From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id E973D1FF0B3 for ; Wed, 09 Sep 2026 12:27:43 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id A4B08215BB; Wed, 09 Sep 2026 12:27:39 +0200 (CEST) Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Wed, 09 Sep 2026 12:27:29 +0200 Message-Id: Subject: Re: [PATCH container] fix: #7148: check CT protection before reassigning volume From: "Jakob Klocker" To: "Fiona Ebner" , "Lukas Sichert" , X-Mailer: aerc 0.20.0 References: <20260601115240.36497-1-j.klocker@proxmox.com> In-Reply-To: X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788949641079 X-SPAM-LEVEL: Spam detection results: 0 AWL 1.598 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: SJOLVZLMQJKWUEPJNT5N77Q2I35BUSAG X-Message-ID-Hash: SJOLVZLMQJKWUEPJNT5N77Q2I35BUSAG X-MailFrom: j.klocker@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Wed Aug 26, 2026 at 4:22 PM CEST, Fiona Ebner wrote: > Am 05.06.26 um 4:26 PM schrieb Lukas Sichert: >> I was able to reproduce the Problem, the Patch worked for me. >>=20 >> One thing I found, which is only indirectly related: >> One can't move storage to a protected container, but one can move >> storage from a protected container to an unprotected container, which to >> my intuition seems wrong. >> Is this expected behaviour? > The documentation agrees that this is wrong: > > protection: (default =3D 0) > Sets the protection flag of the container. This will prevent the CT or > CT=E2=80=99s disk remove/update operation. > > And looking into the code, all direct config changes to > mpX/unusedX/rootfs are prohibited. So reassign should be prohibited in > both directions. > > For VMs, the flag is documented as: > > protection: (default =3D 0) > Sets the protection flag of the VM. This will disable the remove VM and > remove disk operations. > > Adding disks to a protected VM works, but removing a disk does not. So > reassign away from a protected VM should also be prohibited. It > currently isn't. > > If we want to further restrict adding disks to a protected VM, that > should be done for the next major release, but I'm not fully sure we > should go for that. > > @Jakob: could you send follow-ups for those issues? Apologies, I missed Lukas' reply. I'll look into this and send=20 follow-ups. >>=20 >> Tested-by: Lukas Sichert >>=20 >> On 2026-06-01 13:52, Jakob Klocker wrote: >>=20 >>> When reassigning a volume, check the destination config before >>> removing the volume from the source config. >>> >>> Link: https://bugzilla.proxmox.com/show_bug.cgi?id=3D7148 >>> Signed-off-by: Jakob Klocker >>> --- >>> src/PVE/API2/LXC.pm | 2 ++ >>> 1 file changed, 2 insertions(+) >>> >>> diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm >>> index 88067dd..af01de0 100644 >>> --- a/src/PVE/API2/LXC.pm >>> +++ b/src/PVE/API2/LXC.pm >>> @@ -2791,6 +2791,8 @@ __PACKAGE__->register_method({ >>> if !PVE::Storage::storage_can_replicate($storecfg,= $storeid, $format); >>> } >>> =20 >>> + PVE::LXC::Config->check_protection($target_conf, "can't mo= ve volume '$target_mpkey' to CT $target_vmid"); >>> + >>> return ($source_conf, $target_conf, $drive); >>> }; >>> =20 >>> --=20 >>> 2.47.3 >>=20 >>=20 >>=20 >>=20 >>=20