IPtables rules don't always get added at top when 'top=True' is specified
Bug #1037137 reported by
Brian Haley
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Fix Released
|
Undecided
|
Brian Haley |
Bug Description
I have written an out-of-tree module that makes calls into the IPtablesManager code to add/remove iptables chains and rules. I am sometimes using top=True when doing an add_rule(). During testing I noticed that even though I specified top=True, if there were already "non-top" rules in a chain, then it would be added after them.
A very small patch, like the attached, fixed the problem.
I have a proposed patch in gerrit I'll link to this in a bit.
Changed in nova: | |
milestone: | none → folsom-3 |
status: | Fix Committed → Fix Released |
Changed in nova: | |
milestone: | folsom-3 → 2012.2 |
To post a comment you must log in.
https:/ /review. openstack. org/#/c/ 11300/