From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 743E79E0C9 for ; Tue, 6 Jun 2023 15:52:26 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 519F9362F3 for ; Tue, 6 Jun 2023 15:52:26 +0200 (CEST) Received: from proxmox-new.maurer-it.com (proxmox-new.maurer-it.com [94.136.29.106]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS for ; Tue, 6 Jun 2023 15:52:24 +0200 (CEST) Received: from proxmox-new.maurer-it.com (localhost.localdomain [127.0.0.1]) by proxmox-new.maurer-it.com (Proxmox) with ESMTP id 359C848C8B for ; Tue, 6 Jun 2023 15:52:24 +0200 (CEST) From: Dominik Csapak To: pve-devel@lists.proxmox.com Date: Tue, 6 Jun 2023 15:52:02 +0200 Message-Id: <20230606135222.984747-4-d.csapak@proxmox.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20230606135222.984747-1-d.csapak@proxmox.com> References: <20230606135222.984747-1-d.csapak@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.015 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record T_SCC_BODY_TEXT_LINE -0.01 - Subject: [pve-devel] [PATCH qemu-server v5 1/6] enable cluster mapped USB devices for guests X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Jun 2023 13:52:26 -0000 this patch allows configuring usb devices that are mapped via cluster resource mapping when the user has 'Resource.Use' on the ACL path '/resource/usb/{ID}' (in addition to the usual required vm config privileges) for now, this is only valid if there is exactly one mapping for the host, since we don't track passed through usb devices yet this adds a permission check for clone and restore since an admin can now give permissions for specific devices Signed-off-by: Dominik Csapak --- changes from v4: * rename s/resource/mapping/i * add permission check for clone/restore PVE/API2/Qemu.pm | 51 ++++++++++++++++++++++++++++++++++++++++--- PVE/QemuServer.pm | 40 ++++++++++++++++++++++++++++++++- PVE/QemuServer/USB.pm | 27 ++++++++++++++++++++--- 3 files changed, 111 insertions(+), 7 deletions(-) diff --git a/PVE/API2/Qemu.pm b/PVE/API2/Qemu.pm index 587bb222..13cc73d1 100644 --- a/PVE/API2/Qemu.pm +++ b/PVE/API2/Qemu.pm @@ -32,6 +32,7 @@ use PVE::QemuServer::Drive; use PVE::QemuServer::ImportDisk; use PVE::QemuServer::Monitor qw(mon_cmd); use PVE::QemuServer::Machine; +use PVE::QemuServer::USB qw(parse_usb_device); use PVE::QemuMigrate; use PVE::RPCEnvironment; use PVE::AccessControl; @@ -175,6 +176,16 @@ my $check_storage_access = sub { if defined($settings->{vmstatestorage}); }; +my sub check_mapping_access_clone { + my ($rpcenv, $user, $conf) = @_; + + for my $opt (keys $conf->%*) { + if ($opt =~ m/^usb\d+$/) { + PVE::QemuServer::check_vm_clone_restore_usb_perm($rpcenv, $user, $opt, $conf->{$opt}) + } + } +}; + my $check_storage_access_clone = sub { my ($rpcenv, $authuser, $storecfg, $conf, $storage) = @_; @@ -590,8 +601,13 @@ my $check_vm_create_usb_perm = sub { foreach my $opt (keys %{$param}) { next if $opt !~ m/^usb\d+$/; + my $entry = PVE::JSONSchema::parse_property_string('pve-qm-usb', $param->{$opt}); + my $device = parse_usb_device($entry->{host}); - if ($param->{$opt} =~ m/spice/) { + if ($device->{spice}) { + $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.HWType']); + } elsif ($device->{mapped}) { + $rpcenv->check_full($authuser, "/mapping/usb/$entry->{host}", ['Mapping.Use']); $rpcenv->check_vm_perm($authuser, $vmid, $pool, ['VM.Config.HWType']); } else { die "only root can set '$opt' config for real devices\n"; @@ -1696,7 +1712,12 @@ my $update_vm_api = sub { PVE::QemuConfig->add_to_pending_delete($conf, $opt, $force); PVE::QemuConfig->write_config($vmid, $conf); } elsif ($opt =~ m/^usb\d+$/) { - if ($val =~ m/spice/) { + my $device = PVE::JSONSchema::parse_property_string('pve-qm-usb', $val); + my $host = parse_usb_device($device->{host}); + if ($host->{spice}) { + $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); + } elsif ($host->{mapped}) { + $rpcenv->check_full($authuser, "/mapping/usb/$device->{host}", ['Mapping.Use']); $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); } elsif ($authuser ne 'root@pam') { die "only root can delete '$opt' config for real devices\n"; @@ -1761,7 +1782,30 @@ my $update_vm_api = sub { } $conf->{pending}->{$opt} = $param->{$opt}; } elsif ($opt =~ m/^usb\d+/) { - if ((!defined($conf->{$opt}) || $conf->{$opt} =~ m/spice/) && $param->{$opt} =~ m/spice/) { + my $olddevice; + my $oldhost; + if (defined($conf->{$opt})) { + $olddevice = PVE::JSONSchema::parse_property_string('pve-qm-usb', $conf->{$opt}); + $oldhost = parse_usb_device($olddevice->{host}); + } + if (defined($oldhost)) { + if ($oldhost->{spice}) { + $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); + } elsif ($oldhost->{mapped}) { + $rpcenv->check_full($authuser, "/mapping/usb/$olddevice->{host}", ['Mapping.Use']); + $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); + } elsif ($authuser ne 'root@pam') { + die "only root can modify '$opt' config for real devices\n"; + } + } + + my $newdevice = PVE::JSONSchema::parse_property_string('pve-qm-usb', $param->{$opt}); + my $newhost = parse_usb_device($newdevice->{host}); + + if ($newhost->{spice}) { + $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); + } elsif ($newhost->{mapped}) { + $rpcenv->check_full($authuser, "/mapping/usb/$newdevice->{host}", ['Mapping.Use']); $rpcenv->check_vm_perm($authuser, $vmid, undef, ['VM.Config.HWType']); } elsif ($authuser ne 'root@pam') { die "only root can modify '$opt' config for real devices\n"; @@ -3488,6 +3532,7 @@ __PACKAGE__->register_method({ my $oldconf = $snapname ? $conf->{snapshots}->{$snapname} : $conf; my $sharedvm = &$check_storage_access_clone($rpcenv, $authuser, $storecfg, $oldconf, $storage); + check_mapping_access_clone($rpcenv, $authuser, $oldconf); die "can't clone VM to node '$target' (VM uses local storage)\n" if $target && !$sharedvm; diff --git a/PVE/QemuServer.pm b/PVE/QemuServer.pm index ab33aa37..f209a604 100644 --- a/PVE/QemuServer.pm +++ b/PVE/QemuServer.pm @@ -1090,6 +1090,8 @@ The Host USB device or port or the value 'spice'. HOSTUSBDEVICE syntax is: You can use the 'lsusb -t' command to list existing usb devices. +Alternatively, you can used an ID of a mapped usb device. + NOTE: This option allows direct access to host hardware. So it is no longer possible to migrate such machines - use with special care. @@ -1106,6 +1108,8 @@ EODESCR }, }; +PVE::JSONSchema::register_format('pve-qm-usb', $usb_fmt); + my $usbdesc = { optional => 1, type => 'string', format => $usb_fmt, @@ -2243,7 +2247,12 @@ PVE::JSONSchema::register_format('pve-qm-usb-device', \&verify_usb_device); sub verify_usb_device { my ($value, $noerr) = @_; - return $value if parse_usb_device($value); + my $parsed = eval { parse_usb_device($value) }; + if (my $err = $@) { + die $@ if !$noerr; + return; + } + return $value if defined($parsed); return if $noerr; @@ -6616,6 +6625,29 @@ my $restore_cleanup_oldconf = sub { } }; +sub check_vm_clone_restore_usb_perm { + my ($rpcenv, $user, $opt, $value) = @_; + my $entry = PVE::JSONSchema::parse_property_string('pve-qm-usb', $value); + my $device = parse_usb_device($entry->{host}); + if ($device->{mapped}) { + $rpcenv->check_full($user, "/mapping/usb/$entry->{host}", ['Mapping.Use']); + } elsif (!$device->{spice}) { + die "only root can set '$opt' config for real devices\n"; + } +} + +my sub check_restore_config_perms { + my ($rpcenv, $user, $fh) = @_; + + while (defined(my $line = <$fh>)) { + if ($line =~ m/^(usb\d+):\s*(.*)\s*$/) { + my $opt = $1; + my $value = $2; + check_vm_clone_restore_usb_perm($rpcenv, $user, $opt, $value); + } + } +} + # Helper to parse vzdump backup device hints # # $rpcenv: Environment, used to ckeck storage permissions @@ -7067,6 +7099,9 @@ sub restore_proxmox_backup_archive { my $fh = IO::File->new($cfgfn, "r") || die "unable to read qemu-server.conf - $!\n"; + check_restore_config_perms($rpcenv, $user, $fh); + $fh->seek(0, 0) || die "seek failed - $!\n"; + $virtdev_hash = $parse_backup_hints->($rpcenv, $user, $storecfg, $fh, $devinfo, $options); # fixme: rate limit? @@ -7345,6 +7380,9 @@ sub restore_vma_archive { PVE::Tools::file_copy($fwcfgfn, "${pve_firewall_dir}/$vmid.fw"); } + check_restore_config_perms($rpcenv, $user, $fh); + $fh->seek(0, 0) || die "seek failed - $!\n"; + $virtdev_hash = $parse_backup_hints->($rpcenv, $user, $cfg, $fh, $devinfo, $opts); foreach my $info (values %{$virtdev_hash}) { diff --git a/PVE/QemuServer/USB.pm b/PVE/QemuServer/USB.pm index 686461cc..d6b4c531 100644 --- a/PVE/QemuServer/USB.pm +++ b/PVE/QemuServer/USB.pm @@ -6,6 +6,7 @@ use PVE::QemuServer::PCI qw(print_pci_addr); use PVE::QemuServer::Machine; use PVE::QemuServer::Helpers qw(min_version windows_version); use PVE::JSONSchema; +use PVE::Mapping::USB; use base 'Exporter'; our @EXPORT_OK = qw( @@ -17,7 +18,7 @@ get_usb_devices my $OLD_MAX_USB = 5; sub parse_usb_device { - my ($value) = @_; + my ($value, $checkMap) = @_; return if !$value; @@ -31,7 +32,27 @@ sub parse_usb_device { } elsif ($value =~ m/^spice$/i) { $res->{spice} = 1; } else { - return; + # we have no ordinary usb device, must be a mapping + my $devices = PVE::Mapping::USB::find_on_current_node($value); + if ($checkMap) { + die "USB device mapping not found for '$value'\n" if !$devices || !scalar($devices->@*); + die "More than one USB mapping per host not supported\n" if scalar($devices->@*) > 1; + eval { + PVE::Mapping::USB::assert_valid($value, $devices->[0]); + }; + if (my $err = $@) { + die "USB Mapping invalid (hardware probably changed): $err\n"; + } + my $device = $devices->[0]; + + if ($device->{path}) { + $res = parse_usb_device($device->{path}); + } else { + $res = parse_usb_device($device->{id}); + } + } + + $res->{mapped} = 1; } return $res; @@ -111,7 +132,7 @@ sub get_usb_devices { my $port = $use_qemu_xhci ? $i + 1 : undef; if (defined($d->{host})) { - my $hostdevice = parse_usb_device($d->{host}); + my $hostdevice = parse_usb_device($d->{host}, 1); $hostdevice->{usb3} = $d->{usb3}; if ($hostdevice->{spice}) { # usb redir support for spice -- 2.30.2