Version: VyOS 2026.09.16-0028-rolling (amd64)
Summary: A cake policy that has no bandwidth set is accepted and applied to the interface as bandwidth unlimited. CAKE then runs in a degenerate state (capacity estimate: 0bit), its queue memory fills up and it starts dropping packets. No warning is emitted at commit time.
Evidence (tc -s qdisc show dev eth6):
- bandwidth unlimited, capacity estimate: 0bit
- dropped 10731730 out of 218491365 packets (4.9%), queue memory used: 14409472b of 15140Kb (95%)
- After adding set qos policy cake CP_USERS_DOWN bandwidth '900mbit': capacity estimate: 900Mbit, queue memory 2.2 MB/15.1 MB, drops stop.
Impact: On a PPPoE access concentrator this caused ~5% loss on the subscriber downlink. The loss hit LCP echo requests, so accel-ppp declared peers dead and terminated sessions (lcp: no echo reply -> disconnected); one subscriber was disconnected 5 times in a day.
Steps to reproduce: set qos policy cake TEST flow-isolation-nat, set qos interface ethX egress TEST, commit, then tc -s qdisc show dev ethX.
Expected: either require bandwidth, or emit a commit-time warning that the policy will run as unlimited and that CAKE cannot estimate capacity.
Suggested fix: add a validation/warning in conf_mode/qos.py (and document the behaviour).