| libvirt / libvirt | 
            
            
              | 
                   master | 
            
            
              | 
                  
                    | 
                       24 mins and 31 secs |  
                    | 
                        
                           Martin Kletzander |  
                    | qemu: Label uniqDir when probing capabilities
 This does not cause a problem in usual scenarios thanks to us allowing
 CAP_DAC_OVERRIDE for the qemu process, however in some scenarios this might be
 an issue because the directory is created with mkdtemp(3) which explicitly
 creates that with 0700 permissions and qemu running as non-root cannot access
 that.
 
 The scenarios include:
 - Builds without CAPNG
 - Running libvirtd in certain container configurations [1]
 - and possibly others.
 
 [1] https://github.com/kubevirt/kubevirt/pull/2181#issuecomment-481840304
 
 Signed-off-by: Martin Kletzander <mkletzan@redhat.com>
 Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
 |  |