Skip to content

ospf6d: reject backbone Stub area configuration - #23646

Open
dingqipeng wants to merge 1 commit into
FRRouting:masterfrom
dingqipeng:fix/ospf6-backbone-stub-23628
Open

dingqipeng wants to merge 1 commit into
FRRouting:masterfrom
dingqipeng:fix/ospf6-backbone-stub-23628

Conversation

@dingqipeng

Copy link
Copy Markdown

Fixes #23628

area 0 stub currently changes the backbone's Hello Options E bit and
breaks adjacency with a normally configured backbone peer. RFC 5340
Appendix C.2 forbids configuring the backbone as a Stub area.

Share area parsing and configuration between the plain Stub and
no-summary handlers, and reject Area 0 before area lookup/creation or
any Stub/summary update. Keep non-backbone configuration and the existing
virtual-link diagnostic unchanged.

The new ospf6_backbone_stub topotest checks dotted and decimal Area 0
IDs, with and without no-summary, on both a live ABR and an isolated
router with no areas. Refusal must preserve running configuration, normal
area state, the empty area list, Full neighbors, neighbor state-change
origins, the backbone control prefix and daemon PIDs. Both legal Area 1
Stub forms must still form Full neighbors and undo normally.

Validation against source-built x86-64 baseline
c4e94c4aaa4f4562313b4a168f91211afc3bcba2 and the patched binary:

  • The proposed topotest fails on baseline at the missing-refusal
    assertion and passes on patched. Neither run has an error or skip.
  • A separate three-router native program reproduces the original
    dotted/plain command on baseline, and passes all four command variants
    on patched. It uses ordinary configuration and passive captures.
  • Native captures show the backbone Hello E bit remains set after each
    refusal. Neighbor state-change times and daemon PIDs remain unchanged.
    Both legal non-backbone Stub policies restore the original configuration,
    database, Full neighbors and control ping. Owned-resource cleanup passes.
  • Black and git diff --check pass. An independent read-only decoder
    checks OSPFv3 and LSA checksums in all ten native captures.

Standalone reproduction source,
build/validation runner,
and report, raw evidence and manifests.
The reproducer supports --image, --area-id, --no-summary and
--legal-controls; it requires Linux root, Python 3, Docker, iproute2,
tcpdump and ping. It needs no private test suite or Python module.

The raw topotest logs retain environment/teardown warnings, including
forced daemon termination after the framework's wait limit. Owned
containers were removed; this is not a claim of graceful daemon shutdown.
The build cache is local; authors can run the reproducer against their
normally built FRR image. This PR covers backbone Stub, not NSSA.

Reject Area 0 before creating an area or changing its Stub options. Share
the guard between plain Stub and no-summary while retaining the existing
non-backbone behavior.

Add native topology regression coverage for dotted and decimal IDs,
unchanged live neighbors and configuration, absent area creation, and
legal Area 1 Stub configuration and removal.

Fixes FRRouting#23628

Signed-off-by: dingqipeng <dingqipeng@hotmail.com>
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Medium impact] Adds validation to prevent backbone area stub configuration.

The PR appears safe to merge, with a non-blocking test timing concern.

Findings

  1. P2 Slow queries fail healthy tests ▶
Fix with agent prompt
### Issue 1
tests/topotests/ospf6_backbone_stub/test_ospf6_backbone_stub.py:78
If a busy CI worker takes one second or more to query neighbors, `_epochs()` fails even when the daemon and neighbors are healthy. The code already records `start` and `end` to account for query time. Remove this fixed limit and keep the interval comparison.

```suggestion

```

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

Rejects backbone Stub configuration before creating or changing an area.

  • OSPFv3 routers refuse Stub settings for Area 0.

Reviews (1) · Last reviewed commit: "ospf6d: reject backbone Stub area config..." · Reviewed by Greptile

.vtysh_cmd("show ipv6 ospf6 neighbor json", isjson=True)["neighbors"]
)
end = time.monotonic()
assert end - start < 1, "Neighbor observation took too long"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Slow queries fail healthy tests

If a busy CI worker takes one second or more to query neighbors, _epochs() fails even when the daemon and neighbors are healthy. The code already records start and end to account for query time. Remove this fixed limit and keep the interval comparison.

Suggested change
assert end - start < 1, "Neighbor observation took too long"
Prompt To Fix With AI
This is a comment left during a code review.
Path: tests/topotests/ospf6_backbone_stub/test_ospf6_backbone_stub.py
Line: 78

Comment:
**Slow queries fail healthy tests**

If a busy CI worker takes one second or more to query neighbors, `_epochs()` fails even when the daemon and neighbors are healthy. The code already records `start` and `end` to account for query time. Remove this fixed limit and keep the interval comparison.

```suggestion

```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ospf6d: reject backbone Area 0 Stub configuration before it changes Hello options

1 participant