The mdevscan endpoint requires Sys.Audit or Sys.Modify on '/'. This
blocks non-admin users from listing mediated device types for a PCI
mapping, even when they hold Mapping.Use on that mapping.

Check the permission in the API handler based on the parameter type: For
a raw PCI ID, require Sys.Audit or Sys.Modify on '/'. For a mapping,
require Sys.Audit or Sys.Modify on '/', or fall back to requiring
Mapping.Use, Mapping.Modify or Mapping.Audit on the specific mapping
path.

Set the endpoint permission to 'user => all' so the handler performs the
type-dependent check. This keeps raw PCI IDs, which are not valid ACL
paths, out of the declarative ACL evaluation.

Signed-off-by: Elias Huhsovitz <[email protected]>
Reviewed-by: Dominik Csapak <[email protected]>
Tested-by: Dominik Csapak <[email protected]>
---
 PVE/API2/Hardware/PCI.pm | 44 ++++++++++++++++++++++++++++++----------
 1 file changed, 33 insertions(+), 11 deletions(-)

diff --git a/PVE/API2/Hardware/PCI.pm b/PVE/API2/Hardware/PCI.pm
index 36b9741b..eb83824f 100644
--- a/PVE/API2/Hardware/PCI.pm
+++ b/PVE/API2/Hardware/PCI.pm
@@ -3,13 +3,17 @@ package PVE::API2::Hardware::PCI;
 use strict;
 use warnings;
 
+use PVE::Exception qw(raise raise_perm_exc);
 use PVE::JSONSchema qw(get_standard_option);
 
 use PVE::QemuServer::PCI::Mdev;
 use PVE::RESTHandler;
+use PVE::RPCEnvironment;
 
 use base qw(PVE::RESTHandler);
 
+use constant GLOBAL_PERMS => ['Sys.Audit', 'Sys.Modify'];
+
 my $default_class_blacklist = "05;06;0b";
 
 __PACKAGE__->register_method({
@@ -180,7 +184,11 @@ __PACKAGE__->register_method({
     protected => 1,
     proxyto => "node",
     permissions => {
-        check => ['perm', '/', ['Sys.Audit', 'Sys.Modify'], any => 1],
+        description =>
+            "For a PCI ID, requires 'Sys.Audit' or 'Sys.Modify' on '/'. For a 
mapping,"
+            . " requires the same global permissions, or 'Mapping.Use', 
'Mapping.Modify'"
+            . ", or 'Mapping.Audit' on '/mapping/pci/<id>'.",
+        user => 'all',
     },
     parameters => {
         additionalProperties => 0,
@@ -222,20 +230,35 @@ __PACKAGE__->register_method({
     code => sub {
         my ($param) = @_;
 
-        if ($param->{'pci-id-or-mapping'} =~
-            m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/
-        ) {
-            return 
PVE::QemuServer::PCI::Mdev::get_mdev_types($param->{'pci-id-or-mapping'}); # 
PCI ID
+        my $id = $param->{'pci-id-or-mapping'};
+        my $is_pci_id =
+            $id =~ 
m/^(?:[0-9a-fA-F]{4}:)?[0-9a-fA-F]{2}:[0-9a-fA-F]{2}\.[0-9a-fA-F]$/;
+
+        my $rpcenv = PVE::RPCEnvironment::get();
+        my $authuser = $rpcenv->get_user();
+
+        my $has_global_perms = $rpcenv->check_any($authuser, '/', 
GLOBAL_PERMS, 1);
+
+        if ($is_pci_id) {
+            raise_perm_exc("/, " . join("|", GLOBAL_PERMS->@*)) if 
!$has_global_perms;
+
+            return PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
         } else {
-            my $mapping = $param->{'pci-id-or-mapping'};
+            if (!$has_global_perms) {
+                $rpcenv->check_any(
+                    $authuser,
+                    "/mapping/pci/$id",
+                    ['Mapping.Use', 'Mapping.Modify', 'Mapping.Audit'],
+                );
+            }
 
             my $types = {};
-            my $devices = PVE::Mapping::PCI::find_on_current_node($mapping);
+            my $devices = PVE::Mapping::PCI::find_on_current_node($id);
             for my $device ($devices->@*) {
-                my $id = $device->{path};
-                next if $id =~ m/;/; # mdev not supported for multifunction 
devices
+                my $dev_id = $device->{path};
+                next if $dev_id =~ m/;/; # mdev not supported for 
multifunction devices
 
-                my $device_types = 
PVE::QemuServer::PCI::Mdev::get_mdev_types($id);
+                my $device_types = 
PVE::QemuServer::PCI::Mdev::get_mdev_types($dev_id);
 
                 for my $type_definition ($device_types->@*) {
                     my $type = $type_definition->{type};
@@ -247,6 +270,5 @@ __PACKAGE__->register_method({
 
             return [sort { $a->{type} cmp $b->{type} } values($types->%*)];
         }
-
     },
 });
-- 
2.47.3




Reply via email to