Skip to content

Commit 363e83e

Browse files
authored
Merge branch 'main' into ghi7297-messages
2 parents 61f1c3d + b7a834b commit 363e83e

428 files changed

Lines changed: 6377 additions & 1561 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.asf.yaml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,7 @@ github:
5858
- GaOrtiga
5959
- bhouse-nexthop
6060
- Dogface2k
61+
- prashanthr2
6162

6263
rulesets:
6364
- name: "Default Branch Protection"
@@ -73,7 +74,7 @@ github:
7374

7475
copilot_code_review:
7576
enabled: true
76-
review_drafts: true
77+
review_drafts: false
7778
review_on_push: true
7879

7980
notifications:

‎.github/linters/codespell.txt‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -184,6 +184,8 @@ environmnet
184184
equivalant
185185
erro
186186
erronous
187+
errorprone
188+
everthing
187189
everytime
188190
excute
189191
execept

‎.github/workflows/rat.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
uses: ./.github/actions/install-nonoss
4242
- name: RAT licence checks
4343
run: |
44-
mvn -P developer,systemvm -Dsimulator -Dnoredist -pl . org.apache.rat:apache-rat-plugin:0.12:check
44+
mvn -P developer,systemvm -Dsimulator -Dnoredist -pl . org.apache.rat:apache-rat-plugin:0.18:check
4545
- name: Rat Report
4646
if: always()
4747
run: |

‎agent/pom.xml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
<parent>
2525
<groupId>org.apache.cloudstack</groupId>
2626
<artifactId>cloudstack</artifactId>
27-
<version>4.23.0.0-SNAPSHOT</version>
27+
<version>4.24.0.0-SNAPSHOT</version>
2828
</parent>
2929
<dependencies>
3030
<dependency>

‎agent/src/main/java/com/cloud/agent/mockvm/MockVmMgr.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,7 +249,7 @@ public void freeVncPort(int port) {
249249
public MockVm createVmFromSpec(VirtualMachineTO vmSpec) {
250250
String vmName = vmSpec.getName();
251251
long ramSize = vmSpec.getMinRam();
252-
int utilizationPercent = randSeed.nextInt() % 100;
252+
int utilizationPercent = randSeed.nextInt(100);
253253
MockVm vm = null;
254254

255255
synchronized (this) {

‎api/pom.xml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
<parent>
2525
<groupId>org.apache.cloudstack</groupId>
2626
<artifactId>cloudstack</artifactId>
27-
<version>4.23.0.0-SNAPSHOT</version>
27+
<version>4.24.0.0-SNAPSHOT</version>
2828
</parent>
2929
<dependencies>
3030
<dependency>

‎api/src/main/java/com/cloud/projects/ProjectService.java‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@
2323
import com.cloud.exception.ResourceUnavailableException;
2424
import com.cloud.projects.ProjectAccount.Role;
2525
import com.cloud.user.Account;
26+
import com.cloud.user.User;
2627

2728
public interface ProjectService {
2829
/**
@@ -102,4 +103,5 @@ public interface ProjectService {
102103

103104
boolean addUserToProject(Long projectId, String username, String email, Long projectRoleId, Role projectRole) throws ResourceAllocationException;
104105

106+
void moveProjectAssociationsToUser(User oldUser, User newUser) throws ResourceAllocationException;
105107
}

‎api/src/main/java/com/cloud/user/AccountService.java‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -185,4 +185,6 @@ User createUser(String userName, String password, String firstName, String lastN
185185
String getAccessingApiKey(BaseCmd cmd);
186186

187187
List<RolePermissionEntity> getAllKeypairPermissions(String apiKey);
188+
189+
List<? extends ApiKeyPairPermission> getAllExplicitKeyPairPermissions(Long keyPairId);
188190
}

‎api/src/main/java/com/cloud/vm/VirtualMachineProfile.java‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,7 @@ public static class Param {
7979
public static final Param PreserveNics = new Param("PreserveNics");
8080
public static final Param ConsiderLastHost = new Param("ConsiderLastHost");
8181
public static final Param ReturnAfterVolumePrepare = new Param("ReturnAfterVolumePrepare");
82+
public static final Param ResetPasswordOnRestore = new Param("ResetPasswordOnRestore");
8283

8384
private String name;
8485

‎api/src/main/java/org/apache/cloudstack/acl/APIChecker.java‎

Lines changed: 31 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,23 +17,30 @@
1717
package org.apache.cloudstack.acl;
1818

1919
import com.cloud.exception.PermissionDeniedException;
20+
import com.cloud.exception.RequestLimitException;
2021
import com.cloud.user.Account;
2122
import com.cloud.user.User;
2223
import com.cloud.utils.component.Adapter;
24+
import org.apache.cloudstack.acl.apikeypair.ApiKeyPair;
2325
import org.apache.cloudstack.acl.apikeypair.ApiKeyPairPermission;
2426

27+
import java.util.ArrayList;
2528
import java.util.List;
2629

30+
import org.apache.logging.log4j.LogManager;
31+
import org.apache.logging.log4j.Logger;
32+
2733
/**
2834
* APICheckers is designed to verify the ownership of resources and to control the access to APIs.
2935
*/
3036
public interface APIChecker extends Adapter {
37+
Logger LOGGER = LogManager.getLogger(APIChecker.class);
3138
// Interface for checking access for a role using apiname
3239
// If true, apiChecker has checked the operation
3340
// If false, apiChecker is unable to handle the operation or not implemented
3441
// On exception, checkAccess failed don't allow
35-
boolean checkAccess(User user, String apiCommandName, ApiKeyPairPermission... apiKeyPairPermissions) throws PermissionDeniedException;
36-
boolean checkAccess(Account account, String apiCommandName, ApiKeyPairPermission... apiKeyPairPermissions) throws PermissionDeniedException;
42+
boolean checkAccess(User user, String apiCommandName, ApiKeyPair keyPair, ApiKeyPairPermission... apiKeyPairPermissions) throws PermissionDeniedException;
43+
boolean checkAccess(Account account, String apiCommandName, ApiKeyPair keyPair, ApiKeyPairPermission... apiKeyPairPermissions) throws PermissionDeniedException;
3744
/**
3845
* Verifies if the account has permission for the given list of APIs and returns only the allowed ones.
3946
*
@@ -43,6 +50,28 @@ public interface APIChecker extends Adapter {
4350
* @return the list of allowed apis for the given user
4451
*/
4552
List<String> getApisAllowedToUser(Role role, User user, List<String> apiNames) throws PermissionDeniedException;
53+
54+
default List<String> getApisAllowedToAccount(Account account, List<String> apiNames) {
55+
List<String> allowedApis = new ArrayList<>();
56+
for (String apiName : apiNames) {
57+
try {
58+
checkAccess(account, apiName, null);
59+
allowedApis.add(apiName);
60+
} catch (RequestLimitException e) {
61+
// Non-ACL failure (e.g. rate limiting) should not be treated as simple "not allowed".
62+
// Propagate as unchecked so callers are aware of the failure.
63+
throw new RuntimeException("Failed to check access for API [" + apiName + "] due to request limits", e);
64+
} catch (PermissionDeniedException e) {
65+
LOGGER.trace("Account [" + account + "] is not allowed to access API [" + apiName + "]");
66+
}
67+
}
68+
return allowedApis;
69+
}
70+
4671
boolean isEnabled();
4772
List<RolePermissionEntity> getImplicitRolePermissions(RoleType roleType);
73+
74+
default void refreshRoleCacheOnPermissionsChange(Role role) {
75+
// Only applicable for dynamic role based checkers
76+
}
4877
}

0 commit comments

Comments
 (0)