From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id E5DE91FF0B0 for ; Fri, 09 Oct 2026 15:02:57 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 2480521B90; Fri, 09 Oct 2026 14:58:15 +0200 (CEST) From: Lukas Wagner To: pbs-devel@lists.proxmox.com, pve-devel@lists.proxmox.com Subject: [PATCH manager v3 38/39] api: notification: reject matchers with expression if not supported by all nodes Date: Fri, 9 Oct 2026 14:56:45 +0200 Message-ID: <20261009125646.284673-39-l.wagner@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261009125646.284673-1-l.wagner@proxmox.com> References: <20261009125646.284673-1-l.wagner@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791550614228 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.321 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: QJ3JWGZXEQWPAYHXS32RPVDXJWDBWW3B X-Message-ID-Hash: QJ3JWGZXEQWPAYHXS32RPVDXJWDBWW3B X-MailFrom: l.wagner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The new matcher UI will automatically migrate any existing matcher to one with an 'expression', and new matchers will also only use this new parameter. If any of the cluster nodes uses a version of pve-manager that does not yet support the new parameter, any matcher written by an updated node will break notifications on the older nodes. To avoid this, on create/update, we now reject matchers with an 'expression' parameter if any of the online cluster nodes is still running on a too old version of pve-manager. While this still leaves the possibility of an outdated, offline node coming back online and then failing to parse the migrated notification config, it would be unreasonable to disallow editing the notification configuration if any node is offline. Signed-off-by: Lukas Wagner --- Notes: New in v3. Note to maintainers: Please change the version guard to the version of pve-manager that actually includes the change. PVE/API2/Cluster/Notifications.pm | 32 +++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/PVE/API2/Cluster/Notifications.pm b/PVE/API2/Cluster/Notifications.pm index bd3c86cc..fd2f695b 100644 --- a/PVE/API2/Cluster/Notifications.pm +++ b/PVE/API2/Cluster/Notifications.pm @@ -6,11 +6,13 @@ use strict; use Storable qw(dclone); use JSON; +use PVE::Cluster; use PVE::Exception qw(raise_param_exc); use PVE::Tools qw(extract_param); use PVE::JSONSchema qw(get_standard_option); use PVE::RESTHandler; use PVE::Notify; +use PVE::SafeSyslog; use base qw(PVE::RESTHandler); @@ -56,6 +58,23 @@ sub raise_api_error { die $exc; } +my $matcher_expressions_version = "9.2.21"; +my $matcher_expressions_version_array = [9, 2, 21]; + +my sub matcher_expressions_supported { + my $version_info = PVE::Cluster::get_node_kv('version-info'); + for my $node (sort keys $version_info->%*) { + my $node_info = eval { JSON::decode_json($version_info->{$node}); }; + if (my $err = $@) { # warn, but continue + syslog('warn', "cannot parse version info for $node as JSON - $err"); + } elsif (!PVE::Cluster::pvecfg_min_version($node_info->{version}, @$matcher_expressions_version_array)) { + return 0; + } + } + + return 1; +} + __PACKAGE__->register_method({ name => 'index', path => '', @@ -1660,10 +1679,17 @@ __PACKAGE__->register_method({ code => sub { my ($param) = @_; + # FIXME: MAJOR VERSION: This check can be dropped at the next major version bump. + if (defined($param->{expression}) && !matcher_expressions_supported()) { + die "At least one cluster node does not support matcher expressions." + . " Please upgrade pve-manager to at least $matcher_expressions_version."; + } + eval { PVE::Notify::lock_config(sub { my $config = PVE::Notify::read_config(); + $config->add_matcher($param); PVE::Notify::write_config($config); @@ -1708,6 +1734,12 @@ __PACKAGE__->register_method({ my $digest = extract_param($param, 'digest'); my $delete = extract_param($param, 'delete'); + # FIXME: MAJOR VERSION: This check can be dropped at the next major version bump. + if (defined($param->{expression}) && !matcher_expressions_supported()) { + die "At least one cluster node does not support matcher expressions." + . " Please upgrade pve-manager to at least $matcher_expressions_version."; + } + eval { PVE::Notify::lock_config(sub { my $config = PVE::Notify::read_config(); -- 2.47.3