Re: [libvirt] [RFC] security_dac: don't chown iso file

2011-10-05 Thread Laine Stump
On 10/05/2011 06:33 AM, Daniel P. Berrange wrote: On Tue, Oct 04, 2011 at 12:49:03PM -0500, Serge E. Hallyn wrote: Quoting Serge E. Hallyn (serge.hal...@canonical.com): isos are read-only, so libvirt doesn't need to chown them. In one of our testing setups, libvirt uses mirrorred isos. Since

Re: [libvirt] [RFC] security_dac: don't chown iso file

2011-10-05 Thread Serge Hallyn
Quoting Laine Stump (la...@laine.org): On 10/05/2011 06:33 AM, Daniel P. Berrange wrote: On Tue, Oct 04, 2011 at 12:49:03PM -0500, Serge E. Hallyn wrote: Quoting Serge E. Hallyn (serge.hal...@canonical.com): isos are read-only, so libvirt doesn't need to chown them. In one of our testing

Re: [libvirt] [RFC] security_dac: don't chown iso file

2011-10-04 Thread Serge E. Hallyn
Quoting Serge E. Hallyn (serge.hal...@canonical.com): isos are read-only, so libvirt doesn't need to chown them. In one of our testing setups, libvirt uses mirrorred isos. Since libvirt chowns the files, (and especially does not chown them back) the mirror refuses to update the iso. This

[libvirt] [RFC] security_dac: don't chown iso file

2011-09-13 Thread Serge E. Hallyn
isos are read-only, so libvirt doesn't need to chown them. In one of our testing setups, libvirt uses mirrorred isos. Since libvirt chowns the files, (and especially does not chown them back) the mirror refuses to update the iso. This patch prevents libvirt from chowning files. Does this seem