Re: [libvirt] [PATCH v2] qemu: Allow @rednernode for virgl domains

2017-02-20 Thread Michal Privoznik
On 20.02.2017 09:49, Marc-André Lureau wrote: > - Original Message - >> When enabling virgl, qemu opens /dev/dri/render*. So far, we are >> not allowing that in devices cgroup nor creating the file in >> domain's namespace and thus requiring users to set the paths in >> qemu.conf. This,

Re: [libvirt] [PATCH v2] qemu: Allow @rednernode for virgl domains

2017-02-20 Thread Marc-André Lureau
Hi Fix the title @rednernode -> @rendernode - Original Message - > When enabling virgl, qemu opens /dev/dri/render*. So far, we are > not allowing that in devices cgroup nor creating the file in > domain's namespace and thus requiring users to set the paths in > qemu.conf. This,

[libvirt] [PATCH v2] qemu: Allow @rednernode for virgl domains

2017-02-20 Thread Michal Privoznik
When enabling virgl, qemu opens /dev/dri/render*. So far, we are not allowing that in devices cgroup nor creating the file in domain's namespace and thus requiring users to set the paths in qemu.conf. This, however, is suboptimal as it allows access to ALL qemu processes even those which don't