Hello Matthew, Updated the description. Will make further adjustments where needed.
Best, Alan ** Description changed: - Ubuntu Cloud Archive OVN packages for Antelope and Bobcat are missing - the FDP-620 patch (1). + [ Impact ] - About the patch - --------------- - physical: Prevent wrong FDB to be learned with multichassis port. - If multichassis VIF is set with "unknown" address it might store - wrong MAC address into the FDB table. The ICMP Need frag is generated - by swapping the MAC src and dst of the original packet, however the - inport remains the same. As a consequence the match on the inport to - learn FDB will store source MAC address which is the original - destination address, that leads to redirection of traffic the VIF - which is wrong. + * OpenStack Jammy/Antelope and Jammy/Bobcat UCA OVN packages + were never patched for a known issue (1). + + * In environments that use VLAN networks using external + gateways this leads to learning an incorrect MAC address + which in turn causes traffic disconnects post live + migration. + + * The workaround is either re-creating the port of cleaning + up the FDB record in the OVN SB db. + + * Users upgrading from Yoga LTS to Caracal LTS go through step + upgrades. This involves upgrades to Antelope and Bobcat which + requires node evacuation. Lack of this patch causes instance + connectivity issues during live migrations. - Swap the inport and outport for the ICMP error to prevent this issue - it also makes more sense as the ICMP is supposed to be generated by - entity along the way and not by the original VIF. + * This SRU is being initiated to backport the missing patch. - Note that those flows is still needed as userspace datapath is not - capable of PMTUD yet. + [ Test Plan ] - Reported-at: https://issues.redhat.com/browse/FDP-620 + * This bug may not not be easy to reproduce: + * It requires a combination of VLAN networks including external + non-OpenStack gateways to manifest. - Why is this an issue? These are EOL releases - -------------------------------------------- - Users upgrading from Yoga LTS to Caracal LTS go through step upgrades. - This involves upgrades to Antelope and Bobcat which requires node evacuation. - Lack of this patch causes instance connectivity issues during live migrations. + * We are currently attempting to build a lab reproducer + + * If the above is successful, further testing / validation steps + will be provided here. - Instances lose network connectivity and the only way to fix these is to clear - the incorrectly learned MAC from OVN FDB or re-create the port. + * In an affected cloud, after installing the updated packages, + previously breaking live migration attempts should succeed. + The package updates only need to be installed on the compute nodes + as long as external_ids:ovn-match-northd-version=false - None of the above steps are practical when live migrating 10s or 100s of - VMs. + [ Where problems could occur ] - (1) https://github.com/ovn- - org/ovn/commit/3c6791e43714b22335acbce0648be59ad4671d2b + * Updating the OVN packages does restart these services. + + * Make sure to set external_ids:ovn-match-northd-version=false + using sudo ovs-vsctl set open_vswitch command or else data + plane traffic will be affected. + + * The above needs to be applied on all compute nodes or via + juju config on juju deployed clouds (2) + + * Otherwise this is a known patch already applied to Caracal + and does address the mentioned issue (1). + + [ Mode Details about the patch ] + + physical: Prevent wrong FDB to be learned with multichassis port. + If multichassis VIF is set with "unknown" address it might store + wrong MAC address into the FDB table. The ICMP Need frag is generated + by swapping the MAC src and dst of the original packet, however the + inport remains the same. As a consequence the match on the inport to + learn FDB will store source MAC address which is the original + destination address, that leads to redirection of traffic the VIF + which is wrong. + + Swap the inport and outport for the ICMP error to prevent this issue + it also makes more sense as the ICMP is supposed to be generated by + entity along the way and not by the original VIF. + + Note that those flows is still needed as userspace datapath is not + capable of PMTUD yet. + + (1) https://github.com/ovn-org/ovn/commit/3c6791e43714b22335acbce0648be59ad4671d2b + (2) https://charmhub.io/ovn-chassis/configurations#enable-version-pinning ** Summary changed: - OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620 fix + [SRU] OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620 fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168890 Title: [SRU] OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620 fix To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/2168890/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
