Skip to content

ospf6d: restore Router-LSA capabilities and ASBR state on NSSA removal - #23647

Open
dingqipeng wants to merge 1 commit into
FRRouting:masterfrom
dingqipeng:fix/ospf6-nssa-removal-23636
Open

dingqipeng wants to merge 1 commit into
FRRouting:masterfrom
dingqipeng:fix/ospf6-nssa-removal-23636

Conversation

@dingqipeng

Copy link
Copy Markdown

Fixes #23636

After removing the last NSSA, an internal router can keep advertising
NSSA Router-LSA Options, while the former NSSA ABR keeps advertising ASBR
status despite having no configured redistribution. A cost change updates
the Options but does not repair the stale ASBR flag.

Schedule Router-LSA origination on both NSSA entry and exit. On exit,
remember the translator state before clearing it and release only that
translator's existing contribution to redist_count. Other NSSAs and real
redistribution continue to hold ASBR status. Balance the NSSA count on exit
even when the area is administratively disabled, matching unconditional
entry accounting.

The new four-router ospf6_nssa_remove topotest covers repeated cycles
with both summary policies, removal of one of two NSSAs, retained static
redistribution and clean removal of an unused NSSA. It checks Router-LSA
Options and ASBR flags, Full neighbors, unchanged daemon PIDs, restored
configuration, installed external routes and actual forwarding recovery.

Validation on x86-64 source-built baseline
c4e94c4aaa4f4562313b4a168f91211afc3bcba2 and patched images:

  • The final proposed topotest fails on baseline with the expected stale
    Options/ASBR observations and passes the complete matrix on patched.
    Neither final run has an error or skip; owned containers are removed.
  • A separate three-router program reproduces the normal-summary condition
    on baseline. After >=110 seconds of native recovery observation and a
    cost reorigination control, the ASBR flag remains stale. Patched normal
    and no-summary conditions restore the original configuration, database,
    Full neighbors, control routes and reachability without that workaround.
    Process continuity and cleanup pass in all three trials.
  • Independent passive decoding verifies Router-LSA E/N capabilities and
    the separate ASBR E flag against native CLI observations. All 1,808 OSPFv3
    packets and 187 LSA checksums in six captures pass independent checks.
  • Wireshark/TShark reverse-decodes all six native captures without a
    malformed-packet indication. Black and git diff --check pass.
    Raw logs retain two earlier topotest
    assertion/CLI mistakes, their corrections and framework teardown warnings;
    neither earlier failure is reported as a new FRR bug.

Independent standalone program,
exact build/test scripts and raw evidence.
The program takes --image, --output and optional --case 4 / --case 5,
honors DOCKER_HOST, and requires Linux root, Python 3, Docker, iproute2,
tcpdump and ping. It needs no private TestSuite or Python module. The local
build cache is not publicly pullable; a normally built FRR image can be used.

No separate architecture, administrative-shutdown or multi-ABR translator
election regression is claimed. Private counters are source-reviewed;
operational consequences are verified through native LSAs and routes.

Reoriginate the Router-LSA when NSSA capabilities change in either
direction. Preserve the translator's prior state long enough to balance
its ASBR contribution on exit, without clearing other NSSAs or real
redistribution. Balance NSSA exit accounting for disabled areas as well.

Add native topology regressions for repeated summary-policy cycles,
multiple NSSAs, retained static redistribution and unused area removal.

Fixes FRRouting#23636

Signed-off-by: dingqipeng <dingqipeng@hotmail.com>
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Medium impact] Fixes OSPF6 NSSA area state transitions and adds test coverage.

The PR appears safe to merge, with a non-blocking improvement to the external-route test.

Findings

  1. P2 Route loss can go unnoticed ▶
Fix with agent prompt
### Issue 1
tests/topotests/ospf6_nssa_remove/test_ospf6_nssa_remove.py:179-183
The static redistribution case checks `EXTERNAL` only after NSSA removal. It can pass even if the route was missing while NSSA was enabled and appeared only after removal. Move `external_present` above the transitions and wait for the installed route before entry, while NSSA is enabled, and after removal.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

Updates ospf6_area_nssa_update to restore Router-LSA capabilities when an area leaves NSSA.

  • Routers refresh their NSSA capabilities and ASBR state when an area changes.

Acknowledged scope: dingqipeng explicitly excludes separate administrative-shutdown and multi-ABR translator-election regression claims.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Area leaves NSSA] --> B[Restore normal Router-LSA Options]
    B --> C[Decrease NSSA count]
    C --> D{Translator was enabled?}
    D -->|Yes| E[Release its redistribution count]
    E --> F[Update ASBR status from remaining count]
    D -->|No| G[Schedule Router-LSA refresh]
    F --> G
    G --> H[Flush NSSA advertisements and refresh external LSAs]
Loading

Reviews (1) · Last reviewed commit: "ospf6d: restore Router-LSA capabilities ..." · Reviewed by Greptile

Comment on lines +179 to +183
wait_state(set(), True)
area_config(1, True)
wait_state({"0.0.0.1"}, True)
area_config(1, False)
wait_state(set(), True)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Route loss can go unnoticed

The static redistribution case checks EXTERNAL only after NSSA removal. It can pass even if the route was missing while NSSA was enabled and appeared only after removal. Move external_present above the transitions and wait for the installed route before entry, while NSSA is enabled, and after removal.

Knowledge Base Used: Routing integration testing

Prompt To Fix With AI
This is a comment left during a code review.
Path: tests/topotests/ospf6_nssa_remove/test_ospf6_nssa_remove.py
Line: 179-183

Comment:
**Route loss can go unnoticed**

The static redistribution case checks `EXTERNAL` only after NSSA removal. It can pass even if the route was missing while NSSA was enabled and appeared only after removal. Move `external_present` above the transitions and wait for the installed route before entry, while NSSA is enabled, and after removal.

**Knowledge Base Used:** [Routing integration testing](https://app.greptile.com/frrouting/-/custom-context/knowledge-base/frrouting/frr/-/docs/routing-integration-testing.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ospf6d: removing NSSA leaves stale Router-LSA Options and ASBR status

1 participant