Skip to content

Play nice with untracked interfaces. - #776

Open
kraney wants to merge 2 commits into
openconfig:mainfrom
kraney:play-nice
Open

kraney wants to merge 2 commits into
openconfig:mainfrom
kraney:play-nice

Conversation

@kraney

@kraney kraney commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Network Operating System (NOS) containers create many internal interfaces inside their network namespace that are not part of KNE's topology spec.links:

• Juniper EVO (ncptx): Creates internal PFE interfaces (eth1–eth4), internal VRFs (vrf0, iri, vrf36738), and internal bridges (vfb, vcb, vmb0, vmb1, vib). Deleting vrf0 causes /usr/sbin/switchvrf $$ vrf0 in mgd.service to fail with No such vrf (vrf0), crashing mgd and pkid.
• SR Linux (srl): Creates internal interfaces (mgmt0, mgmt0-0, monit_in, gway-2800). • Arista cEOS (ceos): Creates lo0, cpu, fabric*, po1–po3, fwd0, etc.

Because meshnetd only manages KNE interconnect wires (gRPC wires, host veths, and VXLAN tunnels), it should never delete arbitrary interfaces inside the container netns. If an inter-node/same-node link transition occurs for an interface specified in spec.links, transition checks in controller.go:276-305 already handle deleting non-matching interface types specifically for that configured interface name.

  1. Removed intrusive container netns deletion: • In controller.go:154-203: Removed the container netlink.LinkList / netlink.LinkDel scan from cleanupRemovedPodLinks. cleanupRemovedPodLinks now solely cleans up removed gRPC wire instances for links deleted from spec.links.
  2. Added regression test: • In controller_test.go:467-491: Added TestCleanupRemovedPodLinks_DoesNotDeleteContainerInterfaces to ensure cleanupRemovedPodLinks never deletes or attempts to delete internal container interfaces not listed in spec.links.

TAG=agy
CONV=01f6f4c5-7201-412d-be9a-c1e5ac67bf9f

Network Operating System (NOS) containers create many internal interfaces inside their network namespace that are not part
of KNE's topology spec.links:

• Juniper EVO (ncptx): Creates internal PFE interfaces (eth1–eth4), internal VRFs (vrf0, iri, vrf36738), and internal
bridges (vfb, vcb, vmb0, vmb1, vib). Deleting vrf0 causes /usr/sbin/switchvrf $$ vrf0 in mgd.service to fail with No such
vrf (vrf0), crashing mgd and pkid.
• SR Linux (srl): Creates internal interfaces (mgmt0, mgmt0-0, monit_in, gway-2800).
• Arista cEOS (ceos): Creates lo0, cpu, fabric*, po1–po3, fwd0, etc.

Because meshnetd only manages KNE interconnect wires (gRPC wires, host veths, and VXLAN tunnels), it should never delete
arbitrary interfaces inside the container netns. If an inter-node/same-node link transition occurs for an interface
specified in spec.links, transition checks in controller.go:276-305 already handle deleting non-matching interface types
specifically for that configured interface name.

1. Removed intrusive container netns deletion:
    • In controller.go:154-203: Removed the container netlink.LinkList / netlink.LinkDel scan from cleanupRemovedPodLinks.
    cleanupRemovedPodLinks now solely cleans up removed gRPC wire instances for links deleted from spec.links.
2. Added regression test:
    • In controller_test.go:467-491: Added TestCleanupRemovedPodLinks_DoesNotDeleteContainerInterfaces to ensure
    cleanupRemovedPodLinks never deletes or attempts to delete internal container interfaces not listed in spec.links.

TAG=agy
CONV=01f6f4c5-7201-412d-be9a-c1e5ac67bf9f
This is required as a practical matter so this fix to meshnet
can pass presubmit tests - since before this change the presubmit
runs against the *old* meshnet not the fixed one, and thus can
never pass.

Better still, this closes a huge gap in our testing of meshnet - it
means future meshnet changes will be evaluated against vendor images
presubmit.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants