public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-firewall v3 06/16] api: aliases: add option to handle dangling references on delete
Date: Fri, 25 Sep 2026 11:42:20 +0200	[thread overview]
Message-ID: <20260925094230.844917-7-a.bied-charreton@proxmox.com> (raw)
In-Reply-To: <20260925094230.844917-1-a.bied-charreton@proxmox.com>

Deleting an alias referenced by rules, security groups or ipset members
leaves dangling references, which the firewall fails to parse and drops.

Add a 'dangling-references' option to the delete endpoint, to either
'disable' the referencing rules or 'drop' them along with the alias. The
default, 'keep', leaves them as they are. Ipset members have no disabled
state, so they are removed in both cases. For cluster aliases, this also
covers all downstream configs (host, guest and vnet).

Signed-off-by: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
---
 src/PVE/API2/Firewall/Aliases.pm | 24 ++++++++++++++++++++++++
 1 file changed, 24 insertions(+)

diff --git a/src/PVE/API2/Firewall/Aliases.pm b/src/PVE/API2/Firewall/Aliases.pm
index b5bad48..8b9caaf 100644
--- a/src/PVE/API2/Firewall/Aliases.pm
+++ b/src/PVE/API2/Firewall/Aliases.pm
@@ -316,6 +316,16 @@ sub register_delete_alias {
 
     $properties->{name} = $api_properties->{name};
     $properties->{digest} = get_standard_option('pve-config-digest');
+    $properties->{'dangling-references'} = {
+        type => 'string',
+        enum => ['keep', 'disable', 'drop'],
+        optional => 1,
+        description =>
+            "Handle references that the deletion would leave dangling. Use 'disable' to disable "
+            . "the referencing rules, or 'drop' to remove them entirely. IPSet members "
+            . "referencing the alias are always removed, as they cannot be disabled.",
+        default => 'keep',
+    };
 
     $class->register_method({
         name => 'remove_alias',
@@ -344,6 +354,20 @@ sub register_delete_alias {
                     PVE::Tools::assert_if_modified($digest, $param->{digest});
 
                     my $name = lc($param->{name});
+
+                    my $action = $param->{'dangling-references'} // 'keep';
+                    if ($action ne 'keep') {
+                        my $spec = get_object_spec('aliases');
+                        update_refs(
+                            $fw_conf,
+                            $spec,
+                            $param->{name},
+                            undef,
+                            $class->rule_env(),
+                            $action,
+                        );
+                    }
+
                     delete $aliases->{$name};
 
                     $class->save_aliases($param, $fw_conf, $aliases);
-- 
2.47.3




  parent reply	other threads:[~2026-09-25  9:44 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25  9:42 SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-firewall v3 01/16] helpers: add helpers to update firewall object references Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-firewall v3 02/16] parser: do not log errors for disabled rules Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-firewall v3 03/16] api: ipset: add option to update references on edit Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-firewall v3 04/16] api: ipset: add option to handle dangling references on delete Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-firewall v3 05/16] api: aliases: add option to update references on edit Arthur Bied-Charreton
2026-09-25  9:42 ` Arthur Bied-Charreton [this message]
2026-09-25  9:42 ` SPAM: [PATCH pve-firewall v3 07/16] firewall: tests: add tests for object reference update logic Arthur Bied-Charreton
2026-09-25  9:42 ` SPAM: [PATCH pve-network v3 08/16] apply: add option to handle dangling references on VNet deletion Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH qemu-server v3 09/16] api: destroy_vm: add option to handle dangling IPSet references Arthur Bied-Charreton
2026-09-25  9:42 ` SPAM: [PATCH pve-container v3 10/16] " Arthur Bied-Charreton
2026-09-25  9:42 ` SPAM: [PATCH pve-manager v3 11/16] ui: firewall: add common widgets for deleting and updating references Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-manager v3 12/16] ui: firewall: ipset: add controls to update/delete references on edit Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-manager v3 13/16] ui: firewall: aliases: " Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-manager v3 14/16] ui: sdn: apply: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-manager v3 15/16] ui: guest destroy: use let for non-constant variable bindings Arthur Bied-Charreton
2026-09-25  9:42 ` [PATCH pve-manager v3 16/16] ui: guest destroy: add control for dangling IPSet references Arthur Bied-Charreton
2026-09-25 11:05 ` SPAM: [PATCH container/firewall/manager/network/qemu-server v3 00/16] handle dangling references when firewall objects go away Arthur Bied-Charreton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925094230.844917-7-a.bied-charreton@proxmox.com \
    --to=a.bied-charreton@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal