From: Dietmar Maurer <dietmar@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH storage 3/7] iscsi: validate target names with a dedicated format
Date: Tue, 4 Aug 2026 11:08:15 +0200 [thread overview]
Message-ID: <20260804090819.2136483-4-dietmar@proxmox.com> (raw)
In-Reply-To: <20260804090819.2136483-1-dietmar@proxmox.com>
The target property accepted any string, so typos or pasted portal
addresses were only caught later when iscsiadm fails. Validate against
the iSCSI name grammar from RFC 7143 (iqn, eui and naa types, 223 byte
limit). Accept uppercase letters even where the grammar only permits
lowercase, because such admin-typed names exist in the wild and work,
and rejecting them would break existing setups on upgrade.
This also covers the iSCSI direct and ZFS over iSCSI plugins, which
share the property.
Signed-off-by: Dietmar Maurer <dietmar@proxmox.com>
---
src/PVE/Storage/ISCSIPlugin.pm | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/src/PVE/Storage/ISCSIPlugin.pm b/src/PVE/Storage/ISCSIPlugin.pm
index 9944806..0165a58 100644
--- a/src/PVE/Storage/ISCSIPlugin.pm
+++ b/src/PVE/Storage/ISCSIPlugin.pm
@@ -334,6 +334,27 @@ sub iscsi_device_list {
# Configuration
+# Name grammar from RFC 7143 section 6.1: iqn, eui and naa types with a
+# 223 byte limit. The IQN grammar only permits lowercase, but accept any
+# case because admin-typed names with uppercase letters exist and work.
+sub verify_iscsi_target {
+ my ($target, $noerr) = @_;
+
+ if (
+ length($target) > 223
+ || $target !~ m/^(?:
+ iqn\.\d{4}-\d{2}(?:\.[a-z0-9-]+)+(?::[a-z0-9.:-]+)?
+ |eui\.[0-9a-f]{16}
+ |naa\.(?:[0-9a-f]{16}|[0-9a-f]{32})
+ )$/xi
+ ) {
+ return undef if $noerr;
+ die "value does not look like a valid iSCSI target name\n";
+ }
+ return $target;
+}
+PVE::JSONSchema::register_format('pve-storage-iscsi-target', \&verify_iscsi_target);
+
sub type {
return 'iscsi';
}
@@ -351,6 +372,7 @@ sub properties {
target => {
description => "iSCSI target.",
type => 'string',
+ format => 'pve-storage-iscsi-target',
},
portal => {
description => "iSCSI portal (IP or DNS name with optional port).",
--
2.47.3
next prev parent reply other threads:[~2026-08-04 9:08 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 9:08 [PATCH storage 0/7] iscsi: per-node target and portal configuration Dietmar Maurer
2026-08-04 9:08 ` [PATCH storage 1/7] iscsi: discovery: do not stop early on a foreign target Dietmar Maurer
2026-08-04 9:08 ` [PATCH storage 2/7] iscsi: scan: do not persist discovery results in the node database Dietmar Maurer
2026-08-04 9:08 ` Dietmar Maurer [this message]
2026-08-04 9:08 ` [PATCH storage 4/7] iscsi: clarify that the portal property is the discovery address Dietmar Maurer
2026-08-04 9:08 ` [PATCH storage 5/7] iscsi: add iscsi-node-map property for per-node target and portals Dietmar Maurer
2026-08-04 9:08 ` [PATCH storage 6/7] iscsi: iscsi_portals: return empty list instead of fallback portal Dietmar Maurer
2026-08-04 9:08 ` [PATCH storage 7/7] iscsi: add periodic-discovery flag to skip re-discovery on login Dietmar Maurer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804090819.2136483-4-dietmar@proxmox.com \
--to=dietmar@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox