Changes since v2: - made signal rules broader, as suggested by Jamie Strandboge <jamie@xxxxxxxxxxxxx> and indeed my tests confirm v2 was too strict; - allowed libvirtd "ptrace (read)" on libvirt-* guests, as suggested by Jamie Strandboge <jamie@xxxxxxxxxxxxx> - added fine-grained mount rules written by openSUSE's Christian Boltz -- libvir-list mailing list libvir-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/libvir-list