From nobody Sun Feb 8 20:59:52 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of redhat.com designates 207.211.31.120 as permitted sender) client-ip=207.211.31.120; envelope-from=libvir-list-bounces@redhat.com; helo=us-smtp-1.mimecast.com; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 207.211.31.120 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=fail(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1578347955; cv=none; d=zohomail.com; s=zohoarc; b=ACdzSFo5SZMIwhQJIMaEpLpFB/zvSuNfHGhFiEZ+9SzuUWd0F946BWAZR+B3UvIMuy1bAfmoAzn6SJXPM3rEKQYn/o+hAlj8efh7jSpsCBv2SuZzWzXK/hmIL/u6eaS5766OnzLMk1n/g8sdYgFhbFlTJc+PPQ4eVYuH409vgjU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1578347955; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=RWtIxtnemoUCdL5fJjgJALaohGygibMWGWzc7EIR+BI=; b=BfzvHBWkqCXD50xUyTQEhEURJGMMgwBYQGKNlm6nkQyLtv6uq3epVlwVoH8y2gn7ibBJRuQG8nhiaUxWatA0m2u/R71xGUEH5zmbLc0kziHog6sxI93EKH/SBFIAmTFyD0fKc5j9jIPz7051kVzLY4AW16a683j/G0Yvdf66fHI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 207.211.31.120 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=fail header.from= (p=none dis=none) header.from= Return-Path: Received: from us-smtp-1.mimecast.com (us-smtp-delivery-1.mimecast.com [207.211.31.120]) by mx.zohomail.com with SMTPS id 1578347955362629.4239529349308; Mon, 6 Jan 2020 13:59:15 -0800 (PST) Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-217-wGC8lzXYM6us9RRbQ2kbyA-1; Mon, 06 Jan 2020 16:59:11 -0500 Received: from smtp.corp.redhat.com (int-mx07.intmail.prod.int.phx2.redhat.com [10.5.11.22]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 59F69107ACCA; Mon, 6 Jan 2020 21:59:05 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.20]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 325B0108419B; Mon, 6 Jan 2020 21:59:05 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id DD7F518034FD; Mon, 6 Jan 2020 21:59:04 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx06.intmail.prod.int.rdu2.redhat.com [10.11.54.6]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id 006LwVN5007371 for ; Mon, 6 Jan 2020 16:58:31 -0500 Received: by smtp.corp.redhat.com (Postfix) id 4B9972166B2A; Mon, 6 Jan 2020 21:58:31 +0000 (UTC) Received: from mimecast-mx02.redhat.com (mimecast03.extmail.prod.ext.rdu2.redhat.com [10.11.55.19]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 468C62166B29 for ; Mon, 6 Jan 2020 21:58:31 +0000 (UTC) Received: from us-smtp-1.mimecast.com (us-smtp-delivery-1.mimecast.com [207.211.31.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 1F63D800FEA for ; Mon, 6 Jan 2020 21:58:31 +0000 (UTC) Received: from mail-qk1-f193.google.com (mail-qk1-f193.google.com [209.85.222.193]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-381-yyYczqhRMKGyJFWDG73pPA-1; Mon, 06 Jan 2020 16:58:29 -0500 Received: by mail-qk1-f193.google.com with SMTP id a203so41256569qkc.3 for ; Mon, 06 Jan 2020 13:58:29 -0800 (PST) Received: from rekt.ibmuc.com ([2804:431:c7c6:655b:9e1c:e865:3705:e1df]) by smtp.gmail.com with ESMTPSA id x34sm23898440qtd.20.2020.01.06.13.58.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 06 Jan 2020 13:58:26 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1578347954; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=RWtIxtnemoUCdL5fJjgJALaohGygibMWGWzc7EIR+BI=; b=LUIBRxUwUz/ugN+LCbGF3CfvfIDlQjZEXUV3n0egCvqU2yEsX/gmFHDY3/1XHi2S7Dx58B A2gSrrzpe2hGQ+pPtgZOj+EN6hPftpQSkLpH0vNXwsy6STXNzr8ka82AA6zjXgtzLcAMtn b03cO/2qkzS6wX1z7yk18QkrdSCMHbU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=yfjuel9LYn/c7E7P9VEMENal2iYlIPK3jUoFXjr7n7g=; b=YxLBcvZdK0kvLpiOis3oaX275mkONzfbzz5QbdXXNE0u54pLHBM5soT3ggGdTkbTqz gXVThrCUpDq6HV0TF4fpbwQIgBJyDA2pFYWag85Ltt0yO2GT+FFn2Pnky9qu5JlLGS4o jrMMKpEmJWCeiD7Ws0nlLn+cBVpbqEPGCQ5qWpZS+U/7qUUjP3YYHSDh3AejAw/DsY5C epNcj2I7s5ceio2NZP2di9GShgNgNSr1Hi0BiMHrF9X++KkLDSni3J3mIsuaAsE8jXtm Y0S4hPCpfBjm+adExHKJ0ipGTZ+k4vOjmzoG9dfKkrH9SJYBfhhwrtyfRvjOEkc/kXaX cNFQ== X-Gm-Message-State: APjAAAWt9LtrqLqCbn9MtE3tTSgyMmheQ2ztLzssSvUWkhkloAwgy0lR QMOAmQhavreFWVxhRC7b4MB2Qk2H X-Google-Smtp-Source: APXvYqxQoZQSoOUb0UfsBUym3JVKvyeDdAG1d5evEd9C+1K5mU8GoD2tU6WQQv5v1Kvh7k2ZDL736w== X-Received: by 2002:a37:77c5:: with SMTP id s188mr86919247qkc.369.1578347907015; Mon, 06 Jan 2020 13:58:27 -0800 (PST) From: Daniel Henrique Barboza To: libvir-list@redhat.com Date: Mon, 6 Jan 2020 18:57:44 -0300 Message-Id: <20200106215750.361615-21-danielhb413@gmail.com> In-Reply-To: <20200106215750.361615-1-danielhb413@gmail.com> References: <20200106215750.361615-1-danielhb413@gmail.com> MIME-Version: 1.0 X-MC-Unique: yyYczqhRMKGyJFWDG73pPA-1 X-MC-Unique: wGC8lzXYM6us9RRbQ2kbyA-1 X-Scanned-By: MIMEDefang 2.78 on 10.11.54.6 X-MIME-Autoconverted: from quoted-printable to 8bit by lists01.pubmisc.prod.ext.phx2.redhat.com id 006LwVN5007371 X-loop: libvir-list@redhat.com Cc: Daniel Henrique Barboza Subject: [libvirt] [PATCH v1 20/26] security: remove unneeded labels X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.84 on 10.5.11.22 X-Mimecast-Spam-Score: 0 Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @redhat.com) Content-Type: text/plain; charset="utf-8" Signed-off-by: Daniel Henrique Barboza --- src/security/security_dac.c | 26 ++++++++++----------- src/security/security_selinux.c | 26 ++++++++++----------- src/security/virt-aa-helper.c | 41 ++++++++++++++------------------- 3 files changed, 41 insertions(+), 52 deletions(-) diff --git a/src/security/security_dac.c b/src/security/security_dac.c index ccd3874897..2561ee440e 100644 --- a/src/security/security_dac.c +++ b/src/security/security_dac.c @@ -1238,7 +1238,7 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr m= gr, return 0; =20 if (!(usb =3D virUSBDeviceNew(usbsrc->bus, usbsrc->device, vroot))) - goto done; + return -1; =20 ret =3D virUSBDeviceFileIterate(usb, virSecurityDACSetUSBLabel, @@ -1253,14 +1253,14 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr= mgr, pcisrc->addr.slot, pcisrc->addr.function); =20 if (!pci) - goto done; + return -1; =20 if (pcisrc->backend =3D=3D VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) { char *vfioGroupDev =3D virPCIDeviceGetIOMMUGroupDev(pci); =20 if (!vfioGroupDev) { virPCIDeviceFree(pci); - goto done; + return -1; } ret =3D virSecurityDACSetPCILabel(pci, vfioGroupDev, &cbdata); VIR_FREE(vfioGroupDev); @@ -1283,7 +1283,7 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr m= gr, dev->readonly, dev->shareable); =20 if (!scsi) - goto done; + return -1; =20 ret =3D virSCSIDeviceFileIterate(scsi, virSecurityDACSetSCSILabel, @@ -1297,7 +1297,7 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr m= gr, virSCSIVHostDevicePtr host =3D virSCSIVHostDeviceNew(hostsrc->wwpn= ); =20 if (!host) - goto done; + return -1; =20 ret =3D virSCSIVHostDeviceFileIterate(host, virSecurityDACSetHostLabel, @@ -1310,7 +1310,7 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr m= gr, char *vfiodev =3D NULL; =20 if (!(vfiodev =3D virMediatedDeviceGetIOMMUGroupDev(mdevsrc->uuids= tr))) - goto done; + return -1; =20 ret =3D virSecurityDACSetHostdevLabelHelper(vfiodev, &cbdata); =20 @@ -1323,7 +1323,6 @@ virSecurityDACSetHostdevLabel(virSecurityManagerPtr m= gr, break; } =20 - done: return ret; } =20 @@ -1407,7 +1406,7 @@ virSecurityDACRestoreHostdevLabel(virSecurityManagerP= tr mgr, return 0; =20 if (!(usb =3D virUSBDeviceNew(usbsrc->bus, usbsrc->device, vroot))) - goto done; + return -1; =20 ret =3D virUSBDeviceFileIterate(usb, virSecurityDACRestoreUSBLabel= , mgr); virUSBDeviceFree(usb); @@ -1421,14 +1420,14 @@ virSecurityDACRestoreHostdevLabel(virSecurityManage= rPtr mgr, pcisrc->addr.slot, pcisrc->addr.function); =20 if (!pci) - goto done; + return -1; =20 if (pcisrc->backend =3D=3D VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) { char *vfioGroupDev =3D virPCIDeviceGetIOMMUGroupDev(pci); =20 if (!vfioGroupDev) { virPCIDeviceFree(pci); - goto done; + return -1; } ret =3D virSecurityDACRestorePCILabel(pci, vfioGroupDev, mgr); VIR_FREE(vfioGroupDev); @@ -1448,7 +1447,7 @@ virSecurityDACRestoreHostdevLabel(virSecurityManagerP= tr mgr, dev->readonly, dev->shareable); =20 if (!scsi) - goto done; + return -1; =20 ret =3D virSCSIDeviceFileIterate(scsi, virSecurityDACRestoreSCSILa= bel, mgr); virSCSIDeviceFree(scsi); @@ -1460,7 +1459,7 @@ virSecurityDACRestoreHostdevLabel(virSecurityManagerP= tr mgr, virSCSIVHostDevicePtr host =3D virSCSIVHostDeviceNew(hostsrc->wwpn= ); =20 if (!host) - goto done; + return -1; =20 ret =3D virSCSIVHostDeviceFileIterate(host, virSecurityDACRestoreHostLabel, @@ -1474,7 +1473,7 @@ virSecurityDACRestoreHostdevLabel(virSecurityManagerP= tr mgr, char *vfiodev =3D NULL; =20 if (!(vfiodev =3D virMediatedDeviceGetIOMMUGroupDev(mdevsrc->uuids= tr))) - goto done; + return -1; =20 ret =3D virSecurityDACRestoreFileLabel(mgr, vfiodev); VIR_FREE(vfiodev); @@ -1486,7 +1485,6 @@ virSecurityDACRestoreHostdevLabel(virSecurityManagerP= tr mgr, break; } =20 - done: return ret; } =20 diff --git a/src/security/security_selinux.c b/src/security/security_selinu= x.c index 32dc78d777..3a43c4ca7d 100644 --- a/src/security/security_selinux.c +++ b/src/security/security_selinux.c @@ -2094,7 +2094,7 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurityMa= nagerPtr mgr, usbsrc->device, vroot); if (!usb) - goto done; + return -1; =20 ret =3D virUSBDeviceFileIterate(usb, virSecuritySELinuxSetUSBLabel= , &data); virUSBDeviceFree(usb); @@ -2107,14 +2107,14 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurity= ManagerPtr mgr, pcisrc->addr.slot, pcisrc->addr.function); =20 if (!pci) - goto done; + return -1; =20 if (pcisrc->backend =3D=3D VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) { char *vfioGroupDev =3D virPCIDeviceGetIOMMUGroupDev(pci); =20 if (!vfioGroupDev) { virPCIDeviceFree(pci); - goto done; + return -1; } ret =3D virSecuritySELinuxSetPCILabel(pci, vfioGroupDev, &data= ); VIR_FREE(vfioGroupDev); @@ -2135,7 +2135,7 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurityMa= nagerPtr mgr, dev->readonly, dev->shareable); =20 if (!scsi) - goto done; + return -1; =20 ret =3D virSCSIDeviceFileIterate(scsi, virSecuritySELinuxSetSCSILabel, @@ -2149,7 +2149,7 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurityMa= nagerPtr mgr, virSCSIVHostDevicePtr host =3D virSCSIVHostDeviceNew(hostsrc->wwpn= ); =20 if (!host) - goto done; + return -1; =20 ret =3D virSCSIVHostDeviceFileIterate(host, virSecuritySELinuxSetHostLabel, @@ -2162,7 +2162,7 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurityMa= nagerPtr mgr, char *vfiodev =3D NULL; =20 if (!(vfiodev =3D virMediatedDeviceGetIOMMUGroupDev(mdevsrc->uuids= tr))) - goto done; + return ret; =20 ret =3D virSecuritySELinuxSetHostdevLabelHelper(vfiodev, &data); =20 @@ -2175,7 +2175,6 @@ virSecuritySELinuxSetHostdevSubsysLabel(virSecurityMa= nagerPtr mgr, break; } =20 - done: return ret; } =20 @@ -2332,7 +2331,7 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecuri= tyManagerPtr mgr, usbsrc->device, vroot); if (!usb) - goto done; + return -1; =20 ret =3D virUSBDeviceFileIterate(usb, virSecuritySELinuxRestoreUSBL= abel, mgr); virUSBDeviceFree(usb); @@ -2346,14 +2345,14 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecu= rityManagerPtr mgr, pcisrc->addr.slot, pcisrc->addr.function); =20 if (!pci) - goto done; + return -1; =20 if (pcisrc->backend =3D=3D VIR_DOMAIN_HOSTDEV_PCI_BACKEND_VFIO) { char *vfioGroupDev =3D virPCIDeviceGetIOMMUGroupDev(pci); =20 if (!vfioGroupDev) { virPCIDeviceFree(pci); - goto done; + return -1; } ret =3D virSecuritySELinuxRestorePCILabel(pci, vfioGroupDev, m= gr); VIR_FREE(vfioGroupDev); @@ -2373,7 +2372,7 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecuri= tyManagerPtr mgr, dev->readonly, dev->shareable); =20 if (!scsi) - goto done; + return -1; =20 ret =3D virSCSIDeviceFileIterate(scsi, virSecuritySELinuxRestoreSC= SILabel, mgr); virSCSIDeviceFree(scsi); @@ -2385,7 +2384,7 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecuri= tyManagerPtr mgr, virSCSIVHostDevicePtr host =3D virSCSIVHostDeviceNew(hostsrc->wwpn= ); =20 if (!host) - goto done; + return -1; =20 ret =3D virSCSIVHostDeviceFileIterate(host, virSecuritySELinuxRestoreHostL= abel, @@ -2399,7 +2398,7 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecuri= tyManagerPtr mgr, char *vfiodev =3D NULL; =20 if (!(vfiodev =3D virMediatedDeviceGetIOMMUGroupDev(mdevsrc->uuids= tr))) - goto done; + return -1; =20 ret =3D virSecuritySELinuxRestoreFileLabel(mgr, vfiodev, true); =20 @@ -2412,7 +2411,6 @@ virSecuritySELinuxRestoreHostdevSubsysLabel(virSecuri= tyManagerPtr mgr, break; } =20 - done: return ret; } =20 diff --git a/src/security/virt-aa-helper.c b/src/security/virt-aa-helper.c index 2b1d199458..e01ec12d09 100644 --- a/src/security/virt-aa-helper.c +++ b/src/security/virt-aa-helper.c @@ -546,27 +546,24 @@ verify_xpath_context(xmlXPathContextPtr ctxt) =20 if (!ctxt) { vah_warning(_("Invalid context")); - goto error; + return -1; } =20 /* check if have */ if (!(tmp =3D virXPathString("string(./name[1])", ctxt))) { vah_warning(_("Could not find ")); - goto error; + return -1; } VIR_FREE(tmp); =20 /* check if have */ if (!(tmp =3D virXPathString("string(./uuid[1])", ctxt))) { vah_warning(_("Could not find ")); - goto error; + return -1; } VIR_FREE(tmp); =20 - rc =3D 0; - - error: - return rc; + return 0; } =20 /* @@ -636,7 +633,7 @@ virDomainDefParserConfig virAAHelperDomainDefParserConf= ig =3D { static int get_definition(vahControl * ctl, const char *xmlStr) { - int rc =3D -1, ostype, virtType; + int ostype, virtType; virCapsGuestPtr guest; /* this is freed when caps is freed */ =20 /* @@ -644,22 +641,22 @@ get_definition(vahControl * ctl, const char *xmlStr) * but need them for virDomainDefParseString(). */ if (caps_mockup(ctl, xmlStr) !=3D 0) - goto exit; + return -1; =20 if ((ctl->caps =3D virCapabilitiesNew(ctl->arch, true, true)) =3D=3D N= ULL) { vah_error(ctl, 0, _("could not allocate memory")); - goto exit; + return -1; } =20 if (!(ctl->xmlopt =3D virDomainXMLOptionNew(&virAAHelperDomainDefParse= rConfig, NULL, NULL, NULL, NULL))) { vah_error(ctl, 0, _("Failed to create XML config object")); - goto exit; + return -1; } =20 if ((ostype =3D virDomainOSTypeFromString(ctl->os)) < 0) { vah_error(ctl, 0, _("unknown OS type")); - goto exit; + return -1; } =20 if ((guest =3D virCapabilitiesAddGuest(ctl->caps, @@ -670,12 +667,12 @@ get_definition(vahControl * ctl, const char *xmlStr) 0, NULL)) =3D=3D NULL) { vah_error(ctl, 0, _("could not allocate memory")); - goto exit; + return -1; } =20 if ((virtType =3D virDomainVirtTypeFromString(ctl->virtType)) < 0) { vah_error(ctl, 0, _("unknown virtualization type")); - goto exit; + return -1; } =20 if (virCapabilitiesAddGuestDomain(guest, @@ -685,7 +682,7 @@ get_definition(vahControl * ctl, const char *xmlStr) 0, NULL) =3D=3D NULL) { vah_error(ctl, 0, _("could not allocate memory")); - goto exit; + return -1; } =20 ctl->def =3D virDomainDefParseString(xmlStr, @@ -695,23 +692,20 @@ get_definition(vahControl * ctl, const char *xmlStr) =20 if (ctl->def =3D=3D NULL) { vah_error(ctl, 0, _("could not parse XML")); - goto exit; + return -1; } =20 if (!ctl->def->name) { vah_error(ctl, 0, _("could not find name in XML")); - goto exit; + return -1; } =20 if (valid_name(ctl->def->name) !=3D 0) { vah_error(ctl, 0, _("bad name")); - goto exit; + return -1; } =20 - rc =3D 0; - - exit: - return rc; + return 0; } =20 /** @@ -854,11 +848,10 @@ vah_add_file_chardev(virBufferPtr buf, } else { /* add the file */ if (vah_add_file(buf, path, perms) !=3D 0) - goto cleanup; + return -1; rc =3D 0; } =20 - cleanup: return rc; } =20 --=20 2.24.1 -- libvir-list mailing list libvir-list@redhat.com https://www.redhat.com/mailman/listinfo/libvir-list