2017-10-24 00:01:42 -05:00
|
|
|
FROM docker-config-engine
|
|
|
|
|
2018-06-25 12:48:42 -05:00
|
|
|
ARG docker_container_name
|
2018-09-11 16:57:29 -05:00
|
|
|
RUN [ -f /etc/rsyslog.conf ] && sed -ri "s/%syslogtag%/$docker_container_name#%syslogtag%/;" /etc/rsyslog.conf
|
2018-06-25 12:48:42 -05:00
|
|
|
|
2017-10-24 00:01:42 -05:00
|
|
|
## Make apt-get non-interactive
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
|
|
|
2017-11-30 16:59:25 -06:00
|
|
|
COPY ["sonic-dev.gpg.key", "/etc/apt/"]
|
|
|
|
RUN apt-key add /etc/apt/sonic-dev.gpg.key
|
|
|
|
RUN echo "deb http://packages.microsoft.com/repos/sonic-dev/ jessie main" >> /etc/apt/sources.list
|
2017-10-24 00:01:42 -05:00
|
|
|
RUN apt-get update
|
|
|
|
|
|
|
|
RUN apt-get install -y net-tools \
|
2017-11-30 16:59:25 -06:00
|
|
|
arping \
|
Fix potential blackholing/looping traffic when link-local was used and refresh ipv6 neighbor to avoid CPU hit (#1904)
* Fix potential blackholing/looping traffic and refresh ipv6 neighbor to avoid CPU hit
In case ipv6 global addresses were configured on L3 interfaces and used for peering,
and routing protocol was using link-local addresses on the same interfaces as prefered nexthops,
the link-local addresses could be aged out after a while due to no activities towards the link-local
addresses themselves. And when we receive new routes with the link-local nexthops, SONiC won't insert
them to the HW, and thus cause looping or blackholing traffic.
Global ipv6 addresses on L3 interfaces between switches are refreshed by BGP keeplive and other messages.
On server facing side, traffic may hit fowarding plane only, and no refresh for the ipv6 neighbor entries regularly.
This could age-out the linux kernel ipv6 neighbor entries, and HW neighbor table entries could be removed,
and thus traffic going to those neighbors would hit CPU, and cause traffic drop and temperary CPU high load.
Also, if link-local addresses were not learned, we may not get them at all later.
It is intended to fix all above issues.
Changes:
Add ndisc6 package in swss docker and use it for ipv6 ndp ping to update the neighbors' state on Vlan interfaces
Change the default ipv6 neighbor reachable timer to 30mins
Add periodical ipv6 multicast ping to ff02::11 to get/refresh link-local neighbor info.
* Fix review comments:
Add PORTCHANNEL_INTERFACE interface for ipv6 multicast ping
format issue
* Combine regular L3 interface and portchannel interface for looping
* Add ndisc6 package to vs docker
2018-08-12 05:14:55 -05:00
|
|
|
ndisc6 \
|
2017-10-24 00:01:42 -05:00
|
|
|
ethtool \
|
|
|
|
tcpdump \
|
|
|
|
ifupdown \
|
|
|
|
bridge-utils \
|
|
|
|
python-ply \
|
|
|
|
libqt5core5a \
|
|
|
|
libqt5network5 \
|
|
|
|
libboost-program-options1.55.0 \
|
|
|
|
libboost-system1.55.0 \
|
|
|
|
libboost-thread1.55.0 \
|
|
|
|
libgmp10 \
|
|
|
|
libjudydebian1 \
|
|
|
|
libnanomsg0 \
|
|
|
|
libdaemon0 \
|
|
|
|
libjansson4 \
|
|
|
|
libjemalloc1 \
|
|
|
|
openssh-client \
|
|
|
|
openssh-server \
|
|
|
|
libc-ares2 \
|
2017-11-03 19:13:39 -05:00
|
|
|
iproute \
|
2017-11-30 16:59:25 -06:00
|
|
|
libpython2.7 \
|
|
|
|
grub2-common \
|
|
|
|
python-click-default-group \
|
|
|
|
python-click \
|
|
|
|
python-natsort \
|
|
|
|
python-tabulate \
|
|
|
|
bash-completion \
|
|
|
|
libelf1 \
|
2018-11-06 23:07:12 -06:00
|
|
|
libmnl0 \
|
|
|
|
logrotate \
|
|
|
|
apt-utils \
|
2018-11-09 19:06:09 -06:00
|
|
|
psmisc \
|
|
|
|
tcpdump \
|
|
|
|
python-scapy
|
2017-10-24 00:01:42 -05:00
|
|
|
|
2017-11-14 05:23:39 -06:00
|
|
|
RUN pip install setuptools
|
|
|
|
RUN pip install py2_ipaddress
|
2018-08-23 21:11:53 -05:00
|
|
|
RUN pip install six
|
2018-11-09 19:06:09 -06:00
|
|
|
RUN pip install pyroute2==0.5.3 netifaces==0.10.7
|
|
|
|
RUN pip install monotonic==1.5
|
2017-11-13 16:38:07 -06:00
|
|
|
|
2018-05-02 13:46:21 -05:00
|
|
|
{% if docker_sonic_vs_debs.strip() -%}
|
|
|
|
# Copy locally-built Debian package dependencies
|
|
|
|
{%- for deb in docker_sonic_vs_debs.split(' ') %}
|
|
|
|
COPY debs/{{ deb }} /debs/
|
2017-10-24 00:01:42 -05:00
|
|
|
{%- endfor %}
|
|
|
|
|
2018-05-02 13:46:21 -05:00
|
|
|
# Install locally-built Debian packages and implicitly install their dependencies
|
|
|
|
{%- for deb in docker_sonic_vs_debs.split(' ') %}
|
|
|
|
RUN dpkg_apt() { [ -f $1 ] && { dpkg -i $1 || apt-get -y install -f; } || return 1; }; dpkg_apt /debs/{{ deb }}
|
|
|
|
{%- endfor %}
|
|
|
|
{%- endif %}
|
|
|
|
|
|
|
|
# Clean up
|
|
|
|
RUN apt-get clean -y
|
|
|
|
RUN apt-get autoclean -y
|
|
|
|
RUN apt-get autoremove -y
|
|
|
|
RUN rm -rf /debs ~/.cache
|
2017-10-24 00:01:42 -05:00
|
|
|
|
2017-11-13 16:38:07 -06:00
|
|
|
RUN sed -ri 's/^(save .*$)/# \1/g; \
|
|
|
|
s/^daemonize yes$/daemonize no/; \
|
2017-10-24 00:01:42 -05:00
|
|
|
s/^logfile .*$/logfile ""/; \
|
|
|
|
s/^# syslog-enabled no$/syslog-enabled no/; \
|
2017-11-13 16:38:07 -06:00
|
|
|
s/^# unixsocket/unixsocket/; \
|
2017-11-30 16:59:25 -06:00
|
|
|
s/notify-keyspace-events ""/notify-keyspace-events AKE/; \
|
2017-11-13 16:38:07 -06:00
|
|
|
s/^client-output-buffer-limit pubsub [0-9]+mb [0-9]+mb [0-9]+/client-output-buffer-limit pubsub 0 0 0/ \
|
2017-10-24 00:01:42 -05:00
|
|
|
' /etc/redis/redis.conf
|
|
|
|
|
|
|
|
COPY ["50-default.conf", "/etc/rsyslog.d/"]
|
|
|
|
COPY ["start.sh", "orchagent.sh", "/usr/bin/"]
|
|
|
|
COPY ["supervisord.conf", "/etc/supervisor/conf.d/"]
|
2017-11-30 16:59:25 -06:00
|
|
|
COPY ["files/configdb-load.sh", "/usr/bin/"]
|
2019-01-30 04:04:20 -06:00
|
|
|
COPY ["files/arp_update", "/usr/bin/"]
|
2019-02-01 13:18:02 -06:00
|
|
|
COPY ["files/buffers_config.j2", "files/qos_config.j2", "/usr/share/sonic/templates/"]
|
2018-11-21 00:32:40 -06:00
|
|
|
COPY ["files/sonic_version.yml", "/etc/sonic/"]
|
2017-10-24 00:01:42 -05:00
|
|
|
|
2018-11-09 19:06:09 -06:00
|
|
|
# Workaround the tcpdump issue
|
|
|
|
RUN mv /usr/sbin/tcpdump /usr/bin/tcpdump
|
|
|
|
|
2017-11-13 16:38:07 -06:00
|
|
|
RUN echo "docker-sonic-vs" > /etc/hostname
|
2017-11-30 16:59:25 -06:00
|
|
|
RUN touch /etc/quagga/zebra.conf
|
2017-11-13 16:38:07 -06:00
|
|
|
|
2018-11-16 11:40:35 -06:00
|
|
|
# Create /var/warmboot/teamd folder for teammgrd
|
|
|
|
RUN mkdir -p /var/warmboot/teamd
|
|
|
|
|
2017-10-24 00:01:42 -05:00
|
|
|
ENTRYPOINT ["/usr/bin/supervisord"]
|