What's New
This document supports the Cumulus Linux 5.19 release, and lists new features and enhancements.
- For a list of open and fixed issues in Cumulus Linux 5.19, see the Cumulus Linux 5.19 Release Notes.
- To upgrade to Cumulus Linux 5.19, first check the Release Considerations below, then follow the steps in Upgrading Cumulus Linux.
What’s New in Cumulus Linux 5.19.0
Cumulus Linux 5.19.0 supports new platforms, contains new features and improvements, and provides bug fixes.
Cumulus Linux 5.19.0 is currently only qualified for non-Spectrum-X.
Platforms
- NVIDIA SN6600 (128x800G Spectrum-6)
- NVIDIA SN4700-A1, Air-cooled (Spectrum-3)
New Features and Enhancements
- Prevent re-export of VRF-leaked EVPN routes
- Class E (240.0.0.0/4) address space support
- Disjoined multiplane support for EVPN unreachability with 802.1X dynamic VRF assignment
- Layer 3 VXLAN device mode is generally available
- Multi ASIC fast boot support (Beta)
- Full resource mode ISSU on Spectrum-4 and later switches (Beta)
- BFD offload to switch firmware
- Control plane punt classifier drop counters
- The cl-support file captures the SSD internal NAND debug log on a switch with a Virtium NVMe SSD
- Patch uninstall returns the switch to the patch installed underneath, and a new command reclaims the space held by superseded patches
- PFC watchdog detection parameters that distinguish a real deadlock from steady-state congestion
- Security configuration visibility for manufacturing and field inspection
- Back-to-sender notification on congestion tail drop on Spectrum-6 switches
- Back-to-sender notification when an MRC egress link fails
- Adaptive routing extended grading on Spectrum-6 switches
- Step time estimation for AI training workloads
- Adaptive routing ECMP group segregation for round-robin port selection on Spectrum-6 switches
- Dedicated service port ingress buffers on Spectrum-6 switches
- Adaptive routing hybrid scheduling mode, which moves low weight ECMP groups to random forwarding to reduce adaptive routing group merging
- Configurable source address for DNS queries, so that queries leave the switch from a stable loopback identity
- CPO module and laser source visibility on switches with co-packaged optics
- Trimmed packet sent and dropped counters at the global, port, and traffic class level on Spectrum-6 switches
- NVUE
- Passwordless sudo access by default for members of the sudo group, and RBAC os-command allow-lists for granular passwordless access to specific commands
- Switch power off command
- Clear a stale IPv6 ND prefix on demand
- Manage staged platform firmware files, automatic updates, and firmware source per component
- Show and install transceiver firmware
- IPv6-only unnumbered peering command
- Resilient hashing commands
- nv config apply command improvements to prevent latency and timeout during FRR configuration changes
- Suppress ZTP console messages
- Configure the file descriptor limit for the FRR routing daemons
- Show the physical connector for a port
- Telemetry
- WJH metrics for OTEL
- gNMI component type and name for platform components
- gNMI and OTEL metrics for unreachability AFI SAFI
- OTEL metrics for AAA RADIUS login authentication
- Microburst histogram with per-port burst scoring
- Configurable source address for gNMI dial-out connections
- gNMI and OTEL metrics for CPO modules and laser sources
- OTEL metrics for trimmed packet sent and dropped counters on Spectrum-6 switches
Release Considerations
Review the following considerations before you upgrade to Cumulus Linux 5.19.
Upgrade Requirements
You can use optimized image upgrade and package upgrade to upgrade the switch to Cumulus Linux 5.19 from the following releases. Package upgrade supports ISSU (warm boot) for these upgrade paths.
- 5.16.1 through 5.16.7
- 5.17.0
- 5.18.2
If your switch is running Cumulus Linux 5.18.0 or 5.18.1, you must first upgrade to 5.18.2 before you can upgrade to 5.19.
To upgrade to Cumulus Linux 5.19 from a release that does not support package upgrade or optimized image upgrade, you can install an image with ONIE.
For a list of the earliest Cumulus Linux releases supported for each switch model, refer to this knowledge base article.
Spectrum-6 BMC Requirements
For a Spectrum-6 switch, you must upgrade BMC before you upgrade Cumulus Linux. For information about upgrading BMC, refer to BMC.
Linux Configuration Files Overwritten
If you use Linux commands to configure the switch, read the following information before you upgrade to Cumulus Linux 5.19.
NVUE includes a default startup.yaml file. In addition, NVUE enables configuration auto save by default. As a result, NVUE overwrites any manual changes to Linux configuration files on the switch when the switch reboots after upgrade, or you change the cumulus user account password with the Linux passwd command.
These issues occur only if you use Linux commands to configure the switch. If you use NVUE commands to configure the switch, these issues do not occur.
To prevent Cumulus Linux from overwriting manual changes to the Linux configuration files when the switch reboots or when changing the cumulus user account password with the passwd command, follow the steps below before you upgrade to 5.19 or after a new binary image installation:
- Disable NVUE auto save:
cumulus@switch:~$ nv set system config auto-save state disabled
cumulus@switch:~$ nv config apply
cumulus@switch:~$ nv config save
-
Delete the
/etc/nvue.d/startup.yamlfile:cumulus@switch:~$ sudo rm -rf /etc/nvue.d/startup.yaml -
Add the
PASSWORD_NVUE_SYNC=noline to the/etc/default/nvuedfile:cumulus@switch:~$ sudo nano /etc/default/nvued PASSWORD_NVUE_SYNC=no
DHCP Lease with the host-name Option
When a Cumulus Linux switch with NVUE enabled receives a DHCP lease containing the host-name option, it ignores the received hostname and does not apply it. For details, see this knowledge base article.
NVUE Commands After Upgrade
After you upgrade to Cumulus Linux, running NVUE configuration commands might override configuration for features that are now configurable with NVUE and removes configuration you added manually to files or with automation tools like Ansible, Chef, or Puppet. To keep your configuration, you can do one of the following:
- Update your automation tools to use NVUE.
- Configure NVUE to ignore certain underlying Linux files when applying configuration changes.
- Use Linux and FRR (vtysh) commands instead of NVUE for all switch configuration.
nv show vrf <vrf-id> router bgp address-family <address-family>-unreachability route -o json Command
In Cumulus Linux 5.18 and later, running the nv show vrf <vrf-id> router bgp address-family <address-family>-unreachability route -o json command is now equivalent to running the vtysh show bgp vrf <vrf-id> ipv6 unreachability json brief command. Therefore, certain fields, such as path details and reporter AS, no longer show. To show a more detailed view, run the nv show vrf <vrf-id> router bgp address-family <address-family>-unreachability route <prefix> -o json command.
BFD Offload Configuration and Show Output
Cumulus Linux 5.19 replaces the BFD offload boolean with an offload mode that selects where BFD packet processing runs; see BFD Offload.
- The
nv set router bfd offload <enabled|disabled>command is replaced bynv set router bfd offload-mode <control-plane|kernel|hardware>. When you upgrade, Cumulus Linux translatesoffload enabledtooffload-mode kerneland removesoffload disabled, which leaves thecontrol-planedefault in effect. - The per-peer offload field now reports the engine carrying the session. In
nv show vrf <vrf-id> router bfd peersoutput, theOffloadedcolumn showskernel,hardware, orcontrol-plane; in vtysh and JSON output,offload-statusshows the same three values. In Cumulus Linux 5.18 and earlier, this field shows onlyoffloadedorcontrol-plane. Update any automation or monitoring that matches on the stringoffloaded.
PIM and MSDP vtysh Commands
Cumulus Linux 5.19 upgrades FRR, which moves the vtysh commands that configure PIM and MSDP for a routing instance into a router pim [vrf <vrf-name>] block and drops the ip prefix; see Protocol Independent Multicast - PIM.
ip pim rp,ip pim ssm prefix-list,ip pim ecmp,ip pim spt-switchover, theip pimtimer commands, and theip msdp mesh-groupcommands move underrouter pimand lose theipprefix. For example,switch(config)# ip pim rp 10.10.10.101becomesswitch(config)# router pimfollowed byswitch(config-pim)# rp 10.10.10.101.ip pim spt-switchover infinitybecomesspt-switchover infinity-and-beyond.- Per-VRF PIM settings move out of the
vrf <vrf-name>block into a separate top-levelrouter pim vrf <vrf-name>block. - Interface-level commands, such as
ip pim,ip pim hello,ip pim bfd,ip pim use-source,ip pim allow-rp,ip pim active-active,ip multicast boundary oil, and allip igmpcommands, are unchanged. All NVUE commands are unchanged. - Check the
/etc/frr/frr.conffile and any automation that configures PIM or MSDP through vtysh before you upgrade.
Class E Address Space Support
FRR now treats the IPv4 240.0.0.0/4 (Class E) range as valid unicast address space on every switch running Cumulus Linux 5.19, whether or not you allow Class E as routable address space. A Class E interface address and its connected route can appear in nv show interface output and the routing table even if you never run the nv set router allow-reserved-range class-e command.
- The FRR
allow-reserved-rangescommand no longer includes Class E; it now covers only 0.0.0.0/8 and 127.0.0.0/8. If you previously set this command only to use Class E, you no longer need to. - Until you allow Class E, Cumulus Linux still blocks Class E traffic, but the control-plane packet filter drops it instead of the ASIC. If you monitor hardware drop counters for Class E source addresses, you see this difference after you upgrade.
For more information, see Class E Address Space Support.
Cumulus VX
NVIDIA no longer releases Cumulus VX as a standalone image. To simulate a Cumulus Linux switch, use NVIDIA DSX Air.