[libvirt] [PATCH] apparmor, libvirt-qemu: Allow QEMU to gather information about available host resources.

intrigeri intrigeri+libvirt at boum.org
Tue Aug 8 21:57:26 UTC 2017


---
 examples/apparmor/libvirt-qemu | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/examples/apparmor/libvirt-qemu b/examples/apparmor/libvirt-qemu
index f462d7428c..dcfb1a5985 100644
--- a/examples/apparmor/libvirt-qemu
+++ b/examples/apparmor/libvirt-qemu
@@ -169,3 +169,9 @@
   @{PROC}/device-tree/ r,
   @{PROC}/device-tree/** r,
   /sys/firmware/devicetree/** r,
+
+  # for gathering information about available host resources
+  /sys/devices/system/cpu/ r,
+  /sys/devices/system/node/ r,
+  /sys/devices/system/node/node[0-9]*/meminfo r,
+  /sys/module/vhost/parameters/max_mem_regions r,
-- 
2.14.0




More information about the libvir-list mailing list