Re: [libvirt] [PATCH 1/2] security: aa-helper: allow virt-aa-helper to read /dev/dri

2019-02-15 Thread Jamie Strandboge
On Tue, 12 Feb 2019, Christian Ehrhardt wrote: > Change fb01e1a44 "virt-aa-helper: generate rules for gl enabled > graphics devices" implemented the detection for gl enabled > devices in virt-aa-helper. But it will in certain cases e.g. if > no rendernode was explicitly specified need to read /dev

[libvirt] [PATCH 1/2] security: aa-helper: allow virt-aa-helper to read /dev/dri

2019-02-12 Thread Christian Ehrhardt
Change fb01e1a44 "virt-aa-helper: generate rules for gl enabled graphics devices" implemented the detection for gl enabled devices in virt-aa-helper. But it will in certain cases e.g. if no rendernode was explicitly specified need to read /dev/dri which it currently isn't allowed. Add a rule to th