diff --git a/Dockerfile b/Dockerfile index b77cb80..76ee613 100644 --- a/Dockerfile +++ b/Dockerfile @@ -89,12 +89,10 @@ COPY augconf /augconf RUN augtool -f /augconf RUN cd /var && rm -rf run && ln -s ../run . -# Setup permissions and capabilities for non-root VMIs. KubeVirt sets -# XDG_* directories to /var/run. +# Setup permissions and capabilities for non-root VMIs RUN setcap 'cap_net_bind_service=+ep' /usr/bin/virt-launcher && \ setcap 'cap_net_bind_service=+ep' /usr/bin/virt-launcher-monitor && \ setcap 'cap_net_bind_service=+ep' /usr/bin/qemu-system-$(uname -m) && \ - chmod 0755 /etc/libvirt && \ - chown qemu:qemu /var/run + chmod 0755 /etc/libvirt ENTRYPOINT [ "/usr/bin/virt-launcher-monitor" ] diff --git a/virt-launcher-container.changes b/virt-launcher-container.changes index dc107ee..69ef38b 100644 --- a/virt-launcher-container.changes +++ b/virt-launcher-container.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Wed Nov 8 14:08:15 UTC 2023 - Vasily Ulyanov + +- Do not chown /var/run + ------------------------------------------------------------------- Mon Oct 23 12:28:27 UTC 2023 - Vasily Ulyanov