vmauth: introduce arbitrary fs access#2095
Merged
AndrewChubatiuk merged 3 commits intomasterfrom Apr 23, 2026
Merged
Conversation
Contributor
There was a problem hiding this comment.
2 issues found across 9 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="docs/CHANGELOG.md">
<violation number="1" location="docs/CHANGELOG.md:16">
P2: Custom agent: **Changelog Review Agent**
Changelog entry is missing the mandatory user-centric before/now/user-visible impact explanation.</violation>
</file>
<file name="internal/controller/operator/factory/vmauth/vmusers_config.go">
<violation number="1" location="internal/controller/operator/factory/vmauth/vmusers_config.go:126">
P1: `arbitraryFSAccessThroughSMs.deny` is enforced only for VMUser entries, so `unauthorizedUserAccessSpec` can still inject file-based TLS paths and bypass the deny policy.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review, or fix all with cubic.
vrutkovs
approved these changes
Apr 23, 2026
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Signed-off-by: Andrii Chubatiuk <andrew.chubatiuk@gmail.com>
ab545c4 to
363c0be
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fixes #899
Summary by cubic
Adds
arbitraryFSAccessThroughSMstoVMAuthto allow or block file-path references inVMUserconfigs. When denied, VMAuth rejects users that reference node files (e.g., bearer tokens, basic auth, TLS files).arbitraryFSAccessThroughSMs.denytoVMAuthSpec; when true,VMUser.ValidateArbitraryFSAccess()blocks configs with file-path refs (e.g., TLS cert/key/CA).VMAuthSpec; CHANGELOG entry added).Written for commit 363c0be. Summary will update on new commits.