From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Cc: pve-devel@lists.proxmox.com
Subject: Re: SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away
Date: Wed, 30 Sep 2026 10:22:54 +0200 [thread overview]
Message-ID: <3szzwo47yubk7wzebw2ljxudwf7f36rgnu5pfudrn7ocffjeay@axig2y7zxujd> (raw)
In-Reply-To: <DLSHEORJIWSO.1YBVQJ32J47G7@proxmox.com>
On Wed, Sep 30, 2026 at 09:44:25AM +0200, Thomas Ellmenreich wrote:
> Thanks for sending in this series!
>
thanks for having a look :)
> I ran some basic tests on the renaming and dropping functionality and found
> that everything worked well.
>
> Looking at the different operations that now have a new option to deal with
> references, 'disable' is always possible, why is that not the case for rename.
> There might be a technical reason that I'm currently not thinking of, but I
> can see 'disabling' the referencing rules being a worthwhile option when
> performing a rename.
>
good point, I had not considered that. it could be useful when the old
name is going to be reused afterwards. I am not sure how common this
would be in practice, but the helper already implements 'disable', so
wiring it up for rename is cheap.
I will look into this!
> The tests I performed were:
>
> Renaming of aliases and ipsets:
> For this, I created aliases both at the cluster and vm level. I then
> referenced these aliases in the firewall rules of the cluster, node and vm.
> The aliases and ipsets defined at the vm level were only referenced in vm
> level rules. Performing some renames with the different settings acted
> exactly as expected. I also used an alias in one of the ip sets and the
> rename worked perfectly in that case as well.
>
> Simple benchmark for rename:
> By creating 500 guests and then defining a firewall rule on each guest
> referencing a cluster level alias, I could then benchmark the renaming of
> the alias. On average it took ~2,5 seconds which I find reasonable.
>
> Deletion of vms:
> When deleting a vm, one has the option to keep/disable/delete the
> referencing rules. After creating the 500 vms for the benchmark, I added
> some more rules that reference the IPAM aliases. Using keep/disable/delete
> all worked exactly as expected.
>
thanks a lot for the extensive testing!
> So, aside from the question mentioned at the very beginning, consider this:
>
> Tested-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
>
> On Fri Sep 25, 2026 at 11:42 AM CEST, Arthur Bied-Charreton wrote:
>
> > [...]
>
> [snip]
prev parent reply other threads:[~2026-09-30 8:23 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 9:42 SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 01/16] helpers: add helpers to update firewall object references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 02/16] parser: do not log errors for disabled rules Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 03/16] api: ipset: add option to update references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 04/16] api: ipset: add option to handle dangling references on delete Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 05/16] api: aliases: add option to update references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 06/16] api: aliases: add option to handle dangling references on delete Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-firewall v3 07/16] firewall: tests: add tests for object reference update logic Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-network v3 08/16] apply: add option to handle dangling references on VNet deletion Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH qemu-server v3 09/16] api: destroy_vm: add option to handle dangling IPSet references Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-container v3 10/16] " Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-manager v3 11/16] ui: firewall: add common widgets for deleting and updating references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 12/16] ui: firewall: ipset: add controls to update/delete references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 13/16] ui: firewall: aliases: " Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 14/16] ui: sdn: apply: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 15/16] ui: guest destroy: use let for non-constant variable bindings Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 16/16] ui: guest destroy: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25 11:05 ` SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away Arthur Bied-Charreton
2026-09-30 7:44 ` Thomas Ellmenreich
2026-09-30 8:22 ` Arthur Bied-Charreton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3szzwo47yubk7wzebw2ljxudwf7f36rgnu5pfudrn7ocffjeay@axig2y7zxujd \
--to=a.bied-charreton@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
--cc=t.ellmenreich@proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.