From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) by lore.proxmox.com (Postfix) with ESMTPS id 255D81FF15C for ; Wed, 8 Jan 2025 13:09:54 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id C71A51851F; Wed, 8 Jan 2025 13:09:37 +0100 (CET) To: pve-devel@lists.proxmox.com Date: Wed, 8 Jan 2025 13:08:56 +0100 In-Reply-To: <20250108120903.5344-1-lou.lecrivain@wdz.de> References: <20250108120903.5344-1-lou.lecrivain@wdz.de> MIME-Version: 1.0 Message-ID: List-Id: Proxmox VE development discussion List-Post: From: Lou Lecrivain via pve-devel Precedence: list Cc: Lou Lecrivain X-Mailman-Version: 2.1.29 X-BeenThere: pve-devel@lists.proxmox.com List-Subscribe: , List-Unsubscribe: , List-Archive: Reply-To: Proxmox VE development discussion List-Help: Subject: [pve-devel] SPAM: [PATCH pve-network v2 2/7] ipam: nautobot: implement plain prefix allocation Content-Type: multipart/mixed; boundary="===============0754193113344181254==" Errors-To: pve-devel-bounces@lists.proxmox.com Sender: "pve-devel" --===============0754193113344181254== Content-Type: message/rfc822 Content-Disposition: inline Return-Path: X-Original-To: pve-devel@lists.proxmox.com Delivered-To: pve-devel@lists.proxmox.com Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 461C6CAFC1 for ; Wed, 8 Jan 2025 13:09:36 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 2F7C11847B for ; Wed, 8 Jan 2025 13:09:36 +0100 (CET) Received: from smtp.smtpout.orange.fr (smtp-18.smtpout.orange.fr [80.12.242.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS for ; Wed, 8 Jan 2025 13:09:35 +0100 (CET) Received: from localhost ([176.139.8.107]) by smtp.orange.fr with ESMTPA id VUsHtau4onktyVUsKtrsbT; Wed, 08 Jan 2025 13:09:29 +0100 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.fr; s=t20230301; t=1736338169; bh=0bn71uklMAjGaZWbNohnXmzNjPVWbu/E4aaWb+wSBQg=; h=From:To:Subject:Date:Message-Id:MIME-Version; b=d+Ad+1zqU7Bqi26q0/fLa6l3lPkzAEmJTxBv8ID6S1ehITeLCd//H93d5SGkkRP/U b0I+opITjeTmPqM7jxYTnOZh+5lOwN/maed5k4YEkB2ZtB9CtvpyF+rAfwlyx/Okj8 qj7iPVTT1pP8KhQXlPUzmW+gbkP4b3ShnB532BJLDe9CucGydibdAGaAnih42BEjbZ QDtGajPV7FShdFjEIMfeT/pl/OumJR2xLJ7hauT0/io+LhrEt7sTN94USFk52KnYWu UrZ2mHGz0u95QXGp7YxX5JxfZnQviFWDj0W40bo/bMJib+yHj7/5HNXhHafjoqHBAp iFqhhOOmHKZZQ== X-ME-Helo: localhost X-ME-Auth: bG91LmxlY3JpdmFpbkBvcmFuZ2UuZnI= X-ME-Date: Wed, 08 Jan 2025 13:09:29 +0100 X-ME-IP: 176.139.8.107 From: Lou Lecrivain To: pve-devel@lists.proxmox.com subject: SPAM: [PATCH pve-network v2 2/7] ipam: nautobot: implement plain prefix allocation Date: Wed, 8 Jan 2025 13:08:56 +0100 Message-Id: <20250108120903.5344-5-lou.lecrivain@wdz.de> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20250108120903.5344-1-lou.lecrivain@wdz.de> References: <20250108120903.5344-1-lou.lecrivain@wdz.de> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 4 AWL -0.086 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_REJECT 0.1 DMARC reject policy FREEMAIL_FORGED_FROMDOMAIN 0.001 2nd level domains in From and EnvelopeFrom freemail headers are different FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider HEADER_FROM_DIFFERENT_DOMAINS 0.24 From and EnvelopeFrom 2nd level mail domains are different KAM_DMARC_REJECT 6 DKIM has Failed or SPF has failed on the message and the domain has a DMARC reject policy RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust RCVD_IN_MSPIKE_H3 0.001 Good reputation (+3) RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders SPF_HELO_PASS -0.001 SPF: HELO matches SPF record SPF_PASS -0.001 SPF: sender matches SPF record add support for subnet allocation without ranges, where it was previously not supported. Signed-off-by: lou lecrivain --- src/PVE/Network/SDN/Ipams/NautobotPlugin.pm | 68 +++++++++++++++++++++ 1 file changed, 68 insertions(+) diff --git a/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm b/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm index 69e7897..22867df 100644 --- a/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm +++ b/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm @@ -5,6 +5,7 @@ use warnings; use PVE::INotify; use PVE::Cluster; use PVE::Tools; +use NetAddr::IP; use base('PVE::Network::SDN::Ipams::NetboxPlugin'); @@ -95,6 +96,66 @@ sub add_ip { } } +sub add_next_freeip { + my ($class, $plugin_config, $subnetid, $subnet, $hostname, $mac, $vmid, $noerr) = @_; + + my $cidr = $subnet->{cidr}; + + my $url = $plugin_config->{url}; + my $namespace = $plugin_config->{namespace}; + my $headers = default_headers($plugin_config); + + my $internalid = PVE::Network::SDN::Ipams::NetboxPlugin::get_prefix_id($url, $cidr, $headers); + + my $description = "mac:$mac" if $mac; + + my $params = { type => "dhcp", dns_name => $hostname, description => $description, namespace => $namespace, status => default_ip_status() }; + + my $ip = eval { + my $result = PVE::Network::SDN::api_request("POST", "$url/ipam/prefixes/$internalid/available-ips/", $headers, $params); + my ($ip, undef) = split(/\//, $result->{address}); + return $ip; + }; + + if ($@) { + die "can't find free ip in subnet $cidr: $@" if !$noerr; + } + return $ip; +} + +sub add_range_next_freeip { + my ($class, $plugin_config, $subnet, $range, $data, $noerr) = @_; + + my $url = $plugin_config->{url}; + my $namespace = $plugin_config->{namespace}; + my $headers = default_headers($plugin_config); + my $cidr = $subnet->{cidr}; + + # ranges are not supported natively in nautobot, hence why we have to get a little hacky. + my $minimal_size = NetAddr::IP->new($range->{'start-address'}) - NetAddr::IP->new($cidr); + my $internalid = PVE::Network::SDN::Ipams::NetboxPlugin::get_prefix_id($url, $cidr, $headers); + + my $ip = eval { + my $result = PVE::Network::SDN::api_request("GET", "$url/ipam/prefixes/$internalid/available-ips/?limit=$minimal_size", $headers); + # v important for NetAddr::IP comparison! + my @ips = map((split(/\//,$_->{address}))[0], @{$result}); + # get 1st result + my $ip = (get_ips_within_range($range->{'start-address'}, $range->{'end-address'}, @ips))[0]; + + if ($ip) { + print "found free ip $ip in range $range->{'start-address'}-$range->{'end-address'}\n" + } else { die "prefix out of space in range"; } + + $class->add_ip($plugin_config, undef, $subnet, $ip, $data->{hostname}, $data->{mac}, undef, 0, 0); + return $ip; + }; + + if ($@) { + die "can't find free ip in range $range->{'start-address'}-$range->{'end-address'}: $@" if !$noerr; + } + return $ip; +} + sub update_ip { my ($class, $plugin_config, $subnetid, $subnet, $ip, $hostname, $mac, $vmid, $is_gateway, $noerr) = @_; @@ -174,6 +235,13 @@ sub on_update_hook { } # helpers +sub get_ips_within_range { + my ($start_address, $end_address, @list) = @_; + $start_address = NetAddr::IP->new($start_address); + $end_address = NetAddr::IP->new($end_address); + return grep($start_address <= NetAddr::IP->new($_) <= $end_address, @list); +} + sub get_namespace_id { my ($url, $namespace, $headers) = @_; -- 2.39.5 --===============0754193113344181254== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel --===============0754193113344181254==--