From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 4E0D11FF0E4 for ; Tue, 11 Aug 2026 11:36:18 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 13C5621375; Tue, 11 Aug 2026 11:36:18 +0200 (CEST) From: Erik Fastermann To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox-backup] fix #7911: api: report: mark endpoint as protected Date: Tue, 11 Aug 2026 11:36:11 +0200 Message-ID: <20260811093611.228420-1-e.fastermann@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 1 AWL -0.538 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Message-ID-Hash: SNF65FVLFIZBAVT5IE5JXRNJSCR2AE6V X-Message-ID-Hash: SNF65FVLFIZBAVT5IE5JXRNJSCR2AE6V X-MailFrom: efastermann@ruth.proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Erik Fastermann X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The report was generated by proxmox-backup-proxy, which runs as the unprivileged 'backup' user, so commands needing root only partly worked. ethtool printed "netlink error: Operation not permitted" to stderr, which ended up in the report. dmidecode and proxmox-boot-tool failed completely. Forward the request to the privileged API daemon instead, like PVE, PMG and PDM already do. Users with Sys.Audit thus see slightly more host details, which the other products already accept. Signed-off-by: Erik Fastermann --- src/api2/node/report.rs | 1 + 1 file changed, 1 insertion(+) diff --git a/src/api2/node/report.rs b/src/api2/node/report.rs index f71f5b25f..5d728a137 100644 --- a/src/api2/node/report.rs +++ b/src/api2/node/report.rs @@ -9,6 +9,7 @@ use pbs_api_types::{NODE_SCHEMA, PRIV_SYS_AUDIT}; use crate::server::generate_report; #[api( + protected: true, input: { properties: { node: { -- 2.47.3