39 Commits

Author SHA1 Message Date
GoodOlClint 5e5a8fcda4 Merge pull request #63 from GoodOlClint/docs/changelog-and-releasenotes-catchup
docs: cut CHANGELOG into versioned entries, refresh ReleaseNotes
2026-05-20 19:27:05 -05:00
Clint Branham 79c97ec211 docs: cut CHANGELOG into versioned entries, refresh ReleaseNotes
Doc hygiene catch-up surfaced by the PR #62 review:

- CHANGELOG.md: the [Unreleased] section had accumulated all post-preview
  work without ever being cut into release entries. Promote it into:
    - [0.1.3] - new fixes from #58 (DiskSize normalization) and #59
      (HttpClient -TimeoutSeconds + RequestTimeout surfacing)
    - [0.1.2] - #43/#44/#45 fixes from PR #46
    - [0.1.1] - the cmdlet expansion + OpenAPI validation that
      actually shipped to PSGallery as 0.1.1
  Reset [Unreleased] to empty.

- src/PSProxmoxVE/PSProxmoxVE.psd1: replace the stale "Initial preview
  release" ReleaseNotes (carried over since 0.1.0-preview) with actual
  0.1.3 notes. PSGallery shows this on the version page.

- CLAUDE.md: document the release process so future bumps update the
  psd1 version, psd1 ReleaseNotes, and CHANGELOG together before the
  tag is cut. Prevents this hygiene gap from recurring.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 19:23:29 -05:00
GoodOlClint 098ea7e8d4 Merge pull request #62 from GoodOlClint/chore/bump-version-0.1.3
chore: bump version to 0.1.3
2026-05-20 19:19:01 -05:00
Clint Branham ff728fc6d6 chore: bump version to 0.1.3
Releases #58 (LVM disk-size unit normalization) and #59 (HttpClient
timeout / -TimeoutSeconds) fixes to PSGallery.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 19:14:54 -05:00
GoodOlClint 02254ed13b Merge pull request #61 from GoodOlClint/fix/http-client-timeout
fix: add -TimeoutSeconds for long-running HTTP calls (#59)
2026-05-20 18:26:08 -05:00
Clint Branham cb97a86c9f fix: drop net48-incompatible TimeoutException filter in timeout catch
The when filter (ex.InnerException is TimeoutException) only matches on
.NET 5+. On .NET Framework 4.8 — which CI exercises via the test project's
net48 target — HttpClient.Timeout throws a bare TaskCanceledException
with no inner exception, so CI failed:

  Expected: typeof(PSProxmoxVE.Core.Exceptions.PveApiException)
  Actual:   typeof(System.Threading.Tasks.TaskCanceledException)
  ---- System.Threading.Tasks.TaskCanceledException : A task was canceled.

PveHttpClient.SendAsync never passes a CancellationToken to the inner
HttpClient.SendAsync, so the only way a TaskCanceledException can reach
this catch is HttpClient.Timeout firing — true on net48, .NET Core, and
.NET 5+. Drop the filter and wrap unconditionally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 18:22:47 -05:00
Clint Branham a1d9550d83 fix: surface HttpClient timeouts as PveApiException(RequestTimeout)
When HttpClient.Timeout elapses, .NET throws TaskCanceledException — not
HttpRequestException — so the existing catch in PveHttpClient.SendAsync
missed it and callers got a raw stack trace. With -TimeoutSeconds now
configurable and documented, this gap became user-visible.

In .NET 5+ HttpClient surfaces transport timeouts as TaskCanceledException
with a TimeoutException inner; user-driven token cancellation does not.
Catch by that inner-type signature and rethrow as PveApiException with
HttpStatusCode.RequestTimeout, the resource path, and a message that
reports the configured timeout.

Adds SendAsync_TimeoutFires_ThrowsPveApiExceptionWithRequestTimeout which
swaps in a delaying HttpMessageHandler with a 50ms timeout to exercise
the path deterministically. Drops the redundant
DefaultSessionTimeoutIs100Seconds test (covered by
PveSessionTests.Timeout_DefaultIs100Seconds and the existing flow-through
test).

Addresses PR #61 review feedback.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 18:17:31 -05:00
Clint Branham ea2bcdc336 Merge main into fix/http-client-timeout
Resolves findings.json conflict — F086 (from #60, merged into main) and
F087 (this branch) both append to the trailing findings array. Kept both
entries, in numeric order.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 18:17:20 -05:00
GoodOlClint 239a6b8fe9 Merge pull request #60 from GoodOlClint/fix/disk-size-unit-normalization
fix: normalize -DiskSize/-RootFsSize before sending to PVE (#58)
2026-05-20 18:10:36 -05:00
Clint Branham f3b06171b2 fix: add -TimeoutSeconds for long-running HTTP calls
PveHttpClient was constructed without setting HttpClient.Timeout, so
.NET's 100s default applied to every request. Multi-GB ISO uploads via
Send-PveFile on a real LAN reliably tripped this with TaskCanceledException
after 100 seconds, and there was no way to override it.

- PveSession gains a Timeout (TimeSpan) property, defaulting to 100s.
- PveHttpClient accepts an optional per-instance timeout override that
  takes precedence over the session timeout.
- Connect-PveServer exposes -TimeoutSeconds to set the session default.
- Send-PveFile and Invoke-PveStorageDownload expose -TimeoutSeconds with
  a 30-minute implicit default so large uploads/downloads do not trip
  the 100s default. -TimeoutSeconds 0 means Timeout.InfiniteTimeSpan.

Tracked as F087. Closes #59.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 18:08:26 -05:00
Clint Branham fa361a3691 fix: address PR #60 review feedback
- SizeParser: wrap TB-suffix overflow in try/catch so callers get
  ArgumentException with the parameter name rather than OverflowException.
- New-PveVm/New-PveContainer: validate -DiskSize/-RootFsSize before
  ShouldProcess so typos like "512M" are rejected even with -WhatIf and
  even when the matching -DiskStorage/-RootFsStorage is omitted.
- Add Pester tests for the new DiskSize and RootFsSize validation paths,
  including a new New-PveContainer.Tests.ps1.
- Add SizeParserTests coverage for the TB overflow path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 18:06:13 -05:00
Clint Branham 6181c8ce77 fix: normalize -DiskSize and -RootFsSize before sending to PVE
Disk and rootfs size strings were interpolated directly into the disk
spec as "<storage>:<size>", so "60G" produced "local-lvm:60G". On
LVM/LVM-thin storages PVE parses the value after the colon as a volume
name unless it is a bare integer, returning "unable to parse lvm volume
name '60G'". File-backed storages mask this by accepting either form.

SizeParser.NormalizeToGibibytes() now strips G/GB/T/TB suffixes and
returns a bare GiB integer string, so the documented "32G" call shape
works on every storage type. Sub-GB units are rejected with a clear
error rather than being silently truncated.

Tracked as F086. Closes #58.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 17:59:21 -05:00
GoodOlClint f2925ba49f Merge pull request #57 from GoodOlClint/dependabot/nuget/src/PSProxmoxVE.Core/main/SharpCompress-0.48.1
Bump SharpCompress from 0.47.4 to 0.48.1
2026-05-19 14:20:37 -05:00
dependabot[bot] 9a9830f2e1 Bump SharpCompress from 0.47.4 to 0.48.1
---
updated-dependencies:
- dependency-name: SharpCompress
  dependency-version: 0.48.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-19 15:08:29 +00:00
GoodOlClint 4b0ddf566a Merge pull request #56 from GoodOlClint/dependabot/nuget/tests/PSProxmoxVE.Core.Tests/main/coverlet.collector-10.0.1
Bump coverlet.collector from 8.0.1 to 10.0.1
2026-05-19 10:02:10 -05:00
dependabot[bot] e1bb0d0268 Bump coverlet.collector from 8.0.1 to 10.0.1
---
updated-dependencies:
- dependency-name: coverlet.collector
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-19 14:52:38 +00:00
GoodOlClint 46c4ee3713 Merge pull request #54 from GoodOlClint/dependabot/nuget/tests/PSProxmoxVE.Core.Tests/main/Microsoft.NET.Test.Sdk-18.5.1
Bump Microsoft.NET.Test.Sdk from 18.4.0 to 18.5.1
2026-05-19 09:49:47 -05:00
dependabot[bot] 7219133050 Bump Microsoft.NET.Test.Sdk from 18.4.0 to 18.5.1
---
updated-dependencies:
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-04 16:02:50 +00:00
GoodOlClint af4ef8402d Merge pull request #50 from GoodOlClint/dependabot/nuget/tests/PSProxmoxVE.Core.Tests/main/Microsoft.NET.Test.Sdk-18.4.0
Bump Microsoft.NET.Test.Sdk from 18.3.0 to 18.4.0
2026-04-13 09:21:58 -05:00
GoodOlClint 9bf7b2d922 Merge branch 'main' into dependabot/nuget/tests/PSProxmoxVE.Core.Tests/main/Microsoft.NET.Test.Sdk-18.4.0 2026-04-13 09:20:01 -05:00
GoodOlClint a77d2b2062 Merge pull request #48 from GoodOlClint/dependabot/nuget/src/PSProxmoxVE.Core/main/SharpCompress-0.47.4
Bump SharpCompress from 0.47.3 to 0.47.4
2026-04-13 09:19:27 -05:00
GoodOlClint 7dc39646ae Merge branch 'main' into dependabot/nuget/src/PSProxmoxVE.Core/main/SharpCompress-0.47.4 2026-04-13 09:17:59 -05:00
GoodOlClint 6664861ca9 Merge pull request #49 from GoodOlClint/dependabot/github_actions/main/softprops/action-gh-release-3
chore(deps): Bump softprops/action-gh-release from 2 to 3
2026-04-13 09:15:00 -05:00
dependabot[bot] 97ff7701da Bump SharpCompress from 0.47.3 to 0.47.4
---
updated-dependencies:
- dependency-name: SharpCompress
  dependency-version: 0.47.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-13 14:14:39 +00:00
dependabot[bot] 23ffc3531f chore(deps): Bump softprops/action-gh-release from 2 to 3
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-13 14:12:00 +00:00
GoodOlClint 2a809b0374 Merge pull request #52 from GoodOlClint/fix/claude-review-post-comments
fix: post Claude Code Review findings as PR comments
2026-04-13 09:10:59 -05:00
Clint Branham 6e2f25a083 fix: rewrite Claude Code Review workflow to match official examples
Previous approach (/code-review:code-review --comment) was based on
incorrect documentation research. Reviewing the actual official
examples at anthropics/claude-code-action/examples/pr-review-*.yml
reveals the correct pattern:

1. Use a custom prompt with explicit review instructions (not a
   plugin slash command)
2. Use claude_args with --allowedTools to enable the MCP inline
   comment tool and gh pr CLI commands — this is what lets Claude
   actually post to the PR
3. Enable track_progress: true for visual progress tracking

Without --allowedTools, Claude has no way to post anything because
the tools for PR commenting aren't allowed by default.

Also removed the plugins and plugin_marketplaces inputs since
they're not needed — the review runs via prompt instructions and
the allowed tools alone.

The custom prompt is tailored to PSProxmoxVE with focus areas
specific to the module: DECISIONS.md compliance, cmdlet
conventions, API correctness against the PVE OpenAPI spec,
test coverage, and security.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 09:09:54 -05:00
dependabot[bot] aca5ff238b Bump Microsoft.NET.Test.Sdk from 18.3.0 to 18.4.0
---
updated-dependencies:
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-13 13:56:51 +00:00
GoodOlClint ac901dbc1b Merge pull request #51 from GoodOlClint/fix/claude-review-allow-dependabot
fix: allow dependabot PRs in Claude Code Review
2026-04-13 08:53:38 -05:00
Clint Branham 2aa2d5994e fix: allow dependabot PRs in Claude Code Review action
Dependabot PRs were being rejected with:
  Workflow initiated by non-human actor: dependabot (type: Bot)

Add allowed_bots: 'dependabot[bot]' to permit dependency update reviews.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 08:52:36 -05:00
GoodOlClint 007f116cea Merge pull request #47 from GoodOlClint/release/v0.1.2
chore: bump version to 0.1.2
2026-03-27 11:13:28 -05:00
Clint Branham d3953c8c96 chore: bump version to 0.1.2
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-27 11:00:02 -05:00
GoodOlClint 69e3b0b15a Merge pull request #46 from GoodOlClint/fix/issues-43-44-45
fix: resolve issues #43, #44, #45
2026-03-27 10:36:40 -05:00
Clint Branham 5dcbde45a6 fix: resolve issues #43, #44, #45
#44 Get-PveApiToken FullTokenId empty:
  - Make FullTokenId a computed property (UserId + "!" + TokenId)
  - RawFullTokenId captures the API's "full-tokenid" for creation responses

#43 Set-PvePermission token ACLs:
  - Add "token" to Type ValidateSet
  - Auto-detect tokens from "!" in UgId (user@realm!tokenid format)
  - Add tokens parameter to UserService.SetPermission

#45 Connect-PveServer return session by default:
  - Always output session (matches Connect-AzAccount pattern)
  - Add -Quiet switch to suppress output
  - Keep -PassThru as hidden deprecated param for backwards compat

Closes #43, closes #44, closes #45

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-27 10:22:37 -05:00
GoodOlClint aaff8ed42e Merge pull request #42 from GoodOlClint/release/v0.1.1-preview
chore: bump version to 0.1.1-preview
2026-03-26 16:54:52 -05:00
Clint Branham 6e953c1cd7 chore: bump version to 0.1.1 (stable release)
Remove prerelease tag — this is now a stable release.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 16:49:04 -05:00
GoodOlClint 1694d7f693 Merge pull request #41 from GoodOlClint/fix/validate-api-enums-against-openapi
fix: validate API enum values against PVE OpenAPI spec
2026-03-26 16:33:58 -05:00
Clint Branham 7802b853d4 test: version-aware OpenAPI spec validation (PVE 7/8/9)
Replace single-version fixture with per-version specs from pve-api.
Tests now validate enum values against PVE 7 (best-effort), 8, and 9.

Key findings from version-specific specs:
- VM.Monitor: valid in PVE 7+8, removed in PVE 9
- VM.Replicate: added in PVE 9 only
- VM.GuestAgent.*: added in PVE 9 only
- Mapping.*: added in PVE 8+
- glusterfs: not in any version (removed before PVE 7)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 16:26:19 -05:00
Clint Branham d81c850b0b fix: validate API enum values against PVE OpenAPI spec
Add 70 xUnit tests that validate every ValidateSet in the module
against the PVE OpenAPI spec. Three bugs found and fixed:

- Storage: remove `glusterfs` (dropped in PVE 9), add `btrfs`, `esxi`
- Backup compression: `none` → `0` (PVE uses "0" not "none")
- Cluster resources: remove `lxc` filter (PVE uses `vm` for both)

The pve-api-enums.json fixture (199KB) is extracted from the full
OpenAPI spec and contains parameter enum values for 302 API paths.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 15:34:56 -05:00
37 changed files with 27511 additions and 61 deletions
+29 -3
View File
@@ -25,6 +25,32 @@ jobs:
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
plugin_marketplaces: 'https://github.com/anthropics/claude-code.git'
plugins: 'code-review@claude-code-plugins'
prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}'
allowed_bots: 'dependabot[bot]'
track_progress: true
prompt: |
REPO: ${{ github.repository }}
PR NUMBER: ${{ github.event.pull_request.number }}
Review this pull request for the PSProxmoxVE PowerShell module.
Focus areas:
1. **DECISIONS.md compliance** — Check against the 13 architectural
decisions (D001-D013). Any violation is a regression.
2. **Code quality** — Cmdlet conventions (sealed, OutputType,
ConfirmImpact.High for destructive, VmId ValidateRange),
SecureString for passwords, Uri.EscapeDataString on path params,
no bare catch blocks, Newtonsoft-only JSON.
3. **API correctness** — Parameter names and enum values must match
the PVE OpenAPI spec (see tests/PSProxmoxVE.Core.Tests/Fixtures/
pve-api-enums.pve*.json for valid values per PVE version).
4. **Tests** — New cmdlets should have xUnit service tests and
Pester parameter-validation tests.
5. **Security** — No hardcoded credentials, no secrets in logs,
TLS verification on by default.
Provide inline comments for specific issues and a summary comment
for general observations. Skip nitpicks unless they indicate a
real problem.
claude_args: |
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
+1 -1
View File
@@ -108,6 +108,6 @@ jobs:
Publish-Module -Path ./publish/PSProxmoxVE -NuGetApiKey $env:NUGET_API_KEY -Verbose
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@v3
with:
generate_release_notes: true
+45 -18
View File
@@ -7,28 +7,52 @@ and this project adheres to [Conventional Commits](https://www.conventionalcommi
## [Unreleased]
## [0.1.3] - 2026-05-20
### Added
- `Connect-PveServer -TimeoutSeconds` to set the session-default `HttpClient` timeout (default 100s; `0` = infinite). (#59)
- `Send-PveFile -TimeoutSeconds` and `Invoke-PveStorageDownload -TimeoutSeconds` for per-call override with a 30-minute implicit default so large uploads/downloads no longer trip the 100s default. (#59)
### Fixed
- `New-PveVm -DiskSize` and `New-PveContainer -RootFsSize` now normalize unit suffixes (`32G`, `1T`, `32GB`, etc.) to bare GiB before constructing the disk spec. Previously the suffix was passed verbatim, which LVM/LVM-thin storages rejected with `unable to parse lvm volume name '32G'`. Sub-GB units (`M`, `MB`, `K`, `KB`) are now rejected client-side with a clear error. (#58)
- `PveHttpClient.SendAsync` surfaces `HttpClient.Timeout` firings as `PveApiException(RequestTimeout)` with the resource path and configured timeout, instead of leaking a raw `TaskCanceledException`. Works across `net48`, `net10.0`, and `netstandard2.0`. (#59)
- Disk-size validation runs before `ShouldProcess` so typos like `512M` are caught with `-WhatIf`, regardless of whether `-DiskStorage`/`-RootFsStorage` is also supplied. (#58)
## [0.1.2] - 2026-03-27
### Fixed
- `Get-PveApiToken`: `FullTokenId` is now computed from `UserId!TokenId` (was always empty). (#44)
- `Set-PvePermission`: added `token` ACL type with auto-detection from `!` in `-UgId`, enabling permission assignment for API tokens. (#43)
- `Connect-PveServer`: always emits the session to the pipeline. Use `-Quiet` to suppress; `-PassThru` is kept hidden for backwards compatibility. (#45)
## [0.1.1] - 2026-03-26
### Added
- Firewall management cmdlets (21): rules, security groups, aliases, IP sets, options at cluster/node/VM/container levels
- Backup/vzdump cmdlets (5): ad-hoc backup creation and scheduled backup job CRUD
- SDN IPAM cmdlets (3): Get/New/Remove-PveSdnIpam for IPAM plugin management
- SDN DNS cmdlets (3): Get/New/Remove-PveSdnDns for DNS plugin management
- SDN Controller cmdlets (3): Get/New/Remove-PveSdnController for controller management
- PSGallery version badge in README
- Integration tests for firewall rules, aliases, IP sets, backup jobs, and OVA import
- SDN Update cmdlets (7): Set-PveSdnZone/Vnet/Subnet/Controller/Ipam/Dns + Invoke-PveSdnApply
- Set-PveRole, Set-PveStorage, Set-PveApiToken for missing update operations
- Get-PveClusterResource: single-call cluster-wide inventory of all VMs, containers, nodes, storage
- Task management: Get-PveTaskList (list tasks on node), Stop-PveTask (cancel running tasks)
- Pool management cmdlets (4): Get/New/Set/Remove-PvePool
- Get-PveBackupInfo: find VMs/containers not covered by backup jobs
- VM disk operations: Move-PveVmDisk (storage migration), Remove-PveVmDisk (detach/delete)
- Guest agent extensions (6): Get-PveVmGuestOsInfo, Get-PveVmGuestFsInfo, Read/Write-PveVmGuestFile, Set-PveVmGuestPassword, Invoke-PveVmGuestFsTrim
- Container gaps (6): Suspend/Resume-PveContainer, Resize-PveContainerDisk, New-PveContainerTemplate, Move-PveContainerVolume, Get-PveContainerInterface
- Storage content management (4): Get-PveStorageStatus, Remove/Set-PveStorageContent, New-PveStorageDisk
- Node operations (6): Get/Set-PveNodeConfig, Get/Set-PveNodeDns, Start/Stop-PveNodeVms
- Access management (9): Get/New/Set/Remove-PveGroup, Get/New/Set/Remove-PveDomain, Set-PvePassword
- SDN IPAM cmdlets (3): `Get`/`New`/`Remove-PveSdnIpam` for IPAM plugin management
- SDN DNS cmdlets (3): `Get`/`New`/`Remove-PveSdnDns` for DNS plugin management
- SDN Controller cmdlets (3): `Get`/`New`/`Remove-PveSdnController` for controller management
- SDN Update cmdlets (7): `Set-PveSdnZone`/`Vnet`/`Subnet`/`Controller`/`Ipam`/`Dns` + `Invoke-PveSdnApply`
- `Set-PveRole`, `Set-PveStorage`, `Set-PveApiToken` for missing update operations
- `Get-PveClusterResource`: single-call cluster-wide inventory of all VMs, containers, nodes, storage
- Task management: `Get-PveTaskList` (list tasks on node), `Stop-PveTask` (cancel running tasks)
- Pool management cmdlets (4): `Get`/`New`/`Set`/`Remove-PvePool`
- `Get-PveBackupInfo`: find VMs/containers not covered by backup jobs
- VM disk operations: `Move-PveVmDisk` (storage migration), `Remove-PveVmDisk` (detach/delete)
- Guest agent extensions (6): `Get-PveVmGuestOsInfo`, `Get-PveVmGuestFsInfo`, `Read`/`Write-PveVmGuestFile`, `Set-PveVmGuestPassword`, `Invoke-PveVmGuestFsTrim`
- Container gaps (6): `Suspend`/`Resume-PveContainer`, `Resize-PveContainerDisk`, `New-PveContainerTemplate`, `Move-PveContainerVolume`, `Get-PveContainerInterface`
- Storage content management (4): `Get-PveStorageStatus`, `Remove`/`Set-PveStorageContent`, `New-PveStorageDisk`
- Node operations (6): `Get`/`Set-PveNodeConfig`, `Get`/`Set-PveNodeDns`, `Start`/`Stop-PveNodeVms`
- Access management (9): `Get`/`New`/`Set`/`Remove-PveGroup`, `Get`/`New`/`Set`/`Remove-PveDomain`, `Set-PvePassword`
- Two-tier version gating: introduced vs default version with clear user messaging
- 70 xUnit tests validating every `ValidateSet` against the PVE OpenAPI spec, with `pve-api-enums.json` fixture extracted from the full spec
- Integration tests for firewall rules, aliases, IP sets, backup jobs, and OVA import
- PSGallery version badge in README
### Changed
@@ -41,7 +65,7 @@ and this project adheres to [Conventional Commits](https://www.conventionalcommi
- `ValidateRange(100, 999999999)` added to all `VmId` parameters
- `Uri.EscapeDataString()` applied to all dynamic URL path segments
- Hardcoded verb strings replaced with verb class constants (`VerbsCommon.Get`, etc.)
- Auth header magic strings extracted to named constants in PveHttpClient
- Auth header magic strings extracted to named constants in `PveHttpClient`
- Bare `catch` blocks replaced with specific or filtered exception handling
- MAML help (dll-Help.xml) and 170 markdown cmdlet docs generated
- PSGallery publish workflow with PS 5.1 smoke testing
@@ -49,6 +73,9 @@ and this project adheres to [Conventional Commits](https://www.conventionalcommi
### Fixed
- `ConfirmImpact.High` added to all destructive cmdlets (Stop, Reset, Restart, Suspend, Remove, Restore, New-PveTemplate)
- Storage `ValidateSet`: removed `glusterfs` (dropped in PVE 9), added `btrfs` and `esxi`
- Backup compression: `none``0` (PVE expects the string `"0"`, not `"none"`)
- Cluster resource filter: removed `lxc` (PVE uses `vm` for both QEMU and LXC)
- Hardcoded test password moved from CI workflow to GitHub Actions secret
- Terraform variable default password removed (requires env var)
+18
View File
@@ -93,3 +93,21 @@ This repo uses a structured review system to track findings and prevent regressi
Finding IDs (F001, F002...) are permanent. A resolved finding is never deleted from
findings.json — it is marked `resolved` with evidence of the fix. If a finding reappears,
it is marked `regressed` and retains its original ID.
## Releasing to PSGallery
Tag-driven: pushing a `v*` tag to `main` triggers `.github/workflows/publish.yml` (build →
PS 5.1 smoke test → publish to PSGallery → create GitHub Release with auto-generated notes).
Each release PR must update **three** things in lockstep before the tag is cut:
1. `ModuleVersion` in `src/PSProxmoxVE/PSProxmoxVE.psd1` (semver patch for bug-fix-only;
minor for new features; major for breaking changes).
2. `ReleaseNotes` in the same psd1 — this is what PSGallery surfaces on the version page.
Replace the previous version's notes; do not append.
3. `CHANGELOG.md` — cut the `[Unreleased]` section into a new `[X.Y.Z] - YYYY-MM-DD`
block and reset `[Unreleased]` to empty.
After merge, tag `main` with `vX.Y.Z` and push the tag. The publish workflow rewrites
the psd1 `ModuleVersion` in the build artifact from the tag, so the tag and the source
version must match.
+66
View File
@@ -2815,6 +2815,72 @@
"evidence": "Replaced JArray? Nodelist with List<Dictionary<string, object?>>? + NativeListConverter, and JObject? Totem with Dictionary<string, object?>? + NativeDictionaryConverter. Removed Newtonsoft.Json.Linq dependency.",
"verified_by": "dotnet build + dotnet test (382 passed)"
}
},
{
"id": "F086",
"title": "New-PveVm -DiskSize and New-PveContainer -RootFsSize pass unit suffix verbatim, LVM rejects 'NG'",
"category": "api_contract",
"severity": "high",
"status": "resolved",
"first_detected": "2026-05-20",
"github_issue": 58,
"files": [
"src/PSProxmoxVE/Cmdlets/Vms/NewPveVmCmdlet.cs",
"src/PSProxmoxVE/Cmdlets/Containers/NewPveContainerCmdlet.cs"
],
"description": "Disk and rootfs sizes are interpolated directly into the disk spec as '<storage>:<size>'. The parameter docstring advertises 'e.g. 32G' but on LVM/LVM-thin storages PVE parses the value after the colon as a volume name unless it is a bare integer, failing with 'unable to parse lvm volume name \"32G\"'. File-backed storages (NFS, directory) accept either form, masking the bug in mixed environments.",
"scan_history": [
{
"scan_date": "2026-05-20",
"local_id": null,
"status": "new"
},
{
"scan_date": "2026-05-20",
"local_id": null,
"status": "fixed"
}
],
"resolution": {
"scan_date": "2026-05-20",
"evidence": "Added SizeParser.NormalizeToGibibytes() which strips G/GB/T/TB suffixes, rejects sub-GB units with a clear error, and converts TB overflows to ArgumentException. New-PveVm and New-PveContainer normalize -DiskSize and -RootFsSize before ShouldProcess so typos are caught with -WhatIf, regardless of whether the matching -DiskStorage/-RootFsStorage was supplied.",
"verified_by": "dotnet build + dotnet test (577 passed, 32 SizeParserTests) + Pester (39 passed, new DiskSize/RootFsSize validation contexts)"
}
},
{
"id": "F087",
"title": "HttpClient uses 100s default timeout; Send-PveFile and other long-running calls fail on large payloads",
"category": "reliability",
"severity": "high",
"status": "resolved",
"first_detected": "2026-05-20",
"github_issue": 59,
"files": [
"src/PSProxmoxVE.Core/Client/PveHttpClient.cs",
"src/PSProxmoxVE.Core/Authentication/PveSession.cs",
"src/PSProxmoxVE.Core/Authentication/PveAuthenticator.cs",
"src/PSProxmoxVE/Cmdlets/Storage/SendPveFileCmdlet.cs",
"src/PSProxmoxVE/Cmdlets/Storage/InvokePveStorageDownloadCmdlet.cs",
"src/PSProxmoxVE/Cmdlets/Connection/ConnectPveServerCmdlet.cs"
],
"description": "PveHttpClient constructs HttpClient without setting Timeout, so .NET's 100s default applies to every request. Send-PveFile, Invoke-PveStorageDownload, and Connect-PveServer expose no way to override it, so multi-GB ISO uploads on a real LAN reliably trip the 100s timeout with TaskCanceledException. PveHttpClient.SendAsync also failed to surface the timeout as a PveApiException, leaking the raw TaskCanceledException to callers.",
"scan_history": [
{
"scan_date": "2026-05-20",
"local_id": null,
"status": "new"
},
{
"scan_date": "2026-05-20",
"local_id": null,
"status": "fixed"
}
],
"resolution": {
"scan_date": "2026-05-20",
"evidence": "Added PveSession.Timeout (default 100s) and a TimeSpan? override on PveHttpClient. Connect-PveServer exposes -TimeoutSeconds to set the session-default; Send-PveFile and Invoke-PveStorageDownload expose -TimeoutSeconds with a 30-minute implicit default so large uploads/downloads do not trip the 100s HttpClient default. -TimeoutSeconds 0 means Timeout.InfiniteTimeSpan. PveHttpClient.SendAsync now catches the TimeoutException-wrapped TaskCanceledException and rethrows it as PveApiException(RequestTimeout) with the resource path.",
"verified_by": "dotnet build + dotnet test (passed including new SendAsync_TimeoutFires xUnit test) + Pester (-TimeoutSeconds coverage on all three cmdlets)"
}
}
]
}
@@ -18,12 +18,22 @@ namespace PSProxmoxVE.Core.Authentication
/// Authenticates using username and password, obtaining a ticket and CSRF token.
/// The username must be in the form user@realm (e.g. root@pam).
/// </summary>
/// <param name="hostname">Hostname or IP address of the Proxmox VE server.</param>
/// <param name="port">TCP port of the Proxmox VE API.</param>
/// <param name="skipCertificateCheck">When true, skips TLS certificate validation.</param>
/// <param name="username">Username including realm (e.g. root@pam).</param>
/// <param name="password">Plain-text password for the user.</param>
/// <param name="timeout">
/// Optional HTTP timeout to apply both to the authentication call and to subsequent
/// requests made with this session. When null, the default 100s applies.
/// </param>
public static PveSession AuthenticateWithCredentials(
string hostname,
int port,
bool skipCertificateCheck,
string username,
string password)
string password,
TimeSpan? timeout = null)
{
if (string.IsNullOrWhiteSpace(hostname))
throw new ArgumentException("Hostname cannot be null or empty.", nameof(hostname));
@@ -41,7 +51,7 @@ namespace PSProxmoxVE.Core.Authentication
};
string responseBody;
using (var httpClient = new PveHttpClient(hostname, port, skipCertificateCheck))
using (var httpClient = new PveHttpClient(hostname, port, skipCertificateCheck, timeout))
{
responseBody = httpClient.Post("/api2/json/access/ticket", formData);
}
@@ -57,6 +67,8 @@ namespace PSProxmoxVE.Core.Authentication
var ticketExpiry = DateTime.UtcNow.AddHours(2);
var session = new PveSession(hostname, port, skipCertificateCheck, ticket, csrfToken, ticketExpiry);
if (timeout.HasValue)
session.Timeout = timeout.Value;
session.ServerVersion = GetVersion(session);
@@ -67,11 +79,20 @@ namespace PSProxmoxVE.Core.Authentication
/// Authenticates using a Proxmox VE API token.
/// The token must be in the format USER@REALM!TOKENID=UUID (e.g. root@pam!mytoken=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx).
/// </summary>
/// <param name="hostname">Hostname or IP address of the Proxmox VE server.</param>
/// <param name="port">TCP port of the Proxmox VE API.</param>
/// <param name="skipCertificateCheck">When true, skips TLS certificate validation.</param>
/// <param name="apiToken">API token in USER@REALM!TOKENID=UUID format.</param>
/// <param name="timeout">
/// Optional HTTP timeout to apply to requests made with this session.
/// When null, the default 100s applies.
/// </param>
public static PveSession AuthenticateWithApiToken(
string hostname,
int port,
bool skipCertificateCheck,
string apiToken)
string apiToken,
TimeSpan? timeout = null)
{
if (string.IsNullOrWhiteSpace(hostname))
throw new ArgumentException("Hostname cannot be null or empty.", nameof(hostname));
@@ -83,6 +104,8 @@ namespace PSProxmoxVE.Core.Authentication
nameof(apiToken));
var session = new PveSession(hostname, port, skipCertificateCheck, apiToken);
if (timeout.HasValue)
session.Timeout = timeout.Value;
session.ServerVersion = GetVersion(session);
@@ -33,6 +33,13 @@ namespace PSProxmoxVE.Core.Authentication
/// <summary>The Proxmox VE version detected on the server at connection time.</summary>
public PveVersion? ServerVersion { get; internal set; }
/// <summary>
/// The default HTTP request timeout applied to clients created with this session.
/// Defaults to 100 seconds (HttpClient's built-in default). Cmdlets that perform
/// long-running operations (e.g. Send-PveFile) may override this per-call.
/// </summary>
public TimeSpan Timeout { get; internal set; } = TimeSpan.FromSeconds(100);
/// <summary>Returns true if the ticket has expired (only relevant for Ticket auth mode)</summary>
public bool IsExpired
{
+22 -2
View File
@@ -37,7 +37,12 @@ namespace PSProxmoxVE.Core.Client
/// Creates an HTTP client authenticated with the specified PVE session.
/// </summary>
/// <param name="session">The authenticated PVE session providing credentials and base URL.</param>
public PveHttpClient(PveSession session)
/// <param name="timeoutOverride">
/// Optional per-instance timeout override. When supplied, takes precedence over
/// <see cref="PveSession.Timeout"/>. Pass <see cref="System.Threading.Timeout.InfiniteTimeSpan"/>
/// to disable the timeout entirely (useful for multi-GB uploads/downloads).
/// </param>
public PveHttpClient(PveSession session, TimeSpan? timeoutOverride = null)
{
_session = session ?? throw new ArgumentNullException(nameof(session));
_baseUrl = session.BaseUrl;
@@ -49,6 +54,7 @@ namespace PSProxmoxVE.Core.Client
(HttpRequestMessage _, X509Certificate2 _, X509Chain _, SslPolicyErrors _) => true;
}
_httpClient = new HttpClient(handler);
_httpClient.Timeout = timeoutOverride ?? session.Timeout;
_httpClient.DefaultRequestHeaders.Accept.Add(
new MediaTypeWithQualityHeaderValue("application/json"));
@@ -58,7 +64,7 @@ namespace PSProxmoxVE.Core.Client
/// Creates a bare HTTP client for pre-session use (e.g. initial authentication).
/// No auth headers are added to requests made with this constructor.
/// </summary>
internal PveHttpClient(string hostname, int port, bool skipCertificateCheck)
internal PveHttpClient(string hostname, int port, bool skipCertificateCheck, TimeSpan? timeout = null)
{
if (string.IsNullOrWhiteSpace(hostname))
throw new ArgumentException("Hostname cannot be null or empty.", nameof(hostname));
@@ -73,6 +79,8 @@ namespace PSProxmoxVE.Core.Client
(HttpRequestMessage _, X509Certificate2 _, X509Chain _, SslPolicyErrors _) => true;
}
_httpClient = new HttpClient(handler);
if (timeout.HasValue)
_httpClient.Timeout = timeout.Value;
_httpClient.DefaultRequestHeaders.Accept.Add(
new MediaTypeWithQualityHeaderValue("application/json"));
@@ -345,6 +353,18 @@ namespace PSProxmoxVE.Core.Client
{
response = await _httpClient.SendAsync(request).ConfigureAwait(false);
}
catch (TaskCanceledException ex)
{
// PveHttpClient.SendAsync passes no CancellationToken to HttpClient.SendAsync,
// so a TaskCanceledException reaching here can only be HttpClient.Timeout
// firing — on .NET Framework, on .NET Core, and on .NET 5+ (where it also
// carries a TimeoutException inner). Wrap it uniformly across frameworks.
var seconds = _httpClient.Timeout == System.Threading.Timeout.InfiniteTimeSpan
? "infinite"
: _httpClient.Timeout.TotalSeconds.ToString("0", System.Globalization.CultureInfo.InvariantCulture) + "s";
throw new PveApiException(HttpStatusCode.RequestTimeout,
$"Request timed out after {seconds}.", resource, httpMethod, ex);
}
catch (HttpRequestException ex)
{
throw new PveApiException(HttpStatusCode.ServiceUnavailable,
@@ -23,10 +23,20 @@ public class PveApiToken
/// <summary>
/// The full token identifier in "user@realm!tokenid" format, e.g., "admin@pam!automation".
/// Only populated by New-PveApiToken; not returned by the list/get endpoints.
/// Computed from UserId and TokenId. The "full-tokenid" JSON field from New-PveApiToken
/// is captured by <see cref="RawFullTokenId"/> for deserialization, but this property
/// always returns a computed value so it works for list/get endpoints too.
/// </summary>
public string FullTokenId =>
string.IsNullOrEmpty(UserId) || string.IsNullOrEmpty(TokenId)
? RawFullTokenId ?? string.Empty
: $"{UserId}!{TokenId}";
/// <summary>
/// Raw "full-tokenid" value from the API (only present on token creation responses).
/// </summary>
[JsonProperty("full-tokenid")]
public string? FullTokenId { get; set; }
public string? RawFullTokenId { get; set; }
/// <summary>
/// The token secret UUID. <b>Only present on creation</b> — store it immediately,
+1 -1
View File
@@ -18,7 +18,7 @@
<ItemGroup>
<PackageReference Include="Newtonsoft.Json" Version="13.0.3" />
<PackageReference Include="SharpCompress" Version="0.47.3" />
<PackageReference Include="SharpCompress" Version="0.48.1" />
</ItemGroup>
</Project>
@@ -642,6 +642,7 @@ namespace PSProxmoxVE.Core.Services
/// <param name="roles">Comma-separated role IDs.</param>
/// <param name="users">Comma-separated user IDs.</param>
/// <param name="groups">Comma-separated group names.</param>
/// <param name="tokens">Comma-separated API token IDs (user@realm!tokenid).</param>
/// <param name="propagate">Whether to propagate the permission to sub-paths.</param>
/// <param name="delete">If true, removes the specified ACL entries.</param>
public void SetPermission(
@@ -650,6 +651,7 @@ namespace PSProxmoxVE.Core.Services
string roles,
string? users = null,
string? groups = null,
string? tokens = null,
bool propagate = true,
bool delete = false)
{
@@ -666,6 +668,7 @@ namespace PSProxmoxVE.Core.Services
};
if (!string.IsNullOrEmpty(users)) formData["users"] = users!;
if (!string.IsNullOrEmpty(groups)) formData["groups"] = groups!;
if (!string.IsNullOrEmpty(tokens)) formData["tokens"] = tokens!;
IPveHttpClient client = _injectedClient ?? new PveHttpClient(session);
try
@@ -0,0 +1,79 @@
using System;
using System.Globalization;
using System.Text.RegularExpressions;
namespace PSProxmoxVE.Core.Utilities
{
/// <summary>
/// Parses storage size strings (e.g. "32G", "1T", "60") and normalizes them
/// to a bare integer count of gibibytes for use in PVE disk specs.
/// </summary>
/// <remarks>
/// PVE accepts a size suffix on file-backed storages (NFS, directory) but parses
/// the value after the colon as a volume name on LVM-backed storages — so
/// <c>local-lvm:32G</c> fails with "unable to parse lvm volume name '32G'" while
/// <c>local-lvm:32</c> works on every storage type. Cmdlets that build disk specs
/// must normalize size inputs through this helper before joining with the storage.
/// </remarks>
public static class SizeParser
{
private static readonly Regex Pattern = new Regex(
@"^\s*(?<num>\d+)\s*(?<unit>[A-Za-z]*)\s*$",
RegexOptions.Compiled);
/// <summary>
/// Parses a size string and returns the value as a bare integer count of GiB.
/// Accepts values like "60", "60G", "60GB" (= 60), "1T", "1TB" (= 1024).
/// Sub-GB units are rejected because PVE disk allocation is GB-granular.
/// </summary>
/// <param name="value">The size string supplied by the user.</param>
/// <param name="parameterName">Parameter name used in the error message.</param>
/// <returns>The size in whole GiB as a string, suitable for direct use in disk specs.</returns>
/// <exception cref="ArgumentException">The input cannot be parsed or uses an unsupported unit.</exception>
public static string NormalizeToGibibytes(string value, string parameterName = "size")
{
if (string.IsNullOrWhiteSpace(value))
throw new ArgumentException($"{parameterName} must not be null or empty.", parameterName);
var match = Pattern.Match(value);
if (!match.Success)
throw new ArgumentException(
$"{parameterName} '{value}' is not a valid size. Expected a positive integer optionally suffixed with G, GB, T, or TB (e.g. '32G', '1T', '60').",
parameterName);
if (!long.TryParse(match.Groups["num"].Value, NumberStyles.Integer, CultureInfo.InvariantCulture, out var num) || num <= 0)
throw new ArgumentException(
$"{parameterName} '{value}' must be a positive integer.",
parameterName);
var unit = match.Groups["unit"].Value.ToUpperInvariant();
long gib;
switch (unit)
{
case "":
case "G":
case "GB":
case "GIB":
gib = num;
break;
case "T":
case "TB":
case "TIB":
try { gib = checked(num * 1024L); }
catch (OverflowException)
{
throw new ArgumentException(
$"{parameterName} '{value}' is too large to represent in GiB.",
parameterName);
}
break;
default:
throw new ArgumentException(
$"{parameterName} '{value}' uses unsupported unit '{unit}'. Use G, GB, T, or TB. Sub-GB units (M, MB, K, KB) are not supported by PVE disk allocation.",
parameterName);
}
return gib.ToString(CultureInfo.InvariantCulture);
}
}
}
@@ -48,7 +48,7 @@ namespace PSProxmoxVE.Cmdlets.Backup
/// <para type="description">The compression algorithm to use.</para>
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "The compression algorithm.")]
[ValidateSet("zstd", "lzo", "gzip", "none")]
[ValidateSet("zstd", "lzo", "gzip", "0")]
public string? Compress { get; set; }
/// <summary>
@@ -51,7 +51,7 @@ namespace PSProxmoxVE.Cmdlets.Backup
/// <para type="description">The compression algorithm to use.</para>
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "The compression algorithm.")]
[ValidateSet("zstd", "lzo", "gzip", "none")]
[ValidateSet("zstd", "lzo", "gzip", "0")]
public string? Compress { get; set; }
/// <summary>
@@ -56,7 +56,7 @@ namespace PSProxmoxVE.Cmdlets.Backup
/// <para type="description">Updated compression algorithm.</para>
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "The compression algorithm.")]
[ValidateSet("zstd", "lzo", "gzip", "none")]
[ValidateSet("zstd", "lzo", "gzip", "0")]
public string? Compress { get; set; }
/// <summary>
@@ -19,8 +19,8 @@ namespace PSProxmoxVE.Cmdlets.Cluster
/// <summary>
/// <para type="description">Filter by resource type.</para>
/// </summary>
[Parameter(Mandatory = false, Position = 0, HelpMessage = "Filter by resource type (vm, lxc, node, storage, sdn).")]
[ValidateSet("vm", "lxc", "node", "storage", "sdn")]
[Parameter(Mandatory = false, Position = 0, HelpMessage = "Filter by resource type (vm, node, storage, sdn).")]
[ValidateSet("vm", "node", "storage", "sdn")]
public string? Type { get; set; }
/// <summary>
@@ -48,13 +48,35 @@ namespace PSProxmoxVE.Cmdlets.Connection
[Parameter(Mandatory = false, HelpMessage = "Skip TLS certificate validation.")]
public SwitchParameter SkipCertificateCheck { get; set; }
/// <summary>When specified, writes the resulting PveSession object to the pipeline.</summary>
[Parameter(Mandatory = false, HelpMessage = "Output the session object to the pipeline.")]
/// <summary>
/// HTTP request timeout in seconds for all calls made with this session.
/// Defaults to 100 seconds (HttpClient's built-in default). Pass 0 to disable
/// the timeout entirely. Cmdlets that perform long-running operations
/// (Send-PveFile, Invoke-PveStorageDownload) accept their own -TimeoutSeconds
/// that overrides this value per-call.
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "HTTP timeout in seconds (0 = infinite). Default 100s.")]
[ValidateRange(0, int.MaxValue)]
public int? TimeoutSeconds { get; set; }
/// <summary>Deprecated — session is now always output. Kept for backwards compatibility.</summary>
[Parameter(Mandatory = false, DontShow = true)]
public SwitchParameter PassThru { get; set; }
/// <summary>When specified, suppresses the session object from the pipeline output.</summary>
[Parameter(Mandatory = false, HelpMessage = "Do not output the session object to the pipeline.")]
public SwitchParameter Quiet { get; set; }
protected override void ProcessRecord()
{
PveSession session;
TimeSpan? timeout = null;
if (TimeoutSeconds.HasValue)
{
timeout = TimeoutSeconds.Value == 0
? System.Threading.Timeout.InfiniteTimeSpan
: TimeSpan.FromSeconds(TimeoutSeconds.Value);
}
switch (ParameterSetName)
{
@@ -73,7 +95,7 @@ namespace PSProxmoxVE.Cmdlets.Connection
try
{
session = PveAuthenticator.AuthenticateWithCredentials(
Server, Port, SkipCertificateCheck.IsPresent, username, password);
Server, Port, SkipCertificateCheck.IsPresent, username, password, timeout);
}
catch (Exception ex)
{
@@ -92,7 +114,7 @@ namespace PSProxmoxVE.Cmdlets.Connection
try
{
session = PveAuthenticator.AuthenticateWithApiToken(
Server, Port, SkipCertificateCheck.IsPresent, ApiToken!);
Server, Port, SkipCertificateCheck.IsPresent, ApiToken!, timeout);
}
catch (Exception ex)
{
@@ -122,7 +144,7 @@ namespace PSProxmoxVE.Cmdlets.Connection
WriteVerbose($"Connected to {Server}:{Port} as {session.AuthMode} (PVE {session.ServerVersion}).");
if (PassThru.IsPresent)
if (!Quiet.IsPresent)
WriteObject(session);
}
}
@@ -6,6 +6,7 @@ using Newtonsoft.Json.Linq;
using PSProxmoxVE.Core.Client;
using PSProxmoxVE.Core.Models.Vms;
using PSProxmoxVE.Core.Services;
using PSProxmoxVE.Core.Utilities;
namespace PSProxmoxVE.Cmdlets.Containers
{
@@ -59,9 +60,13 @@ namespace PSProxmoxVE.Cmdlets.Containers
public int? Cores { get; set; }
/// <summary>
/// <para type="description">Size of the root filesystem (e.g., "8G").</para>
/// <para type="description">
/// Size of the root filesystem. Accepts a bare integer in GiB ("8") or a value
/// suffixed with G/GB/T/TB (case-insensitive); the value is normalized to a
/// bare GiB count before being sent to the API.
/// </para>
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "Size of the root filesystem (e.g. 8G).")]
[Parameter(Mandatory = false, HelpMessage = "Size of the root filesystem in GiB (e.g. 8 or 8G).")]
public string? RootFsSize { get; set; }
/// <summary>
@@ -125,6 +130,13 @@ namespace PSProxmoxVE.Cmdlets.Containers
protected override void ProcessRecord()
{
// Validate -RootFsSize before ShouldProcess so typos like "512M" are rejected
// even with -WhatIf, and so the error is raised regardless of whether
// -RootFsStorage is also supplied.
string? rootFsSizeGib = null;
if (!string.IsNullOrEmpty(RootFsSize))
rootFsSizeGib = SizeParser.NormalizeToGibibytes(RootFsSize!, nameof(RootFsSize));
if (!ShouldProcess($"Container on node '{Node}'", "New-PveContainer"))
return;
@@ -160,8 +172,8 @@ namespace PSProxmoxVE.Cmdlets.Containers
if (!string.IsNullOrEmpty(RootFsStorage))
{
var rootFsValue = RootFsStorage!;
if (!string.IsNullOrEmpty(RootFsSize))
rootFsValue += $":{RootFsSize}";
if (rootFsSizeGib != null)
rootFsValue += $":{rootFsSizeGib}";
config["rootfs"] = rootFsValue;
}
@@ -44,6 +44,16 @@ namespace PSProxmoxVE.Cmdlets.Storage
[Parameter(Mandatory = false, HelpMessage = "Wait for the task to complete before returning.")]
public SwitchParameter Wait { get; set; }
/// <summary>
/// HTTP timeout for issuing the download request, in seconds. Pass 0 for infinite.
/// When omitted, defaults to 30 minutes. Note: this only bounds the API call that
/// schedules the download; the actual file transfer runs server-side and is tracked
/// by the returned task.
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "HTTP timeout in seconds (0 = infinite). Defaults to 1800 (30 min).")]
[ValidateRange(0, int.MaxValue)]
public int? TimeoutSeconds { get; set; }
protected override void ProcessRecord()
{
if (!ShouldProcess($"{Node}/{Storage}/{Filename}", $"Download from {Url}"))
@@ -51,7 +61,19 @@ namespace PSProxmoxVE.Cmdlets.Storage
var session = GetSession();
RequireVersion(session, "Storage URL download", 7, 0);
using var client = new PveHttpClient(session);
TimeSpan timeout;
if (TimeoutSeconds.HasValue)
{
timeout = TimeoutSeconds.Value == 0
? System.Threading.Timeout.InfiniteTimeSpan
: TimeSpan.FromSeconds(TimeoutSeconds.Value);
}
else
{
timeout = TimeSpan.FromMinutes(30);
}
using var client = new PveHttpClient(session, timeout);
WriteVerbose($"Downloading '{Url}' to {Node}/{Storage}...");
var resource = $"nodes/{Uri.EscapeDataString(Node)}/storage/{Uri.EscapeDataString(Storage)}/download-url";
@@ -25,7 +25,7 @@ namespace PSProxmoxVE.Cmdlets.Storage
/// <summary>The storage type (e.g., "dir", "nfs", "lvm", "zfspool", "cephfs", "rbd").</summary>
[Parameter(Mandatory = true, Position = 1, HelpMessage = "The storage type (e.g. dir, nfs, lvm, zfspool).")]
[ValidateSet("dir", "nfs", "lvm", "lvmthin", "zfspool", "zfs", "cephfs", "rbd",
"iscsi", "iscsidirect", "glusterfs", "cifs", "pbs", IgnoreCase = true)]
"iscsi", "iscsidirect", "cifs", "pbs", "btrfs", "esxi", IgnoreCase = true)]
public string Type { get; set; } = string.Empty;
/// <summary>Comma-separated list of content types to support (e.g., "iso,vztmpl,backup").</summary>
@@ -60,6 +60,15 @@ namespace PSProxmoxVE.Cmdlets.Storage
[Parameter(Mandatory = false, HelpMessage = "Wait for the task to complete before returning.")]
public SwitchParameter Wait { get; set; }
/// <summary>
/// HTTP timeout for this upload, in seconds. Pass 0 for infinite (no timeout).
/// When omitted, defaults to 30 minutes — overriding the session timeout so that
/// large file uploads do not trip the default 100-second HttpClient timeout.
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "HTTP timeout in seconds (0 = infinite). Defaults to 1800 (30 min).")]
[ValidateRange(0, int.MaxValue)]
public int? TimeoutSeconds { get; set; }
protected override void ProcessRecord()
{
var fileName = System.IO.Path.GetFileName(Path);
@@ -75,7 +84,18 @@ namespace PSProxmoxVE.Cmdlets.Storage
+ $"Connected server is PVE {session.ServerVersion}. The upload will proceed without checksum verification.");
}
using var client = new PveHttpClient(session);
TimeSpan timeout;
if (TimeoutSeconds.HasValue)
{
timeout = TimeoutSeconds.Value == 0
? System.Threading.Timeout.InfiniteTimeSpan
: TimeSpan.FromSeconds(TimeoutSeconds.Value);
}
else
{
timeout = TimeSpan.FromMinutes(30);
}
using var client = new PveHttpClient(session, timeout);
WriteVerbose($"Uploading {fileName} to {Node}/{Storage} (content={ContentType})...");
var resource = $"nodes/{Uri.EscapeDataString(Node)}/storage/{Uri.EscapeDataString(Storage)}/upload";
@@ -27,9 +27,10 @@ namespace PSProxmoxVE.Cmdlets.Users
[Parameter(Mandatory = true, Position = 2, HelpMessage = "The role to assign (e.g. Administrator).")]
public string Role { get; set; } = string.Empty;
/// <summary>The ACL entry type: "user" or "group".</summary>
[Parameter(Mandatory = false, HelpMessage = "ACL entry type: user or group.")]
[ValidateSet("user", "group", IgnoreCase = true)]
/// <summary>The ACL entry type: "user", "token", or "group". When set to "user", API tokens
/// (UgId containing "!") are automatically detected and sent as the "tokens" parameter.</summary>
[Parameter(Mandatory = false, HelpMessage = "ACL entry type: user, token, or group.")]
[ValidateSet("user", "token", "group", IgnoreCase = true)]
public string Type { get; set; } = "user";
/// <summary>Whether to propagate this ACL to child paths.</summary>
@@ -58,6 +59,8 @@ namespace PSProxmoxVE.Cmdlets.Users
if (string.Equals(Type, "group", System.StringComparison.OrdinalIgnoreCase))
data["groups"] = UgId;
else if (string.Equals(Type, "token", System.StringComparison.OrdinalIgnoreCase) || UgId.Contains("!"))
data["tokens"] = UgId;
else
data["users"] = UgId;
+16 -4
View File
@@ -4,6 +4,7 @@ using Newtonsoft.Json.Linq;
using PSProxmoxVE.Core.Client;
using PSProxmoxVE.Core.Models.Vms;
using PSProxmoxVE.Core.Services;
using PSProxmoxVE.Core.Utilities;
namespace PSProxmoxVE.Cmdlets.Vms
{
@@ -74,9 +75,13 @@ namespace PSProxmoxVE.Cmdlets.Vms
public string? Machine { get; set; }
/// <summary>
/// <para type="description">Size of the primary disk (e.g., "32G").</para>
/// <para type="description">
/// Size of the primary disk. Accepts a bare integer in GiB ("32") or a value
/// suffixed with G/GB/T/TB (case-insensitive); the value is normalized to a
/// bare GiB count before being sent to the API.
/// </para>
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "Size of the primary disk (e.g. 32G).")]
[Parameter(Mandatory = false, HelpMessage = "Size of the primary disk in GiB (e.g. 32 or 32G).")]
public string? DiskSize { get; set; }
/// <summary>
@@ -123,6 +128,13 @@ namespace PSProxmoxVE.Cmdlets.Vms
protected override void ProcessRecord()
{
// Validate -DiskSize before ShouldProcess so typos like "512M" are rejected
// even with -WhatIf, and so the error is raised regardless of whether
// -DiskStorage is also supplied.
string? diskSizeGib = null;
if (!string.IsNullOrEmpty(DiskSize))
diskSizeGib = SizeParser.NormalizeToGibibytes(DiskSize!, nameof(DiskSize));
if (!ShouldProcess($"VM on node '{Node}'", "New-PveVm"))
return;
@@ -161,9 +173,9 @@ namespace PSProxmoxVE.Cmdlets.Vms
if (!string.IsNullOrEmpty(OsType))
config["ostype"] = OsType!;
if (!string.IsNullOrEmpty(DiskStorage) && !string.IsNullOrEmpty(DiskSize))
if (!string.IsNullOrEmpty(DiskStorage) && diskSizeGib != null)
{
var diskValue = $"{DiskStorage}:{DiskSize}";
var diskValue = $"{DiskStorage}:{diskSizeGib}";
if (!string.IsNullOrEmpty(DiskFormat))
diskValue += $",format={DiskFormat}";
config["virtio0"] = diskValue;
+18 -4
View File
@@ -10,7 +10,7 @@
RootModule = 'PSProxmoxVE.dll'
# Version number of this module.
ModuleVersion = '0.1.0'
ModuleVersion = '0.1.3'
# Supported PSEditions
CompatiblePSEditions = @('Desktop', 'Core')
@@ -349,8 +349,8 @@
PSData = @{
# Prerelease string for the module
Prerelease = 'preview'
# Prerelease string for the module (empty = stable release)
# Prerelease = 'preview'
# Tags applied to this module
Tags = @(
@@ -371,7 +371,21 @@
ProjectUri = 'https://github.com/goodolclint/PSProxmoxVE'
# Release notes for this version
ReleaseNotes = 'Initial preview release. Supports PVE 8.x and 9.x with VM, container, storage, network, SDN, user/role/permission, template, cloud-init, snapshot, and task management.'
ReleaseNotes = @'
## 0.1.3
Fixed:
- New-PveVm -DiskSize / New-PveContainer -RootFsSize normalize unit suffixes
(32G, 1T, etc.) to bare GiB before sending to PVE so the documented call
shape works on LVM/LVM-thin storages (#58).
- HttpClient timeouts are now configurable via -TimeoutSeconds on
Connect-PveServer (session default), Send-PveFile, and
Invoke-PveStorageDownload (per-call, 30-minute implicit default).
Timeouts surface as PveApiException(RequestTimeout) instead of a raw
TaskCanceledException (#59).
Full changelog: https://github.com/goodolclint/PSProxmoxVE/blob/main/CHANGELOG.md
'@
}
@@ -100,5 +100,14 @@ namespace PSProxmoxVE.Core.Tests.Authentication
Assert.True(session.SkipCertificateCheck);
}
[Fact]
public void Timeout_DefaultIs100Seconds()
{
var session = new PveSession(TestHostname, TestPort, false,
"root@pam!mytoken=aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee");
Assert.Equal(TimeSpan.FromSeconds(100), session.Timeout);
}
}
}
@@ -0,0 +1,101 @@
using System;
using System.Net;
using System.Net.Http;
using System.Reflection;
using System.Threading;
using System.Threading.Tasks;
using PSProxmoxVE.Core.Authentication;
using PSProxmoxVE.Core.Client;
using PSProxmoxVE.Core.Exceptions;
using Xunit;
namespace PSProxmoxVE.Core.Tests.Client
{
public class PveHttpClientTimeoutTests
{
private static HttpClient GetInnerHttpClient(PveHttpClient client)
{
var field = typeof(PveHttpClient).GetField("_httpClient",
BindingFlags.Instance | BindingFlags.NonPublic)!;
return (HttpClient)field.GetValue(client)!;
}
private static void SetInnerHttpClient(PveHttpClient client, HttpClient newInner)
{
var field = typeof(PveHttpClient).GetField("_httpClient",
BindingFlags.Instance | BindingFlags.NonPublic)!;
((HttpClient)field.GetValue(client)!).Dispose();
field.SetValue(client, newInner);
}
private static PveSession NewSession()
{
return new PveSession("pve.example.com", 8006, false,
"root@pam!token=aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee");
}
[Fact]
public void Constructor_UsesSessionTimeoutByDefault()
{
var session = NewSession();
session.Timeout = TimeSpan.FromSeconds(42);
using var client = new PveHttpClient(session);
Assert.Equal(TimeSpan.FromSeconds(42), GetInnerHttpClient(client).Timeout);
}
[Fact]
public void Constructor_OverrideTakesPrecedenceOverSessionTimeout()
{
var session = NewSession();
session.Timeout = TimeSpan.FromSeconds(42);
using var client = new PveHttpClient(session, TimeSpan.FromMinutes(30));
Assert.Equal(TimeSpan.FromMinutes(30), GetInnerHttpClient(client).Timeout);
}
[Fact]
public void Constructor_InfiniteTimeSpanIsAccepted()
{
var session = NewSession();
using var client = new PveHttpClient(session, Timeout.InfiniteTimeSpan);
Assert.Equal(Timeout.InfiniteTimeSpan, GetInnerHttpClient(client).Timeout);
}
[Fact]
public async Task SendAsync_TimeoutFires_ThrowsPveApiExceptionWithRequestTimeout()
{
var session = NewSession();
using var client = new PveHttpClient(session);
// Swap in an HttpClient with a delaying handler and a 50ms timeout so
// HttpClient.Timeout fires reliably without any real network.
var delayingClient = new HttpClient(new DelayingHandler(TimeSpan.FromSeconds(30)))
{
Timeout = TimeSpan.FromMilliseconds(50)
};
SetInnerHttpClient(client, delayingClient);
var ex = await Assert.ThrowsAsync<PveApiException>(() => client.GetAsync("version"));
Assert.Equal(HttpStatusCode.RequestTimeout, ex.StatusCode);
Assert.Contains("timed out", ex.Message, StringComparison.OrdinalIgnoreCase);
}
private sealed class DelayingHandler : HttpMessageHandler
{
private readonly TimeSpan _delay;
public DelayingHandler(TimeSpan delay) { _delay = delay; }
protected override async Task<HttpResponseMessage> SendAsync(
HttpRequestMessage request, CancellationToken cancellationToken)
{
await Task.Delay(_delay, cancellationToken).ConfigureAwait(false);
return new HttpResponseMessage(HttpStatusCode.OK);
}
}
}
}
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,434 @@
using System;
using System.Collections.Generic;
using System.Linq;
using Newtonsoft.Json;
using Newtonsoft.Json.Linq;
using Xunit;
namespace PSProxmoxVE.Core.Tests
{
/// <summary>
/// Validates that the module's hardcoded enum values (ValidateSet, privilege names, etc.)
/// match what the PVE API actually accepts, as defined by per-version OpenAPI specs.
///
/// Fixtures pve-api-enums.pve{7,8,9}.json are extracted from the full OpenAPI specs at
/// ~/Source/pve_api/tools/pve-api-parser/ and contain parameter enum values per PVE version.
///
/// PVE 7 = best-effort support, PVE 8 + 9 = fully supported.
/// </summary>
public class OpenApiSpecValidationTests
{
private static readonly Lazy<JObject> _specPve7 = new Lazy<JObject>(() =>
JObject.Parse(TestHelper.LoadFixture("pve-api-enums.pve7.json")));
private static readonly Lazy<JObject> _specPve8 = new Lazy<JObject>(() =>
JObject.Parse(TestHelper.LoadFixture("pve-api-enums.pve8.json")));
private static readonly Lazy<JObject> _specPve9 = new Lazy<JObject>(() =>
JObject.Parse(TestHelper.LoadFixture("pve-api-enums.pve9.json")));
private static JObject SpecPve7 => _specPve7.Value;
private static JObject SpecPve8 => _specPve8.Value;
private static JObject SpecPve9 => _specPve9.Value;
private static HashSet<string> GetEnumValues(JObject spec, string path, string method, string paramName)
{
var pathData = spec["paths"]?[path]?[method]?["params"]?[paramName];
if (pathData == null) return new HashSet<string>(StringComparer.OrdinalIgnoreCase);
var values = new HashSet<string>(StringComparer.OrdinalIgnoreCase);
if (pathData["enum"] is JArray enumArray)
foreach (var v in enumArray)
values.Add(v.ToString());
if (pathData["x-enum-values"] is JArray xEnumArray)
foreach (var v in xEnumArray)
values.Add(v.ToString());
return values;
}
/// <summary>
/// Asserts that a value is valid in at least one of the supported PVE versions.
/// Returns which versions accept/reject it for diagnostic purposes.
/// </summary>
private static void AssertValidInAnyVersion(string path, string method, string paramName, string value)
{
var pve7 = GetEnumValues(SpecPve7, path, method, paramName);
var pve8 = GetEnumValues(SpecPve8, path, method, paramName);
var pve9 = GetEnumValues(SpecPve9, path, method, paramName);
Assert.True(
pve7.Contains(value) || pve8.Contains(value) || pve9.Contains(value),
$"'{value}' not valid in any PVE version for {method.ToUpper()} {path} param '{paramName}'. " +
$"PVE 7: [{string.Join(", ", pve7)}], PVE 8: [{string.Join(", ", pve8)}], PVE 9: [{string.Join(", ", pve9)}]");
}
/// <summary>
/// Asserts that a value is valid in ALL fully-supported PVE versions (8 + 9).
/// </summary>
private static void AssertValidInAllSupported(string path, string method, string paramName, string value)
{
var pve8 = GetEnumValues(SpecPve8, path, method, paramName);
var pve9 = GetEnumValues(SpecPve9, path, method, paramName);
var missing = new List<string>();
if (!pve8.Contains(value)) missing.Add("PVE 8");
if (!pve9.Contains(value)) missing.Add("PVE 9");
Assert.True(missing.Count == 0,
$"'{value}' not valid in: {string.Join(", ", missing)} for {method.ToUpper()} {path} param '{paramName}'. " +
$"PVE 8: [{string.Join(", ", pve8)}], PVE 9: [{string.Join(", ", pve9)}]");
}
// ── Privileges ──────────────────────────────────────────────────────
[Fact]
public void Privileges_AllPve8And9Common()
{
var pve8 = GetEnumValues(SpecPve8, "/access/roles", "post", "privs");
var pve9 = GetEnumValues(SpecPve9, "/access/roles", "post", "privs");
Assert.NotEmpty(pve8);
Assert.NotEmpty(pve9);
var common = pve8.Intersect(pve9, StringComparer.Ordinal).OrderBy(p => p).ToList();
Assert.True(common.Count > 30, $"Expected >30 common privileges, got {common.Count}");
}
[Fact]
public void Privileges_VmMonitor_OnlyPve7And8()
{
var pve7 = GetEnumValues(SpecPve7, "/access/roles", "post", "privs");
var pve8 = GetEnumValues(SpecPve8, "/access/roles", "post", "privs");
var pve9 = GetEnumValues(SpecPve9, "/access/roles", "post", "privs");
Assert.Contains("VM.Monitor", pve7);
Assert.Contains("VM.Monitor", pve8);
Assert.DoesNotContain("VM.Monitor", pve9);
}
[Fact]
public void Privileges_Pve9Only()
{
var pve8 = GetEnumValues(SpecPve8, "/access/roles", "post", "privs");
var pve9 = GetEnumValues(SpecPve9, "/access/roles", "post", "privs");
// These privileges were added in PVE 9
var guestAgentPrivs = new[]
{
"VM.GuestAgent.Audit", "VM.GuestAgent.FileRead", "VM.GuestAgent.FileWrite",
"VM.GuestAgent.FileSystemMgmt", "VM.GuestAgent.Unrestricted",
"VM.Replicate"
};
foreach (var priv in guestAgentPrivs)
{
Assert.DoesNotContain(priv, pve8);
Assert.Contains(priv, pve9);
}
}
[Theory]
[InlineData("VM.Allocate")]
[InlineData("VM.Audit")]
[InlineData("VM.Backup")]
[InlineData("VM.Clone")]
[InlineData("VM.Config.CDROM")]
[InlineData("VM.Config.Cloudinit")]
[InlineData("VM.Config.CPU")]
[InlineData("VM.Config.Disk")]
[InlineData("VM.Config.HWType")]
[InlineData("VM.Config.Memory")]
[InlineData("VM.Config.Network")]
[InlineData("VM.Config.Options")]
[InlineData("VM.Console")]
[InlineData("VM.Migrate")]
[InlineData("VM.PowerMgmt")]
[InlineData("VM.Snapshot")]
[InlineData("VM.Snapshot.Rollback")]
[InlineData("Datastore.Allocate")]
[InlineData("Datastore.AllocateSpace")]
[InlineData("Datastore.AllocateTemplate")]
[InlineData("Datastore.Audit")]
[InlineData("Sys.Audit")]
[InlineData("Sys.Console")]
[InlineData("Sys.Modify")]
[InlineData("Sys.PowerMgmt")]
[InlineData("Sys.Syslog")]
[InlineData("Sys.AccessNetwork")]
[InlineData("Sys.Incoming")]
[InlineData("SDN.Allocate")]
[InlineData("SDN.Audit")]
[InlineData("SDN.Use")]
[InlineData("User.Modify")]
[InlineData("Permissions.Modify")]
[InlineData("Pool.Allocate")]
[InlineData("Pool.Audit")]
[InlineData("Group.Allocate")]
[InlineData("Realm.Allocate")]
[InlineData("Realm.AllocateUser")]
public void Privilege_ValidInAllSupportedVersions(string privilege)
{
AssertValidInAllSupported("/access/roles", "post", "privs", privilege);
}
[Theory]
[InlineData("Mapping.Audit")]
[InlineData("Mapping.Modify")]
[InlineData("Mapping.Use")]
public void Privilege_Pve8AndAbove(string privilege)
{
var pve7 = GetEnumValues(SpecPve7, "/access/roles", "post", "privs");
var pve8 = GetEnumValues(SpecPve8, "/access/roles", "post", "privs");
var pve9 = GetEnumValues(SpecPve9, "/access/roles", "post", "privs");
Assert.DoesNotContain(privilege, pve7);
Assert.Contains(privilege, pve8);
Assert.Contains(privilege, pve9);
}
// ── Storage Types ───────────────────────────────────────────────────
[Theory]
[InlineData("dir")]
[InlineData("nfs")]
[InlineData("lvm")]
[InlineData("lvmthin")]
[InlineData("zfspool")]
[InlineData("zfs")]
[InlineData("cephfs")]
[InlineData("rbd")]
[InlineData("iscsi")]
[InlineData("iscsidirect")]
[InlineData("cifs")]
[InlineData("pbs")]
public void StorageType_ValidInAllSupportedVersions(string storageType)
{
AssertValidInAllSupported("/storage", "post", "type", storageType);
}
[Theory]
[InlineData("btrfs")]
[InlineData("esxi")]
public void StorageType_ValidAcrossAllVersions(string storageType)
{
var pve7 = GetEnumValues(SpecPve7, "/storage", "post", "type");
var pve8 = GetEnumValues(SpecPve8, "/storage", "post", "type");
var pve9 = GetEnumValues(SpecPve9, "/storage", "post", "type");
Assert.Contains(storageType, pve7);
Assert.Contains(storageType, pve8);
Assert.Contains(storageType, pve9);
}
[Fact]
public void StorageType_GlusterfsNotInAnyVersion()
{
// glusterfs was removed before PVE 7 — should not be in any ValidateSet
var pve7 = GetEnumValues(SpecPve7, "/storage", "post", "type");
var pve8 = GetEnumValues(SpecPve8, "/storage", "post", "type");
var pve9 = GetEnumValues(SpecPve9, "/storage", "post", "type");
Assert.DoesNotContain("glusterfs", pve7);
Assert.DoesNotContain("glusterfs", pve8);
Assert.DoesNotContain("glusterfs", pve9);
}
// ── Backup Modes ────────────────────────────────────────────────────
[Theory]
[InlineData("snapshot")]
[InlineData("suspend")]
[InlineData("stop")]
public void BackupMode_ValidInAllSupportedVersions(string mode)
{
AssertValidInAllSupported("/nodes/{node}/vzdump", "post", "mode", mode);
}
// ── Backup Compression ──────────────────────────────────────────────
[Theory]
[InlineData("zstd")]
[InlineData("lzo")]
[InlineData("gzip")]
[InlineData("0")]
public void BackupCompression_ValidInAllSupportedVersions(string compress)
{
AssertValidInAllSupported("/nodes/{node}/vzdump", "post", "compress", compress);
}
// ── Disk Formats ────────────────────────────────────────────────────
[Theory]
[InlineData("raw")]
[InlineData("qcow2")]
[InlineData("vmdk")]
public void DiskFormat_ValidInAllSupportedVersions(string format)
{
AssertValidInAllSupported("/nodes/{node}/qemu/{vmid}/move_disk", "post", "format", format);
}
// ── HA Resource States ──────────────────────────────────────────────
[Theory]
[InlineData("started")]
[InlineData("stopped")]
[InlineData("disabled")]
[InlineData("ignored")]
public void HaResourceState_ValidInAllSupportedVersions(string state)
{
AssertValidInAllSupported("/cluster/ha/resources", "post", "state", state);
}
// ── SDN Zone Types ──────────────────────────────────────────────────
[Theory]
[InlineData("vlan")]
[InlineData("vxlan")]
[InlineData("evpn")]
[InlineData("simple")]
[InlineData("qinq")]
public void SdnZoneType_ValidInAllSupportedVersions(string zoneType)
{
AssertValidInAllSupported("/cluster/sdn/zones", "post", "type", zoneType);
}
// ── SDN Controller Types ────────────────────────────────────────────
[Theory]
[InlineData("evpn")]
[InlineData("bgp")]
public void SdnControllerType_ValidInAllSupportedVersions(string controllerType)
{
AssertValidInAllSupported("/cluster/sdn/controllers", "post", "type", controllerType);
}
// ── SDN IPAM Types ──────────────────────────────────────────────────
[Theory]
[InlineData("pve")]
[InlineData("netbox")]
[InlineData("phpipam")]
public void SdnIpamType_ValidInAllSupportedVersions(string ipamType)
{
AssertValidInAllSupported("/cluster/sdn/ipams", "post", "type", ipamType);
}
// ── SDN DNS Types ───────────────────────────────────────────────────
[Theory]
[InlineData("powerdns")]
public void SdnDnsType_ValidInAllSupportedVersions(string dnsType)
{
AssertValidInAllSupported("/cluster/sdn/dns", "post", "type", dnsType);
}
// ── Firewall Actions ────────────────────────────────────────────────
// The 'action' param uses a pattern regex (also accepts group names),
// not an enum. Validate against the documented pattern instead.
[Theory]
[InlineData("ACCEPT")]
[InlineData("DROP")]
[InlineData("REJECT")]
public void FirewallAction_MatchesApiPattern(string action)
{
// PVE defines action as pattern: [A-Za-z][A-Za-z0-9\-\_]+
Assert.Matches(@"^[A-Za-z][A-Za-z0-9\-_]+$", action);
}
// ── Firewall Directions ─────────────────────────────────────────────
[Theory]
[InlineData("in")]
[InlineData("out")]
[InlineData("group")]
public void FirewallDirection_ValidInAllSupportedVersions(string direction)
{
AssertValidInAllSupported("/cluster/firewall/rules", "post", "type", direction);
}
// ── Auth Domain Types ───────────────────────────────────────────────
[Theory]
[InlineData("pam")]
[InlineData("pve")]
[InlineData("ad")]
[InlineData("ldap")]
[InlineData("openid")]
public void AuthDomainType_ValidInAllSupportedVersions(string domainType)
{
AssertValidInAllSupported("/access/domains", "post", "type", domainType);
}
// ── Cluster Resource Types ──────────────────────────────────────────
[Theory]
[InlineData("vm")]
[InlineData("node")]
[InlineData("storage")]
[InlineData("sdn")]
public void ClusterResourceType_ValidInAllSupportedVersions(string resourceType)
{
AssertValidInAllSupported("/cluster/resources", "get", "type", resourceType);
}
// ── Content Types (Upload) ──────────────────────────────────────────
[Theory]
[InlineData("iso")]
[InlineData("vztmpl")]
public void UploadContentType_ValidInAllSupportedVersions(string contentType)
{
AssertValidInAllSupported("/nodes/{node}/storage/{storage}/upload", "post", "content", contentType);
}
// ── Console Viewer Types ────────────────────────────────────────────
[Theory]
[InlineData("applet")]
[InlineData("vv")]
[InlineData("html5")]
[InlineData("xtermjs")]
public void ConsoleViewer_ValidInAnyVersion(string viewer)
{
// 'applet' was removed in later versions — validate across any
AssertValidInAnyVersion("/cluster/options", "put", "console", viewer);
}
// ── Network Interface Types ─────────────────────────────────────────
[Theory]
[InlineData("bridge")]
[InlineData("bond")]
[InlineData("eth")]
[InlineData("alias")]
[InlineData("vlan")]
[InlineData("OVSBridge")]
[InlineData("OVSBond")]
[InlineData("OVSPort")]
[InlineData("OVSIntPort")]
public void NetworkInterfaceType_ValidInAllSupportedVersions(string ifaceType)
{
AssertValidInAllSupported("/nodes/{node}/network", "post", "type", ifaceType);
}
// ── Version Progression ─────────────────────────────────────────────
[Fact]
public void Pve9_HasMorePrivilegesThanPve8()
{
var pve8 = GetEnumValues(SpecPve8, "/access/roles", "post", "privs");
var pve9 = GetEnumValues(SpecPve9, "/access/roles", "post", "privs");
Assert.True(pve9.Count > pve8.Count,
$"Expected PVE 9 ({pve9.Count}) to have more privileges than PVE 8 ({pve8.Count})");
}
[Fact]
public void Pve9_HasMorePathsThanPve8()
{
var pve8Paths = SpecPve8["paths"]?.Children().Count() ?? 0;
var pve9Paths = SpecPve9["paths"]?.Children().Count() ?? 0;
Assert.True(pve9Paths > pve8Paths,
$"Expected PVE 9 ({pve9Paths}) to have more paths than PVE 8 ({pve8Paths})");
}
}
}
@@ -9,14 +9,14 @@
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.3.0" />
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.5.1" />
<PackageReference Include="xunit" Version="2.9.3" />
<PackageReference Include="xunit.runner.visualstudio" Version="3.1.5">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
<PackageReference Include="Moq" Version="4.20.72" />
<PackageReference Include="coverlet.collector" Version="8.0.1">
<PackageReference Include="coverlet.collector" Version="10.0.1">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
@@ -0,0 +1,90 @@
using System;
using PSProxmoxVE.Core.Utilities;
using Xunit;
namespace PSProxmoxVE.Core.Tests.Utilities
{
public class SizeParserTests
{
[Theory]
[InlineData("32", "32")]
[InlineData("32G", "32")]
[InlineData("32g", "32")]
[InlineData("32GB", "32")]
[InlineData("32gb", "32")]
[InlineData("32GiB", "32")]
[InlineData("1T", "1024")]
[InlineData("1t", "1024")]
[InlineData("1TB", "1024")]
[InlineData("1TiB", "1024")]
[InlineData("2T", "2048")]
[InlineData(" 60G ", "60")]
[InlineData("60 G", "60")]
public void NormalizeToGibibytes_AcceptedInputs_ReturnsBareGibibyteString(string input, string expected)
{
var result = SizeParser.NormalizeToGibibytes(input);
Assert.Equal(expected, result);
}
[Theory]
[InlineData("512M")]
[InlineData("512MB")]
[InlineData("1024K")]
[InlineData("1024KB")]
[InlineData("100B")]
[InlineData("1P")]
[InlineData("1PB")]
public void NormalizeToGibibytes_UnsupportedUnit_Throws(string input)
{
var ex = Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes(input));
Assert.Contains("unsupported unit", ex.Message, StringComparison.OrdinalIgnoreCase);
}
[Theory]
[InlineData("")]
[InlineData(" ")]
[InlineData(null)]
public void NormalizeToGibibytes_EmptyOrWhitespace_Throws(string? input)
{
Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes(input!));
}
[Theory]
[InlineData("abc")]
[InlineData("G")]
[InlineData("-32")]
[InlineData("32.5G")]
[InlineData("32 G B")]
public void NormalizeToGibibytes_Malformed_Throws(string input)
{
Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes(input));
}
[Theory]
[InlineData("0")]
[InlineData("0G")]
public void NormalizeToGibibytes_Zero_Throws(string input)
{
var ex = Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes(input));
Assert.Contains("positive", ex.Message, StringComparison.OrdinalIgnoreCase);
}
[Fact]
public void NormalizeToGibibytes_UsesProvidedParameterNameInError()
{
var ex = Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes("512M", "DiskSize"));
Assert.Equal("DiskSize", ex.ParamName);
Assert.Contains("DiskSize", ex.Message);
}
[Fact]
public void NormalizeToGibibytes_TerabyteOverflow_ThrowsArgumentException()
{
// long.MaxValue with a T suffix overflows when multiplied by 1024.
var input = long.MaxValue.ToString(System.Globalization.CultureInfo.InvariantCulture) + "T";
var ex = Assert.Throws<ArgumentException>(() => SizeParser.NormalizeToGibibytes(input, "DiskSize"));
Assert.Equal("DiskSize", ex.ParamName);
Assert.Contains("too large", ex.Message, StringComparison.OrdinalIgnoreCase);
}
}
}
@@ -94,17 +94,35 @@ Describe 'Connect-PveServer' {
Should -Be ([System.Management.Automation.SwitchParameter])
}
It 'Should have a PassThru switch parameter' {
It 'Should have a PassThru switch parameter (deprecated, hidden)' {
$script:Cmd.Parameters.ContainsKey('PassThru') | Should -BeTrue
$script:Cmd.Parameters['PassThru'].ParameterType |
Should -Be ([System.Management.Automation.SwitchParameter])
}
It 'Should have a Quiet switch parameter' {
$script:Cmd.Parameters.ContainsKey('Quiet') | Should -BeTrue
$script:Cmd.Parameters['Quiet'].ParameterType |
Should -Be ([System.Management.Automation.SwitchParameter])
}
It 'Credential and ApiToken should belong to different parameter sets' {
$credSets = $script:Cmd.Parameters['Credential'].ParameterSets.Keys
$tokenSets = $script:Cmd.Parameters['ApiToken'].ParameterSets.Keys
$overlap = $credSets | Where-Object { $tokenSets -contains $_ }
$overlap | Should -BeNullOrEmpty
}
It 'Should have a TimeoutSeconds parameter' {
$script:Cmd.Parameters.ContainsKey('TimeoutSeconds') | Should -BeTrue
}
It 'TimeoutSeconds should reject negative values' {
$securePass = ConvertTo-SecureString 'hunter2' -AsPlainText -Force
$cred = [System.Management.Automation.PSCredential]::new('root@pam', $securePass)
{
Connect-PveServer -Server 'pve.example.com' -Credential $cred -TimeoutSeconds -1 -ErrorAction Stop
} | Should -Throw
}
}
}
@@ -0,0 +1,68 @@
#Requires -Module Pester
<#
.SYNOPSIS
Pester 5 tests for New-PveContainer.
All tests are fully offline — no live Proxmox VE target is required.
#>
BeforeAll {
. $PSScriptRoot/../_TestHelper.ps1
}
Describe 'New-PveContainer' {
Context 'Command existence' {
It 'Should be available after module import' {
Get-Command 'New-PveContainer' -ErrorAction SilentlyContinue |
Should -Not -BeNullOrEmpty
}
It 'Should be a CmdletInfo (binary cmdlet)' {
(Get-Command 'New-PveContainer').CommandType | Should -Be 'Cmdlet'
}
}
Context 'ShouldProcess support' {
BeforeAll {
$script:Cmd = Get-Command 'New-PveContainer'
}
It 'Should support ShouldProcess (WhatIf parameter present)' {
$script:Cmd.Parameters.ContainsKey('WhatIf') | Should -BeTrue
}
It 'Should support ShouldProcess (Confirm parameter present)' {
$script:Cmd.Parameters.ContainsKey('Confirm') | Should -BeTrue
}
}
Context 'RootFsSize validation' {
# Validation runs before ShouldProcess so -WhatIf is enough to exercise it
# without an active session.
It 'Should reject sub-GB units (e.g. 512M)' {
{ New-PveContainer -Node 'pve-node1' -RootFsStorage 'local-lvm' -RootFsSize '512M' -WhatIf -ErrorAction Stop } |
Should -Throw '*unsupported unit*'
}
It 'Should reject sub-GB units even when -RootFsStorage is omitted' {
{ New-PveContainer -Node 'pve-node1' -RootFsSize '512M' -WhatIf -ErrorAction Stop } |
Should -Throw '*unsupported unit*'
}
It 'Should reject malformed input (e.g. 8.5G)' {
{ New-PveContainer -Node 'pve-node1' -RootFsStorage 'local-lvm' -RootFsSize '8.5G' -WhatIf -ErrorAction Stop } |
Should -Throw '*not a valid size*'
}
It 'Should accept a bare integer with -WhatIf' {
{ New-PveContainer -Node 'pve-node1' -RootFsStorage 'local-lvm' -RootFsSize '8' -WhatIf -ErrorAction Stop } |
Should -Not -Throw
}
It 'Should accept "8G" with -WhatIf' {
{ New-PveContainer -Node 'pve-node1' -RootFsStorage 'local-lvm' -RootFsSize '8G' -WhatIf -ErrorAction Stop } |
Should -Not -Throw
}
}
}
@@ -154,6 +154,20 @@ Describe 'Send-PveFile' {
if (-not $script:CmdExists) { Set-ItResult -Skipped -Because 'Not yet compiled'; return }
$script:Cmd.Parameters.ContainsKey('Session') | Should -BeTrue
}
It 'Should have TimeoutSeconds parameter' {
if (-not $script:CmdExists) { Set-ItResult -Skipped -Because 'Not yet compiled'; return }
$script:Cmd.Parameters.ContainsKey('TimeoutSeconds') | Should -BeTrue
}
It 'TimeoutSeconds should reject negative values' {
if (-not $script:CmdExists) { Set-ItResult -Skipped -Because 'Not yet compiled'; return }
$tmpIso = [System.IO.Path]::GetTempFileName()
try {
{ Send-PveFile -Node 'n' -Storage 's' -Path $tmpIso -TimeoutSeconds -1 -Confirm:$false -ErrorAction Stop } |
Should -Throw
} finally { Remove-Item $tmpIso -ErrorAction SilentlyContinue }
}
}
Context 'Without active session' {
@@ -150,6 +150,17 @@ Describe 'Invoke-PveStorageDownload' {
$script:Cmd.Parameters.ContainsKey('Wait') | Should -BeTrue
$script:Cmd.Parameters['Wait'].SwitchParameter | Should -BeTrue
}
It 'Should have TimeoutSeconds parameter' {
Skip-IfMissing 'Invoke-PveStorageDownload'
$script:Cmd.Parameters.ContainsKey('TimeoutSeconds') | Should -BeTrue
}
It 'TimeoutSeconds should reject negative values' {
Skip-IfMissing 'Invoke-PveStorageDownload'
{ Invoke-PveStorageDownload -Node 'pve1' -Storage 'local' -Url 'https://example.com/test.iso' -Filename 'test.iso' -TimeoutSeconds -1 -Confirm:$false -ErrorAction Stop } |
Should -Throw
}
}
Context 'Session parameter' {
@@ -133,4 +133,39 @@ Describe 'New-PveVm' {
Should -Throw '*No active Proxmox VE session*'
}
}
Context 'DiskSize validation' {
# Validation runs before ShouldProcess so -WhatIf is enough to exercise it
# without an active session.
It 'Should reject sub-GB units (e.g. 512M)' {
{ New-PveVm -Node 'pve-node1' -DiskStorage 'local-lvm' -DiskSize '512M' -WhatIf -ErrorAction Stop } |
Should -Throw '*unsupported unit*'
}
It 'Should reject sub-GB units even when -DiskStorage is omitted' {
{ New-PveVm -Node 'pve-node1' -DiskSize '512M' -WhatIf -ErrorAction Stop } |
Should -Throw '*unsupported unit*'
}
It 'Should reject malformed input (e.g. 32.5G)' {
{ New-PveVm -Node 'pve-node1' -DiskStorage 'local-lvm' -DiskSize '32.5G' -WhatIf -ErrorAction Stop } |
Should -Throw '*not a valid size*'
}
It 'Should accept a bare integer with -WhatIf' {
{ New-PveVm -Node 'pve-node1' -DiskStorage 'local-lvm' -DiskSize '32' -WhatIf -ErrorAction Stop } |
Should -Not -Throw
}
It 'Should accept "32G" with -WhatIf' {
{ New-PveVm -Node 'pve-node1' -DiskStorage 'local-lvm' -DiskSize '32G' -WhatIf -ErrorAction Stop } |
Should -Not -Throw
}
It 'Should accept "1T" with -WhatIf' {
{ New-PveVm -Node 'pve-node1' -DiskStorage 'local-lvm' -DiskSize '1T' -WhatIf -ErrorAction Stop } |
Should -Not -Throw
}
}
}