Hello Matthew,

Updated the description. Will make further adjustments where needed.

Best,
Alan

** Description changed:

- Ubuntu Cloud Archive OVN packages for Antelope and Bobcat are missing
- the FDP-620 patch (1).
+ [ Impact ]
  
- About the patch
- ---------------
- physical: Prevent wrong FDB to be learned with multichassis port.
- If multichassis VIF is set with "unknown" address it might store
- wrong MAC address into the FDB table. The ICMP Need frag is generated
- by swapping the MAC src and dst of the original packet, however the
- inport remains the same. As a consequence the match on the inport to
- learn FDB will store source MAC address which is the original
- destination address, that leads to redirection of traffic the VIF
- which is wrong.
+  * OpenStack Jammy/Antelope and Jammy/Bobcat UCA OVN packages
+    were never patched for a known issue (1).
+    
+  * In environments that use VLAN networks using external
+    gateways this leads to learning an incorrect MAC address
+    which in turn causes traffic disconnects post live 
+    migration.
+    
+  * The workaround is either re-creating the port of cleaning
+    up the FDB record in the OVN SB db.
+    
+  * Users upgrading from Yoga LTS to Caracal LTS go through step
+    upgrades. This involves upgrades to Antelope and Bobcat which
+    requires node evacuation. Lack of this patch causes instance
+    connectivity issues during live migrations. 
  
- Swap the inport and outport for the ICMP error to prevent this issue
- it also makes more sense as the ICMP is supposed to be generated by
- entity along the way and not by the original VIF.
+  * This SRU is being initiated to backport the missing patch.
  
- Note that those flows is still needed as userspace datapath is not
- capable of PMTUD yet.
+ [ Test Plan ]
  
- Reported-at: https://issues.redhat.com/browse/FDP-620
+  * This bug may not not be easy to reproduce:
  
+    * It requires a combination of VLAN networks including external
+      non-OpenStack gateways to manifest.
  
- Why is this an issue? These are EOL releases
- --------------------------------------------
- Users upgrading from Yoga LTS to Caracal LTS go through step upgrades.
- This involves upgrades to Antelope and Bobcat which requires node evacuation.
- Lack of this patch causes instance connectivity issues during live migrations.
+    * We are currently attempting to build a lab reproducer
+    
+    * If the above is successful, further testing / validation steps
+      will be provided here.
  
- Instances lose network connectivity and the only way to fix these is to clear 
- the incorrectly learned MAC from OVN FDB or re-create the port.
+  * In an affected cloud, after installing the updated packages,
+    previously breaking live migration attempts should succeed.
+    The package updates only need to be installed on the compute nodes
+    as long as external_ids:ovn-match-northd-version=false
  
- None of the above steps are practical when live migrating 10s or 100s of
- VMs.
+ [ Where problems could occur ]
  
- (1) https://github.com/ovn-
- org/ovn/commit/3c6791e43714b22335acbce0648be59ad4671d2b
+  * Updating the OVN packages does restart these services.
+ 
+  * Make sure to set external_ids:ovn-match-northd-version=false
+    using sudo ovs-vsctl set open_vswitch command or else data
+    plane traffic will be affected.
+ 
+  * The above needs to be applied on all compute nodes or via
+    juju config on juju deployed clouds (2)
+ 
+  * Otherwise this is a known patch already applied to Caracal
+    and does address the mentioned issue (1).
+ 
+ [ Mode Details about the patch ]
+ 
+  physical: Prevent wrong FDB to be learned with multichassis port.
+  If multichassis VIF is set with "unknown" address it might store
+  wrong MAC address into the FDB table. The ICMP Need frag is generated
+  by swapping the MAC src and dst of the original packet, however the
+  inport remains the same. As a consequence the match on the inport to
+  learn FDB will store source MAC address which is the original
+  destination address, that leads to redirection of traffic the VIF
+  which is wrong.
+ 
+  Swap the inport and outport for the ICMP error to prevent this issue
+  it also makes more sense as the ICMP is supposed to be generated by
+  entity along the way and not by the original VIF.
+ 
+  Note that those flows is still needed as userspace datapath is not
+  capable of PMTUD yet.
+ 
+ (1) 
https://github.com/ovn-org/ovn/commit/3c6791e43714b22335acbce0648be59ad4671d2b
+ (2) https://charmhub.io/ovn-chassis/configurations#enable-version-pinning

** Summary changed:

- OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620 fix
+ [SRU] OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620 fix

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168890

Title:
  [SRU] OpenStack Antelope and Bobcat UCA OVN packages missing FDP-620
  fix

To manage notifications about this bug go to:
https://bugs.launchpad.net/cloud-archive/+bug/2168890/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to