[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-changelog] [xen-unstable] flask/policy: add missing manage_domain rules



# HG changeset patch
# User Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>
# Date 1326211466 0
# Node ID 164ed9b67ad050cbd9efa24f641120733926d7d6
# Parent  db22b1aa11d330b0289bb691842b942fc6799dfd
flask/policy: add missing manage_domain rules

The updated example policy did not include rules to allow managing the
created domains (pause, unpause, destroy); allow these actions.

Signed-off-by: Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>
Committed-by: Ian Jackson <ian.jackson.citrix.com>
---


diff -r db22b1aa11d3 -r 164ed9b67ad0 
tools/flask/policy/policy/modules/xen/xen.if
--- a/tools/flask/policy/policy/modules/xen/xen.if      Tue Jan 10 16:04:25 
2012 +0000
+++ b/tools/flask/policy/policy/modules/xen/xen.if      Tue Jan 10 16:04:26 
2012 +0000
@@ -29,6 +29,13 @@
        allow $1 $2_$1_channel:event create;
 ')
 
+# manage_domain(priv, target)
+#   Allow managing a running domain
+define(`manage_domain', `
+       allow $1 $2:domain { getdomaininfo getvcpuinfo getvcpuaffinity
+                       getaddrsize pause unpause trigger shutdown destroy
+                       setvcpuaffinity setdomainmaxmem };
+')
 
################################################################################
 #
 # Inter-domain communication
diff -r db22b1aa11d3 -r 164ed9b67ad0 
tools/flask/policy/policy/modules/xen/xen.te
--- a/tools/flask/policy/policy/modules/xen/xen.te      Tue Jan 10 16:04:25 
2012 +0000
+++ b/tools/flask/policy/policy/modules/xen/xen.te      Tue Jan 10 16:04:26 
2012 +0000
@@ -86,10 +86,12 @@
 declare_domain(domU_t)
 domain_self_comms(domU_t)
 create_domain(dom0_t, domU_t)
+manage_domain(dom0_t, domU_t)
 domain_comms(dom0_t, domU_t)
 
 declare_domain(isolated_domU_t)
 create_domain(dom0_t, isolated_domU_t)
+manage_domain(dom0_t, isolated_domU_t)
 domain_comms(dom0_t, isolated_domU_t)
 
 ###############################################################################

_______________________________________________
Xen-changelog mailing list
Xen-changelog@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-changelog


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.