public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-firewall v2 05/12] firewall: add restore command
Date: Thu,  1 Oct 2026 14:26:18 +0200	[thread overview]
Message-ID: <20261001122625.348730-6-a.bied-charreton@proxmox.com> (raw)
In-Reply-To: <20261001122625.348730-1-a.bied-charreton@proxmox.com>

Add a 'restore' command that recompiles and applies the firewall from
the config dumped to /var/lib/pve/firewall, to bridge the boot window
before pmxcfs (and thus the real config) is available.

It reuses update() with a local flag: configs are loaded from the local
dumps instead of pmxcfs and nothing is dumped back. A missing or
unreadable SDN dump is treated as empty, and rules referencing an
unavailable IPSet are skipped, so a partial dump still restores the rest
on a best-effort basis.

For the host config, a host.fw.new written by the
pve-network-interface-pinning tool takes precedence over the plain dump
when present. No .new file is ever created for the cluster config, so
that is only loaded from cluster.fw.

Signed-off-by: Arthur Bied-Charreton <a.bied-charreton@proxmox.com>
Reviewed-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Tested-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
---
 src/PVE/Firewall.pm             | 32 +++++++++++++++++++++++++++-----
 src/PVE/Service/pve_firewall.pm | 18 ++++++++++++++++++
 src/pve-firewall                |  9 ++++++---
 3 files changed, 51 insertions(+), 8 deletions(-)

diff --git a/src/PVE/Firewall.pm b/src/PVE/Firewall.pm
index 81901e3..6779bbc 100644
--- a/src/PVE/Firewall.pm
+++ b/src/PVE/Firewall.pm
@@ -4196,11 +4196,11 @@ sub lock_clusterfw_conf {
 }
 
 sub load_clusterfw_conf {
-    my ($filename) = @_;
+    my ($filename, $sdn_conf) = @_;
 
     $filename = $clusterfw_conf_filename if !defined($filename);
 
-    my $sdn_conf = load_sdn_conf();
+    $sdn_conf //= load_sdn_conf();
 
     my $empty_conf = {
         rules => [],
@@ -5573,14 +5573,31 @@ sub delete_dumps_if_owned {
     delete_dumps() if $dump_cache->%*;
 }
 
+my sub get_local_config_dump_path {
+    my ($filename) = @_;
+
+    my $new = "$filename.new";
+    return $new if -f $new;
+    return $filename;
+}
+
 sub update {
+    my ($local) = @_;
+
     my $code = sub {
         my $cfw_dump_path = "$dump_dir/cluster.fw";
         my $hfw_dump_path = "$dump_dir/host.fw";
         my $sdn_dump_path = "$dump_dir/sdn.json";
 
-        my $cluster_conf = load_clusterfw_conf();
-        my $hostfw_conf = load_hostfw_conf($cluster_conf);
+        my $cfw_conf_path = $local ? get_local_config_dump_path($cfw_dump_path) : undef;
+        my $hfw_conf_path = $local ? get_local_config_dump_path($hfw_dump_path) : undef;
+        my $sdn_conf = undef;
+        $sdn_conf = eval { decode_json(PVE::File::file_get_contents($sdn_dump_path)) }
+            if $local;
+        $sdn_conf = undef if $local && (!ref($sdn_conf) || ref($sdn_conf->{ipset}) ne 'HASH');
+
+        my $cluster_conf = load_clusterfw_conf($cfw_conf_path, $sdn_conf);
+        my $hostfw_conf = load_hostfw_conf($cluster_conf, $hfw_conf_path);
 
         if (!is_enabled_and_not_nftables($cluster_conf, $hostfw_conf)) {
             PVE::Firewall::remove_pvefw_chains();
@@ -5588,10 +5605,13 @@ sub update {
             # disabled in config: drop stale dumps so the pre-network restore does not resurrect a
             # disabled ruleset. leave them in nftables mode, since in that case proxmox-firewall
             # owns the dump directory.
-            delete_dumps() if !$cluster_conf->{options}->{enable};
+            delete_dumps() if !$local && !$cluster_conf->{options}->{enable};
+            syslog('info', "iptables firewall is not enabled, not restoring rules\n") if $local;
             return;
         }
 
+        syslog('info', "restoring last remembered ruleset from $dump_dir\n") if $local;
+
         # compile() rewrites rule actions in-place. snapshot the untouched configs now for the
         # post-apply boot-time dump.
         my ($cfw_dump, $hfw_dump) = (dclone($cluster_conf), dclone($hostfw_conf));
@@ -5601,6 +5621,8 @@ sub update {
 
         apply_ruleset($ruleset, $hostfw_conf, $ipset_ruleset, $rulesetv6, $ebtables_ruleset);
 
+        return if $local;
+
         eval {
             mkdir($dump_dir);
             chmod(0700, $dump_dir);
diff --git a/src/PVE/Service/pve_firewall.pm b/src/PVE/Service/pve_firewall.pm
index b39fea7..30b0091 100755
--- a/src/PVE/Service/pve_firewall.pm
+++ b/src/PVE/Service/pve_firewall.pm
@@ -10,6 +10,7 @@ use PVE::CLIHandler;
 use PVE::Cluster qw(cfs_read_file);
 use PVE::Corosync;
 use PVE::Daemon;
+use PVE::File;
 use PVE::INotify;
 use PVE::ProcFSTools;
 use PVE::RPCEnvironment;
@@ -487,6 +488,22 @@ __PACKAGE__->register_method({
     },
 });
 
+__PACKAGE__->register_method({
+    name => 'restore',
+    path => 'restore',
+    method => 'GET',
+    description => 'Attempt to restore the last remembered ruleset',
+    parameters => {
+        additionalProperties => 0,
+        properties => {},
+    },
+    returns => { type => 'null' },
+    code => sub {
+        PVE::Firewall::update(1);
+        return undef;
+    },
+});
+
 our $cmddef = {
     start => [__PACKAGE__, 'start', []],
     restart => [__PACKAGE__, 'restart', []],
@@ -494,6 +511,7 @@ our $cmddef = {
     compile => [__PACKAGE__, 'compile', []],
     simulate => [__PACKAGE__, 'simulate', []],
     localnet => [__PACKAGE__, 'localnet', []],
+    restore => [__PACKAGE__, 'restore', []],
     status => [
         __PACKAGE__,
         'status',
diff --git a/src/pve-firewall b/src/pve-firewall
index 5b62430..ddde69c 100755
--- a/src/pve-firewall
+++ b/src/pve-firewall
@@ -14,12 +14,15 @@ $SIG{'__WARN__'} = sub {
     $@ = $err;
 };
 
+my $is_restore = ($ARGV[0] // '') eq 'restore';
+
 my $prepare = sub {
     my $rpcenv = PVE::RPCEnvironment->init('cli');
 
-    $rpcenv->init_request();
-    $rpcenv->set_language($ENV{LANG});
-    $rpcenv->set_user('root@pam');
+    # 'restore' runs at pre-network, before pmxcfs is up, and needs no ACL
+    $rpcenv->init_request() if !$is_restore;
+    $rpcenv->set_language($ENV{LANG}) if !$is_restore;
+    $rpcenv->set_user('root@pam') if !$is_restore;
 };
 
 PVE::Service::pve_firewall->run_cli_handler(prepare => $prepare);
-- 
2.47.3





  parent reply	other threads:[~2026-10-01 12:27 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 12:26 [RFC firewall/manager/proxmox{,-firewall} v2 00/12] fix #5759: keep firewall rules up across boot and shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-manager v2 01/12] network interface pinning: write new firewall config to local dir Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 02/12] firewall: config: sort OPTIONS when serializing Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 03/12] firewall: dump configs locally after applying Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH pve-firewall v2 04/12] fix #5759: firewall: do not remove chains when host is shutting down Arthur Bied-Charreton
2026-10-01 12:26 ` Arthur Bied-Charreton [this message]
2026-10-01 12:26 ` [PATCH pve-firewall v2 06/12] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox v2 07/12] systemd: systemctl: add is-system-running helper Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 08/12] firewall: fix clippy warnings Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 09/12] fix #5759: firewall: do not clear rules on system shutdown Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 10/12] firewall: dump config to local directory after apply Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 11/12] firewall: add restore command Arthur Bied-Charreton
2026-10-01 12:26 ` [PATCH proxmox-firewall v2 12/12] fix #5759: firewall: restore from dumped config before network-pre Arthur Bied-Charreton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001122625.348730-6-a.bied-charreton@proxmox.com \
    --to=a.bied-charreton@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal