From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 7B3DA1FF0A3 for ; Thu, 01 Oct 2026 14:07:27 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id B98DE216FC; Thu, 01 Oct 2026 14:07:20 +0200 (CEST) Message-ID: Date: Thu, 1 Oct 2026 14:07:17 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH guest-common v6 09/18] guest id: optionally enforce the next-id range and uniqueness From: Fiona Ebner To: =?UTF-8?Q?Michael_K=C3=B6ppl?= , pve-devel@lists.proxmox.com References: <20260924161510.847362-1-m.koeppl@proxmox.com> <20260924161510.847362-10-m.koeppl@proxmox.com> <2d268ca0-7544-4fb3-9c8f-f1eabc1ee25d@proxmox.com> Content-Language: en-US In-Reply-To: <2d268ca0-7544-4fb3-9c8f-f1eabc1ee25d@proxmox.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1790856437269 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.487 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: RLXWIEXT2WKF2QWFRHMR2Y4TJZQEOUBH X-Message-ID-Hash: RLXWIEXT2WKF2QWFRHMR2Y4TJZQEOUBH X-MailFrom: f.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Am 01.10.26 um 2:04 PM schrieb Fiona Ebner: > Am 24.09.26 um 6:16 PM schrieb Michael Köppl: >> If the 'enforce' subproperty of next-id is enabled, ensure that only >> guest IDs from the configured range and, if unique is enabled as well, >> only previously unused IDs can be used. By setting existing => 1, the >> enforcement of these criteria is disabled for actions on existing >> guests, such as destroy, remote migration with --delete, and restore >> over an existing guest. >> >> IDs are recorded before a guest exists and stay recorded if its >> creation fails later. With both 'enforce' and 'unique' set, retrying a >> failed creation with the same ID is therefore rejected. >> >> Signed-off-by: Michael Köppl >> --- >> src/PVE/AbstractConfig.pm | 4 ++-- >> src/PVE/GuestID.pm | 49 ++++++++++++++++++++++++++++++++++----- >> 2 files changed, 45 insertions(+), 8 deletions(-) >> >> diff --git a/src/PVE/AbstractConfig.pm b/src/PVE/AbstractConfig.pm >> index 229e4bd..2f20596 100644 >> --- a/src/PVE/AbstractConfig.pm >> +++ b/src/PVE/AbstractConfig.pm >> @@ -260,9 +260,9 @@ sub create_and_lock_config { >> $vmid, >> 5, >> sub { >> - PVE::Cluster::check_vmid_unused($vmid, $allow_existing); >> + my $is_new = PVE::Cluster::check_vmid_unused($vmid, $allow_existing); >> >> - PVE::GuestID::register_used_id($vmid); >> + PVE::GuestID::register_used_id($vmid, { existing => !$is_new }); >> >> my $conf = eval { $class->load_config($vmid) } || {}; >> $class->check_lock($conf); >> diff --git a/src/PVE/GuestID.pm b/src/PVE/GuestID.pm >> index 4ab6f2d..02abf24 100644 >> --- a/src/PVE/GuestID.pm >> +++ b/src/PVE/GuestID.pm >> @@ -187,26 +187,63 @@ my sub insert_id($ranges, $id) { >> return 1; >> } >> >> -sub register_used_id($id) { >> - cfs_lock_file( >> +my sub check_range($next_id, $id) { > > assert_ rather than check_ since it dies > > I'd also go for something more descriptive like assert_id_in_next_id_range > >> + my $lower = $next_id->{lower}; >> + my $upper = $next_id->{upper}; >> + >> + die "guest ID $id is below the lower boundary $lower of the next-id range\n" >> + if defined($lower) && $id < $lower; >> + die "guest ID $id is not below the upper boundary $upper of the next-id range\n" >> + if defined($upper) && $id >= $upper; >> +} >> + >> +# Dies if the next-id datacenter option enforces its range or uniqueness >> +# and a new guest must not use $id. Existing guests are not considered. >> +sub check_enforced_id($id) { > > Similarly here, maybe assert_id_satisfies_next_id_settings? > > Nit: adding this helper could be its own commit. > >> + my $next_id = cfs_read_file('datacenter.cfg')->{'next-id'} // {}; > > As already noted in patch 4/18, I feel like we should abort if we can't > read the file, since it might mean violating enforce+unique otherwise. Sorry, ignore this one please. It does already die in that case. > > Nit: maybe $next_id_opts to avoid potential ambiguity? > >> + return if !$next_id->{enforce}; >> + >> + check_range($next_id, $id); >> + >> + if ($next_id->{unique}) { >> + my $ranges = cfs_read_file($FILENAME); >> + die "guest ID $id was used before\n" if next_unused($ranges, $id) != $id; >> + } >> +} >> + >> +# Records $id as used. If the next-id datacenter option enforces its >> +# range or uniqueness, IDs a new guest must not use are rejected, unless >> +# $opts->{existing} marks $id as belonging to an existing guest. >> +sub register_used_id($id, $opts = {}) { >> + my $next_id = cfs_read_file('datacenter.cfg')->{'next-id'} // {}; > > Same as above with respect to dying. And this is also a wrong comment I forgot to delete before sending, but the name could be made $next_id_opts > >> + # never reject an existing guest >> + my $enforce = $next_id->{enforce} && !$opts->{existing}; >> + >> + check_range($next_id, $id) if $enforce; >> + >> + my $recorded = cfs_lock_file( >> $FILENAME, >> 10, >> sub { >> my $ranges = cfs_read_file($FILENAME); >> >> - return if !insert_id($ranges, $id); >> + return 0 if !insert_id($ranges, $id); >> >> cfs_write_file($FILENAME, $ranges); >> + return 1; >> }, >> ); >> >> if (my $err = $@) { >> - my $dc_conf = cfs_read_file('datacenter.cfg'); >> - >> my $emsg = "unable to record guest ID $id as used"; >> - die "$emsg - $err" if $dc_conf->{'next-id'}->{unique}; >> + die "$emsg - $err" if $next_id->{unique}; >> warn "$emsg - $err"; >> + >> + return; >> } >> + >> + die "guest ID $id was used before\n" >> + if $enforce && $next_id->{unique} && !$recorded; >> } >> >> cfs_register_file($FILENAME, \&parse_id_list, \&write_id_list); > > > > >