Skip to content

[intfmgr]: Validate interface table keys - #4845

Open
ashutosh-agrawal wants to merge 3 commits into
sonic-net:masterfrom
ashutosh-agrawal:fix/intfmgr-interface-key-validation
Open

ashutosh-agrawal wants to merge 3 commits into
sonic-net:masterfrom
ashutosh-agrawal:fix/intfmgr-interface-key-validation

Conversation

@ashutosh-agrawal

@ashutosh-agrawal ashutosh-agrawal commented Aug 26, 2026 •

Copy link
Copy Markdown
Member

Description of PR

Summary:

Validate interface names at the point where intfmgrd consumes general and address table keys. The check uses swss::isInterfaceNameValid() from sonic-swss-common, so this consumer follows the same interface-name rules as the other SWSS components using the shared helper.

Issue: no GitHub issue is linked.

Type of change

  • Bug fix
  • New feature
  • Refactor / cleanup
  • Documentation update
  • Test improvement

Approach

What is the motivation for this PR?

intfmgrd processes keys read from Redis at runtime. That path should validate the identifier it is about to use instead of assuming every writer has already applied schema validation. Keeping the syntax rule in sonic-swss-common avoids each daemon growing a slightly different interface-name check.

How did you do it?

Validate interface names at the point where intfmgrd consumes general and address table keys. The check uses swss::isInterfaceNameValid() from sonic-swss-common, so this consumer follows the same interface-name rules as the other SWSS components using the shared helper.

This also tightens two related parsing paths:

  • reject an invalid address prefix without applying the entry;
  • match IPv6 neighbor keys by the complete interface identifier, so a key for Ethernet00 is not treated as a key for Ethernet0.

Interface and address values used in shell commands are quoted after validation/parsing. Valid interface names and prefixes continue through the existing processing path unchanged.

Depends on the shared validator added by sonic-swss-common #1240, which is merged. This PR contains only the intfmgrd consumer changes.

How did you verify/test it?

  • Built tests_intfmgrd in the Bookworm environment.
  • All 13 tests passed.
  • Added coverage for an invalid interface key, an invalid prefix, exact neighbor-interface matching, and a malformed neighbor address.

Any platform specific information?

No platform-specific behavior is described in this change.

Documentation

No documentation change is described for this fix.

@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

Temporarily paused until the shared interface-name helper is available on master.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@ashutosh-agrawal
ashutosh-agrawal force-pushed the fix/intfmgr-interface-key-validation branch from ebb1b8b to 48537af Compare August 27, 2026 19:35
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Reject malformed identifiers before processing interface entries and construct command operands safely.

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
@ashutosh-agrawal
ashutosh-agrawal force-pushed the fix/intfmgr-interface-key-validation branch from 48537af to 42b5d7c Compare September 16, 2026 19:18
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@ashutosh-agrawal
ashutosh-agrawal marked this pull request as ready for review September 16, 2026 19:22
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Comment thread cfgmgr/intfmgr.cpp
Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) stages in build 1226782:

✅Stage Test:

  • Job vstest: retried.

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) stages in build 1226782:

✅Stage Test:

  • Job vstest: retried.

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) stages in build 1226782:

✅Stage Test:

  • Job vstest: retried.

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) stages in build 1226782:

✅Stage Test:

  • Job vstest: retried.

@ashutosh-agrawal

Copy link
Copy Markdown
Member Author

/azpw retry

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) jobs...

@mssonicbld

Copy link
Copy Markdown
Collaborator

Retrying failed(or canceled) stages in build 1226782:

✅Stage Test:

  • Job vstest: retried.

Signed-off-by: Ashutosh Agrawal <ashu@cisco.com>
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants