--- apps/qemu.te 2010-12-13 15:11:01.000000000 +0100 +++ apps/qemu.te 2011-01-22 21:35:19.555999967 +0100 @@ -56,6 +56,10 @@ userdom_search_user_home_content(qemu_t) userdom_read_user_tmpfs_files(qemu_t) +allow qemu_t self:socket create_socket_perms; + +kernel_request_load_module(qemu_t) + tunable_policy(`qemu_full_network',` allow qemu_t self:udp_socket create_socket_perms; @@ -116,3 +120,7 @@ allow unconfined_qemu_t self:process { execstack execmem }; allow unconfined_qemu_t qemu_exec_t:file execmod; ') + +optional_policy(` + vde_connect(qemu_t) +')