From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id F40431FF138 for ; Mon, 20 Jul 2026 10:25:28 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id BCA42214C9; Mon, 20 Jul 2026 10:25:28 +0200 (CEST) Message-ID: Date: Mon, 20 Jul 2026 10:24:52 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird From: David Riley Subject: Re: [PATCH pve-network v2 07/10] fix #7294: sdn: vnet: update pool members on vnet migration and deletion To: Daniel Kral , pve-devel@lists.proxmox.com References: <20260626131035.112374-1-d.riley@proxmox.com> <20260626131035.112374-8-d.riley@proxmox.com> Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1784535868609 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.115 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: JTRPFULTECHVW5LZYXUCRVU6TOP2JSRH X-Message-ID-Hash: JTRPFULTECHVW5LZYXUCRVU6TOP2JSRH X-MailFrom: d.riley@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: comment inline. On 7/6/26 2:30 PM, Daniel Kral wrote: > On Fri Jun 26, 2026 at 3:10 PM CEST, David Riley wrote: >> Update or remove corresponding resource pool allocations in user.cfg >> whenever a VNet is altered or deleted. This prevents stale paths and >> dangling references from breaking the configuration integrity. >> >> Link:https://bugzilla.proxmox.com/show_bug.cgi?id=7294 >> Signed-off-by: David Riley >> --- >> src/PVE/Network/SDN.pm | 15 +++++++++++++++ >> 1 file changed, 15 insertions(+) >> >> diff --git a/src/PVE/Network/SDN.pm b/src/PVE/Network/SDN.pm >> index cd563d2..81f5d9a 100644 >> --- a/src/PVE/Network/SDN.pm >> +++ b/src/PVE/Network/SDN.pm >> @@ -261,11 +261,26 @@ sub cleanup { >> PVE::AccessControl::migrate_sdn_resource_access($vnet_move_paths); >> } >> >> + for my $move (@$vnet_move_paths) { >> + my ($src_type, $src_zone, $vnet) = @{ $move->{src_path} }; >> + my ($dest_type, $dest_zone, $dest_vnet) = @{ $move->{dest_path} }; >> + >> + if (defined($src_type) && $src_type eq 'zones' && $src_zone && $vnet && $dest_zone) { > Will there ever be any VNet paths to be moved, that are not zones? > > Otherwise, I think the checks are a little overkill here. Since there > already quite a lot of definedness checks in diff_vnets(), these might > be redundant here. No and you are totally right these checks don't add anything here. I'll remove them. >> + PVE::AccessControl::migrate_vnet_zone_in_pool($src_zone, $dest_zone, $vnet); >> + } >> + } >> + >> my @paths_to_delete = (@$vnet_delete_paths, @$route_map_paths, @$generic_paths); >> if (@paths_to_delete) { >> PVE::AccessControl::remove_sdn_resource_access(\@paths_to_delete); >> } >> >> + for my $path (@$vnet_delete_paths) { >> + my ($type, $zone, $vnet) = @$path; >> + if ($type && $type eq 'zones' && $zone && $vnet) { >> + PVE::AccessControl::remove_vnet_from_pool($zone, $vnet); >> + } > Same here. > >> + } >> } >> >> sub diff_generic_resources { > > >