Red Hat Bugzilla – Bug 1534607
Unable to use paging when searching for VMs available for specific user sorted by name
Last modified: 2018-02-27 02:04:19 EST
Created attachment 1381524 [details]
Engine log produced by GET request.
Description of problem:
Result: it return sorted VMs fine
Result: it return 8 VMs
Result: it return empty result
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Create two VMs
2. Use user other than admin
3. Set UserRole in that VMs for that user
4. Fire get request https://engine/ovirt-engine/api/vms/?max=1&search=SORTBY%20NAME%20ASC
Sorted by name 1 VM
It applies to current master (commit 0427560272) as well. It reproduces even for admin@internal user. 'Filter: true' header has to be sent.
It works like this (swap the search and max):
/api/vms?search=SORTBY NAME ASC&max=2
Oh, but it doesn't work for 'filter: true', I see.
* Order of search and max query params doesn't matter. The problem appears in both cases.
* It appears even in 4.1 branch (commit 2591f4baa5)
* Steps to reproduce 2 (always use user admin@internal):
1. make sure there are no vms in the engine
2. create a vm called "vm"
3. add a UserRole to it for admin@internal user
4. create a template
5. create a vm pool of 1 VM called "a-pool"
6. create a vm pool of 1 VM called "z-pool"
7. fire api request
GET /api/vms?search=SORTBY NAME ASC&max=1
Actual result: <vms/>
* Possible cause:
Method AbstractBackendCollectionResource#getBackendCollection(VdcQueryType, VdcQueryParametersBase, SearchType) executes two queries
* GetAllVmsQuery that results all vms that a user has permission to. Results are trimmed to length of 'max' param.
* SearchQuery that does filtering on name and applies limit and offset criteria.
Result of the get request is a set intersection of results of these queries.
In steps to reproduce 2 GetAllVmsQuery returns VM "vm" and SearchQuery may return a VM from a pool. Intersection of these results is empty.
Urgent because current (and only) VM portal can't reliably show VMs due to this bug.
Search engine is not usable with permissions and it would required complete redesign of it to allow that. That's why we decided to internally provide specialized query which is able to fetch VMs by name for specific user and provide paging support for it.
Martin, we need this fix promptly. It blocks RHEV.TLV. When can we have it?
(In reply to Yaniv Kaul from comment #7)
> Martin, we need this fix promptly. It blocks RHEV.TLV. When can we have it?
It should be merged till tomorrow, but marking this one as a blocker for 4.2.2
Verified by following steps in comment 4 and in the description for non-admin user.