|
|
edecca |
From 17c0f51fb9981dbd372a24952b483a14222674ec Mon Sep 17 00:00:00 2001
|
|
|
edecca |
Message-Id: <17c0f51fb9981dbd372a24952b483a14222674ec@dist-git>
|
|
|
edecca |
From: Erik Skultety <eskultet@redhat.com>
|
|
|
edecca |
Date: Fri, 1 Feb 2019 17:21:54 +0100
|
|
|
edecca |
Subject: [PATCH] qemu: conf: Remove /dev/sev from the default cgroup device
|
|
|
edecca |
acl list
|
|
|
edecca |
MIME-Version: 1.0
|
|
|
edecca |
Content-Type: text/plain; charset=UTF-8
|
|
|
edecca |
Content-Transfer-Encoding: 8bit
|
|
|
edecca |
|
|
|
edecca |
We should not give domains access to something they don't necessarily
|
|
|
edecca |
need by default. Remove it from the qemu driver docs too.
|
|
|
edecca |
|
|
|
edecca |
Signed-off-by: Erik Skultety <eskultet@redhat.com>
|
|
|
edecca |
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
|
|
|
edecca |
(cherry picked from commit b6440119185a4e307654a8d26d6d551a2675bf82)
|
|
|
edecca |
|
|
|
edecca |
https: //bugzilla.redhat.com/show_bug.cgi?id=1665400
|
|
|
edecca |
Signed-off-by: Erik Skultety <eskultet@redhat.com>
|
|
|
edecca |
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
|
edecca |
---
|
|
|
edecca |
docs/drvqemu.html.in | 2 +-
|
|
|
edecca |
src/qemu/qemu.conf | 2 +-
|
|
|
edecca |
src/qemu/qemu_cgroup.c | 2 +-
|
|
|
edecca |
src/qemu/test_libvirtd_qemu.aug.in | 1 -
|
|
|
edecca |
4 files changed, 3 insertions(+), 4 deletions(-)
|
|
|
edecca |
|
|
|
edecca |
diff --git a/docs/drvqemu.html.in b/docs/drvqemu.html.in
|
|
|
edecca |
index d51ccf2412..a692a6dab6 100644
|
|
|
edecca |
--- a/docs/drvqemu.html.in
|
|
|
edecca |
+++ b/docs/drvqemu.html.in
|
|
|
edecca |
@@ -396,7 +396,7 @@ chmod o+x /path/to/directory
|
|
|
edecca |
/dev/null, /dev/full, /dev/zero,
|
|
|
edecca |
/dev/random, /dev/urandom,
|
|
|
edecca |
/dev/ptmx, /dev/kvm, /dev/kqemu,
|
|
|
edecca |
-/dev/rtc, /dev/hpet, /dev/sev
|
|
|
edecca |
+/dev/rtc, /dev/hpet
|
|
|
edecca |
|
|
|
edecca |
|
|
|
edecca |
|
|
|
edecca |
diff --git a/src/qemu/qemu.conf b/src/qemu/qemu.conf
|
|
|
edecca |
index cd57b3cc69..76afe88b0c 100644
|
|
|
edecca |
--- a/src/qemu/qemu.conf
|
|
|
edecca |
+++ b/src/qemu/qemu.conf
|
|
|
edecca |
@@ -485,7 +485,7 @@
|
|
|
edecca |
# "/dev/null", "/dev/full", "/dev/zero",
|
|
|
edecca |
# "/dev/random", "/dev/urandom",
|
|
|
edecca |
# "/dev/ptmx", "/dev/kvm", "/dev/kqemu",
|
|
|
edecca |
-# "/dev/rtc","/dev/hpet", "/dev/sev"
|
|
|
edecca |
+# "/dev/rtc","/dev/hpet"
|
|
|
edecca |
#]
|
|
|
edecca |
#
|
|
|
edecca |
# RDMA migration requires the following extra files to be added to the list:
|
|
|
edecca |
diff --git a/src/qemu/qemu_cgroup.c b/src/qemu/qemu_cgroup.c
|
|
|
edecca |
index c8fba7f9e6..fd54333fb9 100644
|
|
|
edecca |
--- a/src/qemu/qemu_cgroup.c
|
|
|
edecca |
+++ b/src/qemu/qemu_cgroup.c
|
|
|
edecca |
@@ -48,7 +48,7 @@ const char *const defaultDeviceACL[] = {
|
|
|
edecca |
"/dev/null", "/dev/full", "/dev/zero",
|
|
|
edecca |
"/dev/random", "/dev/urandom",
|
|
|
edecca |
"/dev/ptmx", "/dev/kvm", "/dev/kqemu",
|
|
|
edecca |
- "/dev/rtc", "/dev/hpet", "/dev/sev",
|
|
|
edecca |
+ "/dev/rtc", "/dev/hpet",
|
|
|
edecca |
NULL,
|
|
|
edecca |
};
|
|
|
edecca |
#define DEVICE_PTY_MAJOR 136
|
|
|
edecca |
diff --git a/src/qemu/test_libvirtd_qemu.aug.in b/src/qemu/test_libvirtd_qemu.aug.in
|
|
|
edecca |
index f1e8806ad2..61690ee92c 100644
|
|
|
edecca |
--- a/src/qemu/test_libvirtd_qemu.aug.in
|
|
|
edecca |
+++ b/src/qemu/test_libvirtd_qemu.aug.in
|
|
|
edecca |
@@ -62,7 +62,6 @@ module Test_libvirtd_qemu =
|
|
|
edecca |
{ "8" = "/dev/kqemu" }
|
|
|
edecca |
{ "9" = "/dev/rtc" }
|
|
|
edecca |
{ "10" = "/dev/hpet" }
|
|
|
edecca |
- { "11" = "/dev/sev" }
|
|
|
edecca |
}
|
|
|
edecca |
{ "save_image_format" = "raw" }
|
|
|
edecca |
{ "dump_image_format" = "raw" }
|
|
|
edecca |
--
|
|
|
edecca |
2.20.1
|
|
|
edecca |
|