From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 5EFD41FF138 for ; Mon, 20 Jul 2026 13:29:31 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id BBEAB21542; Mon, 20 Jul 2026 13:29:11 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784390785; x=1784995585; darn=lists.proxmox.com; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pN45qlLZanIZyq4QbsTmslm1YEeNFZgD8vZL3z0Gdtk=; b=f08faus1X+x8tzJvHOQPINXnCJpRytPq4i5LZ/jWOAlGBtl6WipD1bBFxD+lh3TaCG +Iviren/KfsqDApNSVZhgfEvKw7pbnuOum1BkvgFcGAaLVmnZ7Cbhr0ezOykWFcK7rMX PzR8gqq6DByZkHT++Hvg66hGd4xZt9W/A/+TADEviZBK+phmIOy7DVb93Wc6X9tEpSBk aYM6R9O1n50+S7gAd9oGVUseBrLnX+Nw0LlltHD5btX/m6TkJuBOz1aZpndpY0CYO2lE XgRh1qWzjmvLtjv1qlniSyk8nY4lOK/zK8UxtKJ9INFFXMt1nQZc6YuDaRgfFZp6k1Ri pgfA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784390785; x=1784995585; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pN45qlLZanIZyq4QbsTmslm1YEeNFZgD8vZL3z0Gdtk=; b=YuJZgX2OsFhKcFpwmIz0xCI7bXQyPAstrfc1sOGooP5PfURQHgcUzgTzN7vYJtp3nr 7JrVz6BYxTgz+vXlq7Z2O931SOR/FgjqSadF28QHBZaEEgHPpFq9Cx8c/sYPaQTWGaJW EWk1N0ZB/gca0J37P7VHJ5iEjkwRMhBPepCYGbCTfb2UeqK3RJJqHKDZtIH6gAZLML15 Oh6X5caEYHIpktR+9jpGbx+lSO916SApo806QKsNkBzXVBpPO8XnFILTG0NG3G3Snyg7 0tlbsDA0cGm8RuSRq9kUcxjlRZN552CLp19TCjcIVfvFhQ1VNvLjl2lw7EAYwO3t5Inn U2RA== X-Gm-Message-State: AOJu0YwCopDxd4HwcoFF+GWAdgSrzQxAj17gZtPPDf2ktOu3EhUCvxcH 7IcH5M0xt6OCH7cTRK3p3X1FSFge/PsCsoBQu+gVLzkxBDzakf9PmJYdIUGyTw== X-Gm-Gg: AfdE7ckP+XHXVjls1EAnSbOAtYhnWtTNJsSBj1QnuoBTnkwoOzFfMoKaO1yfassJHqs qMr/rlPJLAy4yWCvSZD0tcnpVKA31VTVMzW6EIU3frOAnvOfMxhrbabNz6tV70dQvZs5ByqN5Dy 7IdQdPnrosjgQtrLW4cT7VXUGZPDLQfclWJO/qlxiE2CrM744/P0s8/6Avi21QhOfASKgT/RCiO QrVun7epNNveRj8MOj69QkiJWDb7xQjttfALZPVF77inmwLli0puzvpf48omDqdZKqGv43KJaHA dTqd6RieQwG9ju5Dze3ui3UmhtFYE4faAm2f7y/NGr5NiijtGQajUJf3sejc34+J2lMjcoVV/Gr pIs0BoqYbOUTog8fJ/9iFaImPCvzUrI/RAxqJeW+OADR3OXesxSxrC6vq8Lnyh0Sp9miCKy6hFk LxOH0= X-Received: by 2002:a05:6000:228a:b0:47f:6e05:ebb0 with SMTP id ffacd0b85a97d-47f6e05ed25mr2866551f8f.3.1784390784322; Sat, 18 Jul 2026 09:06:24 -0700 (PDT) From: copystring To: pve-devel@lists.proxmox.com subject: SPAM: [RFC PATCH v2 0/4] lxc: add safe OCI rootfs replacement Date: Sat, 18 Jul 2026 18:05:58 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260706194059.280257-1-copystring@gmail.com> References: <20260706194059.280257-1-copystring@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 3 AWL 0.086 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider POISEN_SPAM_PILL 0.1 Meta: its spam POISEN_SPAM_PILL_1 0.1 random spam to be learned in bayes POISEN_SPAM_PILL_3 0.1 random spam to be learned in bayes RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust RCVD_IN_SBL_CSS 3.558 Received via a relay in Spamhaus SBL-CSS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record X-MailFrom: copystring@gmail.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: EAYIFANPTJQPDFYTDLQNIBQCKSOI2IFX X-Message-ID-Hash: EAYIFANPTJQPDFYTDLQNIBQCKSOI2IFX X-Mailman-Approved-At: Mon, 20 Jul 2026 13:29:01 +0200 CC: copystring X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This RFC adds an explicit rootfs replacement path for stopped LXC containers created from OCI images. The intent is to support the common "refresh the OCI image" workflow without pretending that data stored inside the old rootfs can be merged safely. The safety model is intentionally conservative: * require an explicit confirmation parameter; * only operate on stopped, non-template, non-HA, unprotected CTs without snapshots or pending config changes; * only replace the active rootfs volume, while preserving mpX mount points; * keep the previous rootfs as an unusedX volume instead of deleting it; * fail if no unusedX slot is available; * never remove the newly allocated rootfs once config writing has started; * do not use overlayfs or path heuristics such as /config or /data detection; * reject shrink-like requests by requiring the target size to be at least the current rootfs size. This means data that only exists on / becomes data on the old unused volume, not on the new active rootfs. Users are expected to keep persistent application data on separate mount points or to have a backup before replacing the rootfs. By default, the endpoint also updates OCI-derived runtime config such as entrypoint, environment, ostype, arch and OCI-generated lxc keys. A caller can set update-oci-config=0 to preserve the existing runtime config and only switch the rootfs. Changes since v1: * rebased on current master (ed062ee); * renamed generic helpers that were not OCI-specific; * split the new-rootfs allocation and temporary mount/populate flow into a generic helper, keeping the OCI archive restore as the populate callback and following the same allocate-before-unshare shape as copy_volume; * moved the test Makefile integration into the test patch; * fixed the new test runner file mode to 100755. The pve-manager and pve-docs companion patches from v1 are not resent here, since the backend API and user-facing semantics are unchanged. If this backend shape looks reasonable, they can be resent/rebased once the backend direction is clearer. Tested on a disposable PVE 9.2.2 VM: * git am --keep-cr on current origin/master; * git diff --check origin/master...HEAD; * src/test/run_oci_rootfs_replace_tests.pl; * make -C src check; * make clean deb. copystring (4): lxc: create: add isolated OCI rootfs preparation api: lxc: add OCI rootfs replacement endpoint pct: add OCI rootfs replacement command test: cover OCI rootfs replacement API transaction src/PVE/API2/LXC.pm | 300 ++++++++++++++ src/PVE/CLI/pct.pm | 8 + src/PVE/LXC/Create.pm | 115 ++++++ src/test/Makefile | 4 +- src/test/api-oci-rootfs-replace-test.pm | 486 +++++++++++++++++++++++ src/test/oci-rootfs-replace-test.pm | 250 ++++++++++++ src/test/run_oci_rootfs_replace_tests.pl | 10 + 7 files changed, 1172 insertions(+), 1 deletion(-) create mode 100644 src/test/api-oci-rootfs-replace-test.pm create mode 100644 src/test/oci-rootfs-replace-test.pm create mode 100755 src/test/run_oci_rootfs_replace_tests.pl -- 2.55.0.windows.3