Re: CAP_SYS_RAWIO missing for qemu-kvm device passthrough

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



* Gerd v. Egidy (lists@xxxxxxxx) wrote:
> Hi,
> 
> I'm running current git libvirt on Fedora 13 beta. I enabled the use of 
> libcap-ng as it is done in the regular F13 .spec.
> 
> When I now pass a pci card through to a qemu-kvm guest using vt-d I get this 
> error from qemu-kvm:
> 
> Failed to assign irq for "hostdev0": Operation not permitted
> Perhaps you are assigning a device that shares an IRQ with another device?
> 
> I'm running qemu-kvm as root. But that doesn't seem to be enough:
> 
> I traced the issue down to a missing CAP_SYS_RAWIO.The kvm kernel module 
> requires CAP_SYS_RAWIO to use the KVM_ASSIGN_DEV_IRQ ioctl.

There is some pending work in KVM to deal with this.  It simply removes
CAP_SYS_RAWIO.  Need to finish auditing this.  Dropping all but
CAP_SYS_RAWIO in libvirt isn't a good final solution since it
drastically undermines the value of dropping privileges.

thanks,
-chris

--
libvir-list mailing list
libvir-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libvir-list

[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Fedora Tools]