apache / apache/cloudstack

VMware NSX network implementation can fail before backing DV port group is visible

オープン
#13,752 コメント 2 件 リアクション 0 件 担当者 0 名 @Dogface2k が担当を希望しています GitHub で見る
component:vmware component:vpc Severity:Major type:bug
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### Problem

On VMware environments using the NSX integration, implementing a guest network can fail during `PlugNicCommand` even though `CreateNsxSegmentCommand` has already succeeded.

The NSX segment is created outside vCenter. Its backing distributed virtual port group can therefore take a short time to become visible through the vCenter API. `HypervisorHostHelper.prepareNetwork` currently performs only one immediate lookup for NSX networks and returns failure when that first lookup is empty.

Sanitized management-server sequence:

```text
CreateNsxSegmentCommand ... NsxAnswer result=true
Prepare network on vmwaredvs
Failed to create guest network
PlugNicAnswer result=false
```

The failure rolls back the NIC attachment and prevents the persistent VPC guest network from being implemented.

### Versions

- Apache CloudStack 4.22.1.0
- VMware vSphere / vCenter 8.0.3
- CloudStack NSX integration

### Steps to reproduce

1. Configure a VMware zone with the CloudStack NSX integration.
2. Create an NSX-backed VPC guest network.
3. Allow the NSX segment command to complete while the backing DV port group is not yet visible through vCenter.
4. Observe the immediate DV port group lookup fail in `HypervisorHostHelper.prepareNetwork`, followed by a failed `PlugNicCommand`.

### Expected behavior

After successful NSX segment creation, CloudStack should use its existing bounded DV port group readiness wait before attempting to attach the NIC. If the port group never becomes visible, the existing timeout should still fail the operation cleanly.

### Proposed fix

Enable the existing `waitForDvPortGroupReady` path for NSX broadcast domains and add a regression test covering an empty first vCenter lookup followed by a successful lookup.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

HypervisorHostHelper.prepareNetwork から始め、PlugNicCommand 中に使用される既存の waitForDvPortGroupReady のパスを追跡してください。最初の vCenter 検索結果が空で、その後の検索が成功するケースについて、issue に記載されたリグレッションテストを追加し、決められたタイムアウトで、決して現れない port group も引き続き処理できることを確認してください。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
infrastructure, networking
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
明確に書かれている
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。