From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id D8B721FF09C for ; Mon, 05 Oct 2026 16:48:43 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id E0AA121756; Mon, 05 Oct 2026 16:48:15 +0200 (CEST) From: =?UTF-8?q?Michael=20K=C3=B6ppl?= To: pve-devel@lists.proxmox.com Subject: [PATCH guest-common v7 11/24] guest id: add helper to check guest IDs against next-id enforcement Date: Mon, 5 Oct 2026 16:47:52 +0200 Message-ID: <20261005144805.825538-12-m.koeppl@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261005144805.825538-1-m.koeppl@proxmox.com> References: <20261005144805.825538-1-m.koeppl@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791211689578 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.378 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: NQTDUIVJYNSRXHWHBVLXLIFREFRS7S6O X-Message-ID-Hash: NQTDUIVJYNSRXHWHBVLXLIFREFRS7S6O X-MailFrom: m.koeppl@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: With 'enforce' set in the next-id datacenter option, creating a guest with an ID outside the configured range or, with 'unique', an ID that was used before fails when the ID is registered. That only happens once the creation task is already running. Add a helper that runs the same checks without recording the ID, so that callers can reject such IDs early. The helper reads the list of used IDs without taking the lock, so another node may record the ID in between. register_used_id() still checks it under the lock and remains the authoritative check. Signed-off-by: Michael Köppl --- src/PVE/GuestID.pm | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/src/PVE/GuestID.pm b/src/PVE/GuestID.pm index ba71e4f..a068432 100644 --- a/src/PVE/GuestID.pm +++ b/src/PVE/GuestID.pm @@ -205,6 +205,20 @@ my sub assert_id_in_next_id_range($next_id_opts, $id) { if defined($upper) && $id >= $upper; } +# Dies if the next-id datacenter option enforces its range or uniqueness +# and a new guest must not use $id. Existing guests are not considered. +sub assert_id_satisfies_next_id_settings($id) { + my $next_id_opts = cfs_read_file('datacenter.cfg')->{'next-id'} // {}; + return if !$next_id_opts->{enforce}; + + assert_id_in_next_id_range($next_id_opts, $id); + + if ($next_id_opts->{unique}) { + my $ranges = cfs_read_file($FILENAME); + die "guest ID $id was used before\n" if next_unused($ranges, $id) != $id; + } +} + # Records $id as used. If the next-id datacenter option enforces its # range or uniqueness, IDs a new guest must not use are rejected, unless # $opts->{existing} marks $id as belonging to an existing guest. -- 2.47.3