From: Elias Huhsovitz <e.huhsovitz@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Subject: [PATCH manager v4 1/2] fix #6735: api: pci: allow mdevscan access via mapping permissions
Date: Fri, 4 Sep 2026 11:44:53 +0200 [thread overview]
Message-ID: <20260904094456.70309-2-e.huhsovitz@proxmox.com> (raw)
In-Reply-To: <20260904094456.70309-1-e.huhsovitz@proxmox.com>
The mdevscan endpoint requires Sys.Audit or Sys.Modify on '/'. This
blocks non-admin users from listing mediated device types for a PCI
mapping, even when they hold Mapping.Use on that mapping.
Check the permission in the API handler based on the parameter type: For
a raw PCI ID, require Sys.Audit or Sys.Modify on '/'. For a mapping,
require Sys.Audit or Sys.Modify on '/', or fall back to requiring
Mapping.Use, Mapping.Modify or Mapping.Audit on the specific mapping
path.
Set the endpoint permission to 'user => all' so the handler performs the
type-dependent check. This keeps raw PCI IDs, which are not valid ACL
paths, out of the declarative ACL evaluation.
Signed-off-by: Elias Huhsovitz <e.huhsovitz@proxmox.com>
Reviewed-by: Dominik Csapak <d.csapak@proxmox.com>
Tested-by: Dominik Csapak <d.csapak@proxmox.com>
---
PVE/API2/Hardware/PCI.pm | 44 ++++++++++++++++++++++++++++++----------
1 file changed, 33 insertions(+), 11 deletions(-)
diff --git a/PVE/API2/Hardware/PCI.pm b/PVE/API2/Hardware/PCI.pm
index 36b9741b..eb83824f 100644
--- a/PVE/API2/Hardware/PCI.pm
+++ b/PVE/API2/Hardware/PCI.pm
@@ -3,13 +3,17 @@ package PVE::API2::Hardware::PCI;
use strict;
use warnings;
+use PVE::Exception qw(raise raise_perm_exc);
use PVE::JSONSchema qw(get_standard_option);
use PVE::QemuServer::PCI::Mdev;
use PVE::RESTHandler;
+use PVE::RPCEnvironment;
use base qw(PVE::RESTHandler);
+use constant GLOBAL_PERMS => ['Sys.Audit', 'Sys.Modify'];
+
my $default_class_blacklist = "05;06;0b";
__PACKAGE__->register_method({
@@ -180,7 +184,11 @@ __PACKAGE__->register_method({
protected => 1,
proxyto => "node",
permissions => {
- check => ['perm', '/', ['Sys.Audit', 'Sys.Modify'], any => 1],
+ description =>
+ "For a PCI ID, requires 'Sys.Audit' or 'Sys.Modify' on '/'. For a mapping,"
+ . " requires the same global permissions, or 'Mapping.Use', 'Mapping.Modify'"
+ . ", or 'Mapping.Audit' on '/mapping/pci/<id>'.",
+ user => 'all',
},
parameters => {
additionalProperties => 0,
@@ -222,20 +230,35 @@ __PACKAGE__->register_method({
code => sub {
my ($param) = @_;
- if ($param->{'pci-id-or-mapping'} =~
- m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/
- ) {
- return PVE::QemuServer::PCI::Mdev::get_mdev_types($param->{'pci-id-or-mapping'}); # PCI ID
+ my $id = $param->{'pci-id-or-mapping'};
+ my $is_pci_id =
+ $id =~ m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/;
+
+ my $rpcenv = PVE::RPCEnvironment::get();
+ my $authuser = $rpcenv->get_user();
+
+ my $has_global_perms = $rpcenv->check_any($authuser, '/', GLOBAL_PERMS, 1);
+
+ if ($is_pci_id) {
+ raise_perm_exc("/, " . join("|", GLOBAL_PERMS->@*)) if !$has_global_perms;
+
+ return PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
} else {
- my $mapping = $param->{'pci-id-or-mapping'};
+ if (!$has_global_perms) {
+ $rpcenv->check_any(
+ $authuser,
+ "/mapping/pci/$id",
+ ['Mapping.Use', 'Mapping.Modify', 'Mapping.Audit'],
+ );
+ }
my $types = {};
- my $devices = PVE::Mapping::PCI::find_on_current_node($mapping);
+ my $devices = PVE::Mapping::PCI::find_on_current_node($id);
for my $device ($devices->@*) {
- my $id = $device->{path};
- next if $id =~ m/;/; # mdev not supported for multifunction devices
+ my $dev_id = $device->{path};
+ next if $dev_id =~ m/;/; # mdev not supported for multifunction devices
- my $device_types = PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
+ my $device_types = PVE::QemuServer::PCI::Mdev::get_mdev_types($dev_id);
for my $type_definition ($device_types->@*) {
my $type = $type_definition->{type};
@@ -247,6 +270,5 @@ __PACKAGE__->register_method({
return [sort { $a->{type} cmp $b->{type} } values($types->%*)];
}
-
},
});
--
2.47.3
next prev parent reply other threads:[~2026-09-04 9:45 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 9:44 [PATCH manager v4 0/2] fix #6735: api: pci: allow mdevscan access via mapping permissions Elias Huhsovitz
2026-09-04 9:44 ` Elias Huhsovitz [this message]
2026-09-04 9:44 ` [PATCH manager v4 2/2] api: pci: utilize constant perm variable for pci_scan Elias Huhsovitz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904094456.70309-2-e.huhsovitz@proxmox.com \
--to=e.huhsovitz@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox