Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 64 additions & 3 deletions aci-preupgrade-validation-script.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
from textwrap import TextWrapper
from getpass import getpass
from collections import defaultdict, OrderedDict
from datetime import datetime
from datetime import datetime, timedelta
Comment thread
monrog2 marked this conversation as resolved.
from argparse import ArgumentParser
from itertools import chain
import threading
Expand Down Expand Up @@ -6685,7 +6685,12 @@ def stale_dbgacEpgSummaryTask_check(tversion, **kwargs):
if tversion and ((tversion.major1 == "6" and tversion.major2 == "1" and tversion.newer_than("6.1(5e)")) or tversion.newer_than("6.2(1g)")):
return Result(result=NA, msg=VER_NOT_AFFECTED, doc_url=doc_url)

threshold = datetime.utcnow() - timedelta(hours=24)
try:
from datetime import timezone
threshold = datetime.now(timezone.utc).replace(tzinfo=None) - timedelta(hours=24)
except ImportError:
threshold = datetime.utcnow() - timedelta(hours=24)
Comment on lines +6688 to +6692

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this potion is needed to cover

 /data/techsupport/muthu/aci-preupgrade-validation-script.py:6688: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
threshold = datetime.utcnow() - timedelta(hours=24)

Python version	          Path taken	                                                                              Result
Python 2.x	          ImportError caught → datetime.utcnow()	                             ✅ Works
Python 3.0–3.11.        timezone import succeeds → datetime.now(timezone.utc)	✅ Works, no warning
Python 3.12+	         timezone import succeeds → datetime.now(timezone.utc)	✅ Works, no deprecation warning


for obj in icurl("class", 'dbgacEpgSummaryTask.json?query-target-filter=eq(dbgacEpgSummaryTask.operSt,"processing")'):
attr = obj["dbgacEpgSummaryTask"]["attributes"]
dn = attr.get("dn", "")
Expand All @@ -6702,6 +6707,61 @@ def stale_dbgacEpgSummaryTask_check(tversion, **kwargs):
return Result(result=result, headers=headers, data=data, recommended_action=recommended_action, doc_url=doc_url)


@check_wrapper(check_title="InfraVLAN Overlap in Access Policy VLAN Pools")
def infravlan_overlap_access_policy_check(tversion, **kwargs):
result = PASS
headers = ["InfraVLAN", "Encap Block", "VLAN Pool DN"]
data = []
recommended_action = "Remove InfraVLAN from VLAN pool block highligted or upgrade to fix version"

doc_url = "https://datacenter.github.io/ACI-Pre-Upgrade-Validation-Script/validations/#infravlan-overlap-access-policy-check"

if not tversion:
return Result(result=MANUAL, msg=TVER_MISSING)

if not (tversion.same_as("6.2(1g)") or (
not tversion.older_than("6.1(3f)") and not tversion.newer_than("6.1(5e)")
Comment thread
muthu-ku marked this conversation as resolved.
)):
return Result(result=NA, msg=VER_NOT_AFFECTED)

infra_vlan = None
lldpInsts = icurl('class', 'lldpInst.json?query-target-filter=wcard(lldpInst.dn,"/node-1/")')
for lldpInst in lldpInsts:
infra_vlan_id = lldpInst.get('lldpInst', {}).get('attributes', {}).get('infraVlan')
if not infra_vlan_id:
continue
match = re.search(r'\d+', str(infra_vlan_id))
if match:
infra_vlan = int(match.group(0))
break

if infra_vlan is None:
return Result(result=ERROR, msg="Unable to determine InfraVLAN from lldpInst.")

encap_blocks = icurl('class', 'fvnsEncapBlk.json?query-target-filter=eq(fvnsEncapBlk.role,"external")')
for obj in encap_blocks:
blk_attr = obj.get('fvnsEncapBlk', {}).get('attributes', {})

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Filter out non-affected internal blocks. The unfiltered fvnsEncapBlk class response also contains blocks with role: internal, but this loop treats every block as a user VLAN-pool block. A valid internal block containing the InfraVLAN therefore produces FAIL_UF; I reproduced that behavior with an existing internal-role fixture shape. The CDETS example is role: external. Please restrict evaluation to the affected role/object types, and add an internal-role regression case.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@monrog2 copy that. @muthu-ku please rework this to fetch the external block only.

dn = blk_attr.get('dn', '')
from_encap = blk_attr.get('from')
to_encap = blk_attr.get('to')
if not dn or not from_encap or not to_encap:
continue

try:
from_vlan = int(str(from_encap).split('-')[-1])
to_vlan = int(str(to_encap).split('-')[-1])
except (ValueError, TypeError):
continue
Comment on lines +6747 to +6754

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Do not turn unparseable APIC data into a PASS. Missing dn/from/to values and malformed VLAN values are silently skipped. If every returned block is malformed, data remains empty and the check reports PASS without establishing that no overlap exists; this is reproducible with a malformed-only response. Track these objects via unformatted_data and return ERROR (or the repository's equivalent incomplete-data result), with malformed-only and mixed valid/malformed tests.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@muthu-ku please work on the suggestions.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

when you find unformatted Dn, exit loop and print error.


if min(from_vlan, to_vlan) <= infra_vlan <= max(from_vlan, to_vlan):
data.append([str(infra_vlan), "{} to {}".format(from_encap, to_encap), dn])

if data:
result = FAIL_UF

return Result(result=result, headers=headers, data=data, recommended_action=recommended_action, doc_url=doc_url)


# ---- Script Execution ----


Expand Down Expand Up @@ -6877,7 +6937,8 @@ class CheckManager:
wred_affected_model_check,
n9k_c93180yc_fx3_switch_memory_check,
stale_dbgacEpgSummaryTask_check,

infravlan_overlap_access_policy_check,

]
ssh_checks = [
# General
Expand Down
10 changes: 9 additions & 1 deletion docs/docs/validations.md
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,7 @@ Items | Defect | This Script
[WRED with Affected FM Models][d35] | CSCwt50713 | :white_check_mark: | :no_entry_sign:
[N9K-C93180YC-FX3 Switch Memory Less Than 32GB][d36] | CSCwm42741 | :white_check_mark: | :no_entry_sign:
[Stale dbgacEpgSummaryTask Objects][d37] | CSCwt69100 | :white_check_mark: | :no_entry_sign:
[InfraVLAN Overlap in Access Policy VLAN Pools][d38] | CSCwt58626 | :white_check_mark: | :no_entry_sign:

[d1]: #ep-announce-compatibility
[d2]: #eventmgr-db-size-defect-susceptibility
Expand Down Expand Up @@ -244,6 +245,7 @@ Items | Defect | This Script
[d35]: #wred-with-affected-fm-models
[d36]: #n9k-c93180yc-fx3-switch-memory-less-than-32gb
[d37]: #stale-dbgacepgsummarytask-objects
[d38]: #infravlan-overlap-access-policy-check

## General Check Details

Expand Down Expand Up @@ -2846,6 +2848,12 @@ Affected versions: 6.1(5e) and below, or 6.2(1g).
Contact Cisco TAC for next steps. For more details, refer to the workaround in [CSCwt69100][75].


### Infravlan Overlap Access Policy Check

Due to the bug [CSCwt58626][77] , If Apic upgrade planned for target versions 6.1(3f), 6.1(3g), 6.1(4h), 6.1(5e) and 6.2(1g), be aware of fault F4701 being raised if the InfraVLAN overlaps with any user-configured VLAN pool in Access Policies. This also affects vlan pool created by NDO/MSO, VMM, Kubernetes. After the upgrade, domains associated with those VLAN pools cannot be linked to new EPGs, although existing EPGs continue to function.

To avoid this issue, modify the user VLAN pool ranges so that the InfraVLAN does not overlap with any configured block, or select a non-impacted fixed version. After upgrading to a fixed version this fault and Restriction have been removed.

[0]: https://github.com/datacenter/ACI-Pre-Upgrade-Validation-Script
[1]: https://www.cisco.com/c/dam/en/us/td/docs/Website/datacenter/apicmatrix/index.html
[2]: https://www.cisco.com/c/en/us/support/switches/nexus-9000-series-switches/products-release-notes-list.html
Expand Down Expand Up @@ -2923,4 +2931,4 @@ Contact Cisco TAC for next steps. For more details, refer to the workaround in [
[74]: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwm42741
[75]: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt69100
[76]: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt38698

[77]: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt58626
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
[]
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
[
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-200]-to-[vlan-300]",
"role": "external",
"from": "vlan-200",
"to": "vlan-300",
"dn": "uni/infra/vlanns-[vlan_pool1]-static/from-[vlan-200]-to-[vlan-300]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-500]-to-[vlan-1000]",
"role": "external",
"from": "vlan-500",
"to": "vlan-1000",
"dn": "uni/infra/vlanns-[vlan_pool2]-static/from-[vlan-500]-to-[vlan-1000]"
}
}
}
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
[
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-100]-to-[vlan-4094]",
"role": "external",
"from": "vlan-100",
"to": "vlan-4094",
"dn": "uni/infra/vlanns-[vlan_pool1]-static/from-[vlan-100]-to-[vlan-4094]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-2`00]-to-[vlan-4094]",
"role": "internal",
"from": "vlan-100",
"to": "vlan-4094",
"dn": "uni/infra/vlanns-[vlan_pool2]-static/from-[vlan-200]-to-[vlan-4094]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-4000]-to-[vlan-4094]",
"role": "external",
"from": "vlan-4000",
"to": "vlan-4094",
"dn": "uni/infra/vlanns-[vlan_pool3]-static/from-[vlan-4000]-to-[vlan-4094]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-1751]-to-[vlan-4094]",
"role": "external",
"from": "vlan-1751",
"to": "vlan-4094",
"dn": "uni/vmmp-VMware/dom-k8s-scale-vmm/usrcustomaggr-k8srkesetup1/from-[vlan-1751]-to-[vlan-4094]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-1752]-to-[vlan-4094]",
"role": "external",
"from": "vlan-1752",
"to": "vlan-4094",
"dn": "uni/vmmp-VMware/dom-k8s-scale-vmm/usrcustomaggr-k8srkesetup1/from-[vlan-1752]-to-[vlan-4094]"
}
}
}
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
[
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-100]-to-[vlan-4094]",
"role": "external",
"from": "vlan-100",
"to": "vlan-4094",
"dn": "uni/infra/vlanns-[vlan_pool]-static/from-[vlan-100]-to-[vlan-4094]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-1751]-to-[vlan-1751]",
"role": "external",
"from": "vlan-1751",
"to": "vlan-1751",
"dn": "uni/vmmp-VMware/dom-k8s-scale-vmm/usrcustomaggr-k8srkesetup1/from-[vlan-1751]-to-[vlan-1751]"
}
}
},
{
"fvnsEncapBlk": {
"attributes": {
"allocMode": "static",
"annotation": "orchestrator:aci-containers-controller",
"rn": "from-[vlan-1752]-to-[vlan-1752]",
"role": "external",
"from": "vlan-1752",
"to": "vlan-1752",
"dn": "uni/vmmp-VMware/dom-k8s-scale-vmm/usrcustomaggr-k8srkesetup1/from-[vlan-1752]-to-[vlan-1752]"
}
}
}
]
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
[]
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
[
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-201/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-201"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-202/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-202"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-203/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-203"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-204/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-204"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-205/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-205"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-206/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-206"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-207/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-207"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-208/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-208"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-209/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-209"
}
}
},
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-210/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-210"
}
}
}
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
[
{
"lldpInst": {
"attributes": {
"adminSt": "enabled",
"dn": "topology/pod-1/node-201/sys/lldp/inst",
"infraVlan": "vlan-4093",
"sysDesc": "topology/pod-1/node-201"
}
}
}
]
Loading
Loading