Re: SELinux labels change in libvirt

2020-07-16 Thread Daniel P . Berrangé
On Thu, Jul 16, 2020 at 11:22:26AM +0300, Ram Lavi wrote: > On Tue, Jul 14, 2020 at 6:03 PM Daniel P. Berrangé > wrote: > > I checked the dumpxml of the virt-launcher pod (that runs the qemu in > kubevirt) - it has dynamic policy. > > > +107:+107 > +107:+107 > > > Are you saying

Re: SELinux labels change in libvirt

2020-07-16 Thread Ram Lavi
On Tue, Jul 14, 2020 at 6:03 PM Daniel P. Berrangé wrote: > On Tue, Jul 14, 2020 at 04:02:17PM +0300, Ram Lavi wrote: > > On Tue, Jul 14, 2020 at 3:33 PM Daniel P. Berrangé > > wrote: > > > > > On Tue, Jul 14, 2020 at 03:21:17PM +0300, Ram Lavi wrote: > > > > Hello all, > > > > > > > > tl;dr,

Re: SELinux labels change in libvirt

2020-07-14 Thread Daniel P . Berrangé
On Tue, Jul 14, 2020 at 04:02:17PM +0300, Ram Lavi wrote: > On Tue, Jul 14, 2020 at 3:33 PM Daniel P. Berrangé > wrote: > > > On Tue, Jul 14, 2020 at 03:21:17PM +0300, Ram Lavi wrote: > > > Hello all, > > > > > > tl;dr, can you point me to the point in the libvirt repo where it's > > trying > >

Re: SELinux labels change in libvirt

2020-07-14 Thread Ram Lavi
On Tue, Jul 14, 2020 at 3:33 PM Daniel P. Berrangé wrote: > On Tue, Jul 14, 2020 at 03:21:17PM +0300, Ram Lavi wrote: > > Hello all, > > > > tl;dr, can you point me to the point in the libvirt repo where it's > trying > > to change a tap-device's SELinux label? > > > > I am trying to create a

Re: SELinux labels change in libvirt

2020-07-14 Thread Daniel P . Berrangé
On Tue, Jul 14, 2020 at 03:21:17PM +0300, Ram Lavi wrote: > Hello all, > > tl;dr, can you point me to the point in the libvirt repo where it's trying > to change a tap-device's SELinux label? > > I am trying to create a tap device with libvirt on a > super-privileged container, and then use it