Page MenuHomeVyOS Platform

interface: source-validation is not removed when a logical interface is removed
In progress, NormalPublicBUG

Description

When a logical interface like a VIF is configured and has source validation configured, it is not removed if the VIFis removed before the ip or ipv6 sections.

Config:
set interfaces ethernet eth3 vif 201 ip source-validation strict
nfables output:
sudo nft list table ip raw
table ip raw {
        chain VYOS_TCP_MSS {
                type filter hook postrouting priority raw; policy accept;
        }

        chain vyos_global_rpfilter {
                return
        }

        chain vyos_rpfilter {
                type filter hook prerouting priority raw; policy accept;
                iifname "eth3.201" fib saddr . iif oif 0 counter packets 0 bytes 0 drop
                iifname "eth3.201" counter packets 0 bytes 0 return
                counter packets 6557706 bytes 551954132 jump vyos_global_rpfilter
        }

        chain VYOS_PREROUTING_HOOK {
                type filter hook prerouting priority raw; policy accept;
        }
}
Delete the VIF:
delete interfaces ethernet eth3 vif
Rules still present in nftables:
sudo nft list table ip raw
table ip raw {
        chain VYOS_TCP_MSS {
                type filter hook postrouting priority raw; policy accept;
        }

        chain vyos_global_rpfilter {
                return
        }

        chain vyos_rpfilter {
                type filter hook prerouting priority raw; policy accept;
                iifname "eth3.201" fib saddr . iif oif 0 counter packets 0 bytes 0 drop
                iifname "eth3.201" counter packets 0 bytes 0 return
                counter packets 6558453 bytes 552005469 jump vyos_global_rpfilter
        }

        chain VYOS_PREROUTING_HOOK {
                type filter hook prerouting priority raw; policy accept;
        }
}
Add interface back, and then delete the ip section:
set interfaces ethernet eth3 vif 201 ip source-validation strict
commit

delete interfaces ethernet eth3 vif 201 ip
commit

delete interfaces ethernet eth3 vif 201
commit
Interface is now cleared from nftables config:
sudo nft list table ip raw
table ip raw {
        chain VYOS_TCP_MSS {
                type filter hook postrouting priority raw; policy accept;
        }

        chain vyos_global_rpfilter {
                return
        }

        chain vyos_rpfilter {
                type filter hook prerouting priority raw; policy accept;
                counter packets 6560055 bytes 552132880 jump vyos_global_rpfilter
        }

        chain VYOS_PREROUTING_HOOK {
                type filter hook prerouting priority raw; policy accept;
        }
}
NOTE: I plan to submit a PR for https://vyos.dev/T9152. If that is merged, it can include the fix since it's as simple as adding the function calls to the remove() function in addition to update().

Details

Version
2026.07.30-0032-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)