Re: [libvirt] [PATCH 2/3] Grant access to helpers

2015-01-23 Thread Cedric Bosdonnat
On Thu, 2015-01-22 at 09:17 -0700, Mike Latimer wrote: On Thursday, January 22, 2015 08:55:07 AM Cedric Bosdonnat wrote: Seems like the apparmor profile for libvirtd is pretty wide open, so I'm not sure if there will be much of a difference between those two settings. I'm also not sure

Re: [libvirt] [PATCH 2/3] Grant access to helpers

2015-01-22 Thread Cedric Bosdonnat
On Wed, 2015-01-21 at 22:32 -0700, Mike Latimer wrote: On Tuesday, January 20, 2015 09:08:04 AM Cedric Bosdonnat wrote: On Mon, 2015-01-19 at 18:25 -0700, Mike Latimer wrote: Apparmor must not prevent access to required helper programs. The following helpers should be allowed to

Re: [libvirt] [PATCH 2/3] Grant access to helpers

2015-01-22 Thread Mike Latimer
On Thursday, January 22, 2015 08:55:07 AM Cedric Bosdonnat wrote: Seems like the apparmor profile for libvirtd is pretty wide open, so I'm not sure if there will be much of a difference between those two settings. I'm also not sure how best to test the functionality of those helpers to

Re: [libvirt] [PATCH 2/3] Grant access to helpers

2015-01-21 Thread Mike Latimer
On Tuesday, January 20, 2015 09:08:04 AM Cedric Bosdonnat wrote: On Mon, 2015-01-19 at 18:25 -0700, Mike Latimer wrote: Apparmor must not prevent access to required helper programs. The following helpers should be allowed to run in unconfined execution mode: - libvirt_parthelper -

Re: [libvirt] [PATCH 2/3] Grant access to helpers

2015-01-20 Thread Cedric Bosdonnat
On Mon, 2015-01-19 at 18:25 -0700, Mike Latimer wrote: Apparmor must not prevent access to required helper programs. The following helpers should be allowed to run in unconfined execution mode: - libvirt_parthelper - libvirt_iohelper --- examples/apparmor/usr.sbin.libvirtd | 2 ++ 1

[libvirt] [PATCH 2/3] Grant access to helpers

2015-01-19 Thread Mike Latimer
Apparmor must not prevent access to required helper programs. The following helpers should be allowed to run in unconfined execution mode: - libvirt_parthelper - libvirt_iohelper --- examples/apparmor/usr.sbin.libvirtd | 2 ++ 1 file changed, 2 insertions(+) diff --git