Re: [PATCH] security: do not remember/recall labels for VFIO MDEVs

2023-04-13 Thread Eric Farman
On Thu, 2023-04-13 at 16:35 +0200, Michal Prívozník wrote: > On 4/1/23 02:42, Eric Farman wrote: > > Commit dbf1f68410 ("security: do not remember/recall labels for > > VFIO") > > rightly changed the DAC and SELinux labeling parameters to fix a > > problem > > with "VFIO hostdevs" but really only

Re: [PATCH] security: do not remember/recall labels for VFIO MDEVs

2023-04-13 Thread Michal Prívozník
On 4/1/23 02:42, Eric Farman wrote: > Commit dbf1f68410 ("security: do not remember/recall labels for VFIO") > rightly changed the DAC and SELinux labeling parameters to fix a problem > with "VFIO hostdevs" but really only addressed the PCI codepaths. > As a result, we can still encounter this

Re: [PATCH] security: do not remember/recall labels for VFIO MDEVs

2023-04-13 Thread Eric Farman
On Sat, 2023-04-01 at 02:42 +0200, Eric Farman wrote: > Commit dbf1f68410 ("security: do not remember/recall labels for > VFIO") > rightly changed the DAC and SELinux labeling parameters to fix a > problem > with "VFIO hostdevs" but really only addressed the PCI codepaths. > As a result, we can

[PATCH] security: do not remember/recall labels for VFIO MDEVs

2023-03-31 Thread Eric Farman
Commit dbf1f68410 ("security: do not remember/recall labels for VFIO") rightly changed the DAC and SELinux labeling parameters to fix a problem with "VFIO hostdevs" but really only addressed the PCI codepaths. As a result, we can still encounter this with VFIO MDEVs such as vfio-ccw and vfio-ap,