all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Elias Huhsovitz <e.huhsovitz@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Subject: [PATCH manager v4 1/2] fix #6735: api: pci: allow mdevscan access via mapping permissions
Date: Fri,  4 Sep 2026 11:44:53 +0200	[thread overview]
Message-ID: <20260904094456.70309-2-e.huhsovitz@proxmox.com> (raw)
In-Reply-To: <20260904094456.70309-1-e.huhsovitz@proxmox.com>

The mdevscan endpoint requires Sys.Audit or Sys.Modify on '/'. This
blocks non-admin users from listing mediated device types for a PCI
mapping, even when they hold Mapping.Use on that mapping.

Check the permission in the API handler based on the parameter type: For
a raw PCI ID, require Sys.Audit or Sys.Modify on '/'. For a mapping,
require Sys.Audit or Sys.Modify on '/', or fall back to requiring
Mapping.Use, Mapping.Modify or Mapping.Audit on the specific mapping
path.

Set the endpoint permission to 'user => all' so the handler performs the
type-dependent check. This keeps raw PCI IDs, which are not valid ACL
paths, out of the declarative ACL evaluation.

Signed-off-by: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Reviewed-by: Dominik Csapak <d.csapak@proxmox.com>
Tested-by: Dominik Csapak <d.csapak@proxmox.com>
---
 PVE/API2/Hardware/PCI.pm | 44 ++++++++++++++++++++++++++++++----------
 1 file changed, 33 insertions(+), 11 deletions(-)

diff --git a/PVE/API2/Hardware/PCI.pm b/PVE/API2/Hardware/PCI.pm
index 36b9741b..eb83824f 100644
--- a/PVE/API2/Hardware/PCI.pm
+++ b/PVE/API2/Hardware/PCI.pm
@@ -3,13 +3,17 @@ package PVE::API2::Hardware::PCI;
 use strict;
 use warnings;
 
+use PVE::Exception qw(raise raise_perm_exc);
 use PVE::JSONSchema qw(get_standard_option);
 
 use PVE::QemuServer::PCI::Mdev;
 use PVE::RESTHandler;
+use PVE::RPCEnvironment;
 
 use base qw(PVE::RESTHandler);
 
+use constant GLOBAL_PERMS => ['Sys.Audit', 'Sys.Modify'];
+
 my $default_class_blacklist = "05;06;0b";
 
 __PACKAGE__->register_method({
@@ -180,7 +184,11 @@ __PACKAGE__->register_method({
     protected => 1,
     proxyto => "node",
     permissions => {
-        check => ['perm', '/', ['Sys.Audit', 'Sys.Modify'], any => 1],
+        description =>
+            "For a PCI ID, requires 'Sys.Audit' or 'Sys.Modify' on '/'. For a mapping,"
+            . " requires the same global permissions, or 'Mapping.Use', 'Mapping.Modify'"
+            . ", or 'Mapping.Audit' on '/mapping/pci/<id>'.",
+        user => 'all',
     },
     parameters => {
         additionalProperties => 0,
@@ -222,20 +230,35 @@ __PACKAGE__->register_method({
     code => sub {
         my ($param) = @_;
 
-        if ($param->{'pci-id-or-mapping'} =~
-            m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/
-        ) {
-            return PVE::QemuServer::PCI::Mdev::get_mdev_types($param->{'pci-id-or-mapping'}); # PCI ID
+        my $id = $param->{'pci-id-or-mapping'};
+        my $is_pci_id =
+            $id =~ m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/;
+
+        my $rpcenv = PVE::RPCEnvironment::get();
+        my $authuser = $rpcenv->get_user();
+
+        my $has_global_perms = $rpcenv->check_any($authuser, '/', GLOBAL_PERMS, 1);
+
+        if ($is_pci_id) {
+            raise_perm_exc("/, " . join("|", GLOBAL_PERMS->@*)) if !$has_global_perms;
+
+            return PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
         } else {
-            my $mapping = $param->{'pci-id-or-mapping'};
+            if (!$has_global_perms) {
+                $rpcenv->check_any(
+                    $authuser,
+                    "/mapping/pci/$id",
+                    ['Mapping.Use', 'Mapping.Modify', 'Mapping.Audit'],
+                );
+            }
 
             my $types = {};
-            my $devices = PVE::Mapping::PCI::find_on_current_node($mapping);
+            my $devices = PVE::Mapping::PCI::find_on_current_node($id);
             for my $device ($devices->@*) {
-                my $id = $device->{path};
-                next if $id =~ m/;/; # mdev not supported for multifunction devices
+                my $dev_id = $device->{path};
+                next if $dev_id =~ m/;/; # mdev not supported for multifunction devices
 
-                my $device_types = PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
+                my $device_types = PVE::QemuServer::PCI::Mdev::get_mdev_types($dev_id);
 
                 for my $type_definition ($device_types->@*) {
                     my $type = $type_definition->{type};
@@ -247,6 +270,5 @@ __PACKAGE__->register_method({
 
             return [sort { $a->{type} cmp $b->{type} } values($types->%*)];
         }
-
     },
 });
-- 
2.47.3





  reply	other threads:[~2026-09-04  9:45 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04  9:44 [PATCH manager v4 0/2] fix #6735: api: pci: allow mdevscan access via mapping permissions Elias Huhsovitz
2026-09-04  9:44 ` Elias Huhsovitz [this message]
2026-09-04  9:44 ` [PATCH manager v4 2/2] api: pci: utilize constant perm variable for pci_scan Elias Huhsovitz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260904094456.70309-2-e.huhsovitz@proxmox.com \
    --to=e.huhsovitz@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal