From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 756D21FF0B6 for ; Wed, 30 Sep 2026 23:10:37 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 66B982162C; Wed, 30 Sep 2026 23:10:33 +0200 (CEST) From: Thomas Lamprecht To: pve-devel@lists.proxmox.com, Elias Huhsovitz Subject: applied: [PATCH manager v4 0/2] fix #6735: api: pci: allow mdevscan access via mapping permissions Date: Wed, 30 Sep 2026 23:08:05 +0200 Message-ID: <179080248155.2638466.14975802568234452276.b4-ty@b4> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260904094456.70309-1-e.huhsovitz@proxmox.com> References: <20260904094456.70309-1-e.huhsovitz@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1790802625638 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.487 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: J347TKQ4CMJB3KTCCPAKHX2CN2IYW7D2 X-Message-ID-Hash: J347TKQ4CMJB3KTCCPAKHX2CN2IYW7D2 X-MailFrom: t.lamprecht@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Fri, 04 Sep 2026 11:44:52 +0200, Elias Huhsovitz wrote: > This series allows users who have been granted Mapping.Use > (or Mapping.Modify / Mapping.Audit) on a specific PCI mapping to list > the mediated device (mdev) types for that mapping without requiring > global Sys.Audit or Sys.Modify privileges on the entire cluster. > > In multi‑team environments where access is compartmentalized via > resource pools and PCI mappings, the previous requirement forced > administrators to grant overly broad permissions for GPU usage. > By checking mapping‑specific permissions when a mapping name is > supplied, the patch enables non‑administrative users to select and use > vGPU types for their assigned hardware. > > [...] Applied the first one, but dropped the constant, thanks! more rationale: IMO that constant name was not ideal as it was rather generic and even if that was addressed we still had repetition here by listing the privs explicit in the description, which can go out of sync much easier that way. Also, not a common pattern we use in our code base and IMO also just not gaining one that much to add such indirection variables/constants. [1/2] fix #6735: api: pci: allow mdevscan access via mapping permissions https://git.proxmox.com/?p=pve-manager.git;a=commitdiff;h=58350116c198b838dfb50739e886bc92bcc751c3 [2/2] api: pci: utilize constant perm variable for pci_scan DROPPED