public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: Re: [PATCH pve-network v4 24/47] sdn: add prefix lists module
Date: Tue, 5 May 2026 11:22:08 +0200	[thread overview]
Message-ID: <4665ed28-5ca2-4b1c-9729-5cb8d574e73d@proxmox.com> (raw)
In-Reply-To: <20260504160350.395470-25-s.hanreich@proxmox.com>



On 5/4/26 6:02 PM, Stefan Hanreich wrote:
> Defines helpers for common operations (reading / writing
> configuration) as well as the required formats / schema definitions
> for the route map API.
> 
> Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
> ---
>  src/PVE/Network/SDN/Makefile       |  14 ++-
>  src/PVE/Network/SDN/PrefixLists.pm | 134 +++++++++++++++++++++++++++++
>  2 files changed, 147 insertions(+), 1 deletion(-)
>  create mode 100644 src/PVE/Network/SDN/PrefixLists.pm
> 
> diff --git a/src/PVE/Network/SDN/Makefile b/src/PVE/Network/SDN/Makefile
> index d1ffef9..fa6702e 100644
> --- a/src/PVE/Network/SDN/Makefile
> +++ b/src/PVE/Network/SDN/Makefile
> @@ -1,4 +1,16 @@
> -SOURCES=Vnets.pm VnetPlugin.pm Zones.pm Controllers.pm Subnets.pm SubnetPlugin.pm Ipams.pm Dns.pm Dhcp.pm Fabrics.pm Frr.pm
> +SOURCES=Vnets.pm\
> +		VnetPlugin.pm\
> +		Zones.pm\
> +		Controllers.pm\
> +		Subnets.pm\
> +		SubnetPlugin.pm\
> +		Ipams.pm\
> +		Dns.pm\
> +		Dhcp.pm\
> +		Fabrics.pm\
> +		Frr.pm\
> +		RouteMaps.pm\
> +		PrefixLists.pm
>  

seems like I messed up the changes in the Makefile in this and the
following commits - will fix!

>  PERL5DIR=${DESTDIR}/usr/share/perl5
> diff --git a/src/PVE/Network/SDN/PrefixLists.pm b/src/PVE/Network/SDN/PrefixLists.pm
> new file mode 100644
> index 0000000..ced2ebf
> --- /dev/null
> +++ b/src/PVE/Network/SDN/PrefixLists.pm
> @@ -0,0 +1,134 @@
> +package PVE::Network::SDN::PrefixLists;
> +
> +use strict;
> +use warnings;
> +
> +use PVE::Cluster qw(cfs_register_file cfs_read_file cfs_lock_file cfs_write_file);
> +use PVE::JSONSchema qw(get_standard_option);
> +use PVE::INotify;
> +use PVE::Network::SDN;
> +use PVE::RS::SDN::PrefixLists;
> +
> +PVE::JSONSchema::register_format(
> +    'pve-sdn-prefix-list-id',
> +    sub {
> +        my ($id, $noerr) = @_;
> +
> +        if ($id =~ m/^(only_default|only_default_v6|loopbacks_ips)$/) {
> +            return undef if $noerr;
> +            die "prefix list ID '$id' is currently reserved and cannot be used\n";
> +        }
> +
> +        if ($id !~ m/^[a-zA-Z0-9][a-zA-Z0-9-_]{0,30}[a-zA-Z0-9]?$/i) {
> +            return undef if $noerr;
> +            die "prefix list ID '$id' contains illegal characters\n";
> +        }
> +
> +        return $id;
> +    },
> +);
> +
> +PVE::JSONSchema::register_standard_option(
> +    'pve-sdn-prefix-list-id',
> +    {
> +        description => "The SDN prefix list identifier",
> +        type => 'string',
> +        format => 'pve-sdn-prefix-list-id',
> +    },
> +);
> +
> +cfs_register_file(
> +    'sdn/prefix-lists.cfg', \&parse_prefix_lists_config, \&write_prefix_lists_config,
> +);
> +
> +sub parse_prefix_lists_config {
> +    my ($filename, $raw) = @_;
> +    return $raw // '';
> +}
> +
> +sub write_prefix_lists_config {
> +    my ($filename, $config) = @_;
> +    return $config // '';
> +}
> +
> +sub config {
> +    my ($running) = @_;
> +
> +    if ($running) {
> +        my $running_config = PVE::Network::SDN::running_config();
> +
> +        # if the config hasn't yet been applied after the introduction of
> +        # prefix lists then the key does not exist in the running config so we
> +        # default to an empty hash
> +        my $prefix_lists_config = $running_config->{'prefix-lists'}->{ids} // {};
> +        return PVE::RS::SDN::PrefixLists->running_config($prefix_lists_config);
> +    }
> +
> +    my $prefix_lists_config = cfs_read_file("sdn/prefix-lists.cfg");
> +    return PVE::RS::SDN::PrefixLists->config($prefix_lists_config);
> +}
> +
> +sub write_config {
> +    my ($config) = @_;
> +    cfs_write_file("sdn/prefix-lists.cfg", $config->to_raw(), 1);
> +}
> +
> +sub prefix_list_properties {
> +    my ($update) = @_;
> +
> +    my $properties = {
> +        digest => get_standard_option('pve-config-digest'),
> +        entries => {
> +            type => 'array',
> +            optional => 1,
> +            items => {
> +                type => 'string',
> +                format => {
> +                    action => {
> +                        type => 'string',
> +                        enum => ['permit', 'deny'],
> +                    },
> +                    prefix => {
> +                        type => 'string',
> +                        format => 'CIDR',
> +                    },
> +                    le => {
> +                        type => 'integer',
> +                        minimum => 0,
> +                        maximum => 128,
> +                        optional => 1,
> +                    },
> +                    ge => {
> +                        type => 'integer',
> +                        minimum => 0,
> +                        maximum => 128,
> +                        optional => 1,
> +                    },
> +                    seq => {
> +                        type => 'integer',
> +                        minimum => 0,
> +                        maximum => 2**32 - 1,
> +                        optional => 1,
> +                    },
> +                },
> +            },
> +        },
> +    };
> +
> +    if ($update) {
> +        $properties->{delete} = {
> +            type => 'array',
> +            optional => 1,
> +            items => {
> +                type => 'string',
> +                enum => ['entries'],
> +            },
> +        };
> +    } else {
> +        $properties->{id} = get_standard_option('pve-sdn-prefix-list-id');
> +    }
> +
> +    return $properties;
> +}
> +
> +1;





  reply	other threads:[~2026-05-05  9:22 UTC|newest]

Thread overview: 51+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-04 16:02 [PATCH access-control/cluster/manager/network/proxmox{-ve-rs,-perl-rs} v4 00/47] Add support for route maps / prefix lists to SDN Stefan Hanreich
2026-05-04 16:02 ` [PATCH pve-cluster v4 01/47] cfs: add 'sdn/route-maps.cfg' to observed files Stefan Hanreich
2026-05-04 16:02 ` [PATCH pve-cluster v4 02/47] cfs: add 'sdn/prefix-lists.cfg' " Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-access-control v4 03/47] permissions: add ACL path for prefix-lists and route-maps Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 04/47] frr: add constructor to prefix list name Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 05/47] sdn-types: add common route-map helper types Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 06/47] frr: change order type to u16 Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 07/47] frr: implement routemap match/set statements via adjacent tagging Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 08/47] frr: implement support for call and exit action Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 09/47] frr-templates: change route maps template to adapt to new frr types Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 10/47] ve-config: fabrics: adapt frr config generation Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 11/47] ve-config: add prefix list section config Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 12/47] ve-config: frr: implement frr config generation for prefix lists Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 13/47] ve-config: add route map section config Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 14/47] ve-config: frr: implement frr config generation for route maps Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 15/47] ve-config: add prefix lists integration tests Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 16/47] ve-config: add route maps " Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 17/47] fabrics: ospf: fix deserializing OspfDeletableProperties Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 18/47] fabrics: ospf: openfabric: allow user-defined route filter Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-ve-rs v4 19/47] frr: fabrics: apply route_filter setting Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-perl-rs v4 20/47] pve-rs: sdn: add route maps module Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-perl-rs v4 21/47] pve-rs: sdn: add prefix lists module Stefan Hanreich
2026-05-04 16:03 ` [PATCH proxmox-perl-rs v4 22/47] sdn: add prefix list / route maps to frr config generation helper Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 23/47] controller: bgp: evpn: adapt to new match / set frr config syntax Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 24/47] sdn: add prefix lists module Stefan Hanreich
2026-05-05  9:22   ` Stefan Hanreich [this message]
2026-05-04 16:03 ` [PATCH pve-network v4 25/47] sdn: add route map module Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 26/47] api2: add prefix list module Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 27/47] api2: add route maps module Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 28/47] api2: add route map module Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 29/47] api2: add route map entry module Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 30/47] evpn controller: add route_map_{in,out} parameter Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 31/47] bgp controller: allow configuring custom route maps Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 32/47] sdn: change detection for route maps / prefix lists Stefan Hanreich
2026-05-05  9:07   ` Hannes Laimer
2026-05-05  9:14     ` Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 33/47] sdn: generate route map / prefix list configuration on sdn apply Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 34/47] sdn: frr: consider route maps and prefix lists in dry-run Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 35/47] fabrics: ospf: openfabric: add route_filter property Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 36/47] tests: add simple route map test case Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 37/47] tests: add bgp evpn route map/prefix list testcase Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 38/47] tests: add route map with prefix " Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-network v4 39/47] tests: add exit node with custom route map testcase Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 40/47] ui: sdn: add route map selector Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 41/47] ui: sdn: add prefix list selector Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 42/47] ui: sdn: add panel for managing prefix lists Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 43/47] ui: sdn: add panel for managing route map entries Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 44/47] ui: sdn: bgp controller: allow configuring route maps Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 45/47] ui: sdn: evpn " Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 46/47] ui: sdn: openfabric: add route filter Stefan Hanreich
2026-05-04 16:03 ` [PATCH pve-manager v4 47/47] ui: sdn: ospf: add route filter setting Stefan Hanreich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4665ed28-5ca2-4b1c-9729-5cb8d574e73d@proxmox.com \
    --to=s.hanreich@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal