From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 095A21FF09C for ; Mon, 05 Oct 2026 16:49:53 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 1413921822; Mon, 05 Oct 2026 16:48:42 +0200 (CEST) From: =?UTF-8?q?Michael=20K=C3=B6ppl?= To: pve-devel@lists.proxmox.com Subject: [PATCH container v7 15/24] api, migrate: exempt existing CTs from next-id enforcement Date: Mon, 5 Oct 2026 16:47:56 +0200 Message-ID: <20261005144805.825538-16-m.koeppl@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261005144805.825538-1-m.koeppl@proxmox.com> References: <20261005144805.825538-1-m.koeppl@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791211689989 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.350 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 2BAMOISNEF2M6TJ64PTOQKP6H4ZONM3H X-Message-ID-Hash: 2BAMOISNEF2M6TJ64PTOQKP6H4ZONM3H X-MailFrom: m.koeppl@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: With 'enforce' set in the next-id datacenter option, register_used_id() rejects IDs outside the configured range and, with 'unique', IDs that were used before. That is only meant for IDs claimed by new guests. Destroying a CT and removing the source CT after a remote migration with --delete both record the ID of a CT that already exists. That ID was recorded when the CT was created and it may lie outside the configured range if the range was changed later. Thus, exempt these cases from enforcement. Signed-off-by: Michael Köppl --- src/PVE/API2/LXC.pm | 2 +- src/PVE/LXC/Migrate.pm | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/PVE/API2/LXC.pm b/src/PVE/API2/LXC.pm index fb4262c9..179eb3c4 100644 --- a/src/PVE/API2/LXC.pm +++ b/src/PVE/API2/LXC.pm @@ -884,7 +884,7 @@ __PACKAGE__->register_method({ $early_checks->($conf); # record before destroying anything, so a failure here leaves the CT intact - eval { PVE::GuestID::register_used_id($vmid) }; + eval { PVE::GuestID::register_used_id($vmid, { existing => 1 }) }; die "unable to destroy CT $vmid - $@" if $@; my $running_error_msg = "unable to destroy CT $vmid - container is running\n"; diff --git a/src/PVE/LXC/Migrate.pm b/src/PVE/LXC/Migrate.pm index a215dede..5db867aa 100644 --- a/src/PVE/LXC/Migrate.pm +++ b/src/PVE/LXC/Migrate.pm @@ -542,7 +542,7 @@ sub final_cleanup { PVE::Tunnel::write_tunnel($self->{tunnel}, 60, 'start'); } if ($self->{opts}->{delete}) { - eval { PVE::GuestID::register_used_id($vmid) }; + eval { PVE::GuestID::register_used_id($vmid, { existing => 1 }) }; warn $@ if $@; PVE::LXC::destroy_lxc_container( -- 2.47.3