From 17c0f51fb9981dbd372a24952b483a14222674ec Mon Sep 17 00:00:00 2001 Message-Id: <17c0f51fb9981dbd372a24952b483a14222674ec@dist-git> From: Erik Skultety Date: Fri, 1 Feb 2019 17:21:54 +0100 Subject: [PATCH] qemu: conf: Remove /dev/sev from the default cgroup device acl list MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit We should not give domains access to something they don't necessarily need by default. Remove it from the qemu driver docs too. Signed-off-by: Erik Skultety Reviewed-by: Daniel P. Berrangé (cherry picked from commit b6440119185a4e307654a8d26d6d551a2675bf82) https: //bugzilla.redhat.com/show_bug.cgi?id=1665400 Signed-off-by: Erik Skultety Reviewed-by: Ján Tomko --- docs/drvqemu.html.in | 2 +- src/qemu/qemu.conf | 2 +- src/qemu/qemu_cgroup.c | 2 +- src/qemu/test_libvirtd_qemu.aug.in | 1 - 4 files changed, 3 insertions(+), 4 deletions(-) diff --git a/docs/drvqemu.html.in b/docs/drvqemu.html.in index d51ccf2412..a692a6dab6 100644 --- a/docs/drvqemu.html.in +++ b/docs/drvqemu.html.in @@ -396,7 +396,7 @@ chmod o+x /path/to/directory /dev/null, /dev/full, /dev/zero, /dev/random, /dev/urandom, /dev/ptmx, /dev/kvm, /dev/kqemu, -/dev/rtc, /dev/hpet, /dev/sev +/dev/rtc, /dev/hpet

diff --git a/src/qemu/qemu.conf b/src/qemu/qemu.conf index cd57b3cc69..76afe88b0c 100644 --- a/src/qemu/qemu.conf +++ b/src/qemu/qemu.conf @@ -485,7 +485,7 @@ # "/dev/null", "/dev/full", "/dev/zero", # "/dev/random", "/dev/urandom", # "/dev/ptmx", "/dev/kvm", "/dev/kqemu", -# "/dev/rtc","/dev/hpet", "/dev/sev" +# "/dev/rtc","/dev/hpet" #] # # RDMA migration requires the following extra files to be added to the list: diff --git a/src/qemu/qemu_cgroup.c b/src/qemu/qemu_cgroup.c index c8fba7f9e6..fd54333fb9 100644 --- a/src/qemu/qemu_cgroup.c +++ b/src/qemu/qemu_cgroup.c @@ -48,7 +48,7 @@ const char *const defaultDeviceACL[] = { "/dev/null", "/dev/full", "/dev/zero", "/dev/random", "/dev/urandom", "/dev/ptmx", "/dev/kvm", "/dev/kqemu", - "/dev/rtc", "/dev/hpet", "/dev/sev", + "/dev/rtc", "/dev/hpet", NULL, }; #define DEVICE_PTY_MAJOR 136 diff --git a/src/qemu/test_libvirtd_qemu.aug.in b/src/qemu/test_libvirtd_qemu.aug.in index f1e8806ad2..61690ee92c 100644 --- a/src/qemu/test_libvirtd_qemu.aug.in +++ b/src/qemu/test_libvirtd_qemu.aug.in @@ -62,7 +62,6 @@ module Test_libvirtd_qemu = { "8" = "/dev/kqemu" } { "9" = "/dev/rtc" } { "10" = "/dev/hpet" } - { "11" = "/dev/sev" } } { "save_image_format" = "raw" } { "dump_image_format" = "raw" } -- 2.20.1