Page MenuHomeVyOS Platform

VPP: GRE tunnel-type teb validation for a VPP bridge only checks the last member
Open, NormalPublicBUG

Description

set interfaces vpp bridge <name> member interface <gre-iface>

is supposed to require tunnel-type teb on every GRE interface used as a bridge member.
The validation only ever inspects one member, the one left over when the loop exits, instead of checking every member.

A non-TEB GRE interface bypasses validation entirely as long as it isn't the last member.

Steps to reproduce

configure
set interfaces vpp gre vppgre1 tunnel-type l3
set interfaces vpp gre vppgre1 source-address 10.10.1.1
set interfaces vpp gre vppgre1 remote 12.10.1.1

set interfaces vpp gre vppgre9 tunnel-type teb
set interfaces vpp gre vppgre9 source-address 10.10.2.1
set interfaces vpp gre vppgre9 remote 12.10.2.1

set interfaces vpp bridge vppbr1 member interface vppgre1
set interfaces vpp bridge vppbr1 member interface vppgre9
commit

Expected result

commit should fail, since vppgre1 does not have
tunnel-type teb

Actual result

commit succeeds with no error.

Control test

Swapping the two interfaces' tunnel-type values vppgre1 -> teb,
vppgre9 -> l3, and committing again:

[ interfaces vpp gre vppgre9 ]
dependent vpp_interfaces_bridge_vppbr1: GRE interface "vppgre9" in
bridge must have tunnel-type "teb". Current tunnel-type is "l3".
[[interfaces vpp gre vppgre9]] failed
[ interfaces vpp gre vppgre1 ]
dependent vpp_interfaces_bridge_vppbr1: GRE interface "vppgre9" in
bridge must have tunnel-type "teb". Current tunnel-type is "l3".
[[interfaces vpp gre vppgre1]] failed
Commit failed

Details

Version
2026.09.09-0029-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)