Conversation
Network Operating System (NOS) containers create many internal interfaces inside their network namespace that are not part
of KNE's topology spec.links:
• Juniper EVO (ncptx): Creates internal PFE interfaces (eth1–eth4), internal VRFs (vrf0, iri, vrf36738), and internal
bridges (vfb, vcb, vmb0, vmb1, vib). Deleting vrf0 causes /usr/sbin/switchvrf $$ vrf0 in mgd.service to fail with No such
vrf (vrf0), crashing mgd and pkid.
• SR Linux (srl): Creates internal interfaces (mgmt0, mgmt0-0, monit_in, gway-2800).
• Arista cEOS (ceos): Creates lo0, cpu, fabric*, po1–po3, fwd0, etc.
Because meshnetd only manages KNE interconnect wires (gRPC wires, host veths, and VXLAN tunnels), it should never delete
arbitrary interfaces inside the container netns. If an inter-node/same-node link transition occurs for an interface
specified in spec.links, transition checks in controller.go:276-305 already handle deleting non-matching interface types
specifically for that configured interface name.
1. Removed intrusive container netns deletion:
• In controller.go:154-203: Removed the container netlink.LinkList / netlink.LinkDel scan from cleanupRemovedPodLinks.
cleanupRemovedPodLinks now solely cleans up removed gRPC wire instances for links deleted from spec.links.
2. Added regression test:
• In controller_test.go:467-491: Added TestCleanupRemovedPodLinks_DoesNotDeleteContainerInterfaces to ensure
cleanupRemovedPodLinks never deletes or attempts to delete internal container interfaces not listed in spec.links.
TAG=agy
CONV=01f6f4c5-7201-412d-be9a-c1e5ac67bf9f
This is required as a practical matter so this fix to meshnet can pass presubmit tests - since before this change the presubmit runs against the *old* meshnet not the fixed one, and thus can never pass. Better still, this closes a huge gap in our testing of meshnet - it means future meshnet changes will be evaluated against vendor images presubmit.
bstoll
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Network Operating System (NOS) containers create many internal interfaces inside their network namespace that are not part of KNE's topology spec.links:
• Juniper EVO (ncptx): Creates internal PFE interfaces (eth1–eth4), internal VRFs (vrf0, iri, vrf36738), and internal bridges (vfb, vcb, vmb0, vmb1, vib). Deleting vrf0 causes /usr/sbin/switchvrf $$ vrf0 in mgd.service to fail with No such vrf (vrf0), crashing mgd and pkid.
• SR Linux (srl): Creates internal interfaces (mgmt0, mgmt0-0, monit_in, gway-2800). • Arista cEOS (ceos): Creates lo0, cpu, fabric*, po1–po3, fwd0, etc.
Because meshnetd only manages KNE interconnect wires (gRPC wires, host veths, and VXLAN tunnels), it should never delete arbitrary interfaces inside the container netns. If an inter-node/same-node link transition occurs for an interface specified in spec.links, transition checks in controller.go:276-305 already handle deleting non-matching interface types specifically for that configured interface name.
TAG=agy
CONV=01f6f4c5-7201-412d-be9a-c1e5ac67bf9f