Comment 3 for bug 1432644

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

We should not allow access to /dev/shm/lttng-ust-wait-5 to VMs unless libvirt exposes the files in the domain definition and virt-aa-helper can update the policy on a per VM basis. We could add a rule to the libvirt-qemu abstraction, but it would be too generic 'owner /dev/shm/lttng-ust-wait-* rw,' and therefore break guest isolation (though that is of course fine for users to manually add if they need this functionality and understand the compromise).