mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2025-01-03 03:25:20 +00:00
apparmor: allow openGraphicsFD for virt manager >1.4
virt-manager's UI connection will need socket access for openGraphicsFD to work - otherwise users will face a failed connection error when opening the UI view. Depending on the exact versions of libvirt and qemu involved this needs either a rule from qemu to libvirt or vice versa. Acked-by: Jamie Strandboge <jamie@canonical.com> Signed-off-by: Christian Ehrhardt <christian.ehrhardt@canonical.com>
This commit is contained in:
parent
f951277716
commit
1262cbf3a0
@ -188,6 +188,9 @@
|
|||||||
@{PROC}/device-tree/** r,
|
@{PROC}/device-tree/** r,
|
||||||
/sys/firmware/devicetree/** r,
|
/sys/firmware/devicetree/** r,
|
||||||
|
|
||||||
|
# allow connect with openGraphicsFD to work
|
||||||
|
unix (send, receive) type=stream addr=none peer=(label=/usr/sbin/libvirtd),
|
||||||
|
|
||||||
# for gathering information about available host resources
|
# for gathering information about available host resources
|
||||||
/sys/devices/system/cpu/ r,
|
/sys/devices/system/cpu/ r,
|
||||||
/sys/devices/system/node/ r,
|
/sys/devices/system/node/ r,
|
||||||
|
@ -69,6 +69,11 @@
|
|||||||
unix (send, receive) type=stream addr=none peer=(label=/usr/sbin/libvirtd//qemu_bridge_helper),
|
unix (send, receive) type=stream addr=none peer=(label=/usr/sbin/libvirtd//qemu_bridge_helper),
|
||||||
signal (send) set=("term") peer=/usr/sbin/libvirtd//qemu_bridge_helper,
|
signal (send) set=("term") peer=/usr/sbin/libvirtd//qemu_bridge_helper,
|
||||||
|
|
||||||
|
# allow connect with openGraphicsFD, direction reversed in newer versions
|
||||||
|
unix (send, receive) type=stream addr=none peer=(label=libvirt-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*),
|
||||||
|
# unconfined also required if guests run without security module
|
||||||
|
unix (send, receive) type=stream addr=none peer=(label=unconfined),
|
||||||
|
|
||||||
# Very lenient profile for libvirtd since we want to first focus on confining
|
# Very lenient profile for libvirtd since we want to first focus on confining
|
||||||
# the guests. Guests will have a very restricted profile.
|
# the guests. Guests will have a very restricted profile.
|
||||||
/ r,
|
/ r,
|
||||||
|
Loading…
Reference in New Issue
Block a user