public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: "Michael Köppl" <m.koeppl@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH guest-common v7 10/24] guest id: optionally enforce the next-id range and uniqueness
Date: Mon,  5 Oct 2026 16:47:51 +0200	[thread overview]
Message-ID: <20261005144805.825538-11-m.koeppl@proxmox.com> (raw)
In-Reply-To: <20261005144805.825538-1-m.koeppl@proxmox.com>

If the 'enforce' subproperty of next-id is enabled, ensure that only
guest IDs from the configured range and, if unique is enabled as well,
only previously unused IDs can be used. By setting existing => 1, the
enforcement of these criteria is disabled for actions on existing
guests, such as destroy, remote migration with --delete, and restore
over an existing guest.

IDs are recorded before a guest exists and stay recorded if its
creation fails later. With both 'enforce' and 'unique' set, retrying a
failed creation with the same ID is therefore rejected.

Signed-off-by: Michael Köppl <m.koeppl@proxmox.com>
---
 src/PVE/AbstractConfig.pm |  4 ++--
 src/PVE/GuestID.pm        | 35 +++++++++++++++++++++++++++++------
 2 files changed, 31 insertions(+), 8 deletions(-)

diff --git a/src/PVE/AbstractConfig.pm b/src/PVE/AbstractConfig.pm
index 229e4bd..2f20596 100644
--- a/src/PVE/AbstractConfig.pm
+++ b/src/PVE/AbstractConfig.pm
@@ -260,9 +260,9 @@ sub create_and_lock_config {
         $vmid,
         5,
         sub {
-            PVE::Cluster::check_vmid_unused($vmid, $allow_existing);
+            my $is_new = PVE::Cluster::check_vmid_unused($vmid, $allow_existing);
 
-            PVE::GuestID::register_used_id($vmid);
+            PVE::GuestID::register_used_id($vmid, { existing => !$is_new });
 
             my $conf = eval { $class->load_config($vmid) } || {};
             $class->check_lock($conf);
diff --git a/src/PVE/GuestID.pm b/src/PVE/GuestID.pm
index 4ab6c1c..ba71e4f 100644
--- a/src/PVE/GuestID.pm
+++ b/src/PVE/GuestID.pm
@@ -195,25 +195,48 @@ my sub insert_id($ranges, $id) {
     return 1;
 }
 
-sub register_used_id($id) {
-    cfs_lock_file(
+my sub assert_id_in_next_id_range($next_id_opts, $id) {
+    my $lower = $next_id_opts->{lower};
+    my $upper = $next_id_opts->{upper};
+
+    die "guest ID $id is below the lower boundary $lower of the next-id range\n"
+        if defined($lower) && $id < $lower;
+    die "guest ID $id is not below the upper boundary $upper of the next-id range\n"
+        if defined($upper) && $id >= $upper;
+}
+
+# Records $id as used. If the next-id datacenter option enforces its
+# range or uniqueness, IDs a new guest must not use are rejected, unless
+# $opts->{existing} marks $id as belonging to an existing guest.
+sub register_used_id($id, $opts = {}) {
+    my $next_id_opts = cfs_read_file('datacenter.cfg')->{'next-id'} // {};
+    # never reject the ID of a currently existing guest
+    my $enforce = $next_id_opts->{enforce} && !$opts->{existing};
+
+    assert_id_in_next_id_range($next_id_opts, $id) if $enforce;
+
+    my $recorded = cfs_lock_file(
         $FILENAME,
         10,
         sub {
             my $ranges = cfs_read_file($FILENAME);
 
-            return if !insert_id($ranges, $id);
+            return 0 if !insert_id($ranges, $id);
 
             cfs_write_file($FILENAME, $ranges);
+            return 1;
         },
     );
     if (my $err = $@) {
-        my $dc_conf = cfs_read_file('datacenter.cfg');
-
         my $emsg = "unable to record guest ID $id as used";
-        die "$emsg - $err" if $dc_conf->{'next-id'}->{unique};
+        die "$emsg - $err" if $next_id_opts->{unique};
         warn "$emsg - $err";
+
+        return;
     }
+
+    die "guest ID $id was used before\n"
+        if $enforce && $next_id_opts->{unique} && !$recorded;
 }
 
 cfs_register_file($FILENAME, \&parse_id_list, \&write_id_list);
-- 
2.47.3





  parent reply	other threads:[~2026-10-05 14:49 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 14:47 [PATCH many v7 00/24] add option to prevent suggesting previously used VMIDs Michael Köppl
2026-10-05 14:47 ` [PATCH cluster v7 01/24] cluster files: add virtual-guest/used-guest-ids Michael Köppl
2026-10-05 14:47 ` [PATCH cluster v7 02/24] datacenter config: add unique subproperty to next-id Michael Köppl
2026-10-05 14:47 ` [PATCH cluster v7 03/24] datacenter config: next-id: add enforce subproperty Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 04/24] src/makefile: order files alphabetically Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 05/24] add module to track previously used guest IDs Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 06/24] tests: add tests for used guest ID tracking Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 07/24] abstract config: register used guest ID when creating config Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 08/24] guest id: keep used ID list below the pmxcfs file size limit Michael Köppl
2026-10-05 14:47 ` [PATCH guest-common v7 09/24] tests: add tests for used-guest-ids max file size handling Michael Köppl
2026-10-05 14:47 ` Michael Köppl [this message]
2026-10-05 14:47 ` [PATCH guest-common v7 11/24] guest id: add helper to check guest IDs against next-id enforcement Michael Köppl
2026-10-05 14:47 ` [PATCH qemu-server v7 12/24] api: record VM ID as used on destruction and remote migration Michael Köppl
2026-10-05 14:47 ` [PATCH qemu-server v7 13/24] api, remote migrate: exempt existing VMs from next-id enforcement Michael Köppl
2026-10-05 14:47 ` [PATCH container v7 14/24] api: record CT ID as used on destruction and remote migration Michael Köppl
2026-10-05 14:47 ` [PATCH container v7 15/24] api, migrate: exempt existing CTs from next-id enforcement Michael Köppl
2026-10-05 14:47 ` [PATCH manager v7 16/24] ui: guest ID selector: rename exists flag to rejected Michael Köppl
2026-10-05 14:47 ` [PATCH manager v7 17/24] ui: guest ID selector: show the error returned by nextid Michael Köppl
2026-10-05 14:47 ` [PATCH manager v7 18/24] fix #4369: api: optionally only suggest unique IDs Michael Köppl
2026-10-05 14:48 ` [PATCH manager v7 19/24] ui: dc options: rename VMID to guest ID Michael Köppl
2026-10-05 14:48 ` [PATCH manager v7 20/24] fix #4369: ui: dc options: add option for unique VM/CT IDs Michael Köppl
2026-10-05 14:48 ` [PATCH manager v7 21/24] api: nextid: reject IDs forbidden by next-id enforcement Michael Köppl
2026-10-05 14:48 ` [PATCH manager v7 22/24] ui: dc options: add option to enforce next free guest ID settings Michael Köppl
2026-10-05 14:48 ` [PATCH docs v7 23/24] pmxcfs: files: add virtual-guest/used-guest-ids Michael Köppl
2026-10-05 14:48 ` [PATCH docs v7 24/24] pvecm: next-id: document unique and enforce options Michael Köppl

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005144805.825538-11-m.koeppl@proxmox.com \
    --to=m.koeppl@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal