apache / apache/cloudstack

ControlNetworkGuru does not take into account custom CIDR when assigning System VM link local IP address

Open
#6,715 2 comments 0 reactions 0 assignees View on GitHub
component:kvm component:networking no-issue-activity Severity:Minor status:needs-investigation status:stale
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE
* Bug Report

##### COMPONENT NAME
~~~
Management, Network, SystemVM
~~~

##### CLOUDSTACK VERSION
~~~
4.16.1
~~~

##### CONFIGURATION
In database:
```
MariaDB [cloud]> select name,value from configuration where name = 'control.cidr';
+--------------+------------------+
| name | value |
+--------------+------------------+
| control.cidr | 169.254.240.0/20 |
+--------------+------------------+
MariaDB [cloud]> select name,value from configuration where name = 'control.gateway';
+-----------------+---------------+
| name | value |
+-----------------+---------------+
| control.gateway | 169.254.240.1 |
+-----------------+---------------+
MariaDB [cloud]> select count(*) from op_dc_link_local_ip_address_alloc;
+----------+
| count(*) |
+----------+
| 65533 |
+----------+
```
On agent:
```
root@hv-04-02-21:~# grep control.cidr /etc/cloudstack/agent/agent.properties
control.cidr=169.254.240.0/20
```

##### SUMMARY
When having set a `control.cidr` different from the norm (`168.254.0.0/16`) and the database table `op_dc_link_local_ip_address_alloc` is already populated with all the addresses in the default CIDR, then allocating an IP to a System VM does not take into account the requested CIDR, thus allocating an IP address in the wrong range.

https://github.com/apache/cloudstack/blob/main/engine/schema/src/main/java/com/cloud/dc/dao/DataCenterLinkLocalIpAddressDaoImpl.java#L52 should take this into account. This function is called in https://github.com/apache/cloudstack/blob/main/server/src/main/java/com/cloud/network/guru/ControlNetworkGuru.java#L134

##### STEPS TO REPRODUCE
- Install new management server
- After kickstart, disable the zone to prevent any system vm deploys
- In mysql database: `select count(*) from op_dc_link_local_ip_address_alloc;`, it would return `65533`
- Connect agents
- Configure `control.cidr` on the manager and agents, and `control.gateway` on the manager, ie:
```
control.cidr=169.254.240.0/20
control.gateway=169.254.240.1
```
- Enable the zone, check the system vm link local address

##### EXPECTED RESULTS
- The System VMs should receive an IP address in the configured CIDR.
- Additional expected: In mysql database: `select count(*) from op_dc_link_local_ip_address_alloc;`, it should return `4093`

##### ACTUAL RESULTS
- System VMs receive an IP address in the default `169.254.0.0/16` range
```
2022-09-07 22:45:35,338 DEBUG [o.a.c.e.o.NetworkOrchestrator] (Work-Job-Executor-3:ctx-b1c76634 job-149/job-150 ctx-224681ec) (logid:32608415) Network id=201 is already implemented
2022-09-07 22:45:35,524 DEBUG [c.c.n.g.ControlNetworkGuru] (Work-Job-Executor-3:ctx-b1c76634 job-149/job-150 ctx-224681ec) (logid:32608415) Reserved NIC for v-18-VM [ipv4:169.254.167.69 netmask:255.255.240.0 gateway:169.254.240.1]
```

Contributor guide

Open the contributing guide

Research direction

Start with engine/schema/src/main/java/com/cloud/dc/dao/DataCenterLinkLocalIpAddressDaoImpl.java around line 52, then follow its call from server/src/main/java/com/cloud/network/guru/ControlNetworkGuru.java around line 134. Reproduce the configured control.cidr scenario and verify that System VM addresses and op_dc_link_local_ip_address_alloc counts use the configured CIDR rather than the default range.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, mariadb
Domain
networking
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.