The props blockstor writes on a definition itself (the restore marker Blockstor/RestoreFromSnapshot, Blockstor/RestoreVolumes, Blockstor/RestoreAdopted and the rollback mark) are refused in clone prop edits, rd modify and the CLI property verbs since #190. They still get onto a definition through a resource group: rg create and rg modify accept them, and buildSpawnedRD copies rg.Props into the spawned definition unfiltered (pkg/rest/spawn.go).
So a StorageClass can put a restore marker on every PVC of its class. There is no privilege gain, the caller already has full rights, but the satellite restores the new volumes from whatever snapshot the marker names instead of bringing them up blank.
Spawn also accepts override_props, delete_props and delete_namespaces and drops them (pkg/api/v1/resource_group.go), the accept-and-drop shape #190 removes elsewhere.
Fix: filter rg.Props through store.TravellingProps in buildSpawnedRD, refuse the server-owned keys on rg create and rg modify with store.ServerOwnedPropEdit, and either honour or refuse the three spawn fields.
Found while reviewing #190; present on main.
The props blockstor writes on a definition itself (the restore marker
Blockstor/RestoreFromSnapshot,Blockstor/RestoreVolumes,Blockstor/RestoreAdoptedand the rollback mark) are refused in clone prop edits,rd modifyand the CLI property verbs since #190. They still get onto a definition through a resource group:rg createandrg modifyaccept them, andbuildSpawnedRDcopiesrg.Propsinto the spawned definition unfiltered (pkg/rest/spawn.go).So a StorageClass can put a restore marker on every PVC of its class. There is no privilege gain, the caller already has full rights, but the satellite restores the new volumes from whatever snapshot the marker names instead of bringing them up blank.
Spawn also accepts
override_props,delete_propsanddelete_namespacesand drops them (pkg/api/v1/resource_group.go), the accept-and-drop shape #190 removes elsewhere.Fix: filter
rg.Propsthroughstore.TravellingPropsinbuildSpawnedRD, refuse the server-owned keys onrg createandrg modifywithstore.ServerOwnedPropEdit, and either honour or refuse the three spawn fields.Found while reviewing #190; present on main.