Bug#1144931: trixie-pu: package manila/1:20.0.0-3

Thomas Goirand <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <178724034088.282850.14666640251965637658.reportbug__44912.3906948202$1787240494$gmane$org@zbuz.infomaniak.ch>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:manila
User: [email protected]
Usertags: pu

Hi,

[ Reason ]
I'd like to upload Manila manila_20.0.0-3+deb13u1 to address
upstream bug:
https://wiki.openstack.org/wiki/OSSN/OSSN-0103
aka:
https://bugs.debian.org/1143804

[ Impact ]
As per upstream announce:

A non-admin user with a project-scoped token can retrieve another project's
resource lock metadata by supplying a foreign project_id in the GET
/resource-locks request. The API only enforces the all-project policy check
when the all_projects parameter is present; without it, a user-supplied
project_id reaches the database filter unchanged, bypassing project scoping.

[ Tests ]
No new tests in the patch, but the patch itself is super small.

[ Risks ]
Patch is:

+    if project_id is not None:
+        authorize_project_context(context, project_id)

in api.py. That's small enough to be trusted.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

Please allow me to upload manila/20.0.0-3+deb13u1

Cheers,

Thomas Goirand (zigo)
manila_20.0.0-3+deb13u1.debdiff (text/plain, 3.6 KB)
diff -Nru manila-20.0.0/debian/changelog manila-20.0.0/debian/changelog
--- manila-20.0.0/debian/changelog	2025-07-12 10:45:46.000000000 +0200
+++ manila-20.0.0/debian/changelog	2026-08-20 17:26:40.000000000 +0200
@@ -1,3 +1,11 @@
+manila (1:20.0.0-3+deb13u1) trixie; urgency=medium
+
+  * OSSN-0103: resource-lock list trusts a foreign project_id filter. Applied
+    upstream patch: "Prevent unauthorized resource locks search".
+    (Closes: #1143804)
+
+ -- Thomas Goirand <[email protected]>  Thu, 20 Aug 2026 17:26:40 +0200
+
 manila (1:20.0.0-3) unstable; urgency=medium
 
   * Fix uwsgi config.
diff -Nru manila-20.0.0/debian/patches/OSSN-0103_Prevent_unauthorized_resource_locks_search.patch manila-20.0.0/debian/patches/OSSN-0103_Prevent_unauthorized_resource_locks_search.patch
--- manila-20.0.0/debian/patches/OSSN-0103_Prevent_unauthorized_resource_locks_search.patch	1970-01-01 01:00:00.000000000 +0100
+++ manila-20.0.0/debian/patches/OSSN-0103_Prevent_unauthorized_resource_locks_search.patch	2026-08-20 17:26:40.000000000 +0200
@@ -0,0 +1,46 @@
+Author: Carlos da Silva <[email protected]>
+Date: Wed, 22 Jul 2026 21:00:15 -0300
+Description: Prevent unauthorized resource locks search
+ The resource locks mechanism allows filtering locks by project
+ UUIDs. This feature is helpful for identifying the locks and
+ letting their users and/or administrators to quickly filter.
+ .
+ However, in the current code path, we were allowing unauthorized
+ cross-project visibility into resource locks data for users that
+ were not members, admin or readers of a given project.
+ .
+ This change fixes this issue by adding a check to ensure whether
+ the user has authorization to look up resource locks in the
+ project they are supplying as part of the query.
+Bug: https://launchpad.net/bugs/2161287
+Bug-Debian: https://bugs.debian.org/1143804
+Change-Id: I03eebf6bb951583378340365dbf69122f124ffc8
+Signed-off-by: Carlos da Silva <[email protected]>
+Origin: upstream, https://review.opendev.org/c/openstack/manila/+/998569
+Last-Update: 2026-08-06
+
+Index: manila/manila/db/sqlalchemy/api.py
+===================================================================
+--- manila.orig/manila/db/sqlalchemy/api.py
++++ manila/manila/db/sqlalchemy/api.py
+@@ -7700,6 +7700,8 @@ def resource_lock_get_all(context, filte
+     all_projects = filters.get('all_projects') or filters.get('all_tenants')
+     if project_id is None and not all_projects:
+         filters['project_id'] = context.project_id
++    if project_id is not None:
++        authorize_project_context(context, project_id)
+ 
+     legal_filter_keys = ('id', 'user_id', 'resource_id', 'resource_type',
+                          'lock_context', 'resource_action', 'created_since',
+Index: manila/releasenotes/notes/bug-2161287-prevent-unprivileged-locks-filtering-9f40a2f48475429e.yaml
+===================================================================
+--- /dev/null
++++ manila/releasenotes/notes/bug-2161287-prevent-unprivileged-locks-filtering-9f40a2f48475429e.yaml
+@@ -0,0 +1,7 @@
++---
++security:
++  - |
++    Manila now prevents resource locks to be filtered by a project UUID in
++    case the requester is not an admininistrator or a member of the project
++    they are attempting to look up. For more details, please refer to
++    `Launchpad bug <https://bugs.launchpad.net/manila/+bug/2161287>`.
diff -Nru manila-20.0.0/debian/patches/series manila-20.0.0/debian/patches/series
--- manila-20.0.0/debian/patches/series	2025-07-12 10:45:46.000000000 +0200
+++ manila-20.0.0/debian/patches/series	2026-08-20 17:26:40.000000000 +0200
@@ -1 +1,2 @@
 install-missing-files.patch
+OSSN-0103_Prevent_unauthorized_resource_locks_search.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.