[pve-devel] [PATCH storage] plugin: volume snapshot info: untaint snapshot filename

Friedrich Weber f.weber at proxmox.com
Mon Jul 28 15:32:15 CEST 2025


On 28/07/2025 15:30, Friedrich Weber wrote:
[...]
>> should hopefully not be too hard to fix, I'll try to whip up patches..
> 
> Thanks! I guess then (and if we want to add an untaint here at all) we
> could keep this patch as it is, because qemu-img info does seem to
> output an absolute "filename" even if the backing filename is absolute?
> What do you think?

Sorry, didn't see the apply. Thanks! A patch for run_command to always
pass untainted values could be done in addition, I guess.




More information about the pve-devel mailing list