From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:54300) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QORkR-0001H8-I1 for qemu-devel@nongnu.org; Mon, 23 May 2011 05:48:28 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1QORkM-0008QJ-1J for qemu-devel@nongnu.org; Mon, 23 May 2011 05:48:27 -0400 Received: from mx1.redhat.com ([209.132.183.28]:31721) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1QORkL-0008QA-Pq for qemu-devel@nongnu.org; Mon, 23 May 2011 05:48:21 -0400 Date: Mon, 23 May 2011 10:48:17 +0100 From: "Daniel P. Berrange" Message-ID: <20110523094817.GB24143@redhat.com> References: <4DD6B777.9020800@us.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <4DD6B777.9020800@us.ibm.com> Subject: Re: [Qemu-devel] [PATCH] Add support for fd: protocol Reply-To: "Daniel P. Berrange" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Corey Bryant Cc: aliguori@us.ibm.com, qemu-devel@nongnu.org, Tyler C Hicks On Fri, May 20, 2011 at 02:48:23PM -0400, Corey Bryant wrote: > sVirt provides SELinux MAC isolation for Qemu guest processes and their > corresponding resources (image files). sVirt provides this support > by labeling guests and resources with security labels that are stored > in file system extended attributes. Some file systems, such as NFS, do > not support the extended attribute security namespace, which is needed > for image file isolation when using the sVirt SELinux security driver > in libvirt. This will also allow libvirt to run QEMU confined by the Linux container functionality. In particular it lets us use CLONE_NEWNS flag to isolate its root filesystem, without having to worry about setting up passthrough mounts for each disk image it needs to access, which is a real pain when it comes to hotplug. Daniel -- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://autobuild.org -o- http://search.cpan.org/~danberr/ :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :|