commit 07fdbf58511ef88d318957bb307912c7ccdca8da Author: Felix Huettner Date: Tue Jan 24 10:19:26 2023 +0100 Check VMDK create-type against an allowed list Trivial conflicts on xena only in: nova/conf/compute.py Conflicts in victoria: nova/conf/compute.py nova/tests/unit/virt/test_images.py Conflicts in ussuri: nova/conf/compute.py Conflicts in rocky: nova/conf/compute.py Conflicts in queens: nova/virt/images.py Change-Id: I51309acf04aa061fdd40afd5527feff9af376871 diff --git a/nova/conf/compute.py b/nova/conf/compute.py index 2518cd641a..4dbc0d1068 100644 --- a/nova/conf/compute.py +++ b/nova/conf/compute.py @@ -716,6 +716,15 @@ Related options: True, this controls the amount of time to wait before timing out and either failing if ``vif_plugging_is_fatal`` is True, or simply continuing with the live migration +"""), + cfg.ListOpt('vmdk_allowed_types', + default=['streamOptimized', 'monolithicSparse'], + help=""" +A list of strings describing allowed VMDK "create-type" subformats +that will be allowed. This is recommended to only include +single-file-with-sparse-header variants to avoid potential host file +exposure due to processing named extents. If this list is empty, then no +form of VMDK image will be allowed. """), ] diff --git a/nova/tests/unit/virt/test_images.py b/nova/tests/unit/virt/test_images.py index c7ed95d859..5836063f58 100644 --- a/nova/tests/unit/virt/test_images.py +++ b/nova/tests/unit/virt/test_images.py @@ -17,6 +17,8 @@ import os import mock from oslo_concurrency import processutils import six +from oslo_serialization import jsonutils +from oslo_utils import imageutils from nova import exception from nova import test @@ -120,3 +122,47 @@ class QemuTestCase(test.NoDBTestCase): expected = ('qemu-img', 'convert', '-t', 'writethrough', '-O', 'out_format', '-f', 'in_format', 'source', 'dest') self.assertTupleEqual(expected, mock_execute.call_args[0]) + + def test_convert_image_vmdk_allowed_list_checking(self): + info = {'format': 'vmdk', + 'format-specific': { + 'type': 'vmdk', + 'data': { + 'create-type': 'monolithicFlat', + }}} + + # If the format is not in the allowed list, we should get an error + self.assertRaises(exception.ImageUnacceptable, + images.check_vmdk_image, 'foo', + imageutils.QemuImgInfo(jsonutils.dumps(info), + format='json')) + + # With the format in the allowed list, no error + self.flags(vmdk_allowed_types=['streamOptimized', 'monolithicFlat', + 'monolithicSparse'], + group='compute') + images.check_vmdk_image('foo', + imageutils.QemuImgInfo(jsonutils.dumps(info), + format='json')) + + # With an empty list, allow nothing + self.flags(vmdk_allowed_types=[], group='compute') + self.assertRaises(exception.ImageUnacceptable, + images.check_vmdk_image, 'foo', + imageutils.QemuImgInfo(jsonutils.dumps(info), + format='json')) + + @mock.patch.object(images, 'fetch') + @mock.patch('nova.privsep.qemu.unprivileged_qemu_img_info') + def test_fetch_checks_vmdk_rules(self, mock_info, mock_fetch): + info = {'format': 'vmdk', + 'format-specific': { + 'type': 'vmdk', + 'data': { + 'create-type': 'monolithicFlat', + }}} + mock_info.return_value = jsonutils.dumps(info) + with mock.patch('os.path.exists', return_value=True): + e = self.assertRaises(exception.ImageUnacceptable, + images.fetch_to_raw, None, 'foo', 'anypath') + self.assertIn('Invalid VMDK create-type specified', str(e)) diff --git a/nova/virt/images.py b/nova/virt/images.py index dfd415052d..cead08b796 100644 --- a/nova/virt/images.py +++ b/nova/virt/images.py @@ -155,6 +155,34 @@ def get_info(context, image_href): return IMAGE_API.get(context, image_href) +def check_vmdk_image(image_id, data): + # Check some rules about VMDK files. Specifically we want to make + # sure that the "create-type" of the image is one that we allow. + # Some types of VMDK files can reference files outside the disk + # image and we do not want to allow those for obvious reasons. + + types = CONF.compute.vmdk_allowed_types + + if not len(types): + LOG.warning('Refusing to allow VMDK image as vmdk_allowed_' + 'types is empty') + msg = _('Invalid VMDK create-type specified') + raise exception.ImageUnacceptable(image_id=image_id, reason=msg) + + try: + create_type = data.format_specific['data']['create-type'] + except KeyError: + msg = _('Unable to determine VMDK create-type') + raise exception.ImageUnacceptable(image_id=image_id, reason=msg) + + if create_type not in CONF.compute.vmdk_allowed_types: + LOG.warning('Refusing to process VMDK file with create-type of %r ' + 'which is not in allowed set of: %s', create_type, + ','.join(CONF.compute.vmdk_allowed_types)) + msg = _('Invalid VMDK create-type specified') + raise exception.ImageUnacceptable(image_id=image_id, reason=msg) + + def fetch_to_raw(context, image_href, path): path_tmp = "%s.part" % path fetch(context, image_href, path_tmp) @@ -174,6 +202,9 @@ def fetch_to_raw(context, image_href, path): reason=(_("fmt=%(fmt)s backed by: %(backing_file)s") % {'fmt': fmt, 'backing_file': backing_file})) + if fmt == 'vmdk': + check_vmdk_image(image_href, data) + if fmt != "raw" and CONF.force_raw_images: staged = "%s.converted" % path LOG.debug("%s was %s, converting to raw", image_href, fmt)