From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 7CEFD1FF0AF for ; Thu, 08 Oct 2026 11:56:47 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 64A6921480; Thu, 08 Oct 2026 11:56:44 +0200 (CEST) From: Gabriel Goller To: pve-devel@lists.proxmox.com Subject: [PATCH ifupdown2] fix #8130: bond MAC inheritance to avoid outages on first reload Date: Thu, 8 Oct 2026 11:56:32 +0200 Message-ID: <20261008095634.77401-1-g.goller@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791453397983 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.318 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: D5IRX6LIDEFUAXLTRCZML2DVTZKN7JKW X-Message-ID-Hash: D5IRX6LIDEFUAXLTRCZML2DVTZKN7JKW X-MailFrom: g.goller@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The netlink cache can list bond slaves in a different order than they were initially enslaved (index vs order in config). A valid inherited MAC is then considered invalid, which causes the first reload after boot to flap the bond and its bridges. Backport both upstream commits. Upstream-Link: https://github.com/CumulusNetworks/ifupdown2/pull/318 Fixes: https://bugzilla.proxmox.com/show_bug.cgi?id=8130 Signed-off-by: Gabriel Goller --- debian/patches/series | 2 + ...reserve-mac-inherited-from-any-slave.patch | 116 ++++++++++++++++++ ...004-bond-fix-list-index-out-of-range.patch | 40 ++++++ 3 files changed, 158 insertions(+) create mode 100644 debian/patches/upstream/0003-bond-preserve-mac-inherited-from-any-slave.patch create mode 100644 debian/patches/upstream/0004-bond-fix-list-index-out-of-range.patch diff --git a/debian/patches/series b/debian/patches/series index 2865533271c9..45924c8d21dc 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -16,3 +16,5 @@ upstream/0001-use-raw-strings-for-regex-to-fix-backslash-interpret.patch upstream/0002-vxlan-add-support-for-IPv6-vxlan-local-tunnelip.patch pve/0014-nlmanager-read-ipv6-devconf-disable_ipv6-attribute-t.patch pve/0015-revert-addons-bond-warn-if-sub-interface-is-detected-on-bond-slave.patch +upstream/0003-bond-preserve-mac-inherited-from-any-slave.patch +upstream/0004-bond-fix-list-index-out-of-range.patch diff --git a/debian/patches/upstream/0003-bond-preserve-mac-inherited-from-any-slave.patch b/debian/patches/upstream/0003-bond-preserve-mac-inherited-from-any-slave.patch new file mode 100644 index 000000000000..daa8876dfdfd --- /dev/null +++ b/debian/patches/upstream/0003-bond-preserve-mac-inherited-from-any-slave.patch @@ -0,0 +1,116 @@ +From 29807929cce23e0c11875c9efddea45b187e3c86 Mon Sep 17 00:00:00 2001 +From: Julien Fortin +Date: Tue, 28 Nov 2023 23:17:18 +0100 +Subject: [PATCH] addons: bond: change bond mac inheritance code (any slave mac + is fine) + +Upstream-Link: https://github.com/CumulusNetworks/ifupdown2/pull/318 +Signed-off-by: Julien Fortin +--- + ifupdown2/addons/bond.py | 90 +++++++++++++++++++++------------------- + 1 file changed, 48 insertions(+), 42 deletions(-) + +diff --git a/ifupdown2/addons/bond.py b/ifupdown2/addons/bond.py +index deb88def..b691ef44 100644 +--- a/ifupdown2/addons/bond.py ++++ b/ifupdown2/addons/bond.py +@@ -901,51 +901,57 @@ def _up(self, ifaceobj, ifaceobj_getfunc=None): + bond_slaves, + ifaceobj_getfunc, + ) +- +- if not self.bond_mac_mgmt or not link_exists or ifaceobj.get_attr_value_first("hwaddress"): +- return +- +- # check if the bond mac address is correctly inherited from it's +- # first slave. There's a case where that might not be happening: +- # $ ip link show swp1 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ ip link show swp2 | grep ether +- # link/ether 08:00:27:04:d8:02 brd ff:ff:ff:ff:ff:ff +- # $ ip link add dev bond0 type bond +- # $ ip link set dev swp1 master bond0 +- # $ ip link set dev swp2 master bond0 +- # $ ip link show bond0 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ ip link add dev bond1 type bond +- # $ ip link set dev swp1 master bond1 +- # $ ip link show swp1 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ ip link show swp2 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ ip link show bond0 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ ip link show bond1 | grep ether +- # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff +- # $ +- # ifupdown2 will automatically correct and fix this unexpected behavior +- bond_mac = self.cache.get_link_address(ifaceobj.name) +- +- if bond_slaves: +- first_slave_ifname = bond_slaves[0] +- first_slave_mac = self.cache.get_link_info_slave_data_attribute( +- first_slave_ifname, +- Link.IFLA_BOND_SLAVE_PERM_HWADDR +- ) +- +- if first_slave_mac and bond_mac != first_slave_mac: +- self.logger.info( +- "%s: invalid bond mac detected - resetting to %s's mac (%s)" +- % (ifaceobj.name, first_slave_ifname, first_slave_mac) +- ) +- self.netlink.link_set_address(ifaceobj.name, first_slave_mac, utils.mac_str_to_int(first_slave_mac)) ++ self.set_bond_mac(link_exists, ifaceobj, bond_slaves) + except Exception as e: + self.log_error(str(e), ifaceobj) + ++ def set_bond_mac(self, link_exists, ifaceobj, bond_slaves): ++ if not self.bond_mac_mgmt or not link_exists or ifaceobj.get_attr_value_first("hwaddress"): ++ return ++ ++ # check if the bond mac address is correctly inherited from it's ++ # first slave. There's a case where that might not be happening: ++ # $ ip link show swp1 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ip link show swp2 | grep ether ++ # link/ether 08:00:27:04:d8:02 brd ff:ff:ff:ff:ff:ff ++ # $ ip link add dev bond0 type bond ++ # $ ip link set dev swp1 master bond0 ++ # $ ip link set dev swp2 master bond0 ++ # $ ip link show bond0 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ip link add dev bond1 type bond ++ # $ ip link set dev swp1 master bond1 ++ # $ ip link show swp1 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ip link show swp2 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ip link show bond0 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ip link show bond1 | grep ether ++ # link/ether 08:00:27:04:d8:01 brd ff:ff:ff:ff:ff:ff ++ # $ ++ # ifupdown2 will automatically correct and fix this unexpected behavior ++ # Although if the bond's mac belongs to any of its slave we won't update it ++ bond_mac = self.cache.get_link_address(ifaceobj.name) ++ ++ # Get the list of slave macs ++ bond_slave_macs = map( ++ lambda slave_ifname: self.cache.get_link_info_slave_data_attribute(slave_ifname, Link.IFLA_BOND_SLAVE_PERM_HWADDR), ++ bond_slaves ++ ) ++ ++ if bond_slaves and bond_mac not in bond_slave_macs: ++ first_slave_ifname = bond_slaves[0] ++ first_slave_mac = list(bond_slave_macs)[0] ++ ++ if first_slave_mac and bond_mac != first_slave_mac: ++ self.logger.info( ++ "%s: invalid bond mac detected - resetting to %s's mac (%s)" ++ % (ifaceobj.name, first_slave_ifname, first_slave_mac) ++ ) ++ self.netlink.link_set_address(ifaceobj.name, first_slave_mac, utils.mac_str_to_int(first_slave_mac)) ++ + def _down(self, ifaceobj, ifaceobj_getfunc=None): + bond_slaves = self.cache.get_slaves(ifaceobj.name) + diff --git a/debian/patches/upstream/0004-bond-fix-list-index-out-of-range.patch b/debian/patches/upstream/0004-bond-fix-list-index-out-of-range.patch new file mode 100644 index 000000000000..e79653eb8fd8 --- /dev/null +++ b/debian/patches/upstream/0004-bond-fix-list-index-out-of-range.patch @@ -0,0 +1,40 @@ +From 97fb31ce1af89079834d441b59a3d7be865158c4 Mon Sep 17 00:00:00 2001 +From: Julien Fortin +Date: Fri, 5 Jan 2024 15:57:26 +0100 +Subject: [PATCH] addons: bond: fix 'list index out of range' error when + removing first bond slave + +Upstream-Link: https://github.com/CumulusNetworks/ifupdown2/pull/318 +Signed-off-by: Julien Fortin +--- + ifupdown2/addons/bond.py | 14 +++++++++----- + 1 file changed, 9 insertions(+), 5 deletions(-) + +diff --git a/ifupdown2/addons/bond.py b/ifupdown2/addons/bond.py +index b691ef44..2e6edf2d 100644 +--- a/ifupdown2/addons/bond.py ++++ b/ifupdown2/addons/bond.py +@@ -936,14 +936,18 @@ def set_bond_mac(self, link_exists, ifaceobj, bond_slaves): + bond_mac = self.cache.get_link_address(ifaceobj.name) + + # Get the list of slave macs +- bond_slave_macs = map( +- lambda slave_ifname: self.cache.get_link_info_slave_data_attribute(slave_ifname, Link.IFLA_BOND_SLAVE_PERM_HWADDR), ++ bond_slave_macs = list(map( ++ lambda slave_ifname: self.cache.get_link_info_slave_data_attribute( ++ slave_ifname, ++ Link.IFLA_BOND_SLAVE_PERM_HWADDR, ++ default=list() ++ ), + bond_slaves +- ) ++ )) + +- if bond_slaves and bond_mac not in bond_slave_macs: ++ if bond_slaves and bond_slave_macs and bond_mac not in bond_slave_macs: + first_slave_ifname = bond_slaves[0] +- first_slave_mac = list(bond_slave_macs)[0] ++ first_slave_mac = bond_slave_macs[0] + + if first_slave_mac and bond_mac != first_slave_mac: + self.logger.info( -- 2.47.3