Page MenuHomeVyOS Platform

Network services may fail if vyatta-router.service startup takes longer than a few seconds
Open, NormalPublicBUG

Description

Network services starting before vyatta-router.service has started may enter a failed state if they were configured to listen on an interface or address not coming up very quickly within the vyatta-router.service commit phase.

Example ( see also T452):
Hostapd instances will be configured and brought up by vyatta-router.service.
When configuring 5GHz Wifi interfaces with DFS, SSH wil fail to start if SSH was configured to listen on the 5GHz Wifi AP interface address. The 5GHz AP needs at least 60sec startup time because of radar scanning. During startup time, the Wifi interface is down, causing the SSH daemon being restarted by vyatta-router.service with its new config to silently fail. However, the commit sequence passes as it does not detect this lockup. The result is a VyOS system without SSH access despite Wifi AP started working after 60sec.

Other servies may be affected as well.

Workaround
Configure the SSH service to listen on 0.0.0.0 and set up firewall rules to selectively allow access.

Details

Difficulty level
Hard (possibly days)
Version
VyOS 1.2.0
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

alainlamar renamed this task from Network Services start before vyatta-router.service is started to Network services may fail if vyatta-router.service startup takes longe rthan a few seconds.Jan 14 2018, 4:47 PM
alainlamar created this task.
alainlamar renamed this task from Network services may fail if vyatta-router.service startup takes longe rthan a few seconds to Network services may fail if vyatta-router.service startup takes longer than a few seconds.Jan 14 2018, 4:49 PM

@alainlamar that sounds familiar, have you verified that you use the proper priority: tags inside your node.def files?

VyOS/Vyatta will run those in ascending order. We have some files with priorioty > 900 which means that they get executed very late.

syncer triaged this task as Normal priority.Feb 27 2018, 2:58 PM
syncer added subscribers: UnicronNL, syncer.

@UnicronNL maybe you can advise here

erkin set Is it a breaking change? to Unspecified (possibly destroys the router).
zsdc changed Difficulty level from Unknown (require assessment) to Hard (possibly days).Mar 11 2021, 2:05 PM