Tuesday, 2026-09-22

@mnasiadka:matrix.orgOk, had some fiddling with ipv6 on mirror03 in VexxHost's ca-ymq-1 region, and what we're getting is some... rogue ipv6 ND with router bit set? Although it comes from MAC addresses that are not Neutron ports (I checked both projects in VexxHost):11:26
```
# tcpdump -i ens3 -nn -tttt -e 'icmp6 and ip6[40] == 136 and (ip6[44] & 0x80 != 0)' -vvv
tcpdump: listening on ens3, link-type EN10MB (Ethernet), snapshot length 262144 bytes
2026-09-22 11:25:52.405053 fa:16:3e:b0:bb:6e > 33:33:00:00:00:01, ethertype IPv6 (0x86dd), length 86: (hlim 255, next-header ICMPv6 (58) payload length: 32) 2604:e100:1:0:f816:3eff:feb0:bb6e > ff02::1: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is 2604:e100:1:0:f816:3eff:feb0:bb6e, Flags [router, override]
destination link-address option (2), length 8 (1): fa:16:3e:b0:bb:6e
0x0000: fa16 3eb0 bb6e
```
@mnasiadka:matrix.org* Ok, had some fiddling with ipv6 on mirror03 in VexxHost's ca-ymq-1 region, and what we're getting is some... rogue ipv6 ND with router bit set? Although it comes from MAC addresses that are not Neutron ports (I checked both projects in VexxHost):11:27
```
# tcpdump -i ens3 -nn -tttt -e 'icmp6 and ip6[40] == 136 and (ip6[44] & 0x80 != 0)' -vvv
tcpdump: listening on ens3, link-type EN10MB (Ethernet), snapshot length 262144 bytes
2026-09-22 11:25:52.405053 fa:16:3e:b0:bb:6e > 33:33:00:00:00:01, ethertype IPv6 (0x86dd), length 86: (hlim 255, next-header ICMPv6 (58) payload length: 32) 2604:e100:1:0:f816:3eff:feb0:bb6e > ff02::1: [icmp6 sum ok] ICMP6,
neighbor advertisement, length 32, tgt is 2604:e100:1:0:f816:3eff:feb0:bb6e, Flags [router, override]
destination link-address option (2), length 8 (1): fa:16:3e:b0:bb:6e
0x0000: fa16 3eb0 bb6e
```
@mnasiadka:matrix.org* Ok, had some fiddling with ipv6 on mirror03 in VexxHost's ca-ymq-1 region, and what we're getting is some... rogue ipv6 ND with router bit set? Although it comes from MAC addresses that are not Neutron ports (I checked both projects in VexxHost):11:27
```
root@mirror03:~# tcpdump -i ens3 -nn -tttt -e 'icmp6 and ip6[40] == 136 and (ip6[44] & 0x80 != 0)' -vvv
tcpdump: listening on ens3, link-type EN10MB (Ethernet), snapshot length 262144 bytes
2026-09-22 11:25:52.405053 fa:16:3e:b0:bb:6e > 33:33:00:00:00:01, ethertype IPv6 (0x86dd), length 86: (hlim 255, next-header ICMPv6 (58) payload length: 32) 2604:e100:1:0:f816:3eff:feb0:bb6e > ff02::1: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is 2604:e100:1:0:f816:3eff:feb0:bb6e, Flags [router, override]
destination link-address option (2), length 8 (1): fa:16:3e:b0:bb:6e
0x0000: fa16 3eb0 bb6e
```
@mnasiadka:matrix.org* Ok, had some fiddling with ipv6 on mirror03 in VexxHost's ca-ymq-1 region, and what we're getting is some...11:36
rogue ipv6 ND with router bit set?
Although it comes from MAC addresses that are not Neutron ports (I checked both projects in VexxHost):
```
root@mirror03:~# tcpdump -i ens3 -nn -tttt -e 'icmp6 and ip6[40] == 136 and (ip6[44] & 0x80 != 0)' -vvv
tcpdump: listening on ens3, link-type EN10MB (Ethernet), snapshot length 262144 bytes
2026-09-22 11:25:52.405053 fa:16:3e:b0:bb:6e > 33:33:00:00:00:01, ethertype IPv6 (0x86dd), length 86: (hlim 255, next-header ICMPv6 (58) payload length: 32) 2604:e100:1:0:f816:3eff:feb0:bb6e > ff02::1: [icmp6 sum ok] ICMP6, neighbor advertisement, length 32, tgt is 2604:e100:1:0:f816:3eff:feb0:bb6e, Flags [router, override]
destination link-address option (2), length 8 (1): fa:16:3e:b0:bb:6e
0x0000: fa16 3eb0 bb6e
```
@mnasiadka:matrix.orgmnaser: Any idea what can cause this? ^^11:37
@mnasiadka:matrix.orgBasically two mac addresses are sending those packets:11:39
- fa:16:3e:fa:c5:a8
- fa:16:3e:b0:bb:6e
@mnasiadka:matrix.orgOk, opened a ticket in VexxHost11:46
@fungicide:matrix.orgthanks mnasiadka! hopefully that's enough for them to track down through bridge tables/ports to find where they originate12:58
@mnasiadka:matrix.orgYes, they replied they are on it, so I assume there should be an answer soon :-)12:58
@mnasiadka:matrix.orgShould I use some shared mailbox for such tickets in future?12:59
@fungicide:matrix.orgfa:16:3e is our infra-root at openstack.org inbox is what we usually use13:01
@fungicide:matrix.orger, i spliced two comments there, sorry13:01
@fungicide:matrix.orgfa:16:3e is not showing up in my old ieee oui tables13:01
@fungicide:matrix.orglooks likely to be locally-administered13:03
@mnasiadka:matrix.orgIsn't fa:16:3e what Neutron usually uses?13:10
@fungicide:matrix.orgno idea, since (amusingly) i don't really manage neutron with any regularity13:13
@fungicide:matrix.orgbut if it is, then it could either be something leaking from another part of the cloud infrastructure, or from neutron running in a devstack for one of our test nodes (which would still be concerning as it's in a different tenant)13:15
@mnasiadka:matrix.orgthe mac addresses are not visible as neutron ports from any of two tenants that we own, so I'd assume it's a third tenant or something like that? a bit weird13:46
@mnasiadka:matrix.orgmaybe that public network is shared amongst all tenants13:49
@jim:acmegating.comquick update on the blob-store related zuul issue: i don't see any errors today, so i'm going to examine the theory that either the upgrade or restart caused the issues as a one-time event.13:54
@jim:acmegating.comi think i have found the issue with the blob store; i have monkeypatched the production schedulers with the fix, though, due to the nature of the error, there could be some lingering issues; they should clear up on their own eventually.18:41
@clarkb:matrix.orglooks like zuul got a fix proposed too18:42
@jim:acmegating.comyep; would be good to restart with that once it merges18:43
@fungicide:matrix.orgit looks like i'll need to adjust the compacting logic in the prune-borg-backups script, i missed that we're writing a heredoc into sudo so the flag envvar we set in the outer portion of the script doesn't make it into that inner script20:12
@fungicide:matrix.org#status log Pruned /opt/backups-202605 on backup03.ca-ymq-1.vexxhost reducing utilization from 97% to 47%20:49
@status:opendev.org@fungicide:matrix.org: finished logging20:49
@fungicide:matrix.orgthat was after i commented out the conditional to force it to compact on that server20:50
@fungicide:matrix.orgi've added myself a reminder to figure out how to correct the script so the var gets passed in properly20:50
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/system-config] 1006843: Update Gerrit images to 3.13.9 and 3.14.3 https://review.opendev.org/c/opendev/system-config/+/100684321:40
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/system-config] 1006843: Update Gerrit images to 3.13.9 and 3.14.3 https://review.opendev.org/c/opendev/system-config/+/100684321:51
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [opendev/system-config] 1006843: Update Gerrit images to 3.13.9 and 3.14.3 https://review.opendev.org/c/opendev/system-config/+/100684322:50
@fungicide:matrix.org#status notice The Gerrit service on review.opendev.org will be offline momentarily while we upgrade to a new patch release, but should return within a few minutes23:00
@status:opendev.org@fungicide:matrix.org: sending notice23:00
-@status:opendev.org- NOTICE: The Gerrit service on review.opendev.org will be offline momentarily while we upgrade to a new patch release, but should return within a few minutes23:03
@status:opendev.org@fungicide:matrix.org: finished sending notice23:03
@jim:acmegating.com#status log restarted zuul schedulers with blobstore fix23:03
@status:opendev.org@jim:acmegating.com: finished logging23:03
-@gerrit:opendev.org- Clark Boylan proposed: [opendev/bindep] 1006865: DNM push check for gerrit https://review.opendev.org/c/opendev/bindep/+/100686523:06

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!