On Fri, Jan 18, 2013 at 10:07:10PM -0000, Serge Hallyn wrote: > @Jamie,
> do you think we should whitelist /**/OVMF.Fd, whitelist > /usr/share/qemu/**, or are you suggesting something different (in > comments #16 and #8)?
At present we have the following in /etc/apparmor.d/abstractions/libvirt-qemu:
# access to firmware's etc /usr/share/kvm/** r, /usr/share/qemu/** r, /usr/share/bochs/** r, /usr/share/openbios/** r, /usr/share/openhackware/** r, /usr/share/proll/** r, /usr/share/vgabios/** r, /usr/share/seabios/** r,
assuming ovmf is handled consistently to the other bioses, we probably want '/usr/share/ovmf/** r' added to this list, with a symlink from /usr/share/ovmf/OVMF.fd to /usr/share/qemu/OVMF.fd.
On Fri, Jan 18, 2013 at 10:07:10PM -0000, Serge Hallyn wrote:
> @Jamie,
> do you think we should whitelist /**/OVMF.Fd, whitelist
> /usr/share/qemu/**, or are you suggesting something different (in
> comments #16 and #8)?
At present we have the following in d/abstractions/ libvirt- qemu:
/etc/apparmor.
# access to firmware's etc share/qemu/ ** r, share/bochs/ ** r, share/openbios/ ** r, share/openhackw are/** r, share/proll/ ** r, share/vgabios/ ** r, share/seabios/ ** r,
/usr/share/kvm/** r,
/usr/
/usr/
/usr/
/usr/
/usr/
/usr/
/usr/
assuming ovmf is handled consistently to the other bioses, we probably want ovmf/OVMF. fd to /usr/share/ qemu/OVMF. fd.
'/usr/share/ovmf/** r' added to this list, with a symlink from
/usr/share/