public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
* /dev/kvm permissions
@ 2007-06-17 18:44 Baruch Even
       [not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
  0 siblings, 1 reply; 3+ messages in thread
From: Baruch Even @ 2007-06-17 18:44 UTC (permalink / raw)
  To: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f

Hello,

What do peoples do/think about the permissions for /dev/kvm?

I'm the maintainer for the Debian package and currently the package uses 
a group to control access, for no good reason really. I've seen that 
kqemu in Debian simply uses 0666 permissions and consider doing the same 
for kvm. I wanted to know what others do in other distributions and what 
others think the permissions should be.

Thanks,
Baruch

p.s. Please cc me as I'm not subscribed to kvm-devel. Thanks.

-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: /dev/kvm permissions
       [not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
@ 2007-06-17 18:52   ` Avi Kivity
       [not found]     ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
  0 siblings, 1 reply; 3+ messages in thread
From: Avi Kivity @ 2007-06-17 18:52 UTC (permalink / raw)
  To: Baruch Even; +Cc: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f

Baruch Even wrote:
> Hello,
>
> What do peoples do/think about the permissions for /dev/kvm?
>
> I'm the maintainer for the Debian package and currently the package uses 
> a group to control access, for no good reason really. I've seen that 
> kqemu in Debian simply uses 0666 permissions and consider doing the same 
> for kvm. I wanted to know what others do in other distributions and what 
> others think the permissions should be.
>
>   

I recommend 0660, and setting /dev/kvm's group to 'kvm'.  Users which
need access to kvm can be added to that group.

A udev rule which does this is available in the scripts/ directory in
kvm-userspace.git (not sure if it is packaged).

When kvm stops locking so much memory, I guess this can be relaxed.

-- 
Do not meddle in the internals of kernels, for they are subtle and quick to panic.


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: /dev/kvm permissions
       [not found]     ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
@ 2007-06-17 19:17       ` Baruch Even
  0 siblings, 0 replies; 3+ messages in thread
From: Baruch Even @ 2007-06-17 19:17 UTC (permalink / raw)
  To: Avi Kivity; +Cc: kvm-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f

Avi Kivity wrote:
> Baruch Even wrote:
>> Hello,
>>
>> What do peoples do/think about the permissions for /dev/kvm?
>>
>> I'm the maintainer for the Debian package and currently the package uses 
>> a group to control access, for no good reason really. I've seen that 
>> kqemu in Debian simply uses 0666 permissions and consider doing the same 
>> for kvm. I wanted to know what others do in other distributions and what 
>> others think the permissions should be.
>>
>>   
> 
> I recommend 0660, and setting /dev/kvm's group to 'kvm'.  Users which
> need access to kvm can be added to that group.

OK. This is what happens right now.

> When kvm stops locking so much memory, I guess this can be relaxed.

OK. It would be nice if you notify when you think this change is a good 
idea. Relaxing access will make kvm easier to use which is always a good 
thing.

Baruch

-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2007-06-17 19:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-17 18:44 /dev/kvm permissions Baruch Even
     [not found] ` <46758112.4030604-6P1Dz+XQpLLYtjvyW6yDsg@public.gmane.org>
2007-06-17 18:52   ` Avi Kivity
     [not found]     ` <4675830B.3020404-atKUWr5tajBWk0Htik3J/w@public.gmane.org>
2007-06-17 19:17       ` Baruch Even

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox