Skip to content

Switch verify gate defeated: validation marks switch_config_applied without verifying (regression from 2.2) #736

Description

@sadsfae

Summary

Environment validation marks a host switch_config_applied=True without
actually verifying the switchports. The "switch configuration missing" release
gate is effectively dead: an environment can pass network validation and be
released to a tenant even when the switch was never configured or the
configuration failed.

Root cause

Two layers each drop the real result:

  1. src/quads/plugins/dispatchers/switch.py:43 SwitchDispatcher.verify awaits
    the plugin but discards its return value and hardcodes success:
try:
    await self._default_plugin.verify(host, cloud, change)
    return True
except Exception as e:
    logger.error(f"Failed to verify switch: {e}")
    return False
  1. src/quads/plugins/builtin/switches/juniper.py:195 JuniperSwitchPlugin.verify
    never returns a value (all paths fall through or bare return), so it always
    yields None.

Consumer src/quads/plugins/builtin/validators/environment.py:238:

result = await self.switch_dispatcher.verify(host.name, previous_cloud, host.cloud.name)
if result:
    self.quads.update_host(host.name, {"switch_config_applied": True})
else:
    switch_config_missing.append(host.name)

Because the dispatcher always returns True (barring an exception), the host is
marked switch_config_applied=True with no verification, and
switch_config_missing is never populated.

Regression from 2.2

In 2.2, Switch.verify returned None and post_network_test used it directly
(result = switch.verify(...)); None is falsy, so an unverified host went into
switch_config_missing and validation FAILED (conservative hold). The dispatcher
refactor turned this into an unconditional True.

Impact

Fix

  • SwitchDispatcher.verify should return the plugin's actual result.
  • JuniperSwitchPlugin.verify should return True only when the switch state is
    confirmed/applied successfully for all interfaces, False otherwise (including
    not-found and failed set operations).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions