mirror of
https://github.com/dtzp555-max/aci-sim.git
synced 2026-07-21 21:15:12 +00:00
feat(validation): server-side MO value validation — real-APIC 400 on bad values (v0.23.0)
Closes F10: the sim silently stored out-of-range/malformed scalar values
(e.g. vlan-9999, IP 999.888.777.x) that real APIC/NDO reject server-side.
New aci_sim/rest_aci/validators.py: table-driven RULES {(class,prop) -> validator}
(range/enum/IP·MAC-format/vlan-encap). Enforced in writes.py::_validate_planned
(APIC) and ndo/patch.py::apply_json_patch (NDO) before any store mutation.
Fail-safe default-allow: only registered (class,prop) validated; unknown pass.
Bad values now -> APIC Error 103 Malformed MO body. ~45 rules / ~18 classes.
Constraints sourced from vendored cisco.aci arg-specs + standard ACI ranges,
cross-checked against the real-machine var corpus for zero false-rejects
(regression: full create_tenant MS-TN1 + SF-TN1 chains stay green). +176 tests
(1098 passed). Referential integrity split out as F11 (needs real-APIC study).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017zdUTqU9fvCCvF3uVGZsu1
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ffaf9964c2
commit
fe3d13221a
@@ -6,6 +6,32 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
|
||||
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html)
|
||||
(pre-1.0: minor bumps may include breaking changes to the sim's behavior).
|
||||
|
||||
## [0.23.0] - 2026-07-09
|
||||
|
||||
### Added
|
||||
- **Server-side value validation (F10)**: the sim now rejects out-of-range /
|
||||
malformed scalar MO property values that real APIC/NDO reject server-side,
|
||||
instead of silently storing them. New `aci_sim/rest_aci/validators.py` holds a
|
||||
table-driven `RULES: {(class, prop) -> validator}` registry (range / enum /
|
||||
IP·MAC-format / vlan-encap checks); `writes.py::_validate_planned` (APIC) and
|
||||
`ndo/patch.py::apply_json_patch` (NDO) enforce it before any store mutation.
|
||||
**Fail-safe default-allow**: only registered `(class, prop)` pairs are checked,
|
||||
so unknown properties pass untouched (no false-rejects). Bad values now return
|
||||
`APIC Error 103: Malformed MO body: Invalid value ...` (real-APIC-style) —
|
||||
e.g. VLAN encap outside [1,4094], VXLAN outside [1,16777215], invalid
|
||||
IPv4/IPv6 address, ASN out of range, malformed MAC, out-of-range MTU/port.
|
||||
Constraints sourced from the vendored cisco.aci module arg-specs and standard
|
||||
ACI ranges, cross-checked against the real-machine var corpus for zero
|
||||
false-rejects. ~45 rules across ~18 MO classes; +176 tests. Closes the F10
|
||||
fidelity gap (previously a var with `vlan-9999` / `999.888.777.x` pushed
|
||||
rc=0 and was stored; now 400 + not stored).
|
||||
|
||||
### Notes
|
||||
- Referential integrity (service-graph device / BD-VRF must-exist) is
|
||||
deliberately NOT included here — tracked separately (F11), as it needs a
|
||||
real-APIC fidelity study to avoid over-rejecting the dangling refs that real
|
||||
APIC tolerates.
|
||||
|
||||
## [0.22.0] - 2026-07-08
|
||||
|
||||
### Added
|
||||
|
||||
Reference in New Issue
Block a user