From: Numan Siddique <[email protected]>

start_ovsdb__() derives every per-database variable from its DB
argument, so for DB=OVNBR it reads $OVN_OVNBR_LOG and
$OVN_OVNBR_DB_SSL_*.  Neither was defined: set_defaults() defined
OVNBR_DB_SSL_* instead, and nothing defined a log variable.  As a
result:

  - The --ovnbr-db-ssl-* options were accepted and silently ignored,
    so the OVN_Bridge_Controller ovsdb-server always took its TLS
    settings from the database, whatever was passed on the command
    line.
  - --ovn-br-db-log was rejected as an unknown option, and the
    ovsdb-server was started with no logging parameters at all,
    unlike every other database server.
  - --ovsdb-br-wrapper was rejected as an unknown option, and
    start_ovnbr_ovsdb() did not pass a wrapper in any case.

Name the options after the variables start_ovsdb__() reads, the way
the NB, SB and IC databases already do and the way the existing
--ovn-ovnbr-logfile option is named: --ovn-ovnbr-db-ssl-*,
--ovn-ovnbr-log (defaulting to "-vconsole:off -vfile:info", as for
the other database servers) and --ovsdb-ovnbr-wrapper.  None of the
old names ever took effect, so no working configuration is broken by
the rename.

Also fix the example in the ovn-br-db systemd unit, which used
--db-br-create-insecure-remote; the option is
--db-ovnbr-create-insecure-remote.

Fixes: 22dbd8021359 ("ovn-ctl: Add commands to start OVN bridge controller 
services.")
Reported-by: Dumitru Ceara <[email protected]>
Assisted-by: Claude Opus 5.5, Claude Code
Signed-off-by: Numan Siddique <[email protected]>
---
 rhel/usr_lib_systemd_system_ovn-br-db.service |  4 +--
 utilities/ovn-ctl                             | 33 ++++++++++---------
 utilities/ovn-ctl.8.xml                       | 29 +++++++++-------
 3 files changed, 37 insertions(+), 29 deletions(-)

diff --git a/rhel/usr_lib_systemd_system_ovn-br-db.service 
b/rhel/usr_lib_systemd_system_ovn-br-db.service
index 6de2a22f1e..a6f6631b09 100644
--- a/rhel/usr_lib_systemd_system_ovn-br-db.service
+++ b/rhel/usr_lib_systemd_system_ovn-br-db.service
@@ -7,11 +7,11 @@
 # /etc/systemd/system/ovn-br-db.d/local.conf:
 #
 #   [System]
-#   Environment="OVN_BR_DB_OPTS=--db-br-create-insecure-remote=yes"
+#   Environment="OVN_BR_DB_OPTS=--db-ovnbr-create-insecure-remote=yes"
 #
 # Alternatively, you may specify environment variables in the file 
/etc/sysconfig/ovn-br-db:
 #
-#   OVN_BR_DB_OPTS="--db-br-create-insecure-remote=yes"
+#   OVN_BR_DB_OPTS="--db-ovnbr-create-insecure-remote=yes"
 
 [Unit]
 Description=OVN Bridge Controller OVSDB server
diff --git a/utilities/ovn-ctl b/utilities/ovn-ctl
index 788f1c14ba..8b73132e32 100755
--- a/utilities/ovn-ctl
+++ b/utilities/ovn-ctl
@@ -461,7 +461,8 @@ start_ic_ovsdb () {
 
 
 start_ovnbr_ovsdb() {
-    start_ovsdb__ OVNBR br OVN_Bridge_Controller BR_Global
+    start_ovsdb__ OVNBR br OVN_Bridge_Controller BR_Global \
+                  "$OVSDB_OVNBR_WRAPPER"
 }
 
 sync_status() {
@@ -1134,7 +1135,9 @@ set_defaults () {
     OVNBR_CONTROLLER_WRAPPER=
 
     OVNBR_CONTROLLER_LOG="-vconsole:emer -vsyslog:err -vfile:info"
+    OVN_OVNBR_LOG="-vconsole:off -vfile:info"
     OVN_OVNBR_LOGFILE="$ovn_logdir/ovsdb-server-ovnbr.log"
+    OVSDB_OVNBR_WRAPPER=
 
     OVNBR_CONTROLLER_SSL_KEY=""
     OVNBR_CONTROLLER_SSL_CERT=""
@@ -1149,12 +1152,12 @@ set_defaults () {
     DB_OVNBR_DETACH="yes"
     DB_OVNBR_USE_REMOTE_IN_DB="yes"
 
-    OVNBR_DB_SSL_KEY=""
-    OVNBR_DB_SSL_CERT=""
-    OVNBR_DB_SSL_CA_CERT=""
-    OVNBR_DB_SSL_PROTOCOLS=""
-    OVNBR_DB_SSL_CIPHERS=""
-    OVNBR_DB_SSL_CIPHERSUITES=""
+    OVN_OVNBR_DB_SSL_KEY=""
+    OVN_OVNBR_DB_SSL_CERT=""
+    OVN_OVNBR_DB_SSL_CA_CERT=""
+    OVN_OVNBR_DB_SSL_PROTOCOLS=""
+    OVN_OVNBR_DB_SSL_CIPHERS=""
+    OVN_OVNBR_DB_SSL_CIPHERSUITES=""
 }
 
 set_option () {
@@ -1333,15 +1336,15 @@ Options:
   --ovnbr-controller-ssl-protocols=PROTOCOLS OVN Bridge Controller SSL/TLS 
protocols
   --ovnbr-controller-ssl-ciphers=CIPHERS OVN Bridge Controller SSL/TLS cipher 
list
   --ovnbr-controller-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller 
TLSv1.3+ ciphersuite list
-  --ovnbr-db-ssl-key=KEY OVN Bridge Controller DB SSL/TLS private key file
-  --ovnbr-db-ssl-cert=CERT OVN Bridge Controller DB SSL/TLS certificate file
-  --ovnbr-db-ssl-ca-cert=CERT OVN Bridge Controller DB SSL/TLS CA certificate 
file
-  --ovnbr-db-ssl-protocols=PROTOCOLS OVN Bridge Controller DB SSL/TLS protocols
-  --ovnbr-db-ssl-ciphers=CIPHERS OVN Bridge Controller DB SSL/TLS cipher list
-  --ovnbr-db-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller DB TLSv1.3+ 
ciphersuite list
+  --ovn-ovnbr-db-ssl-key=KEY OVN Bridge Controller DB SSL/TLS private key file
+  --ovn-ovnbr-db-ssl-cert=CERT OVN Bridge Controller DB SSL/TLS certificate 
file
+  --ovn-ovnbr-db-ssl-ca-cert=CERT OVN Bridge Controller DB SSL/TLS CA 
certificate file
+  --ovn-ovnbr-db-ssl-protocols=PROTOCOLS OVN Bridge Controller DB SSL/TLS 
protocols
+  --ovn-ovnbr-db-ssl-ciphers=CIPHERS OVN Bridge Controller DB SSL/TLS cipher 
list
+  --ovn-ovnbr-db-ssl-ciphersuites=CIPHERSUITES OVN Bridge Controller DB 
TLSv1.3+ ciphersuite list
   --ovnbr-controller-log=STRING        ovn-br-controller process logging 
params (default: $OVNBR_CONTROLLER_LOG)
-  --ovn-br-db-log=STRING             ovn brdb ovsdb-server processes logging 
params (default: $OVN_BR_DB_LOG)
-  --ovsdb-br-wrapper=WRAPPER     run with a wrapper like valgrind for debugging
+  --ovn-ovnbr-log=STRING         ovn bridge controller ovsdb-server process 
logging params (default: $OVN_OVNBR_LOG)
+  --ovsdb-ovnbr-wrapper=WRAPPER  run with a wrapper like valgrind for debugging
   -h, --help                     display this help message
 
 File location options:
diff --git a/utilities/ovn-ctl.8.xml b/utilities/ovn-ctl.8.xml
index 478487e755..9389397cef 100644
--- a/utilities/ovn-ctl.8.xml
+++ b/utilities/ovn-ctl.8.xml
@@ -219,6 +219,8 @@
       database server under the specified wrapper.</p>
     <p><code>--ovsdb-sb-wrapper=<var>WRAPPER</var></code> runs the Southbound
       database server under the specified wrapper.</p>
+    <p><code>--ovsdb-ovnbr-wrapper=<var>WRAPPER</var></code> runs the OVN
+      bridge controller database server under the specified wrapper.</p>
     <p><code>--ovn-user=<var>USER[:GROUP]</var></code> runs OVN daemons as the
       specified user and optional group.</p>
     <p><code>--ovn-manage-ovsdb=<var>yes|no</var></code> controls whether
@@ -330,11 +332,11 @@
       ovn-br-controller SSL/TLS CA certificate file.</p>
     <p><code>--ovnbr-controller-ssl-bootstrap-ca-cert=<var>CERT</var></code>
       bootstraps the ovn-br-controller SSL/TLS CA certificate file.</p>
-    <p><code>--ovnbr-db-ssl-key=<var>KEY</var></code> sets the
+    <p><code>--ovn-ovnbr-db-ssl-key=<var>KEY</var></code> sets the
       ovn-br-controller database SSL/TLS private key file.</p>
-    <p><code>--ovnbr-db-ssl-cert=<var>CERT</var></code> sets the
+    <p><code>--ovn-ovnbr-db-ssl-cert=<var>CERT</var></code> sets the
       ovn-br-controller database SSL/TLS certificate file.</p>
-    <p><code>--ovnbr-db-ssl-ca-cert=<var>CERT</var></code> sets the
+    <p><code>--ovn-ovnbr-db-ssl-ca-cert=<var>CERT</var></code> sets the
       ovn-br-controller database SSL/TLS CA certificate file.</p>
     <p><code>--db-ovnbr-sock=<var>SOCKET</var></code> sets the OVN bridge
       controller database socket.</p>
@@ -372,10 +374,12 @@
     <p><code>--ovn-nb-log=<var>STRING</var></code>,
       <code>--ovn-sb-log=<var>STRING</var></code>,
       <code>--ovn-ic-nb-log=<var>STRING</var></code>,
-      <code>--ovn-ic-sb-log=<var>STRING</var></code>, and
-      <code>--ovn-sb-relay-log=<var>STRING</var></code> set database-server
-      logging parameters.  The defaults for the NB, SB, IC-NB, and IC-SB
-      database servers are <code>-vconsole:off -vfile:info</code>.  The
+      <code>--ovn-ic-sb-log=<var>STRING</var></code>,
+      <code>--ovn-sb-relay-log=<var>STRING</var></code>, and
+      <code>--ovn-ovnbr-log=<var>STRING</var></code> set database-server
+      logging parameters.  The defaults for the NB, SB, IC-NB, IC-SB, and
+      OVN bridge controller database servers are
+      <code>-vconsole:off -vfile:info</code>.  The
       default for the SB relay database server is
       <code>-vconsole:emer -vsyslog:err -vfile:info</code>.</p>
     <p><code>--ovn-northd-logfile=<var>FILE</var></code>,
@@ -398,7 +402,7 @@
       <code>ovn-controller</code>, <code>ovn-northd</code>,
       <code>ovn-ic</code>, <code>ovn-nb-db</code>, <code>ovn-sb-db</code>,
       <code>ovn-ic-nb-db</code>, <code>ovn-ic-sb-db</code>,
-      <code>ovn-sb-relay-db</code>, and <code>ovnbr-db</code>;
+      <code>ovn-sb-relay-db</code>, and <code>ovn-ovnbr-db</code>;
       append <code>-ssl-key</code>, <code>-ssl-cert</code>,
       or <code>-ssl-ca-cert</code>.  Controller prefixes also accept
       <code>-ssl-bootstrap-ca-cert</code>.  Empty values leave the normal
@@ -445,12 +449,13 @@
       ovn-br-controller SSL/TLS cipher list.</p>
     <p><code>--ovnbr-controller-ssl-ciphersuites=<var>CIPHERSUITES</var></code>
       sets the ovn-br-controller TLS 1.3 and later ciphersuite list.</p>
-    <p><code>--ovnbr-db-ssl-protocols=<var>PROTOCOLS</var></code> sets the
+    <p><code>--ovn-ovnbr-db-ssl-protocols=<var>PROTOCOLS</var></code> sets the
       ovn-br-controller database SSL/TLS protocols.</p>
-    <p><code>--ovnbr-db-ssl-ciphers=<var>CIPHERS</var></code> sets the
+    <p><code>--ovn-ovnbr-db-ssl-ciphers=<var>CIPHERS</var></code> sets the
       ovn-br-controller database SSL/TLS cipher list.</p>
-    <p><code>--ovnbr-db-ssl-ciphersuites=<var>CIPHERSUITES</var></code> sets
-      the ovn-br-controller database TLS 1.3 and later ciphersuite list.</p>
+    <p><code>--ovn-ovnbr-db-ssl-ciphersuites=<var>CIPHERSUITES</var></code>
+      sets the ovn-br-controller database TLS 1.3 and later ciphersuite
+      list.</p>
 
     <h1>Address and port options</h1>
     <p><code>--db-nb-sync-from-addr=<var>IP ADDRESS</var></code>.</p>
-- 
2.55.0

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to