Routed network ACL rules with a protocol number are not applied on the VR (ip nexthdr instead of ip protocol)
維護者通常 1 天內回覆
評估
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 新手友好度
- 82/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- linux, python
- 領域
- networking
研究方向
從 systemvm/debian/opt/cloud/bin/configure.py 中的 CsAcl.AclDevice.__process_routing_ip4() 開始,這裡會產生路由的 IPv4 ACL 規則。將 IPv4 比對條件與正確的 IPv6 路徑進行比較,並依照重現步驟確認產生的規則:新增一條協定 47 的 ACL 規則,接著在 VR 上檢查 nft list table ip ip4_acl。當 IPv4 規則使用 ip protocol,並出現在 ACL 表中且沒有記錄的 nft 失敗時,即為完成。
由索引模型根據 Issue 內容生成。
描述
problem
On a VPC in routed mode (IPv4 routing, introduced in 4.20 with #9470), a network ACL rule that uses a protocol number (e.g. 47 for GRE) is never applied on the VR.
CsAcl.AclDevice.__process_routing_ip4() in systemvm/debian/opt/cloud/bin/configure.py renders it as:
ip saddr 1.2.3.4/32 ip nexthdr 47 accept
nexthdr is an IPv6 header field. The IPv4 equivalent is ip protocol, so nft rejects the rule:
$ nft add rule ip ip4_acl eth3_ingress_policy ip saddr 1.2.3.4/32 ip nexthdr 47 accept
Error: syntax error, unexpected string
add rule ip ip4_acl eth3_ingress_policy ip saddr 1.2.3.4/32 ip nexthdr 47 accept
^^^^^^^
The rules are added one nft add rule at a time and the failure is only logged (/var/log/cloud.log records the non-zero exit status; nft's message goes to stderr), so the rule is silently missing from ip4_acl while the rest of the ACL loads. An allow rule for that protocol therefore never matches. A deny rule for it is also lost, so that traffic falls through to whatever later rule matches it.
The IPv6 path (__process_ip6, ip6 nexthdr) is correct. Non-routed VPCs use iptables and are not affected.
versions
CloudStack 4.20 onward (still present on 4.22).
The steps to reproduce the bug
- Create a VPC in routed mode with an IPv4 tier. (Network ACLs only exist on VPC tiers.)
- Add an ACL rule to the tier's ACL list: protocol number
47, CIDR0.0.0.0/0, action Allow. - On the VR, run
nft list table ip ip4_acl. The rule is missing fromethX_ingress_policy. grep "ip nexthdr" /var/log/cloud.logshows the failednft add rule(returned non-zero exit status 1).
What to do about it?
Render the IPv4 match as ip protocol <n>, which nft accepts (it lists it as ip protocol gre).
- 主要語言
- Java
- 星號
- 3.1k
- 分支
- 1.4k
- 平均合併
- 9 天 44 分鐘
- 30 天內合併 PR
- 14
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
apache/cloudstack 的其他 Issue
-
listPublicIpAddresses NullPointerException on shared networks with a VR (4.22)可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 2/5 1-3 小時 新手友好度 80/100
apache/cloudstack#14248 ·
維護者通常 1 天內回覆
-
CKS: upgradeKubernetesCluster fails on control node when binaries ISO ships headlamp.yaml instead of dashboard.yaml可能已有人在做 @mw-0 於 16 天前認領。 未關閉bug
難度 2/5 1-3 小時 新手友好度 68/100
apache/cloudstack#14244 · 1 則留言 ·
維護者通常 1 天內回覆
-
Resize volume API validation errors are not displayed in the UI可能已有人在做 @sathvikaragi 於 18 天前認領。 未關閉bug
難度 1/5 1 小時以內 新手友好度 90/100
apache/cloudstack#14222 · 2 則留言 ·
維護者通常 1 天內回覆
-
bug component:kubernetes
難度 1/5 1 小時以內 新手友好度 88/100
apache/cloudstack#14180 ·
維護者通常 1 天內回覆
-
bug component:projects component:UI
難度 1/5 1 小時以內 新手友好度 88/100
apache/cloudstack#14070 · 5 則留言 ·
維護者通常 1 天內回覆
查看 apache/cloudstack 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 85/100
objectionary/eo-graphs#80 ·
-
難度 2/5 1-3 小時 新手友好度 74/100
-
enhancement good first issue
難度 2/5 半天 新手友好度 66/100
apache/fineract-consumer-facing#175 ·
維護者通常 1 天內回覆
-
[BUG] 订单:会员凭订单号即可取消其他会员的待付款订单(取消接口不校验订单归属)可能已有人在做 @dadiyang 今天認領。 未關閉
難度 2/5 1-3 小時 新手友好度 70/100
macrozheng/mall#1016 ·
-
難度 2/5 1-3 小時 新手友好度 78/100