From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-firewall v2 2/9] api: ipset: add option to update references on edit
Date: Tue, 18 Aug 2026 15:34:06 +0200 [thread overview]
Message-ID: <20260818133413.450776-3-a.bied-charreton@proxmox.com> (raw)
In-Reply-To: <20260818133413.450776-1-a.bied-charreton@proxmox.com>
Renaming an ipset still referenced by rules leaves dangling references.
The firewall then fails to parse those rules during compilation and
drops them. The errors, while logged to the journal, are not visible
from the GUI - a rename can therefore effectively disable a whole set
of rules.
Add an 'update-references' option to the rename path to rewrite them to
the new name. For cluster ipsets, this also covers references in
downstream configs (host, guest and vnet).
The new ipset is persisted before its references are rewritten, so a
concurrent firewall compilation never observes a dangling reference. If
the cluster-wide rewrite is interrupted, it can be retried by passing
'update-references=force'.
Signed-off-by: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
---
src/PVE/API2/Firewall/IPSet.pm | 59 +++++++++++++++++++++++++++-------
1 file changed, 48 insertions(+), 11 deletions(-)
diff --git a/src/PVE/API2/Firewall/IPSet.pm b/src/PVE/API2/Firewall/IPSet.pm
index ca7228b..0d802aa 100644
--- a/src/PVE/API2/Firewall/IPSet.pm
+++ b/src/PVE/API2/Firewall/IPSet.pm
@@ -528,6 +528,7 @@ package PVE::API2::Firewall::BaseIPSetList;
use strict;
use warnings;
+use PVE::Firewall::Helpers qw(update_refs get_object_spec);
use PVE::JSONSchema qw(get_standard_option);
use PVE::Exception qw(raise_param_exc);
use PVE::Firewall;
@@ -655,6 +656,16 @@ sub register_create {
},
);
+ $properties->{'update-references'} = {
+ type => 'string',
+ enum => ['no', 'yes', 'force'],
+ optional => 1,
+ description =>
+ "Update all references to the IPSet when renaming it. Use 'force' to also "
+ . "overwrite an existing target IPSet, e.g. to resume an interrupted rename.",
+ default => 'no',
+ };
+
$class->register_method({
name => 'create_ipset',
path => '',
@@ -675,6 +686,8 @@ sub register_create {
sub {
my ($param) = @_;
+ my $update_references = $param->{'update-references'} // 'no';
+
my ($cluster_conf, $fw_conf) = $class->load_config($param);
if ($param->{rename}) {
@@ -685,18 +698,42 @@ sub register_create {
if !$fw_conf->{ipset}->{ $param->{rename} };
# prevent overwriting existing ipset
- raise_param_exc({ name => "IPSet '$param->{name}' does already exist" })
- if $fw_conf->{ipset}->{ $param->{name} }
- && $param->{name} ne $param->{rename};
-
- my $data = delete $fw_conf->{ipset}->{ $param->{rename} };
- $fw_conf->{ipset}->{ $param->{name} } = $data;
- if (
- my $comment =
- delete $fw_conf->{ipset_comments}->{ $param->{rename} }
- ) {
- $fw_conf->{ipset_comments}->{ $param->{name} } = $comment;
+
+ if ($param->{name} ne $param->{rename}) {
+ raise_param_exc({
+ name => "IPSet '$param->{name}' does already exist" })
+ if $fw_conf->{ipset}->{ $param->{name} }
+ && ($update_references // '') ne 'force';
+
+ $fw_conf->{ipset}->{ $param->{name} } =
+ $fw_conf->{ipset}->{ $param->{rename} };
+
+ if ($update_references ne 'no') {
+ my $env = $class->rule_env();
+ my $spec = get_object_spec('ipset');
+ my $old = $param->{rename};
+ my $new = $param->{name};
+
+ # persist the new ipset before rewriting references so a concurrent
+ # compilation never sees a reference to a not-yet-saved ipset.
+ $class->save_config($param, $fw_conf) if $env eq 'cluster';
+
+ eval { update_refs($fw_conf, $spec, $old, $new, $env) };
+ die "rename interrupted, references may be partially updated; "
+ . "retry with 'force' to finish: $@"
+ if $@;
+ }
+
+ delete $fw_conf->{ipset}->{ $param->{rename} };
+
+ if (
+ my $comment =
+ delete $fw_conf->{ipset_comments}->{ $param->{rename} }
+ ) {
+ $fw_conf->{ipset_comments}->{ $param->{name} } = $comment;
+ }
}
+
$fw_conf->{ipset_comments}->{ $param->{name} } = $param->{comment}
if defined($param->{comment});
} else {
--
2.47.3
next prev parent reply other threads:[~2026-08-18 13:35 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 13:34 [PATCH firewall/manager v2 0/9] allow updating references when renaming/deleting firewall objects Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-firewall v2 1/9] api: helpers: add helper to update firewall object references Arthur Bied-Charreton
2026-08-18 13:34 ` Arthur Bied-Charreton [this message]
2026-08-18 13:34 ` [PATCH pve-firewall v2 3/9] api: ipset: add option to GC references on delete Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-firewall v2 4/9] api: aliases: add option to update references on edit Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-firewall v2 5/9] api: aliases: add option to GC references on delete Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-firewall v2 6/9] firewall: tests: add tests for object reference update logic Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-manager v2 7/9] ui: firewall: add common widgets for deleting and updating references Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-manager v2 8/9] ui: firewall: ipset: add controls to update/delete references on edit Arthur Bied-Charreton
2026-08-18 13:34 ` [PATCH pve-manager v2 9/9] ui: firewall: aliases: " Arthur Bied-Charreton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260818133413.450776-3-a.bied-charreton@proxmox.com \
--to=a.bied-charreton@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.