Page MenuHomeVyOS Platform

Policy route wildcard Interfaces do not work for pod interfaces
Open, NormalPublicBUG

Description

Policy route wildcard Interfaces do not work for pod interfaces

vyos@r14# set policy route container interface pod*

  Incorrect path /sys/class/net/pod*: no such file or directory
  
  
  
  Invalid value
  Value validation failed
  Set failed

[edit]
vyos@r14# 
[edit]
vyos@r14# set policy route container interface pod-*

  Incorrect path /sys/class/net/pod-*: no such file or directory
  
  
  
  Invalid value
  Value validation failed
  Set failed

[edit]
vyos@r14#

The fix could be as simple as in this example https://github.com/vyos/vyos-1x/pull/4825

Details

Version
VyOS 2025.11.24-0021-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)
Forum thread
https://forum.vyos.io/t/vyos-stream-1-5-2025-q2-policy-route-wildcard-interface-not-working-for-pod-interfaces

Event Timeline

Viacheslav triaged this task as Normal priority.Nov 24 2025, 4:26 PM

Looking at the current regex validation, I think there is a number of issues. The current regex for regular interface types doesn't properly limit interfaces to max 15 characters and the doted numeric validation is super confusing. Obviously the pod interface validation doesn't consider wildcards at all.

We can expand the regex rules to one per prefix to validate lengths for each, but that will get large and probably be hard to manage. Instead, I propose replacing the 2 regex and directory validator with a single python script that can validate the wildcard and non-wildcard interface names. If the below is acceptable, can this issue be assigned to me?

import os
import re
import argparse
from sys import exit

NUMBERED_INTERFACE_TYPES = (
    'bond', 'br', 'dum', 'en', 'ersp', 'eth', 'gnv', 'ifb', 'ipoe', 'lan',
    'l2tp', 'l2tpeth', 'macsec', 'peth', 'ppp', 'pppoe', 'pptp', 'sstp',
    'sstpc', 'tun', 'veth', 'vpptap', 'vpptun', 'vti', 'vtun', 'vxlan',
    'wg', 'wlan', 'wwan',
)

NAMED_INTERFACE_TYPES = (
    'pod-',
)

# Validate numbered interface prefixes with optional sub interfaces and optional wildcard
# Example:
#  eth*
#  eth0
#  eth0*
#  eth0.0
#  eth0.0*
NUMBERED_INTERFACE_RE = re.compile(r'^('
    + '|'.join(sorted(map(re.escape, NUMBERED_INTERFACE_TYPES), key=len, reverse=True))
    + r')(\d+(?:\.\d+)?\*?|\*)$')

# Validate named interface prefixes with optional wildcard
# Example:
#  pod-*
#  pod-network
#  pod-network*
NAMED_INTERFACE_RE = re.compile(r'^('
    + '|'.join(sorted(map(re.escape, NAMED_INTERFACE_TYPES), key=len, reverse=True))
    + r')([A-Za-z0-9._-]+\*?|\*)$')

# Validate generic interface names (must exist in /sys/class/net
GENERIC_RE = re.compile(r'^[A-Za-z0-9._-]+$')

if __name__ == '__main__':
    parser = argparse.ArgumentParser()
    parser.add_argument("--allow-wildcard", action='store_true', help="Allow wildcards")
    parser.add_argument("name", type=str)
    args = parser.parse_args()

    if args.name == 'lo':
        exit(0)

    if len(args.name) > 15:
        print(f'Error: {args.name} is longer than 15 characters')
        exit(1)

    wildcard = args.name.endswith('*')

    if NUMBERED_INTERFACE_RE.match(args.name) or NAMED_INTERFACE_RE.match(args.name):
        if args.allow_wildcard or not wildcard:
            exit(0)
        print(f'Error: {args.name} is not a valid interface name')
        exit(1)
    
    if GENERIC_RE.match(args.name) and os.path.isdir(f'/sys/class/net/{args.name}'):
        exit(0)

    print(f'Error: {args.name} interface does not exist')
    exit(1)

Python is very slow for validations.
With thousands of interfaces, boot time will be impacted.
We usually do not use Python for our validators.

Fair enough. I'm not super advanced in regex definitions, but I will see if I can avoid using a different regex rule for each prefix.