iptables-restore failure message isn't useful

Bug #1306399 reported by Kevin Benton
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Fix Released
Medium
Kevin Benton

Bug Description

When there is an iptables failure, it's difficult to troubleshoot because the exception references a line number from a piped in set of rules that the user can't see. (e.g. http://paste.openstack.org/show/75523/)

The rules should be dumped in this case so the user and subsequent developers fixing the bug can see the rule that caused the problem.

Changed in neutron:
assignee: nobody → Kevin Benton (kevinbenton)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron (master)

Fix proposed to branch: master
Review: https://review.openstack.org/86810

Changed in neutron:
status: New → In Progress
summary: - Troubleshooting iptables failure is difficult
+ iptables-restore failure message isn't useful
Changed in neutron:
importance: Undecided → Medium
milestone: none → juno-1
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to neutron (master)

Reviewed: https://review.openstack.org/86810
Committed: https://git.openstack.org/cgit/openstack/neutron/commit/?id=90df728558ba1f9c1d00aab1fa9d9e9937121c4b
Submitter: Jenkins
Branch: master

commit 90df728558ba1f9c1d00aab1fa9d9e9937121c4b
Author: Kevin Benton <email address hidden>
Date: Thu Apr 10 23:51:53 2014 -0700

    Log iptables rules when they fail to apply

    Log the set of rules that causes iptables-restore
    to fail in the Linux agent iptables manager.

    If a specific rule is identified as the cause, only
    that rule and a few surrounding it will be logged to
    reduce the output.

    Closes-Bug: #1306399
    Change-Id: I8e94c1faae75760e439c5abe3d9b723548398105

Changed in neutron:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in neutron:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in neutron:
milestone: juno-1 → 2014.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.