Re: [libvirt] [PATCH 0/3] security: Don't remember labels for TPM

2019-10-10 Thread Cole Robinson
On 10/1/19 11:00 AM, Michal Privoznik wrote: As it turns out, /dev/tpm0 can't be opened more than once. This doesn't fit into our seclabel remembering approach and thus disable it for TPM devices. There's also another type of files which can't be opened more than once - /dev/vfio/N. Usually,

[libvirt] [PATCH 0/3] security: Don't remember labels for TPM

2019-10-01 Thread Michal Privoznik
As it turns out, /dev/tpm0 can't be opened more than once. This doesn't fit into our seclabel remembering approach and thus disable it for TPM devices. There's also another type of files which can't be opened more than once - /dev/vfio/N. Usually, this won't be a problem unless users try to