManager);
|
|
|
|
return ret;
|
|
|
|
}
|