f4f1d18 qemu: fail on attempts to use <filterref> for non-tap network connections

Authored and Committed by Laine Stump 8 years ago
    qemu: fail on attempts to use <filterref> for non-tap network connections
    
    nwfilter uses iptables and ebtables, which only work properly on
    tap-based network connections (*not* on macvtap, for example), but we
    just ignore any <filterref> elements for other types of networks,
    potentially giving users a false sense of security.
    
    This patch checks the network type and fails/logs an error if any
    domain <interface> has a <filterref> when the connection isn't using a
    tap device.
    
    This resolves:
    
      https://bugzilla.redhat.com/show_bug.cgi?id=1180011
    
        
file modified
+11 -0
file modified
+11 -0