From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 506631FF0AF for ; Thu, 24 Sep 2026 18:15:20 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 56BDA2164D; Thu, 24 Sep 2026 18:15:16 +0200 (CEST) From: =?UTF-8?q?Michael=20K=C3=B6ppl?= To: pve-devel@lists.proxmox.com Subject: [PATCH cluster v6 03/18] datacenter config: next-id: add enforce subproperty Date: Thu, 24 Sep 2026 18:14:55 +0200 Message-ID: <20260924161510.847362-4-m.koeppl@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260924161510.847362-1-m.koeppl@proxmox.com> References: <20260924161510.847362-1-m.koeppl@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1790266512647 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.494 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: OEBVLM5EFTD65IHXCEKKPRTC2RHEIFF6 X-Message-ID-Hash: OEBVLM5EFTD65IHXCEKKPRTC2RHEIFF6 X-MailFrom: m.koeppl@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Add 'enforce' as a subproperty to the next-id config schema. If enabled, guest IDs outside of the configured range are rejected and, if 'unique' is enabled as well, previously used IDs are also rejected, even if they are not currently in use. The boundaries of the range count only when explicitly configured, not for defaults. Signed-off-by: Michael Köppl --- src/PVE/DataCenterConfig.pm | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/src/PVE/DataCenterConfig.pm b/src/PVE/DataCenterConfig.pm index 4a58efe..5f4960c 100644 --- a/src/PVE/DataCenterConfig.pm +++ b/src/PVE/DataCenterConfig.pm @@ -224,6 +224,14 @@ my $next_id_format = { default => 0, optional => 1, }, + enforce => { + type => 'boolean', + description => "Reject IDs for new guests outside of the configured" + . " 'lower' and 'upper' boundaries and, with 'unique', IDs that" + . " were used before.", + default => 0, + optional => 1, + }, }; my $u2f_format = { -- 2.47.3