Page MenuHomeVyOS Platform

`qos policy cake` without `bandwidth` is silently applied as `unlimited` and causes packet loss
Open, Requires assessmentPublicBUG

Description

Version: VyOS 2026.09.16-0028-rolling (amd64)

Summary: A cake policy that has no bandwidth set is accepted and applied to the interface as bandwidth unlimited. CAKE then runs in a degenerate state (capacity estimate: 0bit), its queue memory fills up and it starts dropping packets. No warning is emitted at commit time.

Evidence (tc -s qdisc show dev eth6):

  • bandwidth unlimited, capacity estimate: 0bit
  • dropped 10731730 out of 218491365 packets (4.9%), queue memory used: 14409472b of 15140Kb (95%)
  • After adding set qos policy cake CP_USERS_DOWN bandwidth '900mbit': capacity estimate: 900Mbit, queue memory 2.2 MB/15.1 MB, drops stop.

Impact: On a PPPoE access concentrator this caused ~5% loss on the subscriber downlink. The loss hit LCP echo requests, so accel-ppp declared peers dead and terminated sessions (lcp: no echo reply -> disconnected); one subscriber was disconnected 5 times in a day.

Steps to reproduce: set qos policy cake TEST flow-isolation-nat, set qos interface ethX egress TEST, commit, then tc -s qdisc show dev ethX.

Expected: either require bandwidth, or emit a commit-time warning that the policy will run as unlimited and that CAKE cannot estimate capacity.

Suggested fix: add a validation/warning in conf_mode/qos.py (and document the behaviour).

Details

Version
2026.09.16-0028-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)