* /dev/kvm permissions
@ 2007-06-17 18:44 Baruch Even
[not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
0 siblings, 1 reply; 3+ messages in thread
From: Baruch Even @ 2007-06-17 18:44 UTC (permalink / raw)
To: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f
Hello,
What do peoples do/think about the permissions for /dev/kvm?
I'm the maintainer for the Debian package and currently the package uses
a group to control access, for no good reason really. I've seen that
kqemu in Debian simply uses 0666 permissions and consider doing the same
for kvm. I wanted to know what others do in other distributions and what
others think the permissions should be.
Thanks,
Baruch
p.s. Please cc me as I'm not subscribed to kvm-devel. Thanks.
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: /dev/kvm permissions
[not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
@ 2007-06-17 18:52 ` Avi Kivity
[not found] ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
0 siblings, 1 reply; 3+ messages in thread
From: Avi Kivity @ 2007-06-17 18:52 UTC (permalink / raw)
To: Baruch Even; +Cc: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f
Baruch Even wrote:
> Hello,
>
> What do peoples do/think about the permissions for /dev/kvm?
>
> I'm the maintainer for the Debian package and currently the package uses
> a group to control access, for no good reason really. I've seen that
> kqemu in Debian simply uses 0666 permissions and consider doing the same
> for kvm. I wanted to know what others do in other distributions and what
> others think the permissions should be.
>
>
I recommend 0660, and setting /dev/kvm's group to 'kvm'. Users which
need access to kvm can be added to that group.
A udev rule which does this is available in the scripts/ directory in
kvm-userspace.git (not sure if it is packaged).
When kvm stops locking so much memory, I guess this can be relaxed.
--
Do not meddle in the internals of kernels, for they are subtle and quick to panic.
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: /dev/kvm permissions
[not found] ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
@ 2007-06-17 19:17 ` Baruch Even
0 siblings, 0 replies; 3+ messages in thread
From: Baruch Even @ 2007-06-17 19:17 UTC (permalink / raw)
To: Avi Kivity; +Cc: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f
Avi Kivity wrote:
> Baruch Even wrote:
>> Hello,
>>
>> What do peoples do/think about the permissions for /dev/kvm?
>>
>> I'm the maintainer for the Debian package and currently the package uses
>> a group to control access, for no good reason really. I've seen that
>> kqemu in Debian simply uses 0666 permissions and consider doing the same
>> for kvm. I wanted to know what others do in other distributions and what
>> others think the permissions should be.
>>
>>
>
> I recommend 0660, and setting /dev/kvm's group to 'kvm'. Users which
> need access to kvm can be added to that group.
OK. This is what happens right now.
> When kvm stops locking so much memory, I guess this can be relaxed.
OK. It would be nice if you notify when you think this change is a good
idea. Relaxing access will make kvm easier to use which is always a good
thing.
Baruch
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2007-06-17 19:17 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-17 18:44 /dev/kvm permissions Baruch Even
[not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
2007-06-17 18:52 ` Avi Kivity
[not found] ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
2007-06-17 19:17 ` Baruch Even
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox