Bug 1371828

Summary: Should failed to validate XML if no model name with seclabel
Product: Red Hat Enterprise Linux 7 Reporter: Fangge Jin <fjin>
Component: libvirtAssignee: Ján Tomko <jtomko>
Status: CLOSED WONTFIX QA Contact: yafu <yafu>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.3CC: dyuan, mzhan, rbalakri, xuzhang, yafu, yanqzhan, zpeng
Target Milestone: rc   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-06-07 14:38:58 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Fangge Jin 2016-08-31 08:19:13 UTC
Description of problem:
Set per-disk seclabel as below, guest start failed with error "error: unsupported configuration: Unable to find security driver for model (null)"

# virsh edit rhel7
    <disk type='file' device='disk'>
      <driver name='qemu' type='qcow2' cache='none'/>
      <source file='/var/lib/libvirt/images/rhel7.2.qcow2'>
        **<seclabel relabel='no'/>**
      </source>
      <target dev='vda' bus='virtio'/>
    </disk>

# virsh start rhel7
error: Failed to start domain rhel7
error: unsupported configuration: Unable to find security driver for model (null)

Version-Release number of selected component:
libvirt-2.0.0-6.el7.x86_64

How reproducible:
100%

Steps to Reproduce:
1. Edit domain xml, set per-disk seclabel without model name.
2. Start guest

Actual results:
Edit domain xml successfully, but guest start failed

Expected results:
In step 1, XML document should failed to validate against schema when editing

Additional info:
Set a model with the seclabel, and start guest, NO "Unable to find security driver for model (null)" error appears.
For example:
      <source file='/var/lib/libvirt/images/rhel7.2.qcow2'>
        <seclabel **model='none'** relabel='no'/>
      </source>