Avoid disk scoped NFC ticket for read-only access
This commit is contained in:
+6
-6
@@ -125,12 +125,12 @@ A disk-scoped **read** ticket also works and returns the same
|
|||||||
```
|
```
|
||||||
|
|
||||||
`diskDeviceKey` is `VirtualDisk.key` from `vm.config.hardware.device`
|
`diskDeviceKey` is `VirtualDisk.key` from `vm.config.hardware.device`
|
||||||
(2000 for Hard disk 1). The replacement resolves it from the datastore
|
(2000 for Hard disk 1). Read-only `VixDiskLib_Open` does **not** send
|
||||||
path when `open` is given a VMDK rather than a key. That path may be
|
it: the drop-in uses `NfcGetVmFiles` and puts the VMDK path (leaf or
|
||||||
the current leaf or a parent in `backing.parent` (snapshot deltas such
|
snapshot parent) only on NFC `OPEN_FILE`. Writable `open` resolves a
|
||||||
as `…-000007.vmdk` after the VM has moved on to `…-000008.vmdk`). The
|
key from the datastore path, matching the current leaf or any parent
|
||||||
ticket still uses the device key; `OPEN_FILE` then names the snapshot
|
in `backing.parent` (for example `…-000007.vmdk` after the VM has
|
||||||
file.
|
moved on to `…-000008.vmdk`).
|
||||||
|
|
||||||
### Return value: `vim.HostServiceTicket`
|
### Return value: `vim.HostServiceTicket`
|
||||||
|
|
||||||
|
|||||||
@@ -253,6 +253,12 @@ class VixDiskLibHandle:
|
|||||||
flags: int = VIXDISKLIB_FLAG_OPEN_READ_ONLY) -> Iterator[_DiskHandle]:
|
flags: int = VIXDISKLIB_FLAG_OPEN_READ_ONLY) -> Iterator[_DiskHandle]:
|
||||||
"""Open ``disk_path`` over NFC. Matches ``VixDiskLib_Open``.
|
"""Open ``disk_path`` over NFC. Matches ``VixDiskLib_Open``.
|
||||||
|
|
||||||
|
Read-only opens request ``NfcGetVmFiles`` (VM only). The VMDK
|
||||||
|
path, including a snapshot parent such as ``…-000007.vmdk``, is
|
||||||
|
sent on NFC ``OPEN_FILE``. Writable opens use
|
||||||
|
``NfcRandomAccessOpenDisk`` and resolve a device key from the
|
||||||
|
disk's backing chain.
|
||||||
|
|
||||||
Args:
|
Args:
|
||||||
conn: Connection from ``connect``.
|
conn: Connection from ``connect``.
|
||||||
disk_path: Datastore path of the VMDK.
|
disk_path: Datastore path of the VMDK.
|
||||||
@@ -271,7 +277,8 @@ class VixDiskLibHandle:
|
|||||||
vm = vim.VirtualMachine(conn.vm_moref, conn.si._stub)
|
vm = vim.VirtualMachine(conn.vm_moref, conn.si._stub)
|
||||||
nfc_ssl = conn.transport_mode == "nbdssl"
|
nfc_ssl = conn.transport_mode == "nbdssl"
|
||||||
ticket = nfc_auth.get_nfc_ticket(
|
ticket = nfc_auth.get_nfc_ticket(
|
||||||
conn.si, vm, read_only=read_only, disk_path=disk_path)
|
conn.si, vm, read_only=read_only,
|
||||||
|
disk_path=None if read_only else disk_path)
|
||||||
authd_sock = nfc_auth.connect_authd(
|
authd_sock = nfc_auth.connect_authd(
|
||||||
ticket, allow_untrusted=conn.allow_untrusted, nfc_ssl=nfc_ssl)
|
ticket, allow_untrusted=conn.allow_untrusted, nfc_ssl=nfc_ssl)
|
||||||
session = nfc_auth.NfcAuthSession(
|
session = nfc_auth.NfcAuthSession(
|
||||||
|
|||||||
Reference in New Issue
Block a user