glance/releasenotes/notes
Brian Rosmaita 58311904a7 Adding constraints around qemu-img calls
* All "qemu-img info" calls are now run under resource limitations that
  limit CPU time to 2 seconds and address space usage to 1 GB. This
  helps avoid any DoS attacks via malicious images.
* All "qemu-img convert" calls now specify the import format so that it
  does not have to be inferred by qemu-img.

SecurityImpact

(Hemanth did all the work on this, I'm just doing the backport.)

Co-authored-by: Hemanth Makkapati <hemanth.makkapati@rackspace.com>
Closes-Bug: #1449062
(cherry picked from commit 69a9b659fd)

Change-Id: I65f30b85439a8811545b0ca590555528631954df
2016-09-27 16:11:17 -04:00
..
.placeholder Add reno for release notes management 2015-11-10 12:17:40 -03:00
60fdcaba00e30d02-start-using-reno.yaml add first reno-based release note 2015-11-03 18:00:26 +00:00
InvalidImageStatusTransition-error-1505474-0d6103c0cacea429.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
Prevent-removing-last-image-location-d5ee3e00efe14f34.yaml Prevent user to remove last location of the image 2016-02-03 10:01:00 -05:00
add-processlimits-to-qemu-img-c215f5d90f741d8a.yaml Adding constraints around qemu-img calls 2016-09-27 16:11:17 -04:00
decrease-test-failure-on-second-change-1505675-47281bce0ce14d5a.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
disallow-ACTIVE_IMMUTABLE-deactivated-1517060-1517963-bcebdeaa35746e52.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
import-translations-df0ac95ed279d68a.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
invalid-token-exception-handling-1504184-d06f2828ec7168cd.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
move-store-config-in-tests-1522132-aebd1ad1663d5977.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
pass-conf-to-logging-1505710-63230c1f4a411313.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
stop-id-changes-after-creation-1483353-1483688-ddd3bfd7446de287.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
switchclient-to-test-requirements-1512369-1eecc68fbb161251.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00
updated-requirements-c99564dbd040ae88.yaml Release notes for 11.0.1 2015-12-18 15:00:44 +00:00