1 diff -urp libvirt-5.1.0.orig/src/qemu/qemu_command.c libvirt-5.1.0/src/qemu/qemu_command.c
2 --- libvirt-5.1.0.orig/src/qemu/qemu_command.c 2019-03-23 11:41:18.269000000 +0100
3 +++ libvirt-5.1.0/src/qemu/qemu_command.c 2019-03-23 11:41:44.602000000 +0100
4 @@ -8155,6 +8155,10 @@ qemuBuildGraphicsVNCCommandLine(virQEMUD
5 virCommandAddEnvPair(cmd, "SASL_CONF_PATH", cfg->vncSASLdir);
7 /* TODO: Support ACLs later */
10 + virBufferAddLit(&opt, ",acl");
14 virCommandAddArg(cmd, "-vnc");
15 diff -urp libvirt-5.1.0.orig/src/qemu/qemu.conf libvirt-5.1.0/src/qemu/qemu.conf
16 --- libvirt-5.1.0.orig/src/qemu/qemu.conf 2019-03-23 11:41:18.271000000 +0100
17 +++ libvirt-5.1.0/src/qemu/qemu.conf 2019-03-23 11:41:44.602000000 +0100
22 +# Enable the VNC access control lists. When switched on this will
23 +# initially block all vnc users from accessing the vnc server. To
24 +# add and remove ids from the ACLs you will need to send the appropriate
25 +# commands to the qemu monitor as required by your particular version of
26 +# QEMU. See the QEMU documentation for more details.
31 # The default SASL configuration file is located in /etc/sasl/
32 # When running libvirtd unprivileged, it may be desirable to
33 # override the configs in this location. Set this parameter to
34 diff -urp libvirt-5.1.0.orig/src/qemu/qemu_conf.c libvirt-5.1.0/src/qemu/qemu_conf.c
35 --- libvirt-5.1.0.orig/src/qemu/qemu_conf.c 2019-03-23 11:41:18.270000000 +0100
36 +++ libvirt-5.1.0/src/qemu/qemu_conf.c 2019-03-23 11:47:01.904000000 +0100
37 @@ -471,6 +471,8 @@ virQEMUDriverConfigLoadVNCEntry(virQEMUD
39 if (virConfGetValueBool(conf, "vnc_allow_host_audio", &cfg->vncAllowHostAudio) < 0)
41 + if (virConfGetValueBool(conf, "vnc_acl", &cfg->vncACL) < 0)
46 diff -urp libvirt-5.1.0.orig/src/qemu/qemu_conf.h libvirt-5.1.0/src/qemu/qemu_conf.h
47 --- libvirt-5.1.0.orig/src/qemu/qemu_conf.h 2019-03-23 11:41:18.270000000 +0100
48 +++ libvirt-5.1.0/src/qemu/qemu_conf.h 2019-03-23 11:41:44.603000000 +0100
49 @@ -124,6 +124,7 @@ struct _virQEMUDriverConfig {
50 bool vncTLSx509verify;
51 bool vncTLSx509verifyPresent;
54 char *vncTLSx509certdir;
55 char *vncTLSx509secretUUID;