Re: [libvirt] RFC: a couple ideas regarding selinux/DAC labeling

2015-04-30 Thread Michal Privoznik
On 28.04.2015 00:04, Cole Robinson wrote: Hi all, libvirt's selinux/DAC labeling behavior has been a repeated source of frustration for desktop virt users. Granted much of the frustration comes from the fact that virt-manager runs as $user, talks to libvirtd running as root, which launches

Re: [libvirt] RFC: a couple ideas regarding selinux/DAC labeling

2015-04-30 Thread Daniel P. Berrange
On Thu, Apr 30, 2015 at 01:20:30PM +0200, Michal Privoznik wrote: On 28.04.2015 00:04, Cole Robinson wrote: Hi all, libvirt's selinux/DAC labeling behavior has been a repeated source of frustration for desktop virt users. Granted much of the frustration comes from the fact that

Re: [libvirt] RFC: a couple ideas regarding selinux/DAC labeling

2015-04-30 Thread Cole Robinson
On 04/30/2015 07:30 AM, Daniel P. Berrange wrote: On Thu, Apr 30, 2015 at 01:20:30PM +0200, Michal Privoznik wrote: On 28.04.2015 00:04, Cole Robinson wrote: Hi all, libvirt's selinux/DAC labeling behavior has been a repeated source of frustration for desktop virt users. Granted much of the

[libvirt] RFC: a couple ideas regarding selinux/DAC labeling

2015-04-27 Thread Cole Robinson
Hi all, libvirt's selinux/DAC labeling behavior has been a repeated source of frustration for desktop virt users. Granted much of the frustration comes from the fact that virt-manager runs as $user, talks to libvirtd running as root, which launches VMs running as qemu, and we are mixing it all