<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 19:12:30 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[BGPCEP-259] Noncompliant and insecure handling of internal errors</title>
                <link>https://jira.opendaylight.org/browse/BGPCEP-259</link>
                <project id="10108" key="BGPCEP">bgpcep</project>
                    <description>&lt;p&gt;If some resource gets exhausted (such as execution queue capacity as seen in &lt;a href=&quot;https://jira.opendaylight.org/browse/CONTROLLER-957&quot; title=&quot;Executor pipeline gets full in scale testing of BGP and PCEP&quot; class=&quot;issue-link&quot; data-issue-key=&quot;CONTROLLER-957&quot;&gt;&lt;del&gt;CONTROLLER-957&lt;/del&gt;&lt;/a&gt; or &lt;a href=&quot;https://jira.opendaylight.org/browse/BGPCEP-258&quot; title=&quot;BGP Scale tests with  &amp;gt;= 10k prefixes fail following Transaction chain failure&quot; class=&quot;issue-link&quot; data-issue-key=&quot;BGPCEP-258&quot;&gt;&lt;del&gt;BGPCEP-258&lt;/del&gt;&lt;/a&gt;), the speaker shall (after reporting the condition in the logs) send NOTIFICATION with Code=6 (CEASE) and SubCode=8 (Out Of Resources) and close the connection. The current implementation performs &quot;log spamming&quot; instead, leading to multi-gigabyte logs.&lt;/p&gt;

&lt;p&gt;If some other problem occurs which prevents the connection from working properly, the speaker shall &quot;administratively shutdown the connection&quot; after reporting the problem in the logs. This is done by sending NOTIFICATION with Code=6 (CEASE) and SubCode=2 (Administrative Shutdown), closing the connection and cleaning the mess left behind. A clearer message would be NOTIFICATION with some error code that says &quot;Internal Router Error&quot; but I could not see such error code in the BGP RFCs I was reading so far so I consider the &quot;Administrative Shutdown&quot; to be the best alternative.&lt;/p&gt;

&lt;p&gt;Producing multi-gigabyte logs can easily lead to resource exhaustion, allowing an attacker to crash the connection and then continue pushing more and more updates until the disk holding the log space gets full, rendering the application completely inoperable.&lt;/p&gt;

&lt;p&gt;See RFC4271 and RFC4486&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="23499">BGPCEP-259</key>
            <summary>Noncompliant and insecure handling of internal errors</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="cdgasparini">Claudio David Gasparini</assignee>
                                    <reporter username="jbehran@cisco.com">Jozef Behran</reporter>
                        <labels>
                    </labels>
                <created>Fri, 24 Jul 2015 08:15:18 +0000</created>
                <updated>Sun, 3 Mar 2019 11:50:29 +0000</updated>
                            <resolved>Tue, 6 Oct 2015 14:31:11 +0000</resolved>
                                    <version>Bugzilla Migration</version>
                                    <fixVersion>Bugzilla Migration</fixVersion>
                                    <component>BGP</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>4</watches>
                                                                                                                <comments>
                            <comment id="45082" author="cdgasparini" created="Tue, 6 Oct 2015 14:31:11 +0000"  >&lt;p&gt;This is already implemented and the issue has not been replicated since Helium.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>4049</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=4049]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10206" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Issue Type</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10318"><![CDATA[Change Request]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10204" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>ODL SR Target Milestone</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10351"><![CDATA[Beryllium-M5]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                    <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i02b6n:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>