Bug 1459960 - ipfailover keepalived image lacks IP Address validation
ipfailover keepalived image lacks IP Address validation
Status: VERIFIED
Product: OpenShift Container Platform
Classification: Red Hat
Component: Routing (Show other bugs)
3.5.0
Unspecified Unspecified
unspecified Severity medium
: ---
: 3.7.0
Assigned To: Ben Bennett
zhaozhanqi
: NeedsTestCase
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-06-08 12:48 EDT by Ricardo Medina
Modified: 2017-10-05 13:47 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: No validation of IP addresses Consequence: Bad IP addresses could be specified and break the ipfailover container Fix: Validate the addresses Result: Less brittle config
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Origin (Github) 14527 None None None 2017-06-22 13:30 EDT

  None (edit)
Description Ricardo Medina 2017-06-08 12:48:54 EDT
Description of problem:

The current ipfailover keepalived image doesn't support IPv6 addresses or ranges nor IP address validation. For example, adding an IPv6 address to the `oadm ipfailover` command will result in a new vrrp section pertaining to an address that only contains the numeric components of the address (for example, if using 2001:DB8:1ABC::1F39, one would end up with 200181139 as an IP address).

Version-Release number of selected component (if applicable):
v1.5.1

How reproducible:
Always. Just pass any IPv6 address (or an invalid IPv4 address) to the `oadm ipfailover` command

Steps to Reproduce:
1. oadm ipfailover --virtual-ips="192.0.2.100,2001:DB8:1ABC::1F39"
2. PODNAME=$(oc get pods |grep -o "^ipfailover[0-9a-zA-Z-]*") && oc exec ${PODNAME} cat /etc/keepalived/keepalived.conf 
3. Verify that one of the virtual_ipaddress section contains "200181139"

Actual results:

Address 2001:DB8:1ABC::1F39 is represented as 200181139

Expected results:

Address 2001:DB8:1ABC::1F39 is represented as 2001:DB8:1ABC::1F39


Additional info:

I have a working patch for the image, for which I'll create a pull request referencing this bug.
Comment 1 Ricardo Medina 2017-06-09 15:57:51 EDT
Additional information: The github pull request for this BZ is:

https://github.com/openshift/origin/pull/14527

Thanks!
Comment 3 zhaozhanqi 2017-07-05 02:41:55 EDT
Verified this bug on openshift v3.6.131

when input invalid ipv4/ipv6 address when creating ipfailover pod. it will return the error:

# oadm ipfailover ipf1 --virtual-ips=2001:DB8::39FB:2::2
error: Invalid IP address: 2001:DB8::39FB:2::2
[root@host-8-175-105 ~]# oadm ipfailover ipf1 --virtual-ips=192.12.1.1.1
error: Invalid IP address: 192.12.1.1.1

Note You need to log in before you can comment on or make changes to this bug.