You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
17 lines
540 B
17 lines
540 B
4 months ago
|
type crosvm, domain, coredomain;
|
||
|
type crosvm_exec, system_file_type, exec_type, file_type;
|
||
|
type crosvm_tmpfs, file_type;
|
||
|
|
||
|
# Let crosvm create temporary files.
|
||
|
tmpfs_domain(crosvm)
|
||
|
|
||
|
# Let crosvm receive file descriptors from virtmanager.
|
||
|
allow crosvm virtmanager:fd use;
|
||
|
|
||
|
# Let crosvm open /dev/kvm.
|
||
|
allow crosvm kvm_device:chr_file rw_file_perms;
|
||
|
|
||
|
# Most other domains shouldn't access /dev/kvm.
|
||
|
neverallow { domain -crosvm -ueventd -shell } kvm_device:chr_file getattr;
|
||
|
neverallow { domain -crosvm -ueventd } kvm_device:chr_file ~getattr;
|