quantum-debug ping-all does work with rootwrap enabled

Bug #1071110 reported by Mark McClain
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Fix Released
Undecided
Nachi Ueno

Bug Description

The quantum-debug ping-all does not have enough privileges when rootwrap is enabled.

There are two solutions:

EASY: Add /bin/ping and /bin/ping6 to the list of approved commands.
SECURE: Require that quantum-debug be invoked as the super user.

Requiring quantum-debug be invoked as the super user avoids having to expand filters to programs that would not be run during normal operations.

Revision history for this message
Nachi Ueno (nati-ueno) wrote :

Hi Mark

I'm going to remove probe-exec command, and I would like to add ping or nc to approved command.
probe-exec command will show only exec command.

Is this make sense?

Changed in quantum:
assignee: nobody → Nachi Ueno (nati-ueno)
Revision history for this message
Jeremy Hanmer (fzylogic) wrote :

For security reasons, I'd be wary of promoting sudo access to nc. Ping access would be much less prone to abuse by naive users.

dan wendlandt (danwent)
Changed in quantum:
status: New → Confirmed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to quantum (master)

Fix proposed to branch: master
Review: https://review.openstack.org/16594

Changed in quantum:
status: Confirmed → In Progress
Revision history for this message
Nachi Ueno (nati-ueno) wrote :

Now this bug looks blocker of the quantum-gating

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to quantum (master)

Reviewed: https://review.openstack.org/16594
Committed: http://github.com/openstack/quantum/commit/a37b9276de85742276c0d8f6fa5264daa549702c
Submitter: Jenkins
Branch: master

commit a37b9276de85742276c0d8f6fa5264daa549702c
Author: Nachi Ueno <email address hidden>
Date: Tue Nov 20 14:54:53 2012 -0800

    Add filters for quantum-debug

    only allows ping command here.
    Fixes bug 1071110

    Change-Id: I38f24e40de048845f01dbc07c79bb02acf92da31

Changed in quantum:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in quantum:
milestone: none → grizzly-2
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in quantum:
milestone: grizzly-2 → 2013.1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.