Re: [libvirt PATCH] docs: add a kbase explaining security protections for QEMU passthrough

2020-02-23 Thread Ján Tomko
On Thu, Feb 06, 2020 at 01:05:37PM +, Daniel P. Berrangé wrote: When using command line passthrough users will often trip up over the security protections like SELinux, DAC, namespaces, etc which will deny access to files they are passing. This document explains the various protections and

Re: [libvirt PATCH] docs: add a kbase explaining security protections for QEMU passthrough

2020-02-07 Thread Kashyap Chamarthy
On Thu, Feb 06, 2020 at 01:05:37PM +, Daniel P. Berrangé wrote: The core content reads very well. A couple of minor nit-picks inline. [...] > diff --git a/docs/kbase/qemu-passthrough-security.rst > b/docs/kbase/qemu-passthrough-security.rst > new file mode 100644 > index

[libvirt PATCH] docs: add a kbase explaining security protections for QEMU passthrough

2020-02-06 Thread Daniel P . Berrangé
When using command line passthrough users will often trip up over the security protections like SELinux, DAC, namespaces, etc which will deny access to files they are passing. This document explains the various protections and how to deal with their policy, and/or how to disable them.