Avoid disk scoped NFC ticket for read-only access

This commit is contained in:
Lucian Petrut
2026-09-07 15:45:28 +00:00
parent a82c56b069
commit 51295bdfd0
2 changed files with 14 additions and 7 deletions
+6 -6
View File
@@ -125,12 +125,12 @@ A disk-scoped **read** ticket also works and returns the same
``` ```
`diskDeviceKey` is `VirtualDisk.key` from `vm.config.hardware.device` `diskDeviceKey` is `VirtualDisk.key` from `vm.config.hardware.device`
(2000 for Hard disk 1). The replacement resolves it from the datastore (2000 for Hard disk 1). Read-only `VixDiskLib_Open` does **not** send
path when `open` is given a VMDK rather than a key. That path may be it: the drop-in uses `NfcGetVmFiles` and puts the VMDK path (leaf or
the current leaf or a parent in `backing.parent` (snapshot deltas such snapshot parent) only on NFC `OPEN_FILE`. Writable `open` resolves a
as `…-000007.vmdk` after the VM has moved on to `…-000008.vmdk`). The key from the datastore path, matching the current leaf or any parent
ticket still uses the device key; `OPEN_FILE` then names the snapshot in `backing.parent` (for example `…-000007.vmdk` after the VM has
file. moved on to `…-000008.vmdk`).
### Return value: `vim.HostServiceTicket` ### Return value: `vim.HostServiceTicket`
+8 -1
View File
@@ -253,6 +253,12 @@ class VixDiskLibHandle:
flags: int = VIXDISKLIB_FLAG_OPEN_READ_ONLY) -> Iterator[_DiskHandle]: flags: int = VIXDISKLIB_FLAG_OPEN_READ_ONLY) -> Iterator[_DiskHandle]:
"""Open ``disk_path`` over NFC. Matches ``VixDiskLib_Open``. """Open ``disk_path`` over NFC. Matches ``VixDiskLib_Open``.
Read-only opens request ``NfcGetVmFiles`` (VM only). The VMDK
path, including a snapshot parent such as ``…-000007.vmdk``, is
sent on NFC ``OPEN_FILE``. Writable opens use
``NfcRandomAccessOpenDisk`` and resolve a device key from the
disk's backing chain.
Args: Args:
conn: Connection from ``connect``. conn: Connection from ``connect``.
disk_path: Datastore path of the VMDK. disk_path: Datastore path of the VMDK.
@@ -271,7 +277,8 @@ class VixDiskLibHandle:
vm = vim.VirtualMachine(conn.vm_moref, conn.si._stub) vm = vim.VirtualMachine(conn.vm_moref, conn.si._stub)
nfc_ssl = conn.transport_mode == "nbdssl" nfc_ssl = conn.transport_mode == "nbdssl"
ticket = nfc_auth.get_nfc_ticket( ticket = nfc_auth.get_nfc_ticket(
conn.si, vm, read_only=read_only, disk_path=disk_path) conn.si, vm, read_only=read_only,
disk_path=None if read_only else disk_path)
authd_sock = nfc_auth.connect_authd( authd_sock = nfc_auth.connect_authd(
ticket, allow_untrusted=conn.allow_untrusted, nfc_ssl=nfc_ssl) ticket, allow_untrusted=conn.allow_untrusted, nfc_ssl=nfc_ssl)
session = nfc_auth.NfcAuthSession( session = nfc_auth.NfcAuthSession(