summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorKyrylo Yatsenko <hedrok@gmail.com>2026-08-18 13:31:16 +0300
committerGitHub <noreply@github.com>2026-08-18 13:31:16 +0300
commitce8f2d49ea929a5935f162ea05d7c436a04444c0 (patch)
treebbb195b1c03ed7e21306191f636c8aea7b2c057b /src
parentde57cd205cfd846eb1689967af0dccc3f764b22c (diff)
parente31c2f6e816a70ae246ab04e07db745a3af31249 (diff)
downloadvyos-1x-ce8f2d49ea929a5935f162ea05d7c436a04444c0.tar.gz
vyos-1x-ce8f2d49ea929a5935f162ea05d7c436a04444c0.zip
Merge pull request #5393 from c-po/interface-no-vrf
xml: T9179: reject VRF names in interface-name constraint
Diffstat (limited to 'src')
-rwxr-xr-xsrc/conf_mode/system_flow-accounting.py12
-rwxr-xr-xsrc/validators/interface-exists40
2 files changed, 40 insertions, 12 deletions
diff --git a/src/conf_mode/system_flow-accounting.py b/src/conf_mode/system_flow-accounting.py
index eb728571f..3eafa101c 100755
--- a/src/conf_mode/system_flow-accounting.py
+++ b/src/conf_mode/system_flow-accounting.py
@@ -25,9 +25,7 @@ from vyos.config import config_dict_merge
from vyos.configverify import verify_vrf
from vyos.configverify import verify_interface_exists
from vyos.template import render
-from vyos.utils.dict import dict_search
from vyos.utils.file import read_file
-from vyos.utils.network import get_interface_config
from vyos.utils.network import get_interface_vrf
from vyos.utils.network import interface_exists
from vyos.utils.network import is_addr_assigned
@@ -121,16 +119,6 @@ def verify(flow_config):
verify_interface_exists(
flow_config, data['source_interface'], warning_only=True
)
- # A VRF is not an interface. Cisco and Juniper both source a flow
- # exporter from a routed interface and never from a VRF, and VRF
- # export is already selected with "system flow-accounting vrf", so
- # reject a source-interface that names a VRF device.
- source_interface_config = get_interface_config(data['source_interface'])
- if dict_search('linkinfo.info_kind', source_interface_config) == 'vrf':
- raise ConfigError(
- f'Configured "netflow server {server} source-interface '
- f'{data["source_interface"]}" is a VRF, not an interface!'
- )
# A source-interface used together with a VRF must be a member of
# that VRF, otherwise the exported flows would silently leave via a
# different routing table. Due to the VyOS priorities the interface
diff --git a/src/validators/interface-exists b/src/validators/interface-exists
new file mode 100755
index 000000000..d78247e1b
--- /dev/null
+++ b/src/validators/interface-exists
@@ -0,0 +1,40 @@
+#!/bin/sh
+#
+# Copyright (C) VyOS Inc.
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2 or later as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+# Passes only if $1 is a net device that exists on the system and is not a
+# VRF. Used as a fallback alongside a naming-pattern regex, so a currently
+# existing device is accepted as a physical/logical interface only if it is
+# not a VRF (VRFs are real net devices but must never be accepted where an
+# interface is expected).
+
+case "$1" in
+ ""|.|..|*/*)
+ echo "Error: $1 does not exist"
+ exit 1
+ ;;
+esac
+
+if [ ! -d "/sys/class/net/$1" ]; then
+ echo "Error: $1 does not exist"
+ exit 1
+fi
+
+if ip vrf show "$1" >/dev/null 2>&1; then
+ echo "Error: $1 is a VRF, not a network interface"
+ exit 1
+fi
+
+exit 0