From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 9A9C21FF0AF for ; Thu, 24 Sep 2026 18:17:54 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id EFD04218BC; Thu, 24 Sep 2026 18:15:45 +0200 (CEST) From: =?UTF-8?q?Michael=20K=C3=B6ppl?= To: pve-devel@lists.proxmox.com Subject: [PATCH container v6 13/18] api, migrate: exempt existing CTs from next-id enforcement Date: Thu, 24 Sep 2026 18:15:05 +0200 Message-ID: <20260924161510.847362-14-m.koeppl@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260924161510.847362-1-m.koeppl@proxmox.com> References: <20260924161510.847362-1-m.koeppl@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1790266513533 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.402 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: LDKUM3N7HTDADW4JSCM2QB7T3CL3SQD6 X-Message-ID-Hash: LDKUM3N7HTDADW4JSCM2QB7T3CL3SQD6 X-MailFrom: m.koeppl@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: With 'enforce' set in the next-id datacenter option, register_used_id() rejects IDs outside the configured range and, with 'unique', IDs that were used before. That is only meant for IDs claimed by new guests. Destroying a CT and removing the source CT after a remote migration with --delete both record the ID of a CT that already exists. That ID was recorded when the CT was created and it may lie outside the configured range if the range was changed later. Thus, exempt these cases from enforcement. Signed-off-by: Michael Köppl --- src/PVE/API2/LXC.pm | 2 +- src/PVE/LXC/Migrate.pm | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm index fb4262c9..179eb3c4 100644 --- a/src/PVE/API2/LXC.pm +++ b/src/PVE/API2/LXC.pm @@ -884,7 +884,7 @@ __PACKAGE__->register_method({ $early_checks->($conf); # record before destroying anything, so a failure here leaves the CT intact - eval { PVE::GuestID::register_used_id($vmid) }; + eval { PVE::GuestID::register_used_id($vmid, { existing => 1 }) }; die "unable to destroy CT $vmid - $@" if $@; my $running_error_msg = "unable to destroy CT $vmid - container is running\n"; diff --git a/src/PVE/LXC/Migrate.pm b/src/PVE/LXC/Migrate.pm index a215dede..5db867aa 100644 --- a/src/PVE/LXC/Migrate.pm +++ b/src/PVE/LXC/Migrate.pm @@ -542,7 +542,7 @@ sub final_cleanup { PVE::Tunnel::write_tunnel($self->{tunnel}, 60, 'start'); } if ($self->{opts}->{delete}) { - eval { PVE::GuestID::register_used_id($vmid) }; + eval { PVE::GuestID::register_used_id($vmid, { existing => 1 }) }; warn $@ if $@; PVE::LXC::destroy_lxc_container( -- 2.47.3