From: Fiona Ebner <f.ebner@proxmox.com>
To: Lukas Sichert <l.sichert@proxmox.com>,
Jakob Klocker <j.klocker@proxmox.com>,
pve-devel@lists.proxmox.com
Subject: Re: [PATCH container] fix: #7148: check CT protection before reassigning volume
Date: Wed, 26 Aug 2026 16:22:22 +0200 [thread overview]
Message-ID: <cf28354b-0ba9-4c59-8f30-2abcb8c23fac@proxmox.com> (raw)
In-Reply-To: <DJ16OWI5TDRQ.K6IDKMBUR3F8@proxmox.com>
Am 05.06.26 um 4:26 PM schrieb Lukas Sichert:
> I was able to reproduce the Problem, the Patch worked for me.
>
> One thing I found, which is only indirectly related:
> One can't move storage to a protected container, but one can move
> storage from a protected container to an unprotected container, which to
> my intuition seems wrong.
> Is this expected behaviour?
The documentation agrees that this is wrong:
protection: <boolean> (default = 0)
Sets the protection flag of the container. This will prevent the CT or
CT’s disk remove/update operation.
And looking into the code, all direct config changes to
mpX/unusedX/rootfs are prohibited. So reassign should be prohibited in
both directions.
For VMs, the flag is documented as:
protection: <boolean> (default = 0)
Sets the protection flag of the VM. This will disable the remove VM and
remove disk operations.
Adding disks to a protected VM works, but removing a disk does not. So
reassign away from a protected VM should also be prohibited. It
currently isn't.
If we want to further restrict adding disks to a protected VM, that
should be done for the next major release, but I'm not fully sure we
should go for that.
@Jakob: could you send follow-ups for those issues?
>
> Tested-by: Lukas Sichert <l.sichert@proxmox.com>
>
> On 2026-06-01 13:52, Jakob Klocker <j.klocker@proxmox.com> wrote:
>
>> When reassigning a volume, check the destination config before
>> removing the volume from the source config.
>>
>> Link: https://bugzilla.proxmox.com/show_bug.cgi?id=7148
>> Signed-off-by: Jakob Klocker <j.klocker@proxmox.com>
>> ---
>> src/PVE/API2/LXC.pm | 2 ++
>> 1 file changed, 2 insertions(+)
>>
>> diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm
>> index 88067dd..af01de0 100644
>> --- a/src/PVE/API2/LXC.pm
>> +++ b/src/PVE/API2/LXC.pm
>> @@ -2791,6 +2791,8 @@ __PACKAGE__->register_method({
>> if !PVE::Storage::storage_can_replicate($storecfg, $storeid, $format);
>> }
>>
>> + PVE::LXC::Config->check_protection($target_conf, "can't move volume '$target_mpkey' to CT $target_vmid");
>> +
>> return ($source_conf, $target_conf, $drive);
>> };
>>
>> --
>> 2.47.3
>
>
>
>
>
next prev parent reply other threads:[~2026-08-26 14:22 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-01 11:52 [PATCH container] fix: #7148: check CT protection before reassigning volume Jakob Klocker
2026-06-05 14:26 ` Lukas Sichert
2026-08-26 14:22 ` Fiona Ebner [this message]
2026-08-26 14:16 ` applied: " Fiona Ebner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cf28354b-0ba9-4c59-8f30-2abcb8c23fac@proxmox.com \
--to=f.ebner@proxmox.com \
--cc=j.klocker@proxmox.com \
--cc=l.sichert@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.