From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 15EEF1FF0B3 for ; Fri, 25 Sep 2026 11:44:02 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 78E9C21852; Fri, 25 Sep 2026 11:42:39 +0200 (CEST) From: Arthur Bied-Charreton To: pve-devel@lists.proxmox.com Subject: [PATCH pve-firewall v3 06/16] api: aliases: add option to handle dangling references on delete Date: Fri, 25 Sep 2026 11:42:20 +0200 Message-ID: <20260925094230.844917-7-a.bied-charreton@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260925094230.844917-1-a.bied-charreton@proxmox.com> References: <20260925094230.844917-1-a.bied-charreton@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 2 DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Message-ID-Hash: I6EWABEZZGUEFTNL2UK74GSUOEEQBQ7N X-Message-ID-Hash: I6EWABEZZGUEFTNL2UK74GSUOEEQBQ7N X-MailFrom: abied-charreton@jett.proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Deleting an alias referenced by rules, security groups or ipset members leaves dangling references, which the firewall fails to parse and drops. Add a 'dangling-references' option to the delete endpoint, to either 'disable' the referencing rules or 'drop' them along with the alias. The default, 'keep', leaves them as they are. Ipset members have no disabled state, so they are removed in both cases. For cluster aliases, this also covers all downstream configs (host, guest and vnet). Signed-off-by: Arthur Bied-Charreton --- src/PVE/API2/Firewall/Aliases.pm | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/src/PVE/API2/Firewall/Aliases.pm b/src/PVE/API2/Firewall/Aliases.pm index b5bad48..8b9caaf 100644 --- a/src/PVE/API2/Firewall/Aliases.pm +++ b/src/PVE/API2/Firewall/Aliases.pm @@ -316,6 +316,16 @@ sub register_delete_alias { $properties->{name} = $api_properties->{name}; $properties->{digest} = get_standard_option('pve-config-digest'); + $properties->{'dangling-references'} = { + type => 'string', + enum => ['keep', 'disable', 'drop'], + optional => 1, + description => + "Handle references that the deletion would leave dangling. Use 'disable' to disable " + . "the referencing rules, or 'drop' to remove them entirely. IPSet members " + . "referencing the alias are always removed, as they cannot be disabled.", + default => 'keep', + }; $class->register_method({ name => 'remove_alias', @@ -344,6 +354,20 @@ sub register_delete_alias { PVE::Tools::assert_if_modified($digest, $param->{digest}); my $name = lc($param->{name}); + + my $action = $param->{'dangling-references'} // 'keep'; + if ($action ne 'keep') { + my $spec = get_object_spec('aliases'); + update_refs( + $fw_conf, + $spec, + $param->{name}, + undef, + $class->rule_env(), + $action, + ); + } + delete $aliases->{$name}; $class->save_aliases($param, $fw_conf, $aliases); -- 2.47.3