diff mbox series

[bug#49134] services: libvirt: Change unix-sock-group default.

Message ID 20210620133940.17491-1-brice@waegenei.re
State Accepted
Headers show
Series [bug#49134] services: libvirt: Change unix-sock-group default. | expand

Checks

Context Check Description
cbaines/comparison success View comparision
cbaines/git branch success View Git branch
cbaines/applying patch success View Laminar job
cbaines/issue success View issue

Commit Message

Brice Waegeneire June 20, 2021, 1:39 p.m. UTC
When accessing libvrtd remotely, polkit can't be used unless you are
logged as root.  Instead allow libvirt groups member access to the
control socket.

* gnu/services/virtualization.scm (libvirt-configuration)
[unix-sock-group]: Change default from "root" to "libvirt".
---
 gnu/services/virtualization.scm | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Ludovic Courtès Sept. 3, 2021, 4:09 p.m. UTC | #1
Hi,

Brice Waegeneire <brice@waegenei.re> skribis:

> When accessing libvrtd remotely, polkit can't be used unless you are
> logged as root.  Instead allow libvirt groups member access to the
> control socket.
>
> * gnu/services/virtualization.scm (libvirt-configuration)
> [unix-sock-group]: Change default from "root" to "libvirt".

LGTM!

Ludo’.
Brice Waegeneire Sept. 4, 2021, 7:34 a.m. UTC | #2
Ludovic Courtès <ludo@gnu.org> writes:

> Brice Waegeneire <brice@waegenei.re> skribis:
>
>> * gnu/services/virtualization.scm (libvirt-configuration)
>> [unix-sock-group]: Change default from "root" to "libvirt".
>
> LGTM!

Thank for the reviews Ludo’, pushed as 4dc17cd54e86dbd71d26b87138660d42e8f615a9.
diff mbox series

Patch

diff --git a/gnu/services/virtualization.scm b/gnu/services/virtualization.scm
index 36e9feb05c..126fa52279 100644
--- a/gnu/services/virtualization.scm
+++ b/gnu/services/virtualization.scm
@@ -168,7 +168,7 @@  stopping the Avahi daemon.")
    "Default mDNS advertisement name. This must be unique on the
 immediate broadcast network.")
   (unix-sock-group
-   (string "root")
+   (string "libvirt")
    "UNIX domain socket group ownership. This can be used to
 allow a 'trusted' set of users access to management capabilities
 without becoming root.")