commit 2dc52153215bb6a37532a959c5c98239be21bb56
Author: Eric Young <email address hidden>
Date: Thu Mar 22 20:24:01 2018 -0400
ScaleIO: Prevent usage of unsafe volumes
It is possible for volumes, created from storage pools
which have zero-padding disabled, to contain previous data. This
change prevents these volumes from being created by default. A
user can override this behavior by acknowleding the possibility
with a configuration option.
This is a squash of the four commits that led to the final state in
rocky to not allow the creation of any type of non-zero-padded volumes
to be created. This adds a config option that defaults to the safe
behavior. It is backporting a new config option, and a change in default
behavior, but it should be acceptable in this case so that the security
vulnerability can be addressed.
Closes-Bug: #1784871
Change-Id: I62f8f48b1624fc9abb7427bd4ca51f7873d35b96
Closes-bug: #1699573
(cherry picked from commit f0cef07bef5ea8ed29179ee3774df5f4a634ba86)
(cherry picked from commit 6309c097e653c5f8b40e0602950d0ef54a9efb37)
Reviewed: https:/ /review. openstack. org/604105 /git.openstack. org/cgit/ openstack/ cinder/ commit/ ?id=2dc52153215 bb6a37532a959c5 c98239be21bb56
Committed: https:/
Submitter: Zuul
Branch: stable/ocata
commit 2dc52153215bb6a 37532a959c5c982 39be21bb56
Author: Eric Young <email address hidden>
Date: Thu Mar 22 20:24:01 2018 -0400
ScaleIO: Prevent usage of unsafe volumes
It is possible for volumes, created from storage pools
which have zero-padding disabled, to contain previous data. This
change prevents these volumes from being created by default. A
user can override this behavior by acknowleding the possibility
with a configuration option.
This is a squash of the four commits that led to the final state in
rocky to not allow the creation of any type of non-zero-padded volumes
to be created. This adds a config option that defaults to the safe
behavior. It is backporting a new config option, and a change in default
behavior, but it should be acceptable in this case so that the security
vulnerability can be addressed.
Closes-Bug: #1784871
Change-Id: I62f8f48b1624fc 9abb7427bd4ca51 f7873d35b96 d29179ee3774df5 f4a634ba86) 8b40e0602950d0e f54a9efb37)
Closes-bug: #1699573
(cherry picked from commit f0cef07bef5ea8e
(cherry picked from commit 6309c097e653c5f