From patchwork Tue Oct 8 16:22:24 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Cole Robinson X-Patchwork-Id: 175518 Delivered-To: patch@linaro.org Received: by 2002:a92:7e96:0:0:0:0:0 with SMTP id q22csp5920546ill; Tue, 8 Oct 2019 09:25:08 -0700 (PDT) X-Google-Smtp-Source: APXvYqwSWHJZ+kkj0RYkcYaB/M5LMGaBSehcacON8/knh/guxl7MtSHXdys1axVZEst49knoGHJR X-Received: by 2002:a5d:8ad4:: with SMTP id e20mr5227113iot.203.1570551908262; Tue, 08 Oct 2019 09:25:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1570551908; cv=none; d=google.com; s=arc-20160816; b=XB1w/h9/7j+TmxwqJrN6CquoiY6PAdHkHVNKfACihcEDbCBySMHbzHpZYL2bHVB4vi ofX+ePErFB989677FaOUCgh8RlJYS1ZbjHT6kuFnyPCWLFccDMv9igR8CNIaxBO0mU3a YW/iWhqmio6IAXSwVhiUQ4Hbd4QCmEHEJ6eOV5OrTWlSCKiYXA5/6E1s62/5z7jbf4bO MBkyFoZUiHsFgOY8GrS84D+Bu31hUqBe7TV5wLM6mL0K/uM0HN9v6++JAzH+OtF1yn4y HCpVzD/OV2BQpxc/G9MF6QLpbwero3iRYt4Tf2NFdwiRBXzkRJmIjXwALdrO78l/zDCL K7NA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :cc:mime-version:references:in-reply-to:message-id:date:to:from :delivered-to; bh=yoPeqN5EdxaZYy7BDk8FhM6ZHpQgRcEE8XUvFqLFzlI=; b=iKba35UtHewxpzjwL1nfEkVj40l8BNAo9h0/DCZVlp7+VGkZ7knmJVa6Fu5Rb49+h/ LbEjWLsFPMLztqQsjqhdjdVoD3c8rDzBC/+Zp8V37MKI/umP74+EN1O7JpgBN0/CTMFi zWVAzeAxwFq28FNA+GNY9/iZWaW0UtR2TGxra8KzE1KaybZLlugjlX/xPlf4lLY7FUs5 kZQIhZYKILO5lD1DaMVQRehgAOtvipNYh1UUO4qjV7ioYsmgjPAJbha4VglLA5HpXRfL hiwGdGKJOsD45ecE+9n+EaarskyVkFWLDJ4LX8chTnNO+eC8Sz28DMpEvEgCV/9OJCQF VcmQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 209.132.183.28 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from mx1.redhat.com (mx1.redhat.com. [209.132.183.28]) by mx.google.com with ESMTPS id k11si23491299jaa.35.2019.10.08.09.25.08 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 08 Oct 2019 09:25:08 -0700 (PDT) Received-SPF: pass (google.com: domain of libvir-list-bounces@redhat.com designates 209.132.183.28 as permitted sender) client-ip=209.132.183.28; Authentication-Results: mx.google.com; spf=pass (google.com: domain of libvir-list-bounces@redhat.com designates 209.132.183.28 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id D05459B286; Tue, 8 Oct 2019 16:25:06 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.21]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 863EF6060D; Tue, 8 Oct 2019 16:25:06 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id DA4054EE68; Tue, 8 Oct 2019 16:25:04 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id x98GM1MY008683 for ; Tue, 8 Oct 2019 12:22:01 -0400 Received: by smtp.corp.redhat.com (Postfix) id F34B760606; Tue, 8 Oct 2019 16:22:00 +0000 (UTC) Delivered-To: libvirt-list@redhat.com Received: from worklaptop.bos.redhat.com (dhcp-17-175.bos.redhat.com [10.18.17.175]) by smtp.corp.redhat.com (Postfix) with ESMTP id 8AF2460A9F; Tue, 8 Oct 2019 16:22:00 +0000 (UTC) From: Cole Robinson To: libvirt-list@redhat.com Date: Tue, 8 Oct 2019 12:22:24 -0400 Message-Id: In-Reply-To: References: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-loop: libvir-list@redhat.com Cc: christian.ehrhardt@canonical.com Subject: [libvirt] [PATCH 4/7] security: apparmor: Pass virStorageSource to add_file_path X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Tue, 08 Oct 2019 16:25:07 +0000 (UTC) The virStorageSource must have everything it needs Signed-off-by: Cole Robinson --- src/security/virt-aa-helper.c | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) -- 2.23.0 -- libvir-list mailing list libvir-list@redhat.com https://www.redhat.com/mailman/listinfo/libvir-list diff --git a/src/security/virt-aa-helper.c b/src/security/virt-aa-helper.c index 7148e3c760..9f39eb2e2b 100644 --- a/src/security/virt-aa-helper.c +++ b/src/security/virt-aa-helper.c @@ -911,20 +911,19 @@ file_iterate_pci_cb(virPCIDevicePtr dev ATTRIBUTE_UNUSED, } static int -add_file_path(virDomainDiskDefPtr disk, - const char *path, +add_file_path(virStorageSourcePtr src, size_t depth, virBufferPtr buf) { int ret; if (depth == 0) { - if (disk->src->readonly) - ret = vah_add_file(buf, path, "rk"); + if (src->readonly) + ret = vah_add_file(buf, src->path, "rk"); else - ret = vah_add_file(buf, path, "rwk"); + ret = vah_add_file(buf, src->path, "rwk"); } else { - ret = vah_add_file(buf, path, "rk"); + ret = vah_add_file(buf, src->path, "rk"); } if (ret != 0) @@ -945,7 +944,7 @@ disk_add_files(virDomainDiskDefPtr disk, /* execute the callback only for local storage */ if (virStorageSourceIsLocalStorage(tmp) && tmp->path) { - if (add_file_path(disk, tmp->path, depth, buf) < 0) + if (add_file_path(tmp, depth, buf) < 0) return -1; }