all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Fiona Ebner <f.ebner@proxmox.com>
To: Lukas Sichert <l.sichert@proxmox.com>,
	Jakob Klocker <j.klocker@proxmox.com>,
	pve-devel@lists.proxmox.com
Subject: Re: [PATCH container] fix: #7148: check CT protection before reassigning volume
Date: Wed, 26 Aug 2026 16:22:22 +0200	[thread overview]
Message-ID: <cf28354b-0ba9-4c59-8f30-2abcb8c23fac@proxmox.com> (raw)
In-Reply-To: <DJ16OWI5TDRQ.K6IDKMBUR3F8@proxmox.com>

Am 05.06.26 um 4:26 PM schrieb Lukas Sichert:
> I was able to reproduce the Problem, the Patch worked for me.
> 
> One thing I found, which is only indirectly related:
> One can't move storage to a protected container, but one can move
> storage from a protected container to an unprotected container, which to
> my intuition seems wrong.
> Is this expected behaviour?
The documentation agrees that this is wrong:

protection: <boolean> (default = 0)
Sets the protection flag of the container. This will prevent the CT or
CT’s disk remove/update operation.

And looking into the code, all direct config changes to
mpX/unusedX/rootfs are prohibited. So reassign should be prohibited in
both directions.

For VMs, the flag is documented as:

protection: <boolean> (default = 0)
Sets the protection flag of the VM. This will disable the remove VM and
remove disk operations.

Adding disks to a protected VM works, but removing a disk does not. So
reassign away from a protected VM should also be prohibited. It
currently isn't.

If we want to further restrict adding disks to a protected VM, that
should be done for the next major release, but I'm not fully sure we
should go for that.

@Jakob: could you send follow-ups for those issues?

> 
> Tested-by: Lukas Sichert <l.sichert@proxmox.com>
> 
> On 2026-06-01 13:52, Jakob Klocker <j.klocker@proxmox.com> wrote:
> 
>> When reassigning a volume, check the destination config before
>> removing the volume from the source config.
>>
>> Link: https://bugzilla.proxmox.com/show_bug.cgi?id=7148
>> Signed-off-by: Jakob Klocker <j.klocker@proxmox.com>
>> ---
>>  src/PVE/API2/LXC.pm | 2 ++
>>  1 file changed, 2 insertions(+)
>>
>> diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm
>> index 88067dd..af01de0 100644
>> --- a/src/PVE/API2/LXC.pm
>> +++ b/src/PVE/API2/LXC.pm
>> @@ -2791,6 +2791,8 @@ __PACKAGE__->register_method({
>>                      if !PVE::Storage::storage_can_replicate($storecfg, $storeid, $format);
>>              }
>>  
>> +            PVE::LXC::Config->check_protection($target_conf, "can't move volume '$target_mpkey' to CT $target_vmid");
>> +
>>              return ($source_conf, $target_conf, $drive);
>>          };
>>  
>> -- 
>> 2.47.3
> 
> 
> 
> 
> 





  reply	other threads:[~2026-08-26 14:22 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-01 11:52 [PATCH container] fix: #7148: check CT protection before reassigning volume Jakob Klocker
2026-06-05 14:26 ` Lukas Sichert
2026-08-26 14:22   ` Fiona Ebner [this message]
2026-08-26 14:16 ` applied: " Fiona Ebner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cf28354b-0ba9-4c59-8f30-2abcb8c23fac@proxmox.com \
    --to=f.ebner@proxmox.com \
    --cc=j.klocker@proxmox.com \
    --cc=l.sichert@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal