Page MenuHomeVyOS Platform

`load` silently drops unknown/invalid configuration nodes (no error, service keeps running)
Open, Requires assessmentPublicBUG

Description

Version: VyOS 2026.09.16-0028-rolling (amd64)

Summary: Loading a configuration file that contains an invalid node name succeeds without any error, the invalid node is silently discarded, and the affected service keeps running in its previous state. Operators believe the change was applied while the service still runs -- dangerous in production.

Steps to reproduce:

  1. Create a config file containing an invalid node, e.g. service { dhcp-server { disabled } } (the valid node is disable).
  2. configure, load <file>, commit, save.
  3. Observe LOAD_RC=0, COMMIT_RC=0; show configuration commands does not contain the node; kea-dhcp4 is still running and listening on port 67.
  4. Replacing it with the valid set service dhcp-server disable stops the service.

Actual: Silent success, node dropped, service unchanged.
Expected: load/commit must fail with an error naming the unknown node (or at least warn and refuse to commit).

Impact: In our case it left a second DHCP server active on a production LAN segment (duplicate lease/address-conflict risk) while the operator believed it was disabled.

Related: T7179 (load from file does not apply some properties) and T7718 (refine validate_tree method) are closely related. Even with T7718's validate_tree utility, load <file> still silently discards unknown node names without any error.

Suggested fix: validate every node during load/commit and abort with Configuration error: unknown node ...; optionally suggest the closest valid node name.

Details

Version
2026.09.16-0028-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)