Bug 1834655
| Summary: | payload for icmp6 reply is not as expected when reject acl is added | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux Fast Datapath | Reporter: | Jianlin Shi <jishi> |
| Component: | ovn2.13 | Assignee: | Numan Siddique <nusiddiq> |
| Status: | CLOSED ERRATA | QA Contact: | ying xu <yinxu> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | FDP 20.D | CC: | ctrautma, jishi, nusiddiq, ralongi |
| Target Milestone: | --- | Keywords: | Regression |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-05-26 14:07:18 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Jianlin Shi
2020-05-12 06:53:18 UTC
the reply packet on ovn2.13.0-21: 02:13:15.427723 00:00:00:01:01:02 > 00:00:00:01:02:02, ethertype IPv6 (0x86dd), length 118: (flowlabel 0xa733d, hlim 64, next-header ICMPv6 (58) payload length: 64) 2001::1 > 2001::2: [icmp6 sum ok] ICMP6, echo request, seq 1 02:13:15.428397 00:00:00:01:02:02 > 00:00:00:01:01:02, ethertype IPv6 (0x86dd), length 102: (flowlabel 0xa733d, hlim 255, next-header ICMPv6 (58) payload length: 48) 2001::2 > 2001::1: [icmp6 sum ok] ICMP6, destination unreachable, unreachable prohibited 2001::2 <=== which seems to be ok set regression Verified on ovn2.13.0-30.el8: [root@kvm-04-guest09 bz1834655]# ip netns exec server0 ping6 2001::2 -c 1 PING 2001::2(2001::2) 56 data bytes From 2001::2: icmp_seq=1 Destination unreachable: Administratively prohibited --- 2001::2 ping statistics --- 1 packets transmitted, 0 received, +1 errors, 100% packet loss, time 0ms [root@kvm-04-guest09 ~]# ip netns exec server0 tcpdump -i veth0_s0 -nnle -v tcpdump: listening on veth0_s0, link-type EN10MB (Ethernet), capture size 262144 bytes 22:14:27.973758 00:00:00:01:02:02 > 00:00:00:01:01:02, ethertype IPv6 (0x86dd), length 86: (hlim 255, next-header ICMPv6 (58) payload length: 32) 2001::2 > 2001::1: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is 2001::2, Flags [solicited, override] destination link-address option (2), length 8 (1): 00:00:00:01:02:02 22:14:27.973773 00:00:00:01:01:02 > 00:00:00:01:02:02, ethertype IPv6 (0x86dd), length 118: (flowlabel 0x17322, hlim 64, next-header ICMPv6 (58) payload length: 64) 2001::1 > 2001::2: [icmp6 sum ok] ICMP6, echo request, seq 1 22:14:27.974042 00:00:00:01:02:02 > 00:00:00:01:01:02, ethertype IPv6 (0x86dd), length 166: (flowlabel 0x17322, hlim 255, next-header ICMPv6 (58) payload length: 112) 2001::2 > 2001::1: [icmp6 sum ok] ICMP6, destination unreachable, unreachable prohibited 2001::2 <=== the length is as expected [root@kvm-04-guest09 bz1834655]# rpm -qa | grep -E "openvswitch|ovn" openvswitch-selinux-extra-policy-1.0-23.el8fdp.noarch ovn2.13-2.13.0-30.el8fdp.x86_64 ovn2.13-host-2.13.0-30.el8fdp.x86_64 openvswitch2.13-2.13.0-18.el8fdp.x86_64 ovn2.13-central-2.13.0-30.el8fdp.x86_64 verified on # rpm -qa|grep ovn ovn2.13-central-2.13.0-30.el7fdp.x86_64 ovn2.13-2.13.0-30.el7fdp.x86_64 ovn2.13-host-2.13.0-30.el7fdp.x86_64 03:33:58.603229 00:de:ad:00:01:01 > 00:de:ad:01:00:01, ethertype IPv6 (0x86dd), length 166: (hlim 255, next-header ICMPv6 (58) payload length: 112) 2001:db8:102::22 > 2001:db8:102::11: [icmp6 sum ok] ICMP6, destination unreachable, unreachable prohibited 2001:db8:102::22 03:33:59.602925 00:de:ad:01:00:01 > 00:de:ad:00:01:01, ethertype IPv6 (0x86dd), length 118: (hlim 64, next-header ICMPv6 (58) payload length: 64) 2001:db8:102::11 > 2001:db8:102::22: [icmp6 sum ok] ICMP6, echo request, seq 3 03:33:59.603164 00:de:ad:00:01:01 > 00:de:ad:01:00:01, ethertype IPv6 (0x86dd), length 166: (hlim 255, next-header ICMPv6 (58) payload length: 112) 2001:db8:102::22 > 2001:db8:102::11: [icmp6 sum ok] ICMP6, destination unreachable, unreachable prohibited 2001:db8:102::22 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:2317 |