Comment 4 for bug 2053113

Revision history for this message
Frode Nordahl (fnordahl) wrote : Re: DoS vulnerability transmitting BFD packets from VIF

There has been some discussion on whether it is necessary to make it configurable for end users of OVN, and consensus has arrived at that is not the case. So the patch will be updated to have OVN always set this option on OVS tunnel ports. So a negative test will not be necessary.

The default for the `check_tnl_key` option in OVS will however remain 'false'. This is because it depends on the application consuming OVS and how it configures tunnel ports and designs OpenFlow pipelines whether the `check_tnl_key` option makes sense or not.

For OVN it does make sense because the OVN OpenFlow pipeline design will ensure end user traffic will always have a non-zero tunnel key.

For the test changes they are currently checking all the options OVN deploys into OVS verbatim, so even if OVN now will always set the `check_tnl_key=true` the tests need to include that in the test when confirming the contents of Interface:bfd.