diff options
| author | Christian Breunig <christian@breunig.cc> | 2026-08-11 20:32:52 +0200 |
|---|---|---|
| committer | Christian Breunig <christian@breunig.cc> | 2026-08-17 18:54:14 +0200 |
| commit | a57dd68ed40ec77ba0a0fc5a2c641fe344fc0570 (patch) | |
| tree | ac9da9361ca08caabe98203b7959bb07385abad1 /interface-definitions/include/constraint/interface-name.xml.i | |
| parent | 43b78a835a9672a23524bcec12d86bc420c6df79 (diff) | |
| download | vyos-1x-a57dd68ed40ec77ba0a0fc5a2c641fe344fc0570.tar.gz vyos-1x-a57dd68ed40ec77ba0a0fc5a2c641fe344fc0570.zip | |
xml: T9179: reject VRF names in interface-name constraint
Tab completion for source-interface and other interface leafNodes already
excludes VRF names, but the shared interface-name constraint accepted them
anyway: an existing VRF is a real net device, so it passed the file-path
existence check even though it failed the interface-name regex.
Replace the file-path validator with a new interface-exists validator that
requires the value to both exist under /sys/class/net and not be a VRF.
The regex-match fallback is unchanged, so dynamic interfaces (e.g. pppoe)
referenced before they exist still validate correctly.
Diffstat (limited to 'interface-definitions/include/constraint/interface-name.xml.i')
| -rw-r--r-- | interface-definitions/include/constraint/interface-name.xml.i | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/interface-definitions/include/constraint/interface-name.xml.i b/interface-definitions/include/constraint/interface-name.xml.i index f64ea86f5..33a6ec404 100644 --- a/interface-definitions/include/constraint/interface-name.xml.i +++ b/interface-definitions/include/constraint/interface-name.xml.i @@ -1,4 +1,4 @@ <!-- include start from constraint/interface-name.xml.i --> <regex>(bond|br|dum|en|ersp|eth|gnv|ifb|ipoe|lan|l2tp|l2tpeth|macsec|peth|ppp|pppoe|pptp|sstp|sstpc|tun|veth|vpptap|vpptun|vti|vtun|vxlan|wg|wlan|wwan)[0-9]+(.\d+)?|pod-[-_a-zA-Z0-9]{1,11}|lo</regex> -<validator name="file-path --lookup-path /sys/class/net --directory"/> +<validator name="interface-exists"/> <!-- include end --> |
