From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id BC9021FF0A7 for ; Tue, 18 Aug 2026 15:34:20 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 5FF7721536; Tue, 18 Aug 2026 15:34:18 +0200 (CEST) From: Arthur Bied-Charreton To: pve-devel@lists.proxmox.com Subject: [PATCH pve-firewall v2 4/9] api: aliases: add option to update references on edit Date: Tue, 18 Aug 2026 15:34:08 +0200 Message-ID: <20260818133413.450776-5-a.bied-charreton@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260818133413.450776-1-a.bied-charreton@proxmox.com> References: <20260818133413.450776-1-a.bied-charreton@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 1 AWL -0.706 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Message-ID-Hash: 2SRY3MKDWERIN35JBH3YUBFMFL7AFH5P X-Message-ID-Hash: 2SRY3MKDWERIN35JBH3YUBFMFL7AFH5P X-MailFrom: abied-charreton@jett.proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Renaming an alias still referenced by rules leaves dangling references. The firewall then fails to parse those rules during compilation and drops them. The errors, while logged to the journal, are not visible from the GUI - a rename can therefore effectively disable a whole set of rules. Add an 'update-references' option to the rename path to rewrite them to the new name. For cluster aliases, this also covers references in downstream configs (host, guest and vnet). The new alias is persisted before its references are rewritten, so a concurrent firewall compilation never observes a dangling reference. If the cluster-wide rewrite is interrupted, it can be retried by passing 'update-references=force'. Signed-off-by: Arthur Bied-Charreton --- src/PVE/API2/Firewall/Aliases.pm | 40 +++++++++++++++++++++++++++++--- 1 file changed, 37 insertions(+), 3 deletions(-) diff --git a/src/PVE/API2/Firewall/Aliases.pm b/src/PVE/API2/Firewall/Aliases.pm index 4f6960d..657f333 100644 --- a/src/PVE/API2/Firewall/Aliases.pm +++ b/src/PVE/API2/Firewall/Aliases.pm @@ -2,6 +2,8 @@ package PVE::API2::Firewall::AliasesBase; use strict; use warnings; + +use PVE::Firewall::Helpers qw(update_refs get_object_spec); use PVE::Exception qw(raise raise_param_exc); use PVE::JSONSchema qw(get_standard_option); @@ -219,6 +221,16 @@ sub register_update_alias { $properties->{comment} = $api_properties->{comment}; $properties->{digest} = get_standard_option('pve-config-digest'); + $properties->{'update-references'} = { + type => 'string', + enum => ['no', 'yes', 'force'], + optional => 1, + description => + "Update all references to the alias when renaming it. Use 'force' to also " + . "overwrite an existing target alias, e.g. to resume an interrupted rename.", + default => 'no', + }; + $class->register_method({ name => 'update_alias', path => '{name}', @@ -239,6 +251,8 @@ sub register_update_alias { sub { my ($param) = @_; + my $update_references = $param->{'update-references'} // 'no'; + my ($fw_conf, $aliases) = $class->load_config($param); my $list = &$aliases_to_list($aliases); @@ -261,9 +275,28 @@ sub register_update_alias { if ($rename && ($name ne $rename)) { raise_param_exc({ name => "alias '$param->{rename}' already exists" }) - if defined($aliases->{$rename}); - $aliases->{$name}->{name} = $param->{rename}; - $aliases->{$rename} = $aliases->{$name}; + if defined($aliases->{$rename}) + && $update_references ne 'force'; + + $aliases->{$rename} = + { $aliases->{$name}->%*, name => $param->{rename} }; + + if ($update_references ne 'no') { + my $env = $class->rule_env(); + my $spec = get_object_spec('aliases'); + my $new_name = $param->{rename}; + + # persist the new alias before rewriting references so a concurrent + # compilation never sees a reference to a not-yet-saved alias. + $class->save_aliases($param, $fw_conf, $aliases) + if $env eq 'cluster'; + + eval { update_refs($fw_conf, $spec, $name, $new_name, $env) }; + die "rename interrupted, references may be partially updated; " + . "retry with 'force' to finish: $@" + if $@; + } + delete $aliases->{$name}; } @@ -311,6 +344,7 @@ sub register_delete_alias { PVE::Tools::assert_if_modified($digest, $param->{digest}); my $name = lc($param->{name}); + delete $aliases->{$name}; $class->save_aliases($param, $fw_conf, $aliases); -- 2.47.3