Default behavior of Security groups egress handling has different semantics than ingress

Bug #1143283 reported by Tomoe Sugihara
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Fix Released
High
Tomoe Sugihara

Bug Description

Currently, the default behavior of egress is invisible and has different semantics than egress one. Since the default behavior is hidden from the user, it is counter intuitive and hard to figure out what's happening under the hood.
It'd be better to add default explicit allow-all-egress rule to make it semantically symmetric to ingress.

For more details about the issue, there's a discussion thread in the email list here:
http://lists.openstack.org/pipermail/openstack-dev/2013-February/005982.html

Tags: sg-fw
Changed in quantum:
assignee: nobody → Tomoe Sugihara (tomoe)
status: New → In Progress
dan wendlandt (danwent)
Changed in quantum:
milestone: none → grizzly-rc1
importance: Undecided → High
Akihiro Motoki (amotoki)
tags: added: sg-fw
Revision history for this message
dan wendlandt (danwent) wrote :
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to quantum (master)

Reviewed: https://review.openstack.org/23264
Committed: http://github.com/openstack/quantum/commit/7e26074be5dbe1a9b629b035da46e7122c4c34c9
Submitter: Jenkins
Branch: master

commit 7e26074be5dbe1a9b629b035da46e7122c4c34c9
Author: Tomoe Sugihara <email address hidden>
Date: Fri Mar 1 20:19:13 2013 +0900

    Populate default explicit allow rules for egress

    This way, the default behavior becomes clear and
    symmetric to ingress processing.

    Fixes bug 1143283

    Change-Id: Id6496819aaceda50def597739f7872653d5b2e00

Changed in quantum:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in quantum:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in quantum:
milestone: grizzly-rc1 → 2013.1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.