From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-manager v2 01/12] network interface pinning: write new firewall config to local dir
Date: Thu, 1 Oct 2026 14:26:14 +0200 [thread overview]
Message-ID: <20261001122625.348730-2-a.bied-charreton@proxmox.com> (raw)
In-Reply-To: <20261001122625.348730-1-a.bied-charreton@proxmox.com>
Preparatory step for restoring firewall rules before pve-cluster is up.
The boot-time restore recompiles the ruleset from the firewall config
dumped to local disk. Interface name pinnings only take effect on the
next boot, so a host.fw dumped before a pinning change still carries the
old interface names, and recompiling from it would produce rules
matching interfaces that no longer exist.
pve-network-interface-pinning already writes the updated config to
host.fw.new. Also write it to the local dump directory so the boot-time
restore prefers it over the stale host.fw; the local copy is removed
again in pve-firewall-commit once the pinning has been committed.
Signed-off-by: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
Reviewed-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Tested-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
---
PVE/CLI/pve_network_interface_pinning.pm | 6 +++++-
bin/pve-firewall-commit | 1 +
2 files changed, 6 insertions(+), 1 deletion(-)
diff --git a/PVE/CLI/pve_network_interface_pinning.pm b/PVE/CLI/pve_network_interface_pinning.pm
index 9dff181d..758b2107 100644
--- a/PVE/CLI/pve_network_interface_pinning.pm
+++ b/PVE/CLI/pve_network_interface_pinning.pm
@@ -22,6 +22,8 @@ use base qw(PVE::CLIHandler);
my $PVEETH_LOCK = "/run/lock/proxmox-network-interface-pinning.lck";
+my $local_dump_dir = "/var/lib/pve/firewall";
+
sub setup_environment {
PVE::RPCEnvironment->setup_default_cli_env();
}
@@ -120,7 +122,7 @@ my sub update_host_fw_config {
my ($mapping) = @_;
my $local_node = PVE::INotify::nodename();
- print "Updating /etc/pve/nodes/$local_node/host.fw.new\n";
+ print "Updating /etc/pve/nodes/$local_node/host.fw.new and $local_dump_dir/host.fw.new\n";
my $code = sub {
my $cluster_conf = PVE::Firewall::load_clusterfw_conf();
@@ -143,6 +145,8 @@ my sub update_host_fw_config {
}
PVE::Firewall::save_hostfw_conf($host_conf, "/etc/pve/nodes/$local_node/host.fw.new");
+ make_path($local_dump_dir, { mode => 0700 });
+ PVE::Firewall::save_hostfw_conf($host_conf, "$local_dump_dir/host.fw.new");
};
PVE::Firewall::run_locked($code);
diff --git a/bin/pve-firewall-commit b/bin/pve-firewall-commit
index 3d208f67..cbb71f58 100644
--- a/bin/pve-firewall-commit
+++ b/bin/pve-firewall-commit
@@ -23,5 +23,6 @@ if (-e $new_fw_config_file) {
rename($new_fw_config_file, $current_fw_config_file)
or die "failed to commit new local node firewall config '$new_fw_config_file' - $!\n";
}
+unlink "/var/lib/pve/firewall/host.fw.new";
exit 0;
--
2.47.3
next prev parent reply other threads:[~2026-10-01 12:26 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 12:26 [RFC firewall/manager/proxmox{,-firewall} v2 00/12] fix #5759: keep firewall rules up across boot and shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` Arthur Bied-Charreton [this message]
2026-10-01 12:26 ` [PATCH pve-firewall v2 02/12] firewall: config: sort OPTIONS when serializing Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 03/12] firewall: dump configs locally after applying Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 04/12] fix #5759: firewall: do not remove chains when host is shutting down Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 05/12] firewall: add restore command Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 06/12] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox v2 07/12] systemd: systemctl: add is-system-running helper Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 08/12] firewall: fix clippy warnings Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 09/12] fix #5759: firewall: do not clear rules on system shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 10/12] firewall: dump config to local directory after apply Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 11/12] firewall: add restore command Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 12/12] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001122625.348730-2-a.bied-charreton@proxmox.com \
--to=a.bied-charreton@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.