Project

General

Profile

Bug #3226

osd: invalid capability string can allow arbitrary access

Added by Josh Durgin over 11 years ago. Updated over 11 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
OSD
Target version:
% Done:

0%

Source:
Development
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

If you use the cap osd 'allow rwx pool=bar', the parser will add the grant for 'allow rwx', but fail to parse the 'foo=bar' part without clearing the grants.

History

#1 Updated by Josh Durgin over 11 years ago

The first commit in wip-osd-caps fixes this.

#2 Updated by Josh Durgin over 11 years ago

  • Target version set to v0.54a

#3 Updated by Josh Durgin over 11 years ago

  • Status changed from Fix Under Review to Resolved

#4 Updated by Josh Durgin over 11 years ago

  • Backport deleted (argonaut)

Argonaut does not have this bug. It was introduced in a post-argonaut refactoring of OSDCaps.

Also available in: Atom PDF