Skip to content

Conversation

github-actions[bot]
Copy link

This PR contains a snapshot of wallaby from upstream.

kk7ds and others added 2 commits December 19, 2022 15:37
This does two things:

1. It makes us check that the QCOW backing_file is unset on those
types of images. Nova and Cinder do this already to prevent an
arbitrary (and trivial to accomplish) host file exposure exploit.
2. It makes us restrict VMDK files to only allowed subtypes. These
files can name arbitrary files on disk as extents, providing the
same sort of attack. Default that list to just the types we believe
are actually useful for openstack, and which are monolithic.

The configuration option to specify allowed subtypes is added in
glance's config and not in the import options so that we can extend
this check later to image ingest. The format_inspector can tell us
what the type and subtype is, and we could reject those images early
and even in the case where image_conversion is not enabled.

Closes-Bug: #1996188
Change-Id: Idf561f6306cebf756c787d8eefdc452ce44bd5e0
(cherry picked from commit 0d6282a)
(cherry picked from commit 4967ab6)
(cherry picked from commit dc8e5a5)
(cherry picked from commit f45b5f0)
@github-actions github-actions bot requested a review from a team as a code owner March 13, 2023 08:22
@github-actions github-actions bot added automated Automated action performed by GitHub Actions synchronisation labels Mar 13, 2023
@markgoddard markgoddard merged commit b9de08d into stackhpc/wallaby Mar 13, 2023
@markgoddard markgoddard deleted the upstream/wallaby-2023-03-13 branch March 13, 2023 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automated Automated action performed by GitHub Actions synchronisation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants