From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 14A7C1FF0B2 for ; Mon, 24 Aug 2026 10:58:16 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 3A739216A0; Mon, 24 Aug 2026 10:57:23 +0200 (CEST) From: Daniel Kral To: pve-devel@lists.proxmox.com Subject: [PATCH cluster 05/12] pmxcfs: server: report responses exceeding the maximum message size Date: Mon, 24 Aug 2026 10:56:04 +0200 Message-ID: <20260824085610.111211-7-d.kral@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260824085610.111211-2-d.kral@proxmox.com> References: <20260824085610.111211-2-d.kral@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1787561806273 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.922 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: WIETH2AVE3BMGYPC6XKG6EHE44TRH3AB X-Message-ID-Hash: WIETH2AVE3BMGYPC6XKG6EHE44TRH3AB X-MailFrom: d.kral@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The shared memory ring buffer has a fixed maximum buffer size of MAX_MSG_SIZE (currently 1 MiB), which is set by the pmxcfs' libqb-based IPC client. If the maximium buffer size is exceeded, the QB ringbuffer will fail to allocate the chunk for the response. qb_ipcs_response_sendv() will fail with -EAGAIN, which will be logged by pmxcfs as a rather confusing user error: [ipcs] crit: qb_ipcs_response_send: Resource temporarily unavailable [libqb] error: error receiving from setup sock (/dev/shm/qb-[...]/qb): Bad file descriptor (9) and makes users of $PVE::Cluster::ipcc_send_rec{,_json}() fail with: ipcc_send_rec[13] failed: Transport endpoint is not connected In huge cluster setups with many nodes, storages, and many thousands of guests, the current MAX_MSG_SIZE of 1 MiB could be exceeded. For example, in a test cluster with 10,000 stopped guests, the response of CFS_IPC_GET_RRD_DUMP does already have 919 KiB, where many of the runtime values are undefined (U) and therefore the response size would be much longer if they were all running. Similar response sizes can be reached with CFS_IPC_GET_GUEST_LIST and CFS_IPC_GET_GUEST_CONFIG_PROPERTIES. Report response messages that exceed the maximum message size in the client and server to make the issue clearer to discern from other possible errors, e.g. an unresponsive IPC server. Signed-off-by: Daniel Kral --- src/pmxcfs/server.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/src/pmxcfs/server.c b/src/pmxcfs/server.c index abe1bee..54cd3aa 100644 --- a/src/pmxcfs/server.c +++ b/src/pmxcfs/server.c @@ -449,15 +449,23 @@ static int32_t s1_msg_process_fn(qb_ipcs_connection_t *c, void *data, size_t siz cfs_debug("process result %d", result); + int iov_len = 2; + struct iovec iov[iov_len]; + struct qb_ipc_response_header res_header; + int32_t max_msg_size = qb_ipcs_connection_get_buffer_size(c); + + if (sizeof(res_header) + outbuf->len > max_msg_size) { + cfs_critical( + "response for id %d is too large: %ld > %d", request_id, outbuf->len, max_msg_size + ); + result = -EMSGSIZE; + } + /* Do not send the response body in case of an error */ if (result < 0) { g_string_truncate(outbuf, 0); } - int iov_len = 2; - struct iovec iov[iov_len]; - struct qb_ipc_response_header res_header; - res_header.id = request_id; res_header.size = sizeof(res_header) + outbuf->len; res_header.error = result; -- 2.47.3