public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Elias Huhsovitz <e.huhsovitz@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Subject: [PATCH manager v4 0/2] fix #6735: api: pci: allow mdevscan access via mapping permissions
Date: Fri,  4 Sep 2026 11:44:52 +0200	[thread overview]
Message-ID: <20260904094456.70309-1-e.huhsovitz@proxmox.com> (raw)

This series allows users who have been granted Mapping.Use
(or Mapping.Modify / Mapping.Audit) on a specific PCI mapping to list
the mediated device (mdev) types for that mapping without requiring
global Sys.Audit or Sys.Modify privileges on the entire cluster.

In multi‑team environments where access is compartmentalized via
resource pools and PCI mappings, the previous requirement forced
administrators to grant overly broad permissions for GPU usage.
By checking mapping‑specific permissions when a mapping name is
supplied, the patch enables non‑administrative users to select and use
vGPU types for their assigned hardware.

Patch 1/2 makes the necessary logical change for fixing #6735.
Patch 2/2 utilizes a new constant parameter for the `pci_scan` endpoint

Changes v3->v4
--------------
* factor out global permissions into constant
* de-rerence global permissions array when passing it to
  `raise_perm_exc`
* add optional second patch to utilize global permissions constant for
  `pci_scan` endpoint

Changes v2->v3
--------------
* re-introduce else-statement in API handler
* move permissions checks into respective logical branches
  (previously sepate sesection before core code)
* update commit message

Changes v1->v2
--------------
* Allow all users in the declarative API permissions.
* Implement ACL check in API handler by calling
  check_any and raise_perm_exc.
* Remove else statement in API handler, since return statement
  provides implicit branching
* update commit message

Previous Versions
-----------------
v3: https://lore.proxmox.com/pve-devel/20260903121143.145841-1-e.huhsovitz@proxmox.com/
v2: https://lore.proxmox.com/pve-devel/20260827112525.154445-1-e.huhsovitz@proxmox.com/
v1: https://lore.proxmox.com/pve-devel/20260824112610.148089-1-e.huhsovitz@proxmox.com/

Summary of Changes
------------------
Elias Huhsovitz (2):
  fix #6735: api: pci: allow mdevscan access via mapping permissions
  api: pci: utilize constant perm variable for pci_scan

 PVE/API2/Hardware/PCI.pm | 47 ++++++++++++++++++++++++++++++----------
 1 file changed, 35 insertions(+), 12 deletions(-)

-- 
2.47.3





             reply	other threads:[~2026-09-04  9:45 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04  9:44 Elias Huhsovitz [this message]
2026-09-04  9:44 ` [PATCH manager v4 1/2] fix #6735: api: pci: allow mdevscan access via mapping permissions Elias Huhsovitz
2026-09-04  9:44 ` [PATCH manager v4 2/2] api: pci: utilize constant perm variable for pci_scan Elias Huhsovitz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260904094456.70309-1-e.huhsovitz@proxmox.com \
    --to=e.huhsovitz@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal