New issue
Advanced search Search tips

Issue 898338 link

Starred by 3 users

Issue metadata

Status: Verified
Owner:
Closed: Oct 30
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug



Sign in to add a comment

vsh should validate VM cid

Project Member Reported by smbar...@chromium.org, Oct 23

Issue description

concierge and cicerone already validate the VM cid. vsh should check that an incoming connection to the host comes from the VM cid that is expected.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Oct 24

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/platform2/+/70c9946140c2a202cd109767d0d1108d9b67e6c8

commit 70c9946140c2a202cd109767d0d1108d9b67e6c8
Author: Stephen Barber <smbarber@chromium.org>
Date: Wed Oct 24 23:45:07 2018

system_api: vm_cicerone: add cid to LaunchVshd

vsh will validate the cid when a VM attempts to connect to the
host.

BUG= chromium:898338 
TEST=vsh --target_container=penguin still works

Change-Id: I004e7f3d1f51eb639bac826abf81033de2e349bf
Reviewed-on: https://chromium-review.googlesource.com/1297024
Commit-Ready: Stephen Barber <smbarber@chromium.org>
Tested-by: Stephen Barber <smbarber@chromium.org>
Reviewed-by: Chirantan Ekbote <chirantan@chromium.org>

[modify] https://crrev.com/70c9946140c2a202cd109767d0d1108d9b67e6c8/system_api/dbus/vm_cicerone/cicerone_service.proto

Project Member

Comment 2 by bugdroid1@chromium.org, Oct 25

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/platform2/+/375074fda7fa27df78f8edbc157b18183290ed14

commit 375074fda7fa27df78f8edbc157b18183290ed14
Author: Stephen Barber <smbarber@chromium.org>
Date: Thu Oct 25 07:32:27 2018

vm_tools: vsh: check cid when connecting to container

BUG= chromium:898338 
TEST=vsh --target_container=penguin still works

Change-Id: I3c016d3b125c0dd015a0b2e25d42b7931b6e71a8
Reviewed-on: https://chromium-review.googlesource.com/1297025
Commit-Ready: Stephen Barber <smbarber@chromium.org>
Tested-by: Stephen Barber <smbarber@chromium.org>
Reviewed-by: Stephen Barber <smbarber@chromium.org>

[modify] https://crrev.com/375074fda7fa27df78f8edbc157b18183290ed14/vm_tools/cicerone/service.cc
[modify] https://crrev.com/375074fda7fa27df78f8edbc157b18183290ed14/vm_tools/vsh/vsh.cc

Status: Verified (was: Started)
Verified on 11203.0.0

Sign in to add a comment