diff --git a/templates/usr.bin.nova-compute b/templates/usr.bin.nova-compute index 651aaa1b..427bb72a 100644 --- a/templates/usr.bin.nova-compute +++ b/templates/usr.bin.nova-compute @@ -31,6 +31,7 @@ deny /* w, /bin/* rix, + /dev/ r, /dev/disk/** r, /dev/disk/by-id/* r, /dev/mapper/control wr, @@ -77,7 +78,7 @@ /run/libvirt/libvirt-sock rw, /run/lock/iscsi/ rw, /run/lock/iscsi/** rwl, - /run/lock/nova/nova-iptables wk, + /run/lock/nova/* wk, /run/lock/qemu-nbd-nbd* w, /run/openvswitch/db.sock rw, /run/uuidd/request rw, @@ -96,6 +97,7 @@ /{usr/,}sbin/e2label rix, /{usr/,}sbin/tune2fs rix, /sys/block/ r, + /sys/bus/scsi/devices/ r, /sys/class/fc_host/{,**} r, /sys/class/iscsi_host/ r, /sys/class/iscsi_session/ r,