Bug 2111945

Summary: allow extra IP address found in verification stage
Product: Red Hat Enterprise Linux 8 Reporter: Christoph Stäbler <cstabler>
Component: nmstateAssignee: Gris Ge <fge>
Status: CLOSED ERRATA QA Contact: Mingyu Shi <mshi>
Severity: unspecified Docs Contact:
Priority: high    
Version: 8.6CC: bnemec, cstabler, ellorent, ferferna, fge, jiji, jishi, network-qe, sfaye, till
Target Milestone: rcKeywords: Triaged, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of:
: 2128555 2128556 2130083 (view as bug list) Environment:
Last Closed: 2023-05-16 08:26:38 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2128555, 2128556    

Comment 6 Gris Ge 2022-09-13 09:36:25 UTC
To solve this problem, we agree to introduce support of `type: ignore` for ip address like:


```yaml
---
interfaces:
  - name: eth1
    type: ethernet
    state: up
    ipv4:
      address:
      - ip: 192.0.2.251
        prefix-length: 24
      - ip: 192.168.111.4
        prefix-length: 24
        ignore: true
      dhcp: false
      enabled: true
```

With this, nmstate will ignore the existence(or not) of 192.168.111.4 IP address.

Let me do a demo to confirm this actually solve the problem.

Comment 7 Gris Ge 2022-09-13 14:53:40 UTC
Considering the VIP might change or expand in the future, asking user to set it ignore explicitly add extra maintenance efforts.

Change the approach to use `allow-extra-address: true` for ignoring extra IP address found after apply in verification stage. By default, nmstate will not allow extra IP address in verification stage.

I have created test rpm with `allow-extra-address` set to `true` by default so no changes required for kubernetes-nmstate required:

https://people.redhat.com/fge/bz_2111945/

Comment 12 Gris Ge 2022-09-20 13:46:56 UTC
Patch sent to upstream: https://github.com/nmstate/nmstate/pull/2038

With this patch, nmstate will not fail the verification when found extra ip adress than desired.
To force strict IP address verification, please use `allow-extra-address: false`.

RHEL 8.6 backport patch been tested.

Comment 18 Mingyu Shi 2022-10-24 10:16:08 UTC
Verified with:
nmstate-1.4.0-0.alpha.20221017.el8.x86_64
nispor-1.2.7-1.el8.x86_64
NetworkManager-1.40.2-1.el8.x86_64

Comment 20 errata-xmlrpc 2023-05-16 08:26:38 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (nmstate bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:2772