Skip to content

[dhcp_relay] Cover local giaddr loop rejection - #26325

Draft
Xichen96 wants to merge 1 commit into
sonic-net:masterfrom
Xichen96:dev/xichenlin/item10-local-giaddr-spoof-test
Draft

[dhcp_relay] Cover local giaddr loop rejection#26325
Xichen96 wants to merge 1 commit into
sonic-net:masterfrom
Xichen96:dev/xichenlin/item10-local-giaddr-spoof-test

Conversation

@Xichen96

@Xichen96 Xichen96 commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

Description of PR

Summary:
Correct normal relay-of-relay PTF modeling so valid chained requests use a genuinely nonlocal TEST-NET giaddr and expected forwarded packets preserve it. Add a focused native negative case that uses the DUT Loopback0 as giaddr under forward mode and requires no upstream packet.

This is a low-priority draft placeholder for a non-current deployment scenario. It depends on sonic-net/sonic-dhcp-relay#126 and may intentionally fail on current images until that product dependency merges. DRAFT — MUST NOT MERGE.

Fixes # N/A — draft test placeholder; no issue is linked.

Type of change

  • Bug fix
  • Testbed and Framework(new/improvement)
  • New Test case
    • Skipped for non-supported platforms
  • Test case improvement

Back port request

  • 202311
  • 202405
  • 202411
  • 202505
  • 202511
  • 202512
  • 202605

Tracking issue/work item for backport/cherry-pick request (GitHub issue or Microsoft ADO): N/A; no backport requested.
Failure type: other — low-priority test coverage gap for a non-current deployment scenario.

Tested branch

  • master
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511
  • 202512
  • 202605
  • N/A

Test result

Approach

What is the motivation for this PR?

Using the DUT own Loopback0 for ordinary chained requests models a loop/spoof rather than a downstream relay and conflicts with the intended local-giaddr rejection behavior.

How did you do it?

Use TEST-NET-1 address 192.0.2.1 for valid chained mode cases, preserve that giaddr in expected forwarded packets, and add a separate forward-mode negative case with the actual DUT Loopback0 plus a broad upstream DHCP drop assertion.

How did you verify/test it?

No validation was executed. Validation is deferred until the higher-priority DHCP relay PRs merge. This draft must not merge before the dependency and validation TODOs above are complete.

Any platform specific information?

Scoped to native sonic-relay-agent. Existing mode-test drafts may need rebase or coordination with this shared PTF correction.

Supported testbed topology if it's a new test case?

Existing t0 and m0 DHCP relay topologies; unsupported relay agents remain excluded.

Documentation

No documentation update. This draft only adds or corrects DHCP relay test coverage.

Model valid chained requests with a nonlocal giaddr and add a negative native relay case for a request spoofing the DUT loopback address.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2b881aa9-3a3a-4aaf-b2ca-b941705b2438
Signed-off-by: Xichen96 <lukelin0907@gmail.com>
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

)
else:
expected_forward = self.expected_forward
if expected_forward:
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants