all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Fiona Ebner <f.ebner@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH container v3 21/21] migration: intra-cluster: check config can be parsed on target node
Date: Fri, 18 Sep 2026 18:08:27 +0200	[thread overview]
Message-ID: <20260918160841.128088-22-f.ebner@proxmox.com> (raw)
In-Reply-To: <20260918160841.128088-1-f.ebner@proxmox.com>

For remote migration, we already check that the config can be parsed
on the target. Do the same for intra-cluster migration, to avoid
issues with future new settings unexpectedly being ignored if the
target is too old. For example, migrating a container with a
mountpoint with 'keepattrs' to a node with a too old pve-container
version, results in the mountpoint not being mounted on the target.

Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
---

The node version might need to be adapted when applying!

Changes in v3:
* add skip-config-check flag rather than re-using force.
* check node version to decide if too old or not.

 src/PVE/API2/LXC.pm    | 13 ++++++++++++-
 src/PVE/LXC/Migrate.pm | 30 ++++++++++++++++++++++++++++++
 2 files changed, 42 insertions(+), 1 deletion(-)

diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm
index c89837e..c5e3b04 100644
--- a/src/PVE/API2/LXC.pm
+++ b/src/PVE/API2/LXC.pm
@@ -82,12 +82,23 @@ my $migrate_json_properties = {
         minimum => '0',
         default => 'migrate limit from datacenter or storage config',
     },
+    'skip-config-check' => {
+        type => 'boolean',
+        optional => 1,
+        default => 0,
+        description =>
+            'For intra-cluster migration. Skip checking if the configuration can be parsed'
+            . ' successfully by the target. Using this flag can lead to ignored'
+            . ' configuration options if the target is too old to parse them.',
+    },
 };
 
 # Properties that will be forwarded via the HA stack to the LRM, which will then use them for its
 # own invocation of the migration API endpoint. The other properties are not forwarded and lost for
 # HA migrations with many being hard-coded for the LRM invocation.
-my $ha_migrate_props = {};
+my $ha_migrate_props = {
+    'skip-config-check' => 1,
+};
 
 sub ha_migrate_json_properties {
     my $forwarded_props = {};
diff --git a/src/PVE/LXC/Migrate.pm b/src/PVE/LXC/Migrate.pm
index d243d90..a8d3a3d 100644
--- a/src/PVE/LXC/Migrate.pm
+++ b/src/PVE/LXC/Migrate.pm
@@ -159,6 +159,36 @@ sub prepare {
         my $cmd = [@{ $self->{rem_ssh} }, '/bin/true'];
         eval { $self->cmd_quiet($cmd); };
         die "Can't connect to destination address using public key\n" if $@;
+
+        if (!$self->{opts}->{'skip-config-check'}) {
+            if (PVE::Cluster::node_pvecfg_version_at_least($self->{node}, 9, 2, 21)) {
+                # Fork a short-lived tunnel for checking the config. Later, the proper tunnel with
+                # SSH forwarding info is forked.
+                my $tunnel = PVE::Tunnel::fork_ssh_tunnel(
+                    $self->{rem_ssh},
+                    ['pct', 'mtunnel'],
+                    undef,
+                    sub {
+                        my ($level, $msg) = @_;
+                        $self->log($level, $msg);
+                    },
+                );
+                eval {
+                    my $nodename = PVE::INotify::nodename();
+                    PVE::Tunnel::write_tunnel($tunnel, 30, "config $vmid $nodename");
+                };
+                my $err = $@;
+
+                eval { PVE::Tunnel::finish_tunnel($tunnel); };
+                $self->log('warn', "failed to finish tunnel in prepare() - $@") if $@;
+
+                die "$err - use 'skip-config-check' flag to migrate regardless\n" if $err;
+            } else {
+                $self->log('info', "skipping config check - target pve-manager version < 9.2.21");
+            }
+        } else {
+            $self->log('info', "skipping config check - override option is set");
+        }
     }
 
     # in restart mode, we shutdown the container before migrating
-- 
2.47.3





      parent reply	other threads:[~2026-09-18 16:11 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 16:08 [PATCH-SERIES common/cluster/ha-manager/qemu-server/container v3 00/21] migration: strict config check for intra-cluster migration Fiona Ebner
2026-09-18 16:08 ` [PATCH common v3 01/21] tools: move version_cmp() helper from qemu-server Fiona Ebner
2026-09-18 16:08 ` [PATCH common v3 02/21] rest handler: handle: respect schema's 'type-property' when resolving type Fiona Ebner
2026-09-18 16:08 ` [PATCH cluster v3 03/21] cluster: move pvecfg node version helpers from qemu-server Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 04/21] next state {stopped,started}: factor out helper to handle motion command Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 05/21] lrm: resource migration: support extra migration options Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 06/21] change service state: support hash as a parameter value Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 07/21] next state: handle motion command: support migration options Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 08/21] queue resource motion: " Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 09/21] crm command: support JSON-style migrate command Fiona Ebner
2026-09-18 16:08 ` [PATCH ha-manager v3 10/21] api: resources: migration: support additional migration options Fiona Ebner
2026-09-18 16:21   ` Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 11/21] helpers: move version_cmp() helper to pve-common Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 12/21] helpers: move pvecfg node version helpers to pve-cluster Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 13/21] api: migrate: allow forwarding certain migration properties to HA Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 14/21] fix #7053: api: migrate: pass 'with-conntrack-state' flag to HA migration Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 15/21] qm: mtunnel: reply when a command is unknown Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 16/21] qm: mtunnel: add 'conf' command to do strict configuration parsing Fiona Ebner
2026-09-18 16:08 ` [PATCH qemu-server v3 17/21] migration: intra-cluster: check config can be parsed on target node Fiona Ebner
2026-09-18 16:08 ` [PATCH container v3 18/21] api: migrate: allow forwarding certain migration properties to HA Fiona Ebner
2026-09-18 16:08 ` [PATCH container v3 19/21] pct: introduce mtunnel command Fiona Ebner
2026-09-18 16:08 ` [PATCH container v3 20/21] d/control: bump versioned build dependency for libpve-common-perl to 9.0.12 Fiona Ebner
2026-09-18 16:08 ` Fiona Ebner [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918160841.128088-22-f.ebner@proxmox.com \
    --to=f.ebner@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal