dhcp: send DHCPRELEASE with the client IP addr as ciaddr - #1279
Merged
Conversation
The dhcp IPAM plugin sends DHCPRELEASE packets with 0.0.0.0 as the IP source address instead of the client's assigned IP. This violates RFC 2131 section 4.4.4 and causes DHCP servers (e.g. dnsmasq) to silently ignore the release. Leases are never freed — they only expire via timeout. By using the `nclient4.WithUnicast()` option, the client will stop using a raw packet socket which constructs IP headers with 0.0.0.0 as the source. Using src IP 0.0.0.0 is appropriate for DHCPDISCOVER (no address assigned yet) but wrong for DHCPRELEASE. Signed-off-by: Miguel Duarte Barroso <mdbarroso@redhat.com>
Contributor
Author
|
Tested this fix manually and it is working as expected - CNI DEL with DHCP IPAM sends the DHCPRELEASE msg w/ the proper source IP address, and in turn, dnsmasq actually processes the packet and releases the DHCP lease. |
Contributor
|
LGTM |
MikeZappa87
approved these changes
Aug 3, 2026
Contributor
maiqueb
added a commit
to maiqueb/openperouter
that referenced
this pull request
Aug 4, 2026
Consume the DHCP release fix (containernetworking/plugins#1279) which has not been included in a release yet. Pin to the merge commit SHA and switch the Dockerfile clone strategy to a shallow fetch-by-SHA, since git clone --branch does not accept a commit hash. Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Miguel Duarte Barroso <mdbarroso@redhat.com>
maiqueb
added a commit
to maiqueb/openperouter
that referenced
this pull request
Aug 4, 2026
Now that we consume the upstream fix (containernetworking/plugins#1279), DHCPRELEASE carries the correct ciaddr and dnsmasq honours it. Flip the assertion from expecting the lease to persist to expecting it to be gone. Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Miguel Duarte Barroso <mdbarroso@redhat.com>
maiqueb
added a commit
to maiqueb/openperouter
that referenced
this pull request
Aug 4, 2026
Consume the DHCP release fix (containernetworking/plugins#1279) which has not been included in a release yet. Pin to the merge commit SHA and switch the Dockerfile clone strategy to a shallow fetch-by-SHA, since git clone --branch does not accept a commit hash. Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Miguel Duarte Barroso <mdbarroso@redhat.com>
maiqueb
added a commit
to maiqueb/openperouter
that referenced
this pull request
Aug 4, 2026
Now that we consume the upstream fix (containernetworking/plugins#1279), DHCPRELEASE carries the correct ciaddr and dnsmasq honours it. Flip the assertion from expecting the lease to persist to expecting it to be gone. Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Miguel Duarte Barroso <mdbarroso@redhat.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The dhcp IPAM plugin sends DHCPRELEASE packets with 0.0.0.0 as the IP source address instead of the client's assigned IP.
This violates RFC 2131 section 4.4.4 (quote below) and causes DHCP servers (e.g. dnsmasq) to silently ignore the release. Leases are never freed - they only expire via timeout.
By using the
nclient4.WithUnicast()option to create theDHCPClient, the client will send unicast msgs.Fixes: #1278