-From: Neil Wilson <neil@brightbox.co.uk>
-To: libvir-list@redhat.com
-Date: Mon, 10 Jan 2011 09:52:56 +0000
-Message-ID: <1294653176.3013.16.camel@lenovo-3000-n100>
-
-Hi,
-
-Here's the patch to add basic ACL support to QEMU within libvirt. Like
-SASL it's ignored by RHEL5's default qemu. Newer qemu picks it up as
-expected and you can manipulate the acls using 'virsh'.
-
-
-diff --git a/src/qemu/qemu.conf b/src/qemu/qemu.conf
-index ba41f80..7ab5eee 100644
---- a/src/qemu/qemu.conf
-+++ b/src/qemu/qemu.conf
-@@ -71,6 +71,15 @@
- # vnc_sasl = 1
+diff -ur libvirt-7.5.0.orig/src/qemu/qemu_command.c libvirt-7.5.0/src/qemu/qemu_command.c
+--- libvirt-7.5.0.orig/src/qemu/qemu_command.c 2021-07-10 01:17:10.220677568 +0200
++++ libvirt-7.5.0/src/qemu/qemu_command.c 2021-07-10 01:17:25.635677568 +0200
+@@ -8087,6 +8087,10 @@
+ virCommandAddEnvPair(cmd, "SASL_CONF_PATH", cfg->vncSASLdir);
+
+ /* TODO: Support ACLs later */
++
++ if (cfg->vncACL)
++ virBufferAddLit(&opt, ",acl");
++
+ }
+
+ if (graphics->data.vnc.powerControl != VIR_TRISTATE_BOOL_ABSENT) {
+diff -ur libvirt-7.5.0.orig/src/qemu/qemu.conf libvirt-7.5.0/src/qemu/qemu.conf
+--- libvirt-7.5.0.orig/src/qemu/qemu.conf 2021-07-10 01:17:10.225677568 +0200
++++ libvirt-7.5.0/src/qemu/qemu.conf 2021-07-10 01:17:25.633677568 +0200
+@@ -147,6 +147,15 @@
+ #vnc_sasl = 1
+# Enable the VNC access control lists. When switched on this will
# The default SASL configuration file is located in /etc/sasl/
# When running libvirtd unprivileged, it may be desirable to
# override the configs in this location. Set this parameter to
---- libvirt-1.0.6/src/qemu/qemu_command.c.orig 2013-06-16 15:45:37.115181922 +0200
-+++ libvirt-1.0.6/src/qemu/qemu_command.c 2013-06-16 15:47:49.335179175 +0200
-@@ -6178,6 +6178,10 @@
-
- /* TODO: Support ACLs later */
- }
-+
-+ if (cfg->vncACL)
-+ virBufferAddLit(&opt, ",acl");
-+
- }
-
- virCommandAddArg(cmd, "-vnc");
---- libvirt-1.1.3/src/qemu/qemu_conf.c.orig 2013-10-22 20:38:43.522043292 +0200
-+++ libvirt-1.1.3/src/qemu/qemu_conf.c 2013-10-22 20:45:19.515360007 +0200
-@@ -357,6 +357,7 @@
- GET_VALUE_STR("vnc_sasl_dir", cfg->vncSASLdir);
- GET_VALUE_BOOL("vnc_allow_host_audio", cfg->vncAllowHostAudio);
- GET_VALUE_BOOL("nographics_allow_host_audio", cfg->nogfxAllowHostAudio);
-+ GET_VALUE_LONG("vnc_acl", cfg->vncACL);
+diff -ur libvirt-7.5.0.orig/src/qemu/qemu_conf.c libvirt-7.5.0/src/qemu/qemu_conf.c
+--- libvirt-7.5.0.orig/src/qemu/qemu_conf.c 2021-07-10 01:17:10.220677568 +0200
++++ libvirt-7.5.0/src/qemu/qemu_conf.c 2021-07-10 01:17:25.636677568 +0200
+@@ -450,6 +450,8 @@
+ return -1;
+ if (virConfGetValueBool(conf, "vnc_allow_host_audio", &cfg->vncAllowHostAudio) < 0)
+ return -1;
++ if (virConfGetValueBool(conf, "vnc_acl", &cfg->vncACL) < 0)
++ return -1;
- p = virConfGetValue(conf, "security_driver");
- if (p && p->type == VIR_CONF_LIST) {
---- libvirt-1.0.3/src/qemu/qemu_conf.h.orig 2013-03-09 13:10:30.059751685 +0100
-+++ libvirt-1.0.3/src/qemu/qemu_conf.h 2013-03-09 13:54:17.296308093 +0100
-@@ -102,6 +102,7 @@
- bool vncTLS;
+ return 0;
+ }
+diff -ur libvirt-7.5.0.orig/src/qemu/qemu_conf.h libvirt-7.5.0/src/qemu/qemu_conf.h
+--- libvirt-7.5.0.orig/src/qemu/qemu_conf.h 2021-07-10 01:17:10.220677568 +0200
++++ libvirt-7.5.0/src/qemu/qemu_conf.h 2021-07-10 01:17:25.636677568 +0200
+@@ -114,6 +114,7 @@
bool vncTLSx509verify;
+ bool vncTLSx509verifyPresent;
bool vncSASL;
+ bool vncACL;
char *vncTLSx509certdir;
+ char *vncTLSx509secretUUID;
char *vncListen;
- char *vncPassword;