<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:21:41 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[NETVIRT-488] Openflow DHCP rules not installed with OVS DPDK on controller node</title>
                <link>https://jira.opendaylight.org/browse/NETVIRT-488</link>
                <project id="10144" key="NETVIRT">netvirt</project>
                    <description>&lt;p&gt;My setup is 2 compute nodes, and 1 control node.  The compute nodes both have dpdk ports, with a patch port from br-int to br-phy, using vxlan as the tenant network type.  The control node has no dpdk port, and is using a regular ethernet interface to egress vxlan traffic.&lt;/p&gt;

&lt;p&gt;The issue is when an instance is created, the flows that should be in table 40 on the controller to allow dhcp are missing.  The flows however are installed on the compute node, and vxlan tunnel is created.  The instance comes up fine with a vhostuser port and tries to dhcp.&lt;/p&gt;

&lt;p&gt;I do not see any errors in the log indicating failure to install flows, so I&apos;m not sure if nevirt ever tried to even install them.&lt;/p&gt;

&lt;p&gt;This is with OVS 2.6 and dpdk 16.11.&lt;/p&gt;

&lt;p&gt;Will attach karaf log and ovs outputs.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="20409">NETVIRT-488</key>
            <summary>Openflow DHCP rules not installed with OVS DPDK on controller node</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Cannot Reproduce</resolution>
                                        <assignee username="-1">Unassigned</assignee>
                                    <reporter username="trozet">Tim Rozet</reporter>
                        <labels>
                    </labels>
                <created>Tue, 21 Feb 2017 14:55:46 +0000</created>
                <updated>Tue, 29 May 2018 14:58:55 +0000</updated>
                            <resolved>Fri, 24 Mar 2017 19:00:26 +0000</resolved>
                                    <version>Boron</version>
                                                    <component>General</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="37269" author="trozet@redhat.com" created="Tue, 21 Feb 2017 15:17:17 +0000"  >&lt;p&gt;Attachment logs_output_repro_steps.zip has been added with description: Contains ovs outputs, karaf log, and steps to reproduce&lt;/p&gt;</comment>
                            <comment id="37256" author="trozet@redhat.com" created="Tue, 21 Feb 2017 15:46:18 +0000"  >&lt;p&gt;It looks like the problem is the tap port from the DHCP NS is down:&lt;/p&gt;

&lt;p&gt;&lt;span class=&quot;error&quot;&gt;&amp;#91;root@overcloud-controller-0 hieradata&amp;#93;&lt;/span&gt;# ovs-ofctl -O openflow13 show br-int&lt;br/&gt;
OFPT_FEATURES_REPLY (OF1.3) (xid=0x2): dpid:0000dc5cf7654e1b&lt;br/&gt;
n_tables:254, n_buffers:256&lt;br/&gt;
capabilities: FLOW_STATS TABLE_STATS PORT_STATS GROUP_STATS QUEUE_STATS&lt;br/&gt;
OFPST_PORT_DESC reply (OF1.3) (xid=0x3):&lt;br/&gt;
 1(br-ex-patch): addr:1e:23:b7:d3:55:c6&lt;br/&gt;
     config:     0&lt;br/&gt;
     state:      0&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;br/&gt;
 2(tapc61135c5-ba): addr:00:00:00:00:70:bb&lt;br/&gt;
     config:     PORT_DOWN&lt;br/&gt;
     state:      LINK_DOWN&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;br/&gt;
 3(tund547d93ae28): addr:8a:80:0d:a0:46:98&lt;br/&gt;
     config:     0&lt;br/&gt;
     state:      0&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;br/&gt;
 LOCAL(br-int): addr:dc:5c:f7:65:4e:1b&lt;br/&gt;
     config:     PORT_DOWN&lt;br/&gt;
     state:      LINK_DOWN&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;br/&gt;
OFPT_GET_CONFIG_REPLY (OF1.3) (xid=0x5): frags=normal miss_send_len=0&lt;/p&gt;

&lt;p&gt;2017-02-21T09:23:16.607Z|00035|bridge|INFO|bridge br-int: added interface tapc61135c5-ba on port 2&lt;br/&gt;
2017-02-21T09:23:16.765Z|00036|netdev_linux|INFO|ioctl(SIOCGIFHWADDR) on tapc61135c5-ba device failed: No such device&lt;br/&gt;
2017-02-21T09:23:16.773Z|00037|netdev_linux|WARN|ioctl(SIOCGIFINDEX) on tapc61135c5-ba device failed: No such device&lt;br/&gt;
2017-02-21T09:23:16.774Z|00038|netdev_linux|WARN|tapc61135c5-ba: removing policing failed: No such device&lt;/p&gt;

&lt;p&gt;I&apos;m not sure why it is trying to add it as a netdev device.&lt;/p&gt;</comment>
                            <comment id="37257" author="trozet@redhat.com" created="Tue, 21 Feb 2017 20:41:42 +0000"  >&lt;p&gt;Looking at the DHCP agent Neutron code and OVS driver there, it does not add any config to put the bridge into netdev mode.  It simply uses vsctl and adds a port to the bridge, which is by default being added as netdev.  Therefore my theory is that ODL is putting the bridge into netdev mode, which it shouldn&apos;t when DPDK is not enabled on that openvswitch instance.  Can an ODL dev confirm that ODL puts the switches into netdev mode?&lt;/p&gt;</comment>
                            <comment id="37258" author="jhershbe" created="Thu, 23 Feb 2017 06:52:37 +0000"  >&lt;p&gt;Table 40 is the INGRESS_ACL_TABLE&lt;/p&gt;</comment>
                            <comment id="37259" author="jhershbe" created="Thu, 23 Feb 2017 08:11:32 +0000"  >&lt;p&gt;I&apos;m not certain it&apos;s related to the dhcp port being down as you indicate below. For e.g., it&apos;s always down in my dev environments and it works just fine:&lt;br/&gt;
 2(tap2278122f-1e): addr:7f:74:00:00:00:00&lt;br/&gt;
     config:     PORT_DOWN&lt;br/&gt;
     state:      LINK_DOWN&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;/p&gt;

&lt;p&gt;I did notice that aside from the patch to br-ex br-int also has the auto-configured tun interfaces. There was a problem with this recently where it interfered with DHCP. Can you try this with a version that has the following two patches merged? &lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://code.engineering.redhat.com/gerrit/#/c/97855/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://code.engineering.redhat.com/gerrit/#/c/97855/&lt;/a&gt;&lt;br/&gt;
&lt;a href=&quot;https://code.engineering.redhat.com/gerrit/#/c/97729&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://code.engineering.redhat.com/gerrit/#/c/97729&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="37260" author="jhershbe" created="Thu, 23 Feb 2017 08:26:22 +0000"  >&lt;p&gt;Also, it does not look like the bridge is in netdev:&lt;/p&gt;

&lt;p&gt;&lt;span class=&quot;error&quot;&gt;&amp;#91;heat-admin@overcloud-controller-0 ~&amp;#93;&lt;/span&gt;$ sudo ovs-vsctl get Bridge d7199e75-edcb-484a-ab77-4695e233100b name                                                                                    &lt;br/&gt;
br-int&lt;br/&gt;
&lt;span class=&quot;error&quot;&gt;&amp;#91;heat-admin@overcloud-controller-0 ~&amp;#93;&lt;/span&gt;$ sudo ovs-vsctl get Bridge d7199e75-edcb-484a-ab77-4695e233100b datapath_type                                                                           &lt;br/&gt;
&quot;&quot;&lt;/p&gt;

&lt;p&gt;Which is weird. Plus:&lt;br/&gt;
&lt;span class=&quot;error&quot;&gt;&amp;#91;heat-admin@overcloud-controller-0 ~&amp;#93;&lt;/span&gt;$ sudo ovs-appctl dpctl/dump-dps&lt;br/&gt;
system@ovs-system&lt;/p&gt;

&lt;p&gt;Whereas on the compute you&apos;d get:&lt;br/&gt;
&lt;span class=&quot;error&quot;&gt;&amp;#91;heat-admin@overcloud-novacompute-1 ~&amp;#93;&lt;/span&gt;$ sudo ovs-appctl dpctl/dump-dps&lt;br/&gt;
netdev@ovs-netdev&lt;br/&gt;
system@ovs-system&lt;/p&gt;

&lt;p&gt;So it really looks like netdev is not active on the controller&lt;/p&gt;</comment>
                            <comment id="37261" author="trozet@redhat.com" created="Thu, 23 Feb 2017 14:35:39 +0000"  >&lt;p&gt;OK I saw netdev logging msgs and assumed it was in netdev, but you&apos;re right it is not.  So I manually tried to create a tap port and attach to the namespace and it attaches but link state will not come up in OVS.  I think the issue is the 2.6 OVS I have is using the wrong kmod, let me figure that out and then will report back here.&lt;/p&gt;</comment>
                            <comment id="37262" author="trozet@redhat.com" created="Sat, 25 Feb 2017 14:49:08 +0000"  >&lt;p&gt;Nevermind, it looks like even on other setups that work the port state is always down in OVS:&lt;/p&gt;

&lt;p&gt;13(tap738a631a-f4): addr:00:00:00:00:f0:02&lt;br/&gt;
     config:     PORT_DOWN&lt;br/&gt;
     state:      LINK_DOWN&lt;br/&gt;
     speed: 0 Mbps now, 0 Mbps max&lt;/p&gt;

&lt;p&gt;and DHCP works in that setup.  Must be something broken with the flows.&lt;/p&gt;</comment>
                            <comment id="37263" author="shashidhar.raja@ericsson.com" created="Thu, 2 Mar 2017 10:46:45 +0000"  >&lt;p&gt;It looks like neutron port on controller node is created with port_security_enabled=false.&lt;/p&gt;

&lt;p&gt;To debug further, please provide below details:&lt;/p&gt;

&lt;p&gt;From openstack:&lt;/p&gt;

&lt;p&gt;a.	Neutron ports detail&lt;br/&gt;
b.	neutron security-group-list&lt;br/&gt;
c.	neutron security-rule-list&lt;br/&gt;
d.	neutron security-group-show  default&lt;/p&gt;

&lt;p&gt;From ODL(Rest call outputs):&lt;/p&gt;

&lt;p&gt;a.	http://&amp;lt;controller_ip&amp;gt;:8181/restconf/config/neutron:neutron/security-groups/&lt;br/&gt;
b.	http://&amp;lt;controller_ip&amp;gt;:8181/restconf/config/neutron:neutron/security-rules/&lt;br/&gt;
c.	http://&amp;lt;controller_ip&amp;gt;:8181/restconf/config/neutron:neutron/ports/&lt;br/&gt;
d.	http://&lt;tt&gt;controllerHost&lt;/tt&gt;:8181/restconf/config/ietf-interfaces:interfaces/&lt;br/&gt;
e.	http://&lt;tt&gt;controllerHost&lt;/tt&gt;:8181/restconf/operational/ietf-interfaces:interfaces-state/&lt;/p&gt;</comment>
                            <comment id="37264" author="trozet@redhat.com" created="Thu, 2 Mar 2017 16:49:26 +0000"  >&lt;p&gt;(In reply to Shashidhar R from comment #9)&lt;br/&gt;
Attached the requested info as port_security_info.txt.&lt;/p&gt;

&lt;p&gt;From what I can see the port security in neutron is set to false for a dhcp port, but is set to true for the nova instance. This looks normal when comparing it to another setup.&lt;/p&gt;

&lt;p&gt;However, in Neutron northbound the port security is set to true for some reason:&lt;br/&gt;
neutron-binding:vif-type&quot;:&quot;ovs&quot;,&quot;device-id&quot;:&quot;dhcp827da361-9c56-50f7-913f-5a01f7bfed2c-b6a4a0c3-2ec0-45da-954b-05ae44d6c782&quot;,&quot;tenant-id&quot;:&quot;91a9b66d-c9cf-46a4-ae15-34abff12e786&quot;,&quot;mac-address&quot;:&quot;fa:16:3e:60:b7:e9&quot;,&quot;neutron-portsecurity:port-security-enabled&quot;:true}&lt;/p&gt;

&lt;p&gt;Also, I see in the oper:&lt;br/&gt;
&quot;tapc61135c5-ba&quot;,&quot;odl-interface:l2vlan-mode&quot;:&quot;trunk&quot;,&quot;type&quot;:&quot;iana-if-type:l2vlan&quot;,&quot;enabled&quot;:true}]&lt;/p&gt;

&lt;p&gt;Is it supposed to be a type l2vlan in trunk mode?&lt;/p&gt;

&lt;p&gt;Note, this setup has been up for some time now, and I think I restarted ODL a few times.  It should resync with neutron, but just a caveat the setup may not be 100% in the same original state anymore.&lt;/p&gt;</comment>
                            <comment id="37270" author="trozet@redhat.com" created="Thu, 2 Mar 2017 16:50:38 +0000"  >&lt;p&gt;Attachment port_security_info.txt has been added with description: Requested outputs for security groups&lt;/p&gt;</comment>
                            <comment id="37265" author="shashidhar.raja@ericsson.com" created="Mon, 6 Mar 2017 13:32:20 +0000"  >&lt;p&gt;Neutron north bound issue related to port_security_enabled=false issue is resolved  by &lt;a href=&quot;https://git.opendaylight.org/gerrit/#/c/52267/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/#/c/52267/&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Also, I observed that of port connected to VM is down in control node. Is this being done intentionally to verify some usecase? If not, can you verify this again by making this port UP? &lt;/p&gt;

&lt;p&gt;Along with above fix, few other fixes are in netvirt and genius projects. Please verify this usecase again with latest build.&lt;/p&gt;</comment>
                            <comment id="37266" author="trozet@redhat.com" created="Mon, 6 Mar 2017 18:58:28 +0000"  >&lt;p&gt;(In reply to Shashidhar R from comment #12)&lt;br/&gt;
&amp;gt; Neutron north bound issue related to port_security_enabled=false issue is&lt;br/&gt;
&amp;gt; resolved  by &lt;a href=&quot;https://git.opendaylight.org/gerrit/#/c/52267/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/#/c/52267/&lt;/a&gt;.&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; Also, I observed that of port connected to VM is down in control node. Is&lt;br/&gt;
&amp;gt; this being done intentionally to verify some usecase? If not, can you verify&lt;br/&gt;
&amp;gt; this again by making this port UP? &lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; Along with above fix, few other fixes are in netvirt and genius projects.&lt;br/&gt;
&amp;gt; Please verify this usecase again with latest build.&lt;/p&gt;

&lt;p&gt;Which port are you referring to?  There is no VM on the control node, only namespaces.  I will retry with newer build.&lt;/p&gt;</comment>
                            <comment id="37267" author="shashidhar.raja@ericsson.com" created="Tue, 14 Mar 2017 12:45:54 +0000"  >&lt;p&gt;I was referring to below o/p from &quot;ovs-ofctl -O openflow13 show br-int&quot; command on CONTROL NODE&lt;/p&gt;

&lt;p&gt;2(tapc61135c5-ba): addr:00:00:00:00:70:bb&lt;br/&gt;
     config:     PORT_DOWN&lt;br/&gt;
     state:      LINK_DOWN&lt;/p&gt;

&lt;p&gt;But, this should not have any problems configuring flows in table 40 as it&apos;s been discussed here.&lt;/p&gt;

&lt;p&gt;Is this issue still been observed in the latest build?&lt;/p&gt;</comment>
                            <comment id="37268" author="trozet@redhat.com" created="Fri, 24 Mar 2017 19:00:26 +0000"  >&lt;p&gt;This was not a bug and was a problem with iptables blocking the dhcp request to the controller. After fixing that everything works fine.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                            <attachment id="12448" name="logs_output_repro_steps.zip" size="64759" author="trozet" created="Tue, 21 Feb 2017 15:17:17 +0000"/>
                            <attachment id="12449" name="port_security_info.txt" size="40547" author="trozet" created="Thu, 2 Mar 2017 16:50:38 +0000"/>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>7835</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=7835]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i01s3z:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>