destroy_vm: snippet cleanup reads the config after the VM is deleted, and the delete task is not awaited #15

Open
opened 2026-10-07 21:21:53 +00:00 by christianmanivong · 0 comments
Owner

destroy_vm (vm_provision_mixin.py) has two ordering problems:

  1. Snippet cleanup reads the VM's config after deleting the VM. Step 2 calls qemu(vmid).delete(purge=1, …); step 3 then calls qemu(vmid).config.get() to find cicustom. Once the delete has gone through, the config is gone and the call fails. The except only logs at debug level, so the user-data snippet <vmid>-user-data.yaml stays on the snippet storage for every destroyed VM. Whether the read still succeeds depends on how far the delete task has got, see 2.
  2. The delete is not waited for. DELETE /nodes/{node}/qemu/{vmid} starts a task and returns its UPID; destroy_vm ignores it and returns while the VM may still exist. Its callers (netOrk's deprovisioning) treat the return as "VM is gone".

The tests mock config.get() to keep answering after delete(), and delete() to return None, so neither shows there.

Read from the code, not reproduced on a node. Found while adding a second snippet (network=) to cicustom for BSD guests (NetOrk/netork#794); that change reads cicustom before deleting, which fixes 1. Item 2 stays open here.

`destroy_vm` (`vm_provision_mixin.py`) has two ordering problems: 1. **Snippet cleanup reads the VM's config after deleting the VM.** Step 2 calls `qemu(vmid).delete(purge=1, …)`; step 3 then calls `qemu(vmid).config.get()` to find `cicustom`. Once the delete has gone through, the config is gone and the call fails. The `except` only logs at debug level, so the user-data snippet `<vmid>-user-data.yaml` stays on the snippet storage for every destroyed VM. Whether the read still succeeds depends on how far the delete task has got, see 2. 2. **The delete is not waited for.** `DELETE /nodes/{node}/qemu/{vmid}` starts a task and returns its UPID; `destroy_vm` ignores it and returns while the VM may still exist. Its callers (netOrk's deprovisioning) treat the return as "VM is gone". The tests mock `config.get()` to keep answering after `delete()`, and `delete()` to return None, so neither shows there. Read from the code, not reproduced on a node. Found while adding a second snippet (`network=`) to `cicustom` for BSD guests (NetOrk/netork#794); that change reads `cicustom` before deleting, which fixes 1. Item 2 stays open here.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-proxmox#15