From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away
Date: Fri, 25 Sep 2026 11:42:14 +0200 [thread overview]
Message-ID: <20260925094230.844917-1-a.bied-charreton@proxmox.com> (raw)
Renaming or deleting a firewall object (an IPSet or an alias) that rules
still reference leaves those references dangling. The firewall fails to
parse the affected rules and drops them from the generated ruleset, so
an edit in one place can disable a whole set of rules somewhere. This
is especially bad in the rename case, where one might reasonably expect
the references to follow the new object name.
This series makes the affected operations offer to deal with the
references instead of leaving them behind.
pve-firewall gains a shared helper, update_refs(), whcih finds
references in rules, security groups and IPset members and applies one
of three actions: 'rename' points them at the new name, 'disable'
disables the referencing rules, and 'drop' removes them. An IPSet member
has no disabled state, so 'disable' removes members as well. For a
cluster object, the helper also walks every downstream config in the
cluster (guest, host and vnet), locking and saving each one.
On top of this, three wrappers cover the SDN-generated IPSets that no
caller can delete directly.
These options are added to the API as follows:
POST .../firewall/ipset update-references no|yes|force
PUT .../firewall/aliases/{name} update-references no|yes|force
DELETE .../ipset/{name} dangling-references keep|disable|drop
DELETE .../aliases/{name} dangling-references keep|disable|drop
PUT /cluster/sdn dangling-ipset-references keep|disable|drop
DELETE /nodes/{node}/qemu/{vmid} dangling-ipset-references keep|disable|drop
DELETE /nodes/{node}/lxc/{vmid} dangling-ipset-references keep|disable|drop
On a rename, the new object is persisted before its references are
rewritten, so a concurrent compilation does not observe a reference to
an object that does not exist yet. If a cluster-wide rewrite is
interrupted part way, passing 'force' resumes it (without this, the
next attempt would fail due to the target name already existing in the
config).
While these options allow to trigger changes to the firewall
configurations from other endpoints requiring different permissions,
like guest destroy and SDN apply, they do not require any additional
permissions, see full explanation here [0].
Changes since [v2]:
- Handle references to SDN-generated IPSets in SDN apply and guest
destroy
- Support disabling rules referencing a deleted object instead of only
deleting them
[v2] https://lore.proxmox.com/pve-devel/20260818133413.450776-1-a.bied-charreton@proxmox.com/
[v1] https://lore.proxmox.com/pve-devel/20260407073658.90818-1-a.bied-charreton@proxmox.com/
[0] https://lore.proxmox.com/pve-devel/awaoshjzbr7adisjngsrcts4zs3hxgoxw2lgcoq66gtiap3al2@mpxrbmtyfcwj/
pve-firewall:
Arthur Bied-Charreton (7):
helpers: add helpers to update firewall object references
parser: do not log errors for disabled rules
api: ipset: add option to update references on edit
api: ipset: add option to handle dangling references on delete
api: aliases: add option to update references on edit
api: aliases: add option to handle dangling references on delete
firewall: tests: add tests for object reference update logic
src/PVE/API2/Firewall/Aliases.pm | 63 ++++++-
src/PVE/API2/Firewall/IPSet.pm | 83 +++++++--
src/PVE/Firewall.pm | 2 +-
src/PVE/Firewall/Helpers.pm | 308 +++++++++++++++++++++++++++++++
test/Makefile | 1 +
test/referenceupdatetests.pl | 296 +++++++++++++++++++++++++++++
6 files changed, 737 insertions(+), 16 deletions(-)
create mode 100755 test/referenceupdatetests.pl
pve-network:
Arthur Bied-Charreton (1):
apply: add option to handle dangling references on VNet deletion
src/PVE/API2/Network/SDN.pm | 32 ++++++++++++++++++++++++++++++++
1 file changed, 32 insertions(+)
qemu-server:
Arthur Bied-Charreton (1):
api: destroy_vm: add option to handle dangling IPSet references
src/PVE/API2/Qemu.pm | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
pve-container:
Arthur Bied-Charreton (1):
api: destroy_vm: add option to handle dangling IPSet references
src/PVE/API2/LXC.pm | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
pve-manager:
Arthur Bied-Charreton (6):
ui: firewall: add common widgets for deleting and updating references
ui: firewall: ipset: add controls to update/delete references on edit
ui: firewall: aliases: add controls to update/delete references on
edit
ui: sdn: apply: add control for dangling IPSet references
ui: guest destroy: use let for non-constant variable bindings
ui: guest destroy: add control for dangling IPSet references
www/manager6/Makefile | 1 +
www/manager6/grid/FirewallAliases.js | 80 ++++++++----
www/manager6/grid/FirewallObjectCommon.js | 143 ++++++++++++++++++++++
www/manager6/panel/IPSet.js | 35 +++++-
www/manager6/sdn/StatusView.js | 105 +++++++++++++---
www/manager6/window/SafeDestroyGuest.js | 48 +++++++-
6 files changed, 364 insertions(+), 48 deletions(-)
create mode 100644 www/manager6/grid/FirewallObjectCommon.js
Summary over all repositories:
15 files changed, 1169 insertions(+), 64 deletions(-)
--
Generated by murpp 0.12.1
next reply other threads:[~2026-09-25 9:43 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 9:42 Arthur Bied-Charreton [this message]
2026-09-25 9:42 ` [PATCH pve-firewall v3 01/16] helpers: add helpers to update firewall object references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 02/16] parser: do not log errors for disabled rules Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 03/16] api: ipset: add option to update references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 04/16] api: ipset: add option to handle dangling references on delete Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 05/16] api: aliases: add option to update references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-firewall v3 06/16] api: aliases: add option to handle dangling references on delete Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-firewall v3 07/16] firewall: tests: add tests for object reference update logic Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-network v3 08/16] apply: add option to handle dangling references on VNet deletion Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH qemu-server v3 09/16] api: destroy_vm: add option to handle dangling IPSet references Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-container v3 10/16] " Arthur Bied-Charreton
2026-09-25 9:42 ` SPAM: [PATCH pve-manager v3 11/16] ui: firewall: add common widgets for deleting and updating references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 12/16] ui: firewall: ipset: add controls to update/delete references on edit Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 13/16] ui: firewall: aliases: " Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 14/16] ui: sdn: apply: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 15/16] ui: guest destroy: use let for non-constant variable bindings Arthur Bied-Charreton
2026-09-25 9:42 ` [PATCH pve-manager v3 16/16] ui: guest destroy: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25 11:05 ` SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away Arthur Bied-Charreton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925094230.844917-1-a.bied-charreton@proxmox.com \
--to=a.bied-charreton@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox