Gentoo Archives: gentoo-hardened

From: "Marcin Mirosław" <marcin@×××××.pl>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with usb-passthrough using libvirt with hardened-sources-3.15.8
Date: Wed, 17 Sep 2014 12:05:12
Message-Id: 541978D2.6030202@mejor.pl
In Reply to: Re: [gentoo-hardened] Problem with usb-passthrough using libvirt with hardened-sources-3.15.8 by "Tóth Attila"
1 W dniu 16.09.2014 o 14:34, "Tóth Attila" pisze:
2 > 2014.Szeptember 16.(K) 11:05 időpontban Marcin Mirosław ezt írta:
3 >> A few days ago I boot KVM host with hardened kernel. After some time I
4 >> noticed that usb passthrough from host to kvm guest doesn't work. Simply
5 >> sayoing guest didn't seen any usb device. After switching kernel on host
6 >> to gentoo-sources-{3.14.14,3.16.2} usb-passthrough works as I expect. I
7 >> didn't any related information in logs.
8 >> Does libvirt or grsec need special configuration to have such feature
9 >> working?
10 >
11 > I don't use KVM or libvirt, but I would suggest to check out your grsec
12 > logs for denials.
13 > Also there is a new capability introduced not so long ago:
14 > CAP_BLOCK_SUSPEND
15 > Some daemons and executables may complain - but in my case were
16 > functioning properly anyways. May be not related to your problem.
17
18 Hi!
19 I don't use RBAC nor in kernel.log nor in dmesg nor in libvirt log I
20 didn't see any suspicious entries.
21 Regards,
22 Marcin

Replies

Subject Author
Re: [gentoo-hardened] Problem with usb-passthrough using libvirt with hardened-sources-3.15.8 "Anthony G. Basile" <basile@××××××××××××××.edu>