]> git.ipfire.org Git - thirdparty/libvirt.git/commit
security: aa-helper: allow virt-aa-helper to read /dev/dri
authorChristian Ehrhardt <christian.ehrhardt@canonical.com>
Tue, 12 Feb 2019 09:33:23 +0000 (10:33 +0100)
committerChristian Ehrhardt <christian.ehrhardt@canonical.com>
Mon, 25 Feb 2019 07:50:38 +0000 (08:50 +0100)
commitd85e8e400b48f1b4c1dfbf438dda83cd959eacf7
tree8e985bd913e209e284e6e7d67fbdf14a58b98ace
parent12f4bf80a72418bd94e2ff1bec5bb62de4ac9dba
security: aa-helper: allow virt-aa-helper to read /dev/dri

Change fb01e1a44 "virt-aa-helper: generate rules for gl enabled
graphics devices" implemented the detection for gl enabled
devices in virt-aa-helper. But it will in certain cases e.g. if
no rendernode was explicitly specified need to read /dev/dri
which it currently isn't allowed.

Add a rule to the apparmor profile of virt-aa-helper itself to
be able to do that.

Acked-by: Jamie Strandboge <jamie@canonical.com>
Signed-off-by: Christian Ehrhardt <christian.ehrhardt@canonical.com>
src/security/apparmor/usr.lib.libvirt.virt-aa-helper