RDKB-66541 : Initial code changes for gaurdian - #40
Draft
rajkamal-cv wants to merge 4 commits into
Draft
rajkamal-cv wants to merge 4 commits into
rajkamal-cv wants to merge 4 commits into
Conversation
|
📋 PR Format Reminder
Expected: |
rajkamal-cv
marked this pull request as draft
September 8, 2026 11:36
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The new guardian OVS “show” path can mask command failures and config parsing silently truncates over-limit entries, both of which can lead to incorrect/opaque runtime behavior.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds an initial native-C “guardian” OpenFlow policy agent to the existing OVS agent build, intended as an early scaffold/port of guardian.sh with incremental follow-up work planned.
Changes:
- Integrates a new
source/guardiansubdirectory and wires it into Autotools (SUBDIRS,AC_CONFIG_FILES). - Introduces a
guardianCLI binary with basic command parsing and partial flow generation scaffolding. - Implements initial OVS interaction using
ovs-ofctl(clear + add-flows; show via dump-flows).
File summaries
| File | Description |
|---|---|
| source/Makefile.am | Adds guardian to build subdirectories. |
| source/guardian/Makefile.am | Defines build for the new guardian program. |
| source/guardian/guardian.h | Adds shared constants and CLI command enum. |
| source/guardian/guardian_ovs.h | Declares OVS apply/clear/show interface. |
| source/guardian/guardian_ovs.c | Implements ovs-ofctl-based apply/clear/show. |
| source/guardian/guardian_main.c | Implements CLI parsing and command dispatch. |
| source/guardian/guardian_flows.h | Declares flowset representation and generator API. |
| source/guardian/guardian_flows.c | Adds initial flow generation scaffold. |
| source/guardian/guardian_config.h | Declares config load/accessor APIs. |
| source/guardian/guardian_config.c | Implements initial INI-style config parsing scaffold. |
| configure.ac | Adds guardian Makefile generation to configure. |
Review details
Suppressed comments (1)
source/guardian/guardian_config.c:106
- When the number of parsed [devices] entries exceeds MAX_DEVICES, the current logic silently ignores additional entries (because of the
cfg->n_devices < MAX_DEVICESguard). That can result in a partially applied policy with no error returned to the caller.
char mac[MAX_NAME], grp[MAX_NAME];
if (sscanf(s, "%63s %63s", mac, grp) == 2 && cfg->n_devices < MAX_DEVICES) {
struct device_entry *d = &cfg->devices[cfg->n_devices++];
snprintf(d->mac, sizeof d->mac, "%s", mac);
snprintf(d->group, sizeof d->group, "%s", grp);
- Files reviewed: 11/11 changed files
- Comments generated: 4
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Initial port of https://gerrit.teamccp.com/#/c/964212/