oss-sec: [OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented
oss-sec<br>mailing list archives
By Date
By Thread
[OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented
From: Jay Faulkner
Date: Thu, 13 Aug 2026 13:42:03 -0700
Ironic Python Agent Container HardwareManager Security Misimplemented
### Summary ###<br>Ironic Python Agent's ContainerHardwareManager plugin, shipped in<br>2025.2, was merged with a misimplemented security model.
Ironic developers have pushed an updated version of this feature,<br>including patches for Ironic and Ironic Python Agent, with properly<br>implemented security controls. These patches will not be universally<br>backported as they are not backwards-compatible.
### Affected Services / Software ###<br>- ironic-python-agent: >=11.0.0, https://review.opendev.org/q/hashtag:%22container-hwm-patches%22<br>to the branch they are currently using. Then, evaluate your use<br>case against the updated documentation<br>https://docs.openstack.org/ironic/latest/admin/container-based-steps.html<br>to ensure the changes were not breaking for any existing deployment.
### Credits ###<br>- Tuomo Tanskanen, Ericsson Software Technology (Metal3.io Security Team)<br>- Riccardo Pittau, Red Hat (Metal3.io Security Team)
### Contacts / References ###<br>Authors:<br>- Jay Faulkner, G-Research OSS
This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0107<br>Original Launchpad bug: https://bugs.launchpad.net/ironic/+bug/2160143<br>Mailing List : [security-sig] tag on openstack-discuss () lists openstack org<br>OpenStack Security : https://security.openstack.org/<br>CVE: none
Attachment:<br>OpenPGP_signature.asc
Description: OpenPGP digital signature
By Date
By Thread
Current thread:
[OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented Jay Faulkner (Aug 13)