Bug#859941: [systemd] systemd-networkd: bridge vlan: does not remove vlan 1

2017-04-09 Thread Timo Weingärtner
Package: systemd
Version: 232-22
Severity: important

When adding a port to a VLAN-enabled bridge VLAN 1 is not removed.
That leads to information leakage from VLAN 1 to other VLANs and IPv6 
misconfiguration (via RAdv).
In my use case the other end is a VM whose interface is created by libvirt, 
but that does not seem to make a difference, so I use a veth device here.


Timo

Configuration:

/etc/systemd/network/00-test.network:
8<8<8<
[Match]
Name=test

[Link]
ARP=false

[Network]
Bridge=br

[BridgeVLAN]
VLAN=2
EgressUntagged=2
PVID=2
8<8<8<

/etc/systemd/network/00-br.netdev:
8<8<8<
[NetDev]
Kind=bridge
Name=br

[Bridge]
VLANFiltering=true
STP=false
8<8<8<

/etc/systemd/network/00-br.network:
8<8<8<
[Match]
Name=br

[Link]
ARP=false

[Network]
IPv6AcceptRA=false
8<8<8<

Steps to reproduce:

8<8<8<
# ip link add type veth peer name test
# bridge vlan show dev test
portvlan ids
test 1 Egress Untagged
 2 PVID Egress Untagged
8<8<8<

Expected result:

8<8<8<
# bridge vlan show dev test
portvlan ids
test 2 PVID Egress Untagged
8<8<8<



--- System information. ---
Architecture: amd64
Kernel:   Linux 4.9.0-2-amd64

Debian Release: 9.0
  900 testing deb.debian.org 


signature.asc
Description: This is a digitally signed message part.
___
Pkg-systemd-maintainers mailing list
Pkg-systemd-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-systemd-maintainers

Bug#859941: [systemd] systemd-networkd: bridge vlan: does not remove vlan 1

2017-04-09 Thread Michael Biebl
Am 09.04.2017 um 15:13 schrieb Timo Weingärtner:
> Package: systemd
> Version: 232-22
> Severity: important
> 
> When adding a port to a VLAN-enabled bridge VLAN 1 is not removed.
> That leads to information leakage from VLAN 1 to other VLANs and IPv6 
> misconfiguration (via RAdv).
> In my use case the other end is a VM whose interface is created by libvirt, 
> but that does not seem to make a difference, so I use a veth device here.

I can't really comment on the bug report as such, but it doesn't look
like it's a Debian specific issue. So it would be great if you can raise
this upstream at
https://github.com/systemd/systemd/issues




-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?



signature.asc
Description: OpenPGP digital signature
___
Pkg-systemd-maintainers mailing list
Pkg-systemd-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-systemd-maintainers

Processed: bug 859941 is forwarded to https://github.com/systemd/systemd/issues/5716

2017-04-09 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> forwarded 859941 https://github.com/systemd/systemd/issues/5716
Bug #859941 [systemd] [systemd] systemd-networkd: bridge vlan: does not remove 
vlan 1
Ignoring request to change the forwarded-to-address of bug#859941 to the same 
value
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
859941: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859941
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
Pkg-systemd-maintainers mailing list
Pkg-systemd-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-systemd-maintainers


Bug#859941: [systemd] systemd-networkd: bridge vlan: does not remove vlan 1

2017-04-09 Thread Timo Weingärtner
control: forwarded -1 https://github.com/systemd/systemd/issues/5716

09.04.17 20:09:02 CEST Michael Biebl:
> I can't really comment on the bug report as such, but it doesn't look
> like it's a Debian specific issue. So it would be great if you can raise
> this upstream at
> https://github.com/systemd/systemd/issues

You're lucky I still have an account there…



signature.asc
Description: This is a digitally signed message part.
___
Pkg-systemd-maintainers mailing list
Pkg-systemd-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-systemd-maintainers

Processed: Re: Bug#859941: [systemd] systemd-networkd: bridge vlan: does not remove vlan 1

2017-04-09 Thread Debian Bug Tracking System
Processing control commands:

> forwarded -1 https://github.com/systemd/systemd/issues/5716
Bug #859941 [systemd] [systemd] systemd-networkd: bridge vlan: does not remove 
vlan 1
Set Bug forwarded-to-address to 
'https://github.com/systemd/systemd/issues/5716'.

-- 
859941: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859941
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
Pkg-systemd-maintainers mailing list
Pkg-systemd-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-systemd-maintainers