firewall-policy-create steals rules associated with the other policy
Bug #1223465 reported by
Akihiro Motoki
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Medium
|
Sumit Naiksatam |
Bug Description
In my understanding, one firewall rule can belong to one firewall policy and if a rule is already associated with some policy the rule cannot be associated with a new policy without removing a rule from the current policy.
However, if firewall-
the rule is associated with the newly created policy.
I think it is a bug. Is it right?
The detail sequence of operations can be found at http://
Changed in neutron: | |
assignee: | nobody → Sumit Naiksatam (snaiksat) |
Changed in neutron: | |
status: | New → Confirmed |
importance: | Undecided → Medium |
milestone: | none → havana-rc1 |
Changed in neutron: | |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | havana-rc1 → 2013.2 |
To post a comment you must log in.
Thanks Akihiro for pointing this out. The 1:1 association of firewall_rule to policy is still maintained, however like you point out, the rule is yanked out from the older policy and associated with the new one. A check is missing in the implementation to prevent this.
This issue will not be seen when using Horizon, it is seen only when using the CLI.