Created attachment 1839473 [details] action_list Description of problem: Log in with a normal user and assign view permission to a different namespace, check VM actions in the view only namespace, pause and migration is enabled. Version-Release number of selected component (if applicable): 4.9.0 How reproducible: 100% Steps to Reproduce: 1. create a normal user 'test' and give it view permission to a different namespace 'default' $ oc adm policy add-role-to-user view test -n default 2. create a VM in namespace 'default' 3. login with user 'test' and view VM actions in 'default' Actual results: pause and migration is enabled. Expected results: pause and migration should be disabled just like other actions "stop", "restart". Additional info:
Due to complexity, the fix will be tracked in Jira: https://issues.redhat.com/browse/CNV-14855
Reopen the bug, it's not fixed by bz2028106
Gilad note: When enabling live migrate action we also need to check the VMI (vm-instance) condition 'type:LiveMigratable' to be 'True'
Verified on 4.10.0-0.ci-2021-12-30-053634
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: OpenShift Container Platform 4.10.3 security update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2022:0056