With SB RBAC, a chassis may update the status of a BFD row only if the
row's chassis_name is the name of that chassis. ovn-northd takes
chassis_name from the binding of the logical router port, and the value
is wrong in the following cases:
- For a distributed gateway port, the binding of the logical router port
is a patch port, and no chassis claims a patch port. So chassis_name
stays empty. The BFD sessions of the port run on the chassis where
its chassisredirect port is bound.
- For an existing row, ovn-northd writes chassis_name only when the row
already has the new value, so the value never changes. When
ovn-controller claims a gateway router port after ovn-northd created
the row, chassis_name stays empty. When the gateway router moves to
another chassis, chassis_name keeps the name of the old chassis.
- The northd engine node ignores a change of the chassis of a binding.
So the BFD rows are synced again only when an unrelated change
recomputes the bfd_sync node.
The SB database then rejects every status update that ovn-controller
makes for these rows. Each rejection fails the whole SB transaction of
that ovn-controller iteration, with all its other writes. So a route
that uses the session can stay withdrawn while the session is up, or
stay in place while the session is down.
Set chassis_name from the binding that decides where the sessions run:
the binding of the chassisredirect port for a distributed gateway port,
and the binding of the port itself otherwise. Update it when the
chassis of that binding changes, and clear it when the binding has no
chassis, where 4885e337f kept the last name, so that a chassis that
released the port can no longer update the row. The bfd_sync engine
node now has SB Port_Binding as an input. Its handler recomputes the
node when the chassis changes in the binding of a port with BFD
sessions or of its chassisredirect port, including a new binding that
already has a chassis, and ignores all other binding changes. Each
change of chassis_name is an SB BFD update, so ovn-northd then
recomputes its logical flows, as it does for every BFD status update.
ovn-controller writes the status only on a state change of the session
and does not retry a rejected update. So a chassis that claims a port,
for the first time, after a move, or again after it released it, waits
for ovn-northd to set chassis_name to its name, and a state change that
it writes before that is still rejected. The status then stays wrong
until the next state change, unless ovn-controller also corrects the
status once chassis_name names its chassis, which is a separate
ovn-controller change.
Fixes: 4885e337f929 ("rbac: Only allow relevant chassis to update BFD.")
Fixes: 15c9c9f42ad8 ("northd: Add bfd, static_routes, route_policies and
bfd_sync nodes to I-P engine.")
Submitted-at: https://github.com/ovn-org/ovn/pull/334
<https://www.google.com/url?q=https://github.com/ovn-org/ovn/pull/334&source=gmail&ust=1791296558430000&sa=E>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5), Cursor Grok Bot / Ultimum
harness assistants
Signed-off-by: Premysl Kouril <[email protected]>
---
NOTE: commit message only here. Before sending, attach
0001-northd-Keep-BFD-chassis_name-aligned-for-SB-RBAC.patch from
/home/ibmko/aiworkspaces/Ultimum/harness-runs/ovn-ml-series-20261005/
or use git send-email on that directory. A matching Gmail Draft was also
saved.
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev