Bugs related to reused VMIDs

joebaires

Member
May 20, 2015
7
1
23
Hello,

This is my first message in this forum and I would like to discuss an issue I find problematic on Proxmox.

In brief: VMIDs should be auto-incremental, like in a database.

Currently, when you remove a VM/CT, the ID becomes available again, and the next time you create a virtual machine It will be used (proxmox will suggest the least available ID).

One of the severe consequences of this, is that the new machine will inherit access privileges of the previous VM, as Proxmox doesn't drop privileges when removing the VM, and they are referenced using the VMID.

I just had to learn this the hard way, with a customer complaining somebody was accessing his console.

I also think that in the same way stale privileges remain in the system, there might be similar issues with other parts of the Proxmox system.

Would like to hear your opinions. Thank you

-J
 
the new machine will inherit access privileges of the previous VM, as Proxmox doesn't drop privileges when removing the VM, and they are referenced using the VMID.

Hi,
maybe it will be more clear if you detail a bit which "privileges" you are specifically referring to...

if you created a user which can access pve web interface to use a VMID, someone could answer that if you remove the VMID then is your duty to make sure your permissions are always updated.

nobody else can know if you recreate the same VMID and give it to the ANOTHER customer, or if you recreate the same VMID and give it to the SAME customer (then if pve destroyed your previous permissions, your customer would complain that he's no more able to access the same VMID...)

I agree that pve could at least WARN you if some resource (permissions, pools I don't know what is left, I don't have external customers) related to the VMID will be left untouched (or not), so for you to know and act accordingly.

Marco
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!