Re: [libvirt] [PATCH 7/7] qemu: Allow /dev/dri/render* for virgl domains

2017-02-19 Thread Michal Privoznik
On 16.02.2017 13:47, Marc-André Lureau wrote: > Hi > > On Fri, Feb 10, 2017 at 6:57 PM Michal Privoznik > wrote: > >> When enabling virgl, qemu opens /dev/dri/render*. So far, we are >> not allowing that in devices cgroup nor creating the file in >> domain's namespace and

Re: [libvirt] [PATCH 7/7] qemu: Allow /dev/dri/render* for virgl domains

2017-02-16 Thread Marc-André Lureau
Hi On Fri, Feb 10, 2017 at 6:57 PM Michal Privoznik wrote: > When enabling virgl, qemu opens /dev/dri/render*. So far, we are > not allowing that in devices cgroup nor creating the file in > domain's namespace and thus requiring users to set the paths in > qemu.conf. This,

[libvirt] [PATCH 7/7] qemu: Allow /dev/dri/render* for virgl domains

2017-02-10 Thread Michal Privoznik
When enabling virgl, qemu opens /dev/dri/render*. So far, we are not allowing that in devices cgroup nor creating the file in domain's namespace and thus requiring users to set the paths in qemu.conf. This, however, is suboptimal as it allows access to ALL qemu processes even those which don't