[libvirt] [PATCHv2 7/8] audit: also audit cgroup ACL permissions
Eric Blake
eblake at redhat.com
Wed Mar 9 18:51:11 UTC 2011
On 03/09/2011 08:26 AM, Daniel P. Berrange wrote:
> On Tue, Mar 08, 2011 at 10:13:49PM -0700, Eric Blake wrote:
>> * src/qemu/qemu_audit.h (qemuAuditCgroupMajor)
>> (qemuAuditCgroupPath): Add parameter.
>> * src/qemu/qemu_audit.c (qemuAuditCgroupMajor)
>> (qemuAuditCgroupPath): Add 'acl=rwm' to cgroup audit entries.
>> * src/qemu/qemu_cgroup.c: Update clients.
>> * src/qemu/qemu_driver.c (qemudDomainSaveFlag): Likewise.
>> ---
>>
>> v2: new patch; perhaps patch should be floated before patch 2, and
>> then this patch squashed into patch 2, so that I'm only touching
>> qemuAuditCgroupPath once?
>
> I don't think it hugely matters.
>
>> src/qemu/qemu_audit.c | 12 ++++++++----
>> src/qemu/qemu_audit.h | 2 ++
>> src/qemu/qemu_cgroup.c | 15 ++++++++-------
>> src/qemu/qemu_driver.c | 6 +++---
>> 4 files changed, 21 insertions(+), 14 deletions(-)
>
> ACK, unless it needs some changes based on my two comments to
> the previous patch about certain RWM vs RW usage.
It needed a tweak ("rw" vs. "rwm"). I've applied patches 1-3 and 5-7,
and will be doing a PATCHv3 for patch 4, 8, and other followups for
auditing network devices after I finish more testing.
--
Eric Blake eblake at redhat.com +1-801-349-2682
Libvirt virtualization library http://libvirt.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 619 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20110309/452f2a56/attachment-0001.sig>
More information about the libvir-list
mailing list