[dhcp_relay] Cover local giaddr loop rejection - #26325
Draft
Xichen96 wants to merge 1 commit into
Draft
Conversation
Model valid chained requests with a nonlocal giaddr and add a negative native relay case for a request spoofing the DUT loopback address. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2b881aa9-3a3a-4aaf-b2ca-b941705b2438 Signed-off-by: Xichen96 <lukelin0907@gmail.com>
Collaborator
|
/azp run |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
| ) | ||
| else: | ||
| expected_forward = self.expected_forward | ||
| if expected_forward: |
This was referenced Jul 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of PR
Summary:
Correct normal relay-of-relay PTF modeling so valid chained requests use a genuinely nonlocal TEST-NET
giaddrand expected forwarded packets preserve it. Add a focused native negative case that uses the DUT Loopback0 asgiaddrunderforwardmode and requires no upstream packet.This is a low-priority draft placeholder for a non-current deployment scenario. It depends on sonic-net/sonic-dhcp-relay#126 and may intentionally fail on current images until that product dependency merges. DRAFT — MUST NOT MERGE.
Fixes # N/A — draft test placeholder; no issue is linked.
Type of change
Back port request
Tracking issue/work item for backport/cherry-pick request (GitHub issue or Microsoft ADO): N/A; no backport requested.
Failure type: other — low-priority test coverage gap for a non-current deployment scenario.
Tested branch
Test result
NOT RUN: no pytest, PTF, syntax-check, or hardware validation was executed.
Validation is intentionally deferred until the higher-priority DHCP relay PRs merge.
This draft must not merge before its dependency and validation TODOs are complete.
Dependency TODO: rebase/validate after [dhcp4relay] Reject chained requests with a local giaddr sonic-dhcp-relay#126 merges; coordinate with [dhcp_relay] Cover DHCP relay forward agent mode #26323.
Validation TODO: run valid nonlocal chained mode cases and the focused local-giaddr negative hardware/PTF case after the higher-priority DHCP relay PRs merge.
Approach
What is the motivation for this PR?
Using the DUT own Loopback0 for ordinary chained requests models a loop/spoof rather than a downstream relay and conflicts with the intended local-giaddr rejection behavior.
How did you do it?
Use TEST-NET-1 address 192.0.2.1 for valid chained mode cases, preserve that giaddr in expected forwarded packets, and add a separate forward-mode negative case with the actual DUT Loopback0 plus a broad upstream DHCP drop assertion.
How did you verify/test it?
No validation was executed. Validation is deferred until the higher-priority DHCP relay PRs merge. This draft must not merge before the dependency and validation TODOs above are complete.
Any platform specific information?
Scoped to native sonic-relay-agent. Existing mode-test drafts may need rebase or coordination with this shared PTF correction.
Supported testbed topology if it's a new test case?
Existing t0 and m0 DHCP relay topologies; unsupported relay agents remain excluded.
Documentation
No documentation update. This draft only adds or corrects DHCP relay test coverage.