Sign inSign up

stormotron/lbd

By stormotron

•Updated over 1 year ago

LBD is a program for detecting loops in complex infrastructure built on libvirt/qemu

Image
Networking
Security
0

405

stormotron/lbd repository overview

⁠LBD

Copyright (c) Netstorm, 2025

LBD is a program for detecting loops in complex infrastructure built on libvirt/qemu, such as Openstack. The detection is built similar to the functionality of D-Link switches, see https://www.dlink.ru/ru/faq/62/242.html⁠ .

The program settings are stored in the /etc/lbd.conf file and have the following parameters:

1) interfaces - comma separated list of interfaces to be processed, wildcard is allowed;
2) block - whether blocking is required in case of loop detection, true or false - the function is licensed;
3) interval - interval in seconds (from 1 to 60) with which interfaces should be polled by LBD;
4) recover - time in seconds (from 60 to 600) to recover from the loop, relevant only when block is enabled;
5) mac - MAC address of the system on behalf of which LBD packets are sent (unicast MAC);
6) serial - serial number of the program or demo. To get your serial number, please copy Request code and contact [email protected].

Example /etc/lbd.conf:

interfaces=tap*
block=true
interval=3
recover=61
mac=00:11:22:33:44:55
serial=demo

The LBD is essentially a stormcontrol (by Netstorm) successor, which previously in older Openstack revisions performed the loop detection function from indirect signs such as Multicast and Broadcast storm bursts. As well as the switches have stormcontrol functionality, it also performed a similar function with the ability to block traffic on Linux bridges. However, LBD is more versatile in this regard and is able to detect a loop directly in the interface.

When you start the program, you will see inscriptions indicating the beginning of traffic processing in separate threads like:

[INFO] Start listening on tap104cb8b4-44

Systems like Openstack are constantly adding and removing interfaces, the program dynamically tracks the appearance and removal of interfaces, and will report on this:

[INFO] Stop listening on tap2002b3a4-65
[INFO] Start listening on tap2002b3a4-65

If a loop is detected on one of the ports being monitored, a warning will be issued:

[ALERT] Loopback detected on tap367367a2-53

The loop detection phenomenon is not a state at a specific point in time, so detection messages are throttled to avoid redundant information in the operator console. Each detection message will only be repeated after one minute if the loop state persists.

If the block flag is set and the program license is correct, port blocking will occur:

[INFO] Blocking interface tap367367a2-53 for 61 seconds
[INFO] Stop listening on tap367367a2-53

When the block timer expires, the port will be unlocked:

[INFO] Unblocked interface tap367367a2-53
[INFO] Start listening on tap367367a2-53

The program must be run as root, i.e. uid=0, gid=0, because it has system access. The program is supplied only as a binary file, no open source code is supplied for it. If you have found any defects, please inform us at [email protected]⁠ .

Docker:

Since version 0.0.5, all LBD images have been ported to Docker and allow you to run the program on almost any x86-amd64 Linux platform.

Use the following command to run LBD:

# docker run --cap-add=NET_ADMIN --net=host --name lbd -d stormotron/lbd:latest

The following environment variables can be used when running Docker:

- SERIAL - string, default demon;
- INTERFACES - string, default tap*;
- BLOCK - string, true or false, default false;
- INTERVAL - integer, default, default 3;
- RECOVER - integer, default, default 61;
- MAC - MAC, default 00:11:22:33:44:55.

Example:

# docker run --cap-add=NET_ADMIN --net=host -e INTERVAL=5 -e RECOVER=120 --name lbd -d stormotron/lbd:latest

Changelog:

  • 0.0.3 – LongTerm release
  • 0.0.4 – Huge performance optimizations (4 times speedup)
  • 0.0.5 – Fix bug in 0.0.4 - doesn’t re-inspect interface when BLOCK=true and unblocked after Loopdetect

Tag summary

Content type

Image

Digest

sha256:56a28df57…

Size

5.8 MB

Last updated

over 1 year ago

docker pull stormotron/lbd