Skip to content

Server-owned definition props get in through resource-group spawn #202

Description

@kvaps

The props blockstor writes on a definition itself (the restore marker Blockstor/RestoreFromSnapshot, Blockstor/RestoreVolumes, Blockstor/RestoreAdopted and the rollback mark) are refused in clone prop edits, rd modify and the CLI property verbs since #190. They still get onto a definition through a resource group: rg create and rg modify accept them, and buildSpawnedRD copies rg.Props into the spawned definition unfiltered (pkg/rest/spawn.go).

So a StorageClass can put a restore marker on every PVC of its class. There is no privilege gain, the caller already has full rights, but the satellite restores the new volumes from whatever snapshot the marker names instead of bringing them up blank.

Spawn also accepts override_props, delete_props and delete_namespaces and drops them (pkg/api/v1/resource_group.go), the accept-and-drop shape #190 removes elsewhere.

Fix: filter rg.Props through store.TravellingProps in buildSpawnedRD, refuse the server-owned keys on rg create and rg modify with store.ServerOwnedPropEdit, and either honour or refuse the three spawn fields.

Found while reviewing #190; present on main.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions