From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 5D4CF1FF09C for ; Mon, 05 Oct 2026 16:51:19 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 05CA121974; Mon, 05 Oct 2026 16:48:59 +0200 (CEST) From: =?UTF-8?q?Michael=20K=C3=B6ppl?= To: pve-devel@lists.proxmox.com Subject: [PATCH manager v7 21/24] api: nextid: reject IDs forbidden by next-id enforcement Date: Mon, 5 Oct 2026 16:48:02 +0200 Message-ID: <20261005144805.825538-22-m.koeppl@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261005144805.825538-1-m.koeppl@proxmox.com> References: <20261005144805.825538-1-m.koeppl@proxmox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791211690521 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.325 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: WC54AULI6CUECB2TKK7NAP3TV36WX57U X-Message-ID-Hash: WC54AULI6CUECB2TKK7NAP3TV36WX57U X-MailFrom: m.koeppl@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: With 'enforce' set in the next-id datacenter option, new guests may only use IDs within the configured range and, with 'unique', IDs that were not used before. Creating a guest with any other ID fails anyway, but the GUI validates its guest ID field through this endpoint, so reject such IDs here as well to report the problem before a task is started. Since the endpoint serves both VMs and CTs and its error is now shown in the GUI, also change the message for IDs of existing guests to refer to guest IDs. Signed-off-by: Michael Köppl --- PVE/API2/Cluster.pm | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/PVE/API2/Cluster.pm b/PVE/API2/Cluster.pm index e5017f6c4..c487980a4 100644 --- a/PVE/API2/Cluster.pm +++ b/PVE/API2/Cluster.pm @@ -1036,8 +1036,13 @@ __PACKAGE__->register_method({ my $idlist = $vmlist->{ids} || {}; if (my $vmid = $param->{vmid}) { - return $vmid if !defined($idlist->{$vmid}); - raise_param_exc({ vmid => "VM $vmid already exists" }); + raise_param_exc({ vmid => "guest ID $vmid is already in use" }) + if defined($idlist->{$vmid}); + + eval { PVE::GuestID::assert_id_satisfies_next_id_settings($vmid) }; + raise_param_exc({ vmid => $@ }) if $@; + + return $vmid; } my $dc_conf = PVE::Cluster::cfs_read_file('datacenter.cfg'); -- 2.47.3