Page MenuHomeVyOS Platform

Fix parse_icmp_attr() split delimiter and UnboundLocalError in firewall_rules facts
Open, NormalPublic

Description

Bug

parse_icmp_attr() in plugins/module_utils/network/vyos/facts/firewall_rules/firewall_rules.py has two bugs in the ICMP type/code parsing branch (around line 414):

Bug 1 — wrong split delimiter:

if "/" in val:  # type/code
    (type_no, code) = val.split(".")   # should be val.split("/")

Checks for "/" in the value but then splits on ".", so "1/2" raises ValueError (not enough values to unpack).

Bug 2 — UnboundLocalError:

elif val.isnumeric():
    config["type"] = type_no   # type_no only defined in the if-branch above

type_no is only defined when the if "/" branch runs. If the value is a plain integer (e.g. "1"), this raises UnboundLocalError: name 'type_no' is not defined.

Fix

if "/" in val:
    (type_no, code) = val.split("/")
    config["type"] = int(type_no)
    config["code"] = int(code)
elif val.isnumeric():
    config["type"] = int(val)
else:
    config["type_name"] = val

Impact

Any playbook gathering firewall rules with ICMP type conditions set as integers or type/code pairs will fail at facts gathering time with either a ValueError or UnboundLocalError.

Discovered

Surfaced by GitHub Copilot review of PR T8511 (#456) as a suppressed low-confidence comment.

Details

Version
6.0.0
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

syncer triaged this task as Normal priority.