]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
qemu: conf: Remove /dev/sev from the default cgroup device acl list
authorErik Skultety <eskultet@redhat.com>
Mon, 21 Jan 2019 13:48:02 +0000 (14:48 +0100)
committerErik Skultety <eskultet@redhat.com>
Fri, 1 Feb 2019 11:39:41 +0000 (12:39 +0100)
We should not give domains access to something they don't necessarily
need by default. Remove it from the qemu driver docs too.

Signed-off-by: Erik Skultety <eskultet@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
docs/drvqemu.html.in
src/qemu/qemu.conf
src/qemu/qemu_cgroup.c
src/qemu/test_libvirtd_qemu.aug.in

index bf60a9144b09389019340a2fdc15a6bee2b95af1..5ad956740fd3e3ef5a18584aba2ee6f344e00a9c 100644 (file)
@@ -396,7 +396,7 @@ chmod o+x /path/to/directory
 /dev/null, /dev/full, /dev/zero,
 /dev/random, /dev/urandom,
 /dev/ptmx, /dev/kvm, /dev/kqemu,
-/dev/rtc, /dev/hpet, /dev/sev
+/dev/rtc, /dev/hpet
 </pre>
 
     <p>
index c1f12011341cc889412263e56c83afdfc965ff14..7820e72dd88c08fa21d605fb11d87df994f9f9cd 100644 (file)
 #    "/dev/null", "/dev/full", "/dev/zero",
 #    "/dev/random", "/dev/urandom",
 #    "/dev/ptmx", "/dev/kvm", "/dev/kqemu",
-#    "/dev/rtc","/dev/hpet", "/dev/sev"
+#    "/dev/rtc","/dev/hpet"
 #]
 #
 # RDMA migration requires the following extra files to be added to the list:
index 9ceecb884ecfd5799b672a0b9d115ad19042fd7b..7b7cd4258b2411393a9fac6cc1570c00df52cd7b 100644 (file)
@@ -46,7 +46,7 @@ const char *const defaultDeviceACL[] = {
     "/dev/null", "/dev/full", "/dev/zero",
     "/dev/random", "/dev/urandom",
     "/dev/ptmx", "/dev/kvm", "/dev/kqemu",
-    "/dev/rtc", "/dev/hpet", "/dev/sev",
+    "/dev/rtc", "/dev/hpet",
     NULL,
 };
 #define DEVICE_PTY_MAJOR 136
index 42354645305d3435a68869da9851cb5300cc8ac1..51a7ad58926d890dc1bac81260aa2887feed6941 100644 (file)
@@ -63,7 +63,6 @@ module Test_libvirtd_qemu =
     { "8" = "/dev/kqemu" }
     { "9" = "/dev/rtc" }
     { "10" = "/dev/hpet" }
-    { "11" = "/dev/sev" }
 }
 { "save_image_format" = "raw" }
 { "dump_image_format" = "raw" }