os-brick/os_brick/privileged
Gorka Eguileor 5d5f8e02ef Fix os-brick in virtual environments
When running os-brick in a virtual environment created by a non root
user, we get the following error:

  ModuleNotFoundError: No module named 'os_brick.privileged.rootwrap'

This happens because the privsep daemon drops all the privileged except
those defined in the context, and our current context doesn't bypass
file read permission checks, so the Daemon cannot read the file with the
code it was asked to run, because it belongs to a different user.

This patch adds the CAP_DAC_READ_SEARCH capability to our privsep
context so we can load the libraries, but only when we are running on a
virtual environment to follow the principle of least privilege.

This bug doesn't affect system-wide installations because the files
installed under /sys/python*/site-packages belong to the Daemon user
(root), so no special capabilities are necessary.

Change-Id: Ib191c075ad1250822f6ac842f39214af8f3a02f0
Close-Bug: #1884059
2020-06-19 09:32:24 +02:00
..
__init__.py Fix os-brick in virtual environments 2020-06-19 09:32:24 +02:00
rootwrap.py Refactor iSCSI connect 2017-06-16 16:09:35 +02:00
scaleio.py Remove VxFlex OS credentials from connection_properties 2020-06-03 11:27:21 +00:00