From: "Michael S. Tsirkin" <mst@redhat.com>
Date: Sun, 23 Nov 2014 22:30:32 +0200
qemu runs in the host, but it's unpriveledged: it gets
passed tun FDs by a priveledged daemon, and it only
has the rights to some operations,
in particular to attach and detach queues.
The assumption always was that this operation is safe
and can't make kernel run out of resources.
This creates a rather rediculous situation in my opinion.
Configuring a network device is a privileged operation, the daemon
should be setting this thing up.
In no other context would we have to worry about something like this.