OpenStack Compute (Nova)
 
 
 
Go to file
Sean Mooney 9588cdbfd4 address open redirect with 3 forward slashes
Ie36401c782f023d1d5f2623732619105dc2cfa24 was intended
to address OSSA-2021-002 (CVE-2021-3654) however after its
release it was discovered that the fix only worked
for urls with 2 leading slashes or more then 4.

This change adresses the missing edgecase for 3 leading slashes
and also maintian support for rejecting 2+.

Conflicts:
  nova/tests/unit/console/test_websocketproxy.py

NOTE: conflict is due to I58b0382c86d4ef798572edb63d311e0e3e6937bb
is missing in Victoria and Ie36401c782f023d1d5f2623732619105dc2cfa24
backport contained conflicts and methods order was swapped.

Change-Id: I95f68be76330ff09e5eabb5ef8dd9a18f5547866
co-authored-by: Matteo Pozza
Closes-Bug: #1927677
(cherry picked from commit 6fbd0b758d)
(cherry picked from commit 47dad4836a)
2021-09-08 21:00:08 +02:00
api-guide/source Fallback to same-cell resize with qos ports 2021-01-11 16:20:03 +01:00
api-ref/source trivial: Final cleanup 2020-09-11 14:09:06 +01:00
devstack lower-constraints: Bump packaging to 20.4 2020-12-11 17:08:48 +01:00
doc Ignore PCI devices with 32bit domain 2021-05-17 16:35:50 +01:00
etc/nova Allow versioned discovery unauthenticated 2020-04-03 21:24:28 +00:00
gate zuul: Replace grenade and nova-grenade-multinode with grenade-multinode 2021-06-03 19:33:24 +00:00
nova address open redirect with 3 forward slashes 2021-09-08 21:00:08 +02:00
playbooks zuul: Replace grenade and nova-grenade-multinode with grenade-multinode 2021-06-03 19:33:24 +00:00
releasenotes Merge "Reject open redirection in the console proxy" into stable/victoria 2021-07-26 17:50:58 +00:00
roles zuul: Replace nova-live-migration with zuulv3 jobs 2020-11-30 09:43:51 +00:00
tools Move 'check-cherry-picks' test to gate, n-v check 2021-06-18 10:49:26 +01:00
.coveragerc Remove nova/openstack/* from .coveragerc 2016-10-12 16:20:49 -04:00
.gitignore tox: Integrate mypy 2020-05-15 15:59:53 +01:00
.gitreview [stable-only] Update .gitreview for stable/victoria 2020-09-25 14:16:20 +02:00
.mailmap Add mailmap entry 2014-05-07 12:14:26 -07:00
.pre-commit-config.yaml Switch to hacking 2.x 2020-01-17 11:30:40 +00:00
.stestr.conf Finish stestr migration 2017-11-24 16:51:12 -05:00
.zuul.yaml Move 'check-cherry-picks' test to gate, n-v check 2021-06-18 10:49:26 +01:00
CONTRIBUTING.rst [Community goal] Update contributor documentation 2020-03-25 12:01:37 +00:00
HACKING.rst Remove hacking rules for python 2/3 compatibility 2020-06-17 08:19:13 +00:00
LICENSE initial commit 2010-05-27 23:05:26 -07:00
MAINTAINERS Fix broken URLs 2017-09-07 15:42:31 +02:00
README.rst docs: Remove references to XenAPI driver 2020-08-31 15:53:31 +01:00
bindep.txt Add lsscsi to bindep 2020-08-05 16:16:49 -05:00
lower-constraints.txt lower-constraints: Bump packaging to 20.4 2020-12-11 17:08:48 +01:00
mypy-files.txt Add type hints to 'nova.virt.libvirt.utils' 2020-09-04 14:42:18 +01:00
requirements.txt Migrate default policy file from JSON to YAML 2020-09-09 08:09:38 -05:00
setup.cfg tox: Integrate mypy 2020-05-15 15:59:53 +01:00
setup.py Updated from global requirements 2017-03-02 11:50:48 +00:00
test-requirements.txt [goal] Prepare for job migration to Ubuntu Focal (20.04) 2020-08-18 11:28:32 +00:00
tox.ini Move 'check-cherry-picks' test to gate, n-v check 2021-06-18 10:49:26 +01:00

README.rst

OpenStack Nova

image

OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, OpenStack Ironic and PowerVM.

Use the following resources to learn more.

API

To learn how to use Nova's API, consult the documentation available online at:

For more information on OpenStack APIs, SDKs and CLIs in general, refer to:

Operators

To learn how to deploy and configure OpenStack Nova, consult the documentation available online at:

In the unfortunate event that bugs are discovered, they should be reported to the appropriate bug tracker. If you obtained the software from a 3rd party operating system vendor, it is often wise to use their own bug tracker for reporting problems. In all other cases use the master OpenStack bug tracker, available at:

Developers

For information on how to contribute to Nova, please see the contents of the CONTRIBUTING.rst.

Any new code must follow the development guidelines detailed in the HACKING.rst file, and pass all unit tests.

Further developer focused documentation is available at:

Other Information

During each Summit and Project Team Gathering, we agree on what the whole community wants to focus on for the upcoming release. The plans for nova can be found at: