-
Notifications
You must be signed in to change notification settings - Fork 48
Added validation check for CSCwt58626 #405
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: v4.2.0-dev
Are you sure you want to change the base?
Changes from all commits
8f68a28
8f858b8
cd8d121
1dad1ef
bb531b5
5afb200
8c4e053
3c90277
0867b24
bb07f23
9b20a12
fc2681d
7d7a314
d270b6d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -22,7 +22,7 @@ | |
| from textwrap import TextWrapper | ||
| from getpass import getpass | ||
| from collections import defaultdict, OrderedDict | ||
| from datetime import datetime | ||
| from datetime import datetime, timedelta | ||
| from argparse import ArgumentParser | ||
| from itertools import chain | ||
| import threading | ||
|
|
@@ -6293,6 +6293,9 @@ def is_affected_target(ver): | |
| in_61 = ver.newer_than("6.1(1a)") and ver.older_than("6.1(4h)") | ||
| return in_60 or in_61 | ||
|
|
||
| if not tversion or not cversion: | ||
| return Result(result=MANUAL, msg=TVER_MISSING) | ||
|
|
||
| pre_apic_upg = is_affected_source(cversion) and is_affected_target(tversion) # Before APIC upgrade | ||
| post_apic_upg = is_affected_target(cversion) and is_affected_target(tversion) and cversion.same_as(tversion) # After APIC upgrade (and before switch) | ||
|
|
||
|
|
@@ -6477,6 +6480,9 @@ def inband_management_policy_misconfig_check(cversion, tversion, **kwargs): | |
| recommended_action = "Contact Cisco TAC to remove any identified misconfigured 'mgmtRsInBStNode' objects" | ||
| doc_url = "https://datacenter.github.io/ACI-Pre-Upgrade-Validation-Script/validations/#inband-management-policy-misconfiguration" | ||
|
|
||
| if not tversion or not cversion: | ||
| return Result(result=MANUAL, msg=TVER_MISSING) | ||
|
|
||
| if (cversion.older_than("5.2(8d)")) and (tversion.newer_than("6.0(4c)") or tversion.same_as("6.0(4c)")): | ||
| mgmtRsInBStNodes = icurl('class', 'mgmtRsInBStNode.json?query-target-filter=and(or(eq(mgmtRsInBStNode.addr,"0.0.0.0"),eq(mgmtRsInBStNode.gw,"0.0.0.0")),or(eq(mgmtRsInBStNode.v6Addr,"::"),eq(mgmtRsInBStNode.v6Gw,"::")))') | ||
| for mgmtRsInBStNode in mgmtRsInBStNodes: | ||
|
|
@@ -6685,7 +6691,12 @@ def stale_dbgacEpgSummaryTask_check(tversion, **kwargs): | |
| if tversion and ((tversion.major1 == "6" and tversion.major2 == "1" and tversion.newer_than("6.1(5e)")) or tversion.newer_than("6.2(1g)")): | ||
| return Result(result=NA, msg=VER_NOT_AFFECTED, doc_url=doc_url) | ||
|
|
||
| threshold = datetime.utcnow() - timedelta(hours=24) | ||
| try: | ||
| from datetime import timezone | ||
| threshold = datetime.now(timezone.utc).replace(tzinfo=None) - timedelta(hours=24) | ||
| except ImportError: | ||
| threshold = datetime.utcnow() - timedelta(hours=24) | ||
|
Comment on lines
+6694
to
+6698
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. this potion is needed to cover |
||
|
|
||
| for obj in icurl("class", 'dbgacEpgSummaryTask.json?query-target-filter=eq(dbgacEpgSummaryTask.operSt,"processing")'): | ||
| attr = obj["dbgacEpgSummaryTask"]["attributes"] | ||
| dn = attr.get("dn", "") | ||
|
|
@@ -6702,6 +6713,81 @@ def stale_dbgacEpgSummaryTask_check(tversion, **kwargs): | |
| return Result(result=result, headers=headers, data=data, recommended_action=recommended_action, doc_url=doc_url) | ||
|
|
||
|
|
||
| @check_wrapper(check_title="InfraVLAN Overlap in Access Policy VLAN Pools") | ||
| def infravlan_overlap_access_policy_check(tversion, **kwargs): | ||
| result = FAIL_UF | ||
| msg = "" | ||
| headers = ["InfraVLAN", "Encap Block", "VLAN Pool DN"] | ||
| unformatted_headers = ["InfraVLAN", "Encap Block", "VLAN Pool DN"] | ||
|
|
||
| data = [] | ||
| unformatted_data = [] | ||
| recommended_action = "Remove InfraVLAN from VLAN pool block highligted or upgrade to fix version" | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [P2] Do not prescribe unsupported edits to orchestrator-managed blocks. The current CSCwt58626 defect record lists
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. RNE should be updated with proper workaround steps we are proposing here |
||
|
|
||
| doc_url = "https://datacenter.github.io/ACI-Pre-Upgrade-Validation-Script/validations/#infravlan-overlap-access-policy-check" | ||
|
|
||
| if not tversion: | ||
| return Result(result=MANUAL, msg=TVER_MISSING) | ||
|
|
||
| if not (tversion.same_as("6.2(1g)") or ( | ||
| not tversion.older_than("6.1(3f)") and not tversion.newer_than("6.1(5e)") | ||
|
muthu-ku marked this conversation as resolved.
|
||
| )): | ||
|
monrog2 marked this conversation as resolved.
|
||
| return Result(result=NA, msg=VER_NOT_AFFECTED) | ||
|
|
||
| dn_regex1 = r'uni/infra/vlanns-\[.+\]-(static|dynamic)/from-\[vlan-\d+\]-to-\[vlan-\d+\]' | ||
|
|
||
| dn_regex2 = r'uni/vmmp-[^/]+/dom-[^/]+/.+/from-\[vlan-\d+\]-to-\[vlan-\d+\]' | ||
|
|
||
| infra_vlan = None | ||
| has_error = False | ||
| lldpInsts = icurl('class', 'lldpInst.json?query-target-filter=wcard(lldpInst.dn,"/node-1/")') | ||
| for lldpInst in lldpInsts: | ||
| infra_vlan_id = lldpInst.get('lldpInst', {}).get('attributes', {}).get('infraVlan') | ||
| if not infra_vlan_id: | ||
| continue | ||
| match = re.search(r'\d+', str(infra_vlan_id)) | ||
| if match: | ||
| infra_vlan = int(match.group(0)) | ||
| break | ||
|
|
||
| if infra_vlan is None: | ||
| return Result(result=ERROR, msg="Unable to determine InfraVLAN from lldpInst.") | ||
|
|
||
| encap_blocks = icurl('class', 'fvnsEncapBlk.json?query-target-filter=eq(fvnsEncapBlk.role,"external")') | ||
| for obj in encap_blocks: | ||
| blk_attr = obj.get('fvnsEncapBlk', {}).get('attributes', {}) | ||
|
muthu-ku marked this conversation as resolved.
|
||
| dn = blk_attr.get('dn', '') | ||
| from_encap = blk_attr.get('from') | ||
| to_encap = blk_attr.get('to') | ||
|
|
||
| if not dn or not from_encap or not to_encap: | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [P1] Preserve incomplete overlapping blocks in the failure evidence. This path sets |
||
| has_error = True | ||
| continue | ||
|
|
||
| try: | ||
| from_vlan = int(str(from_encap).split('-')[-1]) | ||
| to_vlan = int(str(to_encap).split('-')[-1]) | ||
| except (ValueError, TypeError): | ||
| has_error = True | ||
| continue | ||
|
|
||
| if min(from_vlan, to_vlan) <= infra_vlan <= max(from_vlan, to_vlan): | ||
| row = [str(infra_vlan), "{} to {}".format(from_encap, to_encap), dn] | ||
| if re.search(dn_regex1, dn) or re.search(dn_regex2, dn): | ||
| data.append(row) | ||
| else: | ||
| unformatted_data.append(row) | ||
|
|
||
| if not data and not unformatted_data: | ||
| result = PASS | ||
| if has_error: | ||
| result = ERROR | ||
| msg = "Overlap check for InfraVLAN {} could not be determined because one or more VLAN pool blocks contain improper data or Error while fetching data.".format(infra_vlan) | ||
|
|
||
|
|
||
| return Result(result=result, msg=msg, headers=headers, data=data, unformatted_headers=unformatted_headers, unformatted_data=unformatted_data, recommended_action=recommended_action, doc_url=doc_url) | ||
|
|
||
|
|
||
| # ---- Script Execution ---- | ||
|
|
||
|
|
||
|
|
@@ -6877,7 +6963,8 @@ class CheckManager: | |
| wred_affected_model_check, | ||
| n9k_c93180yc_fx3_switch_memory_check, | ||
| stale_dbgacEpgSummaryTask_check, | ||
|
|
||
| infravlan_overlap_access_policy_check, | ||
|
|
||
| ] | ||
| ssh_checks = [ | ||
| # General | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| [] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,39 @@ | ||
| [ | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-3000]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-3000", | ||
| "to": "vlan-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-3001]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "", | ||
| "to": "vlan-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-10]-to-[vlan-20]", | ||
| "role": "external", | ||
| "from": "vlan-10", | ||
| "to": "vlan-20", | ||
| "dn": "uni/infra/vlanns-[vlan_pool3]-static/from-[vlan-10]-to-[vlan-20]" | ||
| } | ||
| } | ||
| } | ||
| ] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,39 @@ | ||
| [ | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-3000]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-3000", | ||
| "to": "vlan-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-3001]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "", | ||
| "to": "vlan-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-4000]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-4000", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanns-[vlan_pool3]-static/from-[vlan-4000]-to-[vlan-4094]" | ||
| } | ||
| } | ||
| } | ||
| ] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| [ | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-200]-to-[vlan-300]", | ||
| "role": "external", | ||
| "from": "vlan-200", | ||
| "to": "vlan-300", | ||
| "dn": "uni/infra/vlanns-[vlan_pool1]-static/from-[vlan-200]-to-[vlan-300]" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-500]-to-[vlan-1000]", | ||
| "role": "external", | ||
| "from": "vlan-500", | ||
| "to": "vlan-1000", | ||
| "dn": "uni/infra/vlanns-[vlan_pool2]-static/from-[vlan-500]-to-[vlan-1000]" | ||
| } | ||
| } | ||
| } | ||
| ] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| [ | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-4000]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-4000", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanpool/vlan-4000-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-400]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-400", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanpool/vlan-400-4094" | ||
| } | ||
| } | ||
| } | ||
| ] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,41 @@ | ||
| [ | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-100]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-100", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanns-[vlan_pool1]-static/from-[vlan-100]-to-[vlan-4094]" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-4000]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-4000", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanpool/vlan-4000-4094" | ||
| } | ||
| } | ||
| }, | ||
| { | ||
| "fvnsEncapBlk": { | ||
| "attributes": { | ||
| "allocMode": "static", | ||
| "annotation": "orchestrator:aci-containers-controller", | ||
| "rn": "from-[vlan-400]-to-[vlan-4094]", | ||
| "role": "external", | ||
| "from": "vlan-400", | ||
| "to": "vlan-4094", | ||
| "dn": "uni/infra/vlanpool/vlan-400-4094" | ||
| } | ||
| } | ||
| } | ||
| ] |
Uh oh!
There was an error while loading. Please reload this page.