iptables-restore error when table not loaded

Bug #1103436 reported by Ghe Rivero
48
This bug affects 7 people
Affects Status Importance Assigned to Milestone
OpenStack Compute (nova)
Fix Released
High
Ghe Rivero

Bug Description

When restoring iptables within nova rules, if a iptable_[table] module is not loaded, it generates a faulty file does is rejected by iptables-restore, making nova-api not able to boot.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to nova (master)

Fix proposed to branch: master
Review: https://review.openstack.org/20320

Changed in nova:
assignee: nobody → Ghe Rivero (ghe.rivero)
status: New → In Progress
Revision history for this message
Ghe Rivero (ghe.rivero) wrote :
Revision history for this message
aeva black (tenbrae) wrote :
Revision history for this message
aeva black (tenbrae) wrote :

Reported upstream bug:
  https://bugs.launchpad.net/ubuntu/+source/iptables/+bug/1104362

For easy reference, here's a log of iptables commands showing the bug:
  http://paste.openstack.org/show/29809/

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to nova (master)

Reviewed: https://review.openstack.org/20320
Committed: http://github.com/openstack/nova/commit/7d7fcf1d126d764a273b96d8ba1c940327470841
Submitter: Jenkins
Branch: master

commit 7d7fcf1d126d764a273b96d8ba1c940327470841
Author: Ghe Rivero <email address hidden>
Date: Wed Jan 23 12:53:43 2013 +0100

    iptables-restore error when table not loaded.

    When adding openstack rules, if a table module is not loaded,
    the resulted file doesn't include the section for the missing
    table, making new rules added to it, out of place and
    a no valid file for iptables-restore

    Fixes bug #1103436

    Change-Id: I34ae51a23efec57bfec37b8fa378d043fcf62d70

Changed in nova:
status: In Progress → Fix Committed
Changed in nova:
importance: Undecided → High
Thierry Carrez (ttx)
Changed in nova:
milestone: none → grizzly-3
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in nova:
milestone: grizzly-3 → 2013.1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.