From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id DC6041FF09B for ; Mon, 31 Aug 2026 09:24:07 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 91F1A21408; Mon, 31 Aug 2026 09:24:07 +0200 (CEST) Message-ID: <2cebd5ea-788b-4a01-9eeb-3d3c3205438d@proxmox.com> Date: Mon, 31 Aug 2026 09:24:00 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Beta Subject: Re: [PATCH proxmox-backup] fix #7911: api: report: mark endpoint as protected To: Christian Ebner , pbs-devel@lists.proxmox.com References: <20260811093611.228420-1-e.fastermann@proxmox.com> Content-Language: en-US From: Erik Fastermann In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788161028139 X-SPAM-LEVEL: Spam detection results: 0 AWL 1.782 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: OHNOOYPFUHBB5TXBFNPQDOTBHR54YFHP X-Message-ID-Hash: OHNOOYPFUHBB5TXBFNPQDOTBHR54YFHP X-MailFrom: e.fastermann@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On 8/28/26 9:41 AM, Christian Ebner wrote: > On 8/11/26 11:36 AM, Erik Fastermann wrote: >> The report was generated by proxmox-backup-proxy, which runs as the >> unprivileged 'backup' user, so commands needing root only partly >> worked. ethtool printed "netlink error: Operation not permitted" to >> stderr, which ended up in the report. dmidecode and proxmox-boot-tool >> failed completely. >> >> Forward the request to the privileged API daemon instead, like PVE, >> PMG and PDM already do. Users with Sys.Audit thus see slightly more >> host details, which the other products already accept. > > Fixes: https://bugzilla.proxmox.com/show_bug.cgi?id=7911 > >> Signed-off-by: Erik Fastermann > > Reviewed-by: Christian Ebner > Tested-by: Christian Ebner > Thanks for the review and test! > One question which came to mind during review is if we should maybe also > add stricter type checks on the allowed parameters returned by > dynamic_commands()? > > We do allow arbitrary strings to be returned there. While the current > use-case is protected by proxmox-network-api config parsing, I think it > would make sense to restrict this to avoid potential future miss-use and > potential code execution by injection (after all one runs as privileged > user now). > > Maybe we could add an enum with allowed command -> args pairs? The args > assured to be type checked? I'd rather not. Could only cover the narrowest of the three collection paths and e.g. function_calls() already runs arbitrary Rust, including spawning 'top'. Constraining the dynamic arguments while that stays buys little. I'm also not sure how the type checked pairs would look without becoming unwieldy and we will probably rarely touch the code in practice. Note also that after the shared crate series [0], dynamic_commands() lives in proxmox-system-report as common_dynamic_commands() and DynamicArgsCommandSpec is private there. generate_report() only accepts StaticArgsCommandSpec from the products, so the dynamic surface is a single crate-internal function. [0] https://lore.proxmox.com/pbs-devel/20260811114332.283776-1-e.fastermann@proxmox.com/ >> --- a/src/api2/node/report.rs >> +++ b/src/api2/node/report.rs >> @@ -9,6 +9,7 @@ use pbs_api_types::{NODE_SCHEMA, PRIV_SYS_AUDIT}; >>   use crate::server::generate_report; >>   #[api( >> +    protected: true, >>       input: { >>           properties: { >>               node: { >