ProxmoxMCP-Plus v0.5.27
The independent review after v0.5.26 publication found four additional defects.
This patch repairs them and corrects the command-policy documentation.
Fixes
- Validate VM, source VM and destination VM identifiers as positive ASCII integers
before MCP dispatch. A VM configuration tool can no longer use a relative guest
path to reach LXC configuration while only VM tools are exposed. - Recheck snapshot dependencies before every rollback submission, including
in-process and persisted retries. Refuse malformed or incomplete inventories.
New child snapshots must be explicitly removed before a rollback can be retried. - Compare approval secrets as UTF-8 bytes in constant time. Incorrect non-ASCII
tokens and invalid Unicode text fail safely; valid Unicode secrets can match. - Add structured completeness metadata to partial backup inventories so monitoring
recordspartialinstead of successful complete enumeration. - Clarify that command allowlist expressions use regex search. Anchor expressions
when a policy must match the entire command; a regex policy is not a shell sandbox.
Validation
Regression tests exercise the actual MCP tool call with real Proxmoxer/Requests
URL preparation, retry behavior before and after process restart, safe Unicode
approval comparison and structured partial inventory results. No live destructive
Proxmox requests were made.
The full runtime coverage gate remains 100% with zero missing statements across
all 55 runtime modules. Local Windows/Python 3.13 validation passed 855 tests with
3 skips and zero warnings, covering all 5,751 statements. Ruff, Mypy, build, Twine,
release metadata and the clean installed wheel checks passed.
Release CI, CodeQL and downstream publication must succeed
before this version is treated as verified.
Upgrade
Upgrade to proxmox-mcp-plus==0.5.27 or the matching container tag and restart all
workers. Keep the existing SQLite and PostgreSQL state. No schema migration or
configuration changes are required. Guest identifier validation now rejects
non-numeric strings, URL controls and relative paths before contacting Proxmox.
All v0.5.26 runtime and deployment improvements remain included.