public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Dietmar Maurer <dietmar@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH storage 3/7] iscsi: validate target names with a dedicated format
Date: Tue,  4 Aug 2026 11:08:15 +0200	[thread overview]
Message-ID: <20260804090819.2136483-4-dietmar@proxmox.com> (raw)
In-Reply-To: <20260804090819.2136483-1-dietmar@proxmox.com>

The target property accepted any string, so typos or pasted portal
addresses were only caught later when iscsiadm fails. Validate against
the iSCSI name grammar from RFC 7143 (iqn, eui and naa types, 223 byte
limit). Accept uppercase letters even where the grammar only permits
lowercase, because such admin-typed names exist in the wild and work,
and rejecting them would break existing setups on upgrade.

This also covers the iSCSI direct and ZFS over iSCSI plugins, which
share the property.

Signed-off-by: Dietmar Maurer <dietmar@proxmox.com>
---
 src/PVE/Storage/ISCSIPlugin.pm | 22 ++++++++++++++++++++++
 1 file changed, 22 insertions(+)

diff --git a/src/PVE/Storage/ISCSIPlugin.pm b/src/PVE/Storage/ISCSIPlugin.pm
index 9944806..0165a58 100644
--- a/src/PVE/Storage/ISCSIPlugin.pm
+++ b/src/PVE/Storage/ISCSIPlugin.pm
@@ -334,6 +334,27 @@ sub iscsi_device_list {
 
 # Configuration
 
+# Name grammar from RFC 7143 section 6.1: iqn, eui and naa types with a
+# 223 byte limit. The IQN grammar only permits lowercase, but accept any
+# case because admin-typed names with uppercase letters exist and work.
+sub verify_iscsi_target {
+    my ($target, $noerr) = @_;
+
+    if (
+        length($target) > 223
+        || $target !~ m/^(?:
+            iqn\.\d{4}-\d{2}(?:\.[a-z0-9-]+)+(?::[a-z0-9.:-]+)?
+            |eui\.[0-9a-f]{16}
+            |naa\.(?:[0-9a-f]{16}|[0-9a-f]{32})
+        )$/xi
+    ) {
+        return undef if $noerr;
+        die "value does not look like a valid iSCSI target name\n";
+    }
+    return $target;
+}
+PVE::JSONSchema::register_format('pve-storage-iscsi-target', \&verify_iscsi_target);
+
 sub type {
     return 'iscsi';
 }
@@ -351,6 +372,7 @@ sub properties {
         target => {
             description => "iSCSI target.",
             type => 'string',
+            format => 'pve-storage-iscsi-target',
         },
         portal => {
             description => "iSCSI portal (IP or DNS name with optional port).",
-- 
2.47.3




  parent reply	other threads:[~2026-08-04  9:08 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04  9:08 [PATCH storage 0/7] iscsi: per-node target and portal configuration Dietmar Maurer
2026-08-04  9:08 ` [PATCH storage 1/7] iscsi: discovery: do not stop early on a foreign target Dietmar Maurer
2026-08-04  9:08 ` [PATCH storage 2/7] iscsi: scan: do not persist discovery results in the node database Dietmar Maurer
2026-08-04  9:08 ` Dietmar Maurer [this message]
2026-08-04  9:08 ` [PATCH storage 4/7] iscsi: clarify that the portal property is the discovery address Dietmar Maurer
2026-08-04  9:08 ` [PATCH storage 5/7] iscsi: add iscsi-node-map property for per-node target and portals Dietmar Maurer
2026-08-04  9:08 ` [PATCH storage 6/7] iscsi: iscsi_portals: return empty list instead of fallback portal Dietmar Maurer
2026-08-04  9:08 ` [PATCH storage 7/7] iscsi: add periodic-discovery flag to skip re-discovery on login Dietmar Maurer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260804090819.2136483-4-dietmar@proxmox.com \
    --to=dietmar@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal