Re: [Xen-devel] [PATCH v3] run QEMU as non-root

2015-06-01 Thread Stefano Stabellini
On Fri, 29 May 2015, Ian Campbell wrote: On Fri, 2015-05-29 at 14:47 +0100, Stefano Stabellini wrote: Try to use xen-qemudepriv-$domname first, then xen-qemudepriv-base + domid, finally xen-qemudepriv-shared and root if everything else fails. The uids need to be manually created by the

[Xen-devel] [PATCH v3] run QEMU as non-root

2015-05-29 Thread Stefano Stabellini
Try to use xen-qemudepriv-$domname first, then xen-qemudepriv-base + domid, finally xen-qemudepriv-shared and root if everything else fails. The uids need to be manually created by the user or, more likely, by the xen package maintainer. To actually secure QEMU when running in Dom0, we need at

Re: [Xen-devel] [PATCH v3] run QEMU as non-root

2015-05-29 Thread Ian Campbell
On Fri, 2015-05-29 at 14:47 +0100, Stefano Stabellini wrote: Try to use xen-qemudepriv-$domname first, then xen-qemudepriv-base + domid, finally xen-qemudepriv-shared and root if everything else fails. The uids need to be manually created by the user or, more likely, by the xen package