From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 002AE1FF0ED for ; Fri, 31 Jul 2026 11:43:34 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 90E53214B6; Fri, 31 Jul 2026 11:43:28 +0200 (CEST) From: Elias Huhsovitz To: pve-devel@lists.proxmox.com Subject: [PATCH access-control v3 0/2] fix: #6510: Allow deleting ACLs for non-existent entities & add API tests Date: Fri, 31 Jul 2026 11:43:14 +0200 Message-ID: <20260731094316.46388-1-e.huhsovitz@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785490994584 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.030 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) POISEN_SPAM_PILL 0.1 Meta: its spam POISEN_SPAM_PILL_1 0.1 random spam to be learned in bayes POISEN_SPAM_PILL_3 0.1 random spam to be learned in bayes RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: SWN5WESHN4RKLPBELFOF4LE2KG6FHQJG X-Message-ID-Hash: SWN5WESHN4RKLPBELFOF4LE2KG6FHQJG X-MailFrom: e.huhsovitz@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Elias Huhsovitz X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This series fixes Bug #6510, which prevents the deletion of ACLs for non-existent users, groups, API tokens, and roles. Edge cases, such as manual edits, can leave orphaned ACLs in the cluster configuration. Deletion of an orphaned ACL is currently prevented and an error is thrown (e.g., "user 'foo@pve' does not exist"). This happens because the API endpoint strictly validates the existence of the target entity, before processing any request. Patch 1/2 introduces automated tests for the `PUT /access/acl` endpoint. The test suite verifies standard creation, modification, and deletion workflows, enforces privilege boundaries, validates input parameters, and specifically tests the edge cases mentioned in the bug report. Patch 2/2 modifies the `update_acl` API endpoint to bypass the entity and role existence checks when the `delete` flag is set. This allows administrators to clean up orphaned ACL entries. Changes v2 -> v3: ----------------- * Fix a bug that caused the API to crash or skip deletions when removing ACLs for non-existent roles. * Remove dead `noop('cfs_update')` mock in the test suite. * Rename test descriptions to consistently end with 'succeeds' or 'fails'. * Add missing test cases for parameter validation, path validation, idempotent deletes, privilege regressions and deleting ACLs with non-existent roles. * Reword commit message: Use plain prose instead of bullet lists. Changes v1 -> v2: ----------------- * Declare all tests up front in $tests. * Run all tests using the same logic in loop. * Evaluate test results using `Test::More::is_deeply`. * Use redefine() instead of mock(). * Use `no_auto => 1` for MockModule to prvent auto loading. * Run make tidy. Previous Versions ----------------- v2: https://lore.proxmox.com/pve-devel/20260723110939.84932-1-e.huhsovitz@proxmox.com/ v1: https://lore.proxmox.com/pve-devel/20260720134535.136172-1-e.huhsovitz@proxmox.com/ Summary of Changes ------------------ Elias Huhsovitz (2): test: api: acl: add tests for modification endpoint fix #6510: api: acl: allow deletion for non-existent entities src/PVE/API2/ACL.pm | 13 +- src/test/api-tests.pl | 2 +- src/test/api-update-acl-test.pl | 356 ++++++++++++++++++++++++++++++++ 3 files changed, 364 insertions(+), 7 deletions(-) create mode 100644 src/test/api-update-acl-test.pl -- 2.47.3