Avoid disk scoped NFC ticket for read-only access
This commit is contained in:
+6
-6
@@ -125,12 +125,12 @@ A disk-scoped **read** ticket also works and returns the same
|
||||
```
|
||||
|
||||
`diskDeviceKey` is `VirtualDisk.key` from `vm.config.hardware.device`
|
||||
(2000 for Hard disk 1). The replacement resolves it from the datastore
|
||||
path when `open` is given a VMDK rather than a key. That path may be
|
||||
the current leaf or a parent in `backing.parent` (snapshot deltas such
|
||||
as `…-000007.vmdk` after the VM has moved on to `…-000008.vmdk`). The
|
||||
ticket still uses the device key; `OPEN_FILE` then names the snapshot
|
||||
file.
|
||||
(2000 for Hard disk 1). Read-only `VixDiskLib_Open` does **not** send
|
||||
it: the drop-in uses `NfcGetVmFiles` and puts the VMDK path (leaf or
|
||||
snapshot parent) only on NFC `OPEN_FILE`. Writable `open` resolves a
|
||||
key from the datastore path, matching the current leaf or any parent
|
||||
in `backing.parent` (for example `…-000007.vmdk` after the VM has
|
||||
moved on to `…-000008.vmdk`).
|
||||
|
||||
### Return value: `vim.HostServiceTicket`
|
||||
|
||||
|
||||
@@ -253,6 +253,12 @@ class VixDiskLibHandle:
|
||||
flags: int = VIXDISKLIB_FLAG_OPEN_READ_ONLY) -> Iterator[_DiskHandle]:
|
||||
"""Open ``disk_path`` over NFC. Matches ``VixDiskLib_Open``.
|
||||
|
||||
Read-only opens request ``NfcGetVmFiles`` (VM only). The VMDK
|
||||
path, including a snapshot parent such as ``…-000007.vmdk``, is
|
||||
sent on NFC ``OPEN_FILE``. Writable opens use
|
||||
``NfcRandomAccessOpenDisk`` and resolve a device key from the
|
||||
disk's backing chain.
|
||||
|
||||
Args:
|
||||
conn: Connection from ``connect``.
|
||||
disk_path: Datastore path of the VMDK.
|
||||
@@ -271,7 +277,8 @@ class VixDiskLibHandle:
|
||||
vm = vim.VirtualMachine(conn.vm_moref, conn.si._stub)
|
||||
nfc_ssl = conn.transport_mode == "nbdssl"
|
||||
ticket = nfc_auth.get_nfc_ticket(
|
||||
conn.si, vm, read_only=read_only, disk_path=disk_path)
|
||||
conn.si, vm, read_only=read_only,
|
||||
disk_path=None if read_only else disk_path)
|
||||
authd_sock = nfc_auth.connect_authd(
|
||||
ticket, allow_untrusted=conn.allow_untrusted, nfc_ssl=nfc_ssl)
|
||||
session = nfc_auth.NfcAuthSession(
|
||||
|
||||
Reference in New Issue
Block a user