mirror of
https://hubproxy.babadafafafafa.cn/https://github.com/kube-vip/kube-vip.git
synced 2026-09-20 08:03:47 +08:00
fix(kubevip): reject out-of-range routing protocol values
Netlink carries the address and route protocol in a single byte, so a configured value above 255 was silently truncated on the wire and never matched again on readback. Reject it during config validation instead. Signed-off-by: Marcel Fest <marcel.fest@telekom.de>
This commit is contained in:
@@ -2,6 +2,7 @@ package kubevip
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"math"
|
||||||
"net/url"
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
@@ -24,10 +25,23 @@ func (c *Config) Validate() error {
|
|||||||
if err := validateInstanceName(c.InstanceName); err != nil {
|
if err := validateInstanceName(c.InstanceName); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
if err := validateRoutingProtocol(c.RoutingProtocol); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// validateRoutingProtocol rejects values the kernel cannot represent: netlink
|
||||||
|
// carries the address and route protocol in a single byte, so a larger value is
|
||||||
|
// silently truncated on the wire and never matches on readback.
|
||||||
|
func validateRoutingProtocol(protocol int) error {
|
||||||
|
if protocol < 0 || protocol > math.MaxUint8 {
|
||||||
|
return fmt.Errorf("routingProtocol %d is out of range, must be between 0 and %d", protocol, math.MaxUint8)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
func validateInstanceName(name string) error {
|
func validateInstanceName(name string) error {
|
||||||
if name == "" {
|
if name == "" {
|
||||||
return nil
|
return nil
|
||||||
|
|||||||
@@ -62,6 +62,30 @@ func TestValidate_InstanceName(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestValidate_RoutingProtocol(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
protocol int
|
||||||
|
wantErr bool
|
||||||
|
}{
|
||||||
|
{name: "unset", protocol: 0, wantErr: false},
|
||||||
|
{name: "kube-vip default", protocol: 248, wantErr: false},
|
||||||
|
{name: "maximum byte value", protocol: 255, wantErr: false},
|
||||||
|
{name: "truncated on the wire", protocol: 256, wantErr: true},
|
||||||
|
{name: "negative", protocol: -1, wantErr: true},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
config := &Config{RoutingProtocol: tt.protocol}
|
||||||
|
err := config.Validate()
|
||||||
|
if (err != nil) != tt.wantErr {
|
||||||
|
t.Fatalf("Validate() error = %v, wantErr %t", err, tt.wantErr)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestInstanceNameLimitReservesNftablesPrefixAndFamilySuffix(t *testing.T) {
|
func TestInstanceNameLimitReservesNftablesPrefixAndFamilySuffix(t *testing.T) {
|
||||||
name := strings.Repeat("a", instanceNameMaxLength)
|
name := strings.Repeat("a", instanceNameMaxLength)
|
||||||
if got := len(egressNftablesTablePrefix + name + egressNftablesTableSuffix); got != nftablesNameMaxLength {
|
if got := len(egressNftablesTablePrefix + name + egressNftablesTableSuffix); got != nftablesNameMaxLength {
|
||||||
|
|||||||
Reference in New Issue
Block a user