Re: [libvirt] PATCH: 3/3: Control file device access

2009-02-27 Thread Daniel Veillard
On Thu, Feb 26, 2009 at 04:42:59PM +, Daniel P. Berrange wrote: This patch is more focused on access control. CGroups has a controller that enforces ACLs on device nodes. This allows us to restrict exactly what block/character devices a guest is allowed to access. So in the absence of

Re: [libvirt] PATCH: 3/3: Control file device access

2009-02-26 Thread Daniel P. Berrange
This patch is more focused on access control. CGroups has a controller that enforces ACLs on device nodes. This allows us to restrict exactly what block/character devices a guest is allowed to access. So in the absence of something like SELinux sVirt, you can get a degree of isolation between