Repository navigation
Conversation
Since v2.7.5 (amazonlinux#162), get_meta() forwards curl's stderr to syslog at err priority on every attempt. Single-attempt callers query keys that may legitimately be absent (ipv4-prefix when no prefix is delegated, network-card on single-card instance types), so each refresh of a secondary interface now logs 'curl: (22) The requested URL returned error: 404' as an error. get_meta() already suppresses its own summary error for max_tries=1 for exactly this reason. Apply the same rule to curl's stderr, and keep forwarding it at err priority for retrying callers. Add regression tests in tests/imds.bats covering both paths. Fixes amazonlinux#175
joeysk2012
reviewed
Sep 30, 2026
| # network-card on single-card instance types), so a 404 is an | ||
| # expected outcome rather than an error. Discard curl's stderr to | ||
| # match the summary error suppression below. | ||
| meta=$(curl "${curl_opts[@]}" "$url" 2> /dev/null) |
Contributor
There was a problem hiding this comment.
would this swallow the errors?
Contributor
Author
There was a problem hiding this comment.
Yes, as designed. See full GH issue & PR description for context on why this is actually ok.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #175
Description of changes
Since v2.7.5 (#162),
get_meta()forwards curl's stderr to syslog aterrpriority on every attempt. Single-attempt callers query keys that may legitimately be absent, so every refresh of a secondary interface now logs:once for
ipv4-prefix(no prefix delegated) and once fornetwork-card(single-card instance types).get_meta()already suppresses its own summary error formax_tries=1, for exactly this reason:This change applies the same rule to curl's stderr. Retrying callers (
max_tries > 1) keep forwarding curl's stderr aterrpriority, so the diagnostics added in #162 for transient IMDS failures are unchanged.Behaviour
errorlinemax_tries > 1err(as today)max_tries = 1The four single-attempt call sites on
mainareipv4-prefix/ipv6-prefixincreate_rules(),device-numberin_get_device_number(), andnetwork-cardin_get_network_card()(twice). All already treat a failed lookup as a normal outcome, and none of them lose a real error signal with this change:create_rules()treats a missing prefix as "no prefixes delegated" (|| true)._get_device_number()retries in its own loop and logs its ownerror("Unable to identify device-number ...") if it finally gives up, so a genuine failure is still reported._get_network_card()retries in its own loop and, by design, treats running out of retries as "this instance type has nonetwork-cardkey", recording that with the.no-network-cardmarker and returning0. A 404 here is the expected signal on single-card instance types, not a failure.Tests
Two regression tests are added to
tests/imds.bats, following the existing style of mockingcurlandloggeras shell functions:get_meta does not log curl errors for single-attempt optional keys: a single-attempt 404 produces noerr-priority log line and no curl error text. The expected debug[get_meta] Querying IMDStrace is still allowed.get_meta logs curl errors at err priority when retrying: withmax_tries=2, curl's stderr still reachesloggeratuser.err. This guards against over-correcting and losing Fix bug where transient IMDS failure could revert secondary ip addres… #162's diagnostics.Because the retrying path forwards stderr through an asynchronous process substitution, the tests poll briefly for the log rather than sleeping for a fixed time.
Verification
make check(ShellCheck--severity warningplus the full Bats suite): 39 ok, 0 failed, compared with 37 ok onmainbefore the change.lib/lib.shchange reverted and the new tests kept,get_meta does not log curl errors for single-attempt optional keysfails, confirming it catches the regression.im4gn.8xlarge, Ubuntu 26.04, systemd 259, one secondary ENI): the twoerrlines per refresh of the secondary interface come fromipv4-prefixandnetwork-card, both returning HTTP 404.By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.