Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Routed network ACL rules with a protocol number are not applied on the VR (ip nexthdr instead of ip protocol)

未關閉 適合新手
#14,351 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

@bhouse-nexthop 已經在處理了。

開始於 2026年10月8日。

  • #14352 來自 @bhouse-nexthop —— 未關閉

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
82/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
linux, python
領域
networking

研究方向

從 systemvm/debian/opt/cloud/bin/configure.py 中的 CsAcl.AclDevice.__process_routing_ip4() 開始,這裡會產生路由的 IPv4 ACL 規則。將 IPv4 比對條件與正確的 IPv6 路徑進行比較,並依照重現步驟確認產生的規則:新增一條協定 47 的 ACL 規則,接著在 VR 上檢查 nft list table ip ip4_acl。當 IPv4 規則使用 ip protocol,並出現在 ACL 表中且沒有記錄的 nft 失敗時,即為完成。

由索引模型根據 Issue 內容生成。

描述

component:virtual-router
problem

On a VPC in routed mode (IPv4 routing, introduced in 4.20 with #9470), a network ACL rule that uses a protocol number (e.g. 47 for GRE) is never applied on the VR.

CsAcl.AclDevice.__process_routing_ip4() in systemvm/debian/opt/cloud/bin/configure.py renders it as:

ip saddr 1.2.3.4/32 ip nexthdr 47 accept

nexthdr is an IPv6 header field. The IPv4 equivalent is ip protocol, so nft rejects the rule:

$ nft add rule ip ip4_acl eth3_ingress_policy ip saddr 1.2.3.4/32 ip nexthdr 47 accept
Error: syntax error, unexpected string
add rule ip ip4_acl eth3_ingress_policy ip saddr 1.2.3.4/32 ip nexthdr 47 accept
                                                            ^^^^^^^

The rules are added one nft add rule at a time and the failure is only logged (/var/log/cloud.log records the non-zero exit status; nft's message goes to stderr), so the rule is silently missing from ip4_acl while the rest of the ACL loads. An allow rule for that protocol therefore never matches. A deny rule for it is also lost, so that traffic falls through to whatever later rule matches it.

The IPv6 path (__process_ip6, ip6 nexthdr) is correct. Non-routed VPCs use iptables and are not affected.

versions

CloudStack 4.20 onward (still present on 4.22).

The steps to reproduce the bug
  1. Create a VPC in routed mode with an IPv4 tier. (Network ACLs only exist on VPC tiers.)
  2. Add an ACL rule to the tier's ACL list: protocol number 47, CIDR 0.0.0.0/0, action Allow.
  3. On the VR, run nft list table ip ip4_acl. The rule is missing from ethX_ingress_policy.
  4. grep "ip nexthdr" /var/log/cloud.log shows the failed nft add rule (returned non-zero exit status 1).
What to do about it?

Render the IPv4 match as ip protocol <n>, which nft accepts (it lists it as ip protocol gre).

主要語言
Java
星號
3.1k
分支
1.4k
平均合併
9 天 44 分鐘
30 天內合併 PR
14

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

apache/cloudstack 的其他 Issue

查看 apache/cloudstack 的全部 Issue

相似的 Issue

更多 Java Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。