Monday, 2025-12-01

opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876101:56
*** mhen_ is now known as mhen02:22
opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876105:45
opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876110:45
opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876111:00
opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876111:07
opendevreviewmengxiangzhi proposed openstack/cinder master: Support ZTE driver plugin code  https://review.opendev.org/c/openstack/cinder/+/96876111:12
opendevreviewAbhishek Gupta proposed openstack/cinder master: Add support for Dell PowerFlex Driver UT coverage  https://review.opendev.org/c/openstack/cinder/+/96135515:24
opendevreviewAbhishek Gupta proposed openstack/cinder master: Dell PowerFlex : Add support for Dell PowerFlex 5.1  https://review.opendev.org/c/openstack/cinder/+/95054616:04
mhenHi. I have found that I can circumvent any Glance Property Protections [1] by creating a volume from an image and then using `openstack volume set --image-property key=value` on it even if the same property key would have been denied by Glance.17:12
mhen[1] https://docs.openstack.org/glance/latest/admin/property-protections.html17:12
mhenThe original blueprint for the Cinder feature to modify those properties did include a section about mimicking the property protection within Cinder [2] but it seems that part was never implemented?17:13
mhen[2] https://specs.openstack.org/openstack/cinder-specs/specs/liberty/support-modify-volume-image-metadata.html#documentation-impact17:13
mhenI cannot find any references in the code or documentation of Cinder that would suggest that any such protection is available, or am I looking in the wrong places?17:15
mhenIs disabling `volume_extension:volume_image_metadata:set` via API policy RBAC the only way to avoid this exploitation by end users?17:17
opendevreviewAbhishek Gupta proposed openstack/cinder master: Add support for Dell PowerFlex Driver UT coverage  https://review.opendev.org/c/openstack/cinder/+/96135517:44
opendevreviewKonrad Gube proposed openstack/cinder-specs master: Propose support for assisted extending of attached volumes  https://review.opendev.org/c/openstack/cinder-specs/+/94950919:00
opendevreviewKonrad Gube proposed openstack/cinder-specs master: Propose support for assisted online volume extend  https://review.opendev.org/c/openstack/cinder-specs/+/94950919:12
opendevreviewKonrad Gube proposed openstack/cinder-specs master: Propose support for assisted online volume extend  https://review.opendev.org/c/openstack/cinder-specs/+/94950919:15
jbernardmhen: i think you may be correct20:00
jbernardmhen: i cannot find any references either20:00
rosmaitamhen: isn't it the case that you can add image metadata to a volume, but when you go to upload the volume as an image, the image creation will fail because of property protection violations?20:04
rosmaitaso i don't think you can do an exploit, i think what you have is a bad user experience20:04
opendevreviewIvan Anfimov proposed openstack/cinder master: Remove installation guide for openSUSE/SLES  https://review.opendev.org/c/openstack/cinder/+/94876620:23
opendevreviewAbhishek Gupta proposed openstack/cinder master: Add support for Dell PowerFlex Driver UT coverage  https://review.opendev.org/c/openstack/cinder/+/96135520:31
opendevreviewMerged openstack/cinder master: api: Simplify enable/disable APIs (clusters)  https://review.opendev.org/c/openstack/cinder/+/96583621:52
opendevreviewMerged openstack/cinder master: tests: Add API sample tests for os-services API  https://review.opendev.org/c/openstack/cinder/+/96583721:52
jbernardagalica_: heya, i couldn't quickly find your lp username, take a look at https://bugs.launchpad.net/cinder/+bug/2133572 if you get a chance21:55
opendevreviewMerged openstack/cinder master: NetApp: Fix terminate_connection on unmapped vol  https://review.opendev.org/c/openstack/cinder/+/73116722:37
*** agalica_ is now known as agalica22:43
agalicajberhard: will do22:48
opendevreviewAnthony Galica proposed openstack/cinder master: Hitachi: Add Adaptive QoS setting based on volume size.  https://review.opendev.org/c/openstack/cinder/+/96714123:40

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!