Skip to content

fix(dim): make ndcli list containers 0.0.0.0/0 not throw a 1064 - #319

Open
miesi wants to merge 1 commit into
IONOS-Core:masterfrom
miesi:fix/ancestor-query-prefix-zero
Open

miesi wants to merge 1 commit into
IONOS-Core:masterfrom
miesi:fix/ancestor-query-prefix-zero

Conversation

@miesi

@miesi miesi commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

…ding it

_ancestors_noparent_condition() builds its WHERE clause by joining one term per prefix length above the block. At prefix 0 there is nothing above, so the join produced an empty string, which it then wrapped in parentheses and handed to the database as "()" -- a 1064 syntax error.

That was worked around by giving each caller that could reach prefix 0 its own if ip.prefix != 0 guard: in Ipblock._tree_update(), in _find_ipblock() and on the guess_function of ipblock_create(). The broken query stayed, waiting for the next caller.

Fix the cause: an empty disjunction is false, so return false() and let callers get the empty result set that is the correct answer. The three guards then say nothing the query does not already say, and are removed.

Verified behaviour-neutral: of the seven new tests, five pass both with and without this change -- they pin down exactly what the guards used to provide. The other two go at the query directly and are the ones that fail without it.

Not addressed, found while reading: _find_ipblock() computes status_str = ' or '.join(status) unconditionally, but its status parameter defaults to None and ipblock_list() passes it through. Reachable over the API with a block that does not exist exactly; not reachable through ndcli, which never calls ipblock_list.

Internal ticket: ITOUDP-5168

…ding it

_ancestors_noparent_condition() builds its WHERE clause by joining one term
per prefix length above the block. At prefix 0 there is nothing above, so the
join produced an empty string, which it then wrapped in parentheses and handed
to the database as "()" -- a 1064 syntax error.

That was worked around by giving each caller that could reach prefix 0 its own
`if ip.prefix != 0` guard: in Ipblock._tree_update(), in _find_ipblock() and on
the guess_function of ipblock_create(). The broken query stayed, waiting for
the next caller.

Fix the cause: an empty disjunction is false, so return false() and let callers
get the empty result set that is the correct answer. The three guards then say
nothing the query does not already say, and are removed.

Verified behaviour-neutral: of the seven new tests, five pass both with and
without this change -- they pin down exactly what the guards used to provide.
The other two go at the query directly and are the ones that fail without it.

Not addressed, found while reading: _find_ipblock() computes
`status_str = ' or '.join(status)` unconditionally, but its `status` parameter
defaults to None and ipblock_list() passes it through. Reachable over the API
with a block that does not exist exactly; not reachable through ndcli, which
never calls ipblock_list.

@eschweikert eschweikert left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eschweikert eschweikert left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cood looks good. Please add the sql sheme update

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants