fix(region): validate port mappings range of pod (#20128)

This commit is contained in:
Zexi Li
2024-04-25 13:35:25 +08:00
committed by GitHub
parent be62b3e049
commit 5532cd07ca
3 changed files with 19 additions and 14 deletions
+5
View File
@@ -47,6 +47,11 @@ const (
//PodPortMappingProtocolSCTP = "sctp"
)
const (
POD_PORT_MAPPING_RANGE_START = 20000
POD_PORT_MAPPING_RANGE_END = 25000
)
type PodPortMappingPortRange struct {
Start int `json:"start"`
End int `json:"end"`
+9 -9
View File
@@ -162,19 +162,19 @@ func (p *SPodDriver) validatePortRange(portRange *api.PodPortMappingPortRange) e
if portRange.Start > portRange.End {
return httperrors.NewInputParameterError("port range start %d is large than %d", portRange.Start, portRange.End)
}
if portRange.Start <= 0 {
return httperrors.NewInputParameterError("port range start %d <= 0", portRange.Start)
if portRange.Start <= api.POD_PORT_MAPPING_RANGE_START {
return httperrors.NewInputParameterError("port range start %d <= %d", api.POD_PORT_MAPPING_RANGE_START, portRange.Start)
}
if portRange.End > 65535 {
return httperrors.NewInputParameterError("port range end %d > 65535", portRange.End)
if portRange.End > api.POD_PORT_MAPPING_RANGE_END {
return httperrors.NewInputParameterError("port range end %d > %d", api.POD_PORT_MAPPING_RANGE_END, portRange.End)
}
}
return nil
}
func (p *SPodDriver) validatePort(port int) error {
if port <= 0 || port > 65535 {
return httperrors.NewInputParameterError("port number %d isn't within 1 to 65535", port)
func (p *SPodDriver) validatePort(port int, start int, end int) error {
if port < start || port > end {
return httperrors.NewInputParameterError("port number %d isn't within %d to %d", port, start, end)
}
return nil
}
@@ -184,11 +184,11 @@ func (p *SPodDriver) validatePortMapping(pm *api.PodPortMapping) error {
return err
}
if pm.HostPort != nil {
if err := p.validatePort(*pm.HostPort); err != nil {
if err := p.validatePort(*pm.HostPort, api.POD_PORT_MAPPING_RANGE_START, api.POD_PORT_MAPPING_RANGE_END); err != nil {
return errors.Wrap(err, "validate host_port")
}
}
if err := p.validatePort(pm.ContainerPort); err != nil {
if err := p.validatePort(pm.ContainerPort, 1, 65535); err != nil {
return errors.Wrap(err, "validate container_port")
}
if pm.Protocol == "" {
+5 -5
View File
@@ -411,8 +411,8 @@ func (s *sPodGuestInstance) getPortMapping(pm *computeapi.PodPortMapping) (*runt
}
return runtimePm, nil
} else {
start := 20000
end := 25000
start := computeapi.POD_PORT_MAPPING_RANGE_START
end := computeapi.POD_PORT_MAPPING_RANGE_END
if pm.HostPortRange != nil {
start = pm.HostPortRange.Start
end = pm.HostPortRange.End
@@ -1157,15 +1157,15 @@ func (s *sPodGuestInstance) PullImage(ctx context.Context, userCred mcclient.Tok
}), nil
}
}
podCfg, err := s.getPodSandboxConfig()
/*podCfg, err := s.getPodSandboxConfig()
if err != nil {
return nil, errors.Wrap(err, "get pod sandbox config")
}
}*/
req := &runtimeapi.PullImageRequest{
Image: &runtimeapi.ImageSpec{
Image: input.Image,
},
SandboxConfig: podCfg,
// SandboxConfig: podCfg,
}
if input.Auth != nil {
authCfg := &runtimeapi.AuthConfig{