]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
udev: allow kvm group to access vhost-vsock device
authorMarc-André Lureau <marcandre.lureau@redhat.com>
Tue, 12 Jan 2021 12:03:37 +0000 (16:03 +0400)
committerMarc-André Lureau <marcandre.lureau@redhat.com>
Wed, 13 Jan 2021 09:10:19 +0000 (13:10 +0400)
/dev/vhost-vsock allows to setup a guest CID and running
state (VHOST_VSOCK_SET_GUEST_CID, VHOST_VSOCK_SET_RUNNING)

All this should be legitimate and safe for KVM users.

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
rules.d/50-udev-default.rules.in
tmpfiles.d/static-nodes-permissions.conf.in

index 6688b840d697c7100d7f8f9ad7ed7aa885db37ca..0cc70b1bd0dcb1a914b34dc970c3625d6a2d351e 100644 (file)
@@ -86,6 +86,7 @@ KERNEL=="fuse", MODE="0666", OPTIONS+="static_node=fuse"
 KERNEL=="kvm", GROUP="kvm", MODE="@DEV_KVM_MODE@", OPTIONS+="static_node=kvm"
 
 KERNEL=="vsock", MODE="0666"
+KERNEL=="vhost-vsock", GROUP="kvm", MODE="@DEV_KVM_MODE@", OPTIONS+="static_node=vhost-vsock"
 
 KERNEL=="udmabuf", GROUP="kvm"
 
index 50cffe2cd96ca8560dfb7fa09d4b9b92f148c020..923ce7d93e87e4ee9b9e64753613975e12c4f5f8 100644 (file)
@@ -15,3 +15,4 @@ z /dev/loop-control 0660 - disk  -
 z /dev/net/tun      0666 - -     -
 z /dev/fuse         0666 - -     -
 z /dev/kvm          @DEV_KVM_MODE@ - kvm -
+z /dev/vhost-vsock  @DEV_KVM_MODE@ - kvm -