-
Notifications
You must be signed in to change notification settings - Fork 520
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[aclorch] Validate that provided IN/OUT_PORTS are physical interfaces #1156
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
- Add a check during the rule validation step to make sure provided IN/OUT_PORTS rules only include physical interfaces - Add vs test cases for invalid IN/OUT_PORTS inputs Signed-off-by: Danny Allen <[email protected]>
qiluo-msft
reviewed
Dec 18, 2019
qiluo-msft
previously approved these changes
Dec 18, 2019
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
with naming suggestion
retest this please |
1 similar comment
retest this please |
yxieca
previously approved these changes
Jan 6, 2020
qiluo-msft
previously approved these changes
Jan 6, 2020
retest this please |
retest this please |
retest this please |
1 similar comment
retest this please |
yxieca
approved these changes
Jan 17, 2020
yxieca
pushed a commit
that referenced
this pull request
Jan 17, 2020
…#1156) * [aclorch] Validate that provided IN/OUT_PORTS are physical interfaces - Add a check during the rule validation step to make sure provided IN/OUT_PORTS rules only include physical interfaces - Add vs test cases for invalid IN/OUT_PORTS inputs Signed-off-by: Danny Allen <[email protected]> * Clarify test names * Add extra delay for table teardown * Check if new tests are causing tests to fail * Check if new tests are causing tests to fail * Check if ProducerStateTable is having problems * Make delete ACL table test more strict * Remove invalid interface test cases * Undo change to delete test * Undo change to delete test
abdosi
pushed a commit
that referenced
this pull request
Jan 21, 2020
…#1156) * [aclorch] Validate that provided IN/OUT_PORTS are physical interfaces - Add a check during the rule validation step to make sure provided IN/OUT_PORTS rules only include physical interfaces - Add vs test cases for invalid IN/OUT_PORTS inputs Signed-off-by: Danny Allen <[email protected]> * Clarify test names * Add extra delay for table teardown * Check if new tests are causing tests to fail * Check if new tests are causing tests to fail * Check if ProducerStateTable is having problems * Make delete ACL table test more strict * Remove invalid interface test cases * Undo change to delete test * Undo change to delete test
lguohan
pushed a commit
that referenced
this pull request
Jan 30, 2020
…#1156) * [aclorch] Validate that provided IN/OUT_PORTS are physical interfaces - Add a check during the rule validation step to make sure provided IN/OUT_PORTS rules only include physical interfaces - Add vs test cases for invalid IN/OUT_PORTS inputs Signed-off-by: Danny Allen <[email protected]> * Clarify test names * Add extra delay for table teardown * Check if new tests are causing tests to fail * Check if new tests are causing tests to fail * Check if ProducerStateTable is having problems * Make delete ACL table test more strict * Remove invalid interface test cases * Undo change to delete test * Undo change to delete test
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: Danny Allen [email protected]
What I did
Added a safety check to the rule validation step in AclOrch so that rules that include the IN_PORTS or OUT_PORTS field can only include physical interfaces.
Why I did it
The SAI only supports physical ports for this particular ACL field, so it'll throw an error if a user tries to pass in a PortChannel, VLAN, or some other interface in one of the PORTS lists. This prevents that from happening.
How I verified it
I added tests to the virtual switch to confirm that invalid rules are being rejected:
Details if related