Exceed ssh sessions on Nexus device when running on RHEL

Bug #1454734 reported by Carol Bouchard
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
networking-cisco
Fix Released
Undecided
Rich Curran
Kilo
Fix Committed
Undecided
Rich Curran
Liberty
Fix Released
Undecided
Rich Curran

Bug Description

When creating and deleting VMs on Nexus device, an error is seen in log file showing Nexus closing ssh session. This is due to multi neutron processes running on RHEL causing Nexus device to reach max ssh session count.

Changed in networking-cisco:
assignee: nobody → Carol Bouchard (caboucha)
assignee: Carol Bouchard (caboucha) → nobody
tags: added: cisco ml2
Rich Curran (rcurran)
Changed in networking-cisco:
assignee: nobody → Rich Curran (rcurran)
tags: added: nexus
Leon Zachery (lzachery)
tags: added: e-rel
Changed in networking-cisco:
status: New → In Progress
Changed in networking-cisco:
status: In Progress → Fix Committed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to networking-cisco (stable/kilo)

Fix proposed to branch: stable/kilo
Review: https://review.openstack.org/209249

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to networking-cisco (stable/kilo)

Reviewed: https://review.openstack.org/209249
Committed: https://git.openstack.org/cgit/openstack/networking-cisco/commit/?id=77d4a60fbce7f81275c3cdd9fec3b28a1ca0c57c
Submitter: Jenkins
Branch: stable/kilo

commit 77d4a60fbce7f81275c3cdd9fec3b28a1ca0c57c
Author: Rich Curran <email address hidden>
Date: Wed Jul 1 13:06:07 2015 -0400

    ML2 cisco_nexus MD: If configured, close ssh sessions

    Most (if not all) Nexus switches have a limit of eight ssh sessions open
    at one time. With the openstack/neutron introduction of rpc and api workers
    (setting these variables results in additional neutron-server processes
    being forked) when more than eight processes are in use (including one for
    the parent neutron-server process) the ssh limit on the nexus switches is
    exceeded and exceptions are taken. More importantly is that communication
    to the nexus switches can not be made for the nineth (or above) processes.

    This nexus switch limitation will be fixed by closing each session after
    each event if the overall number of processes is >= eight.

    Change-Id: Ie953c955c6e045a1b252e6973f53b38284833f37
    Closes-Bug: #1454734
    (cherry picked from commit 1eec7fb821e4d75fb6f875f9edeb2977bfcd88ef)

tags: added: in-stable-kilo
Sam Betts (sambetts)
Changed in networking-cisco:
milestone: none → 1.1.0
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to networking-cisco (master)

Fix proposed to branch: master
Review: https://review.openstack.org/246547

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to networking-cisco (master)
Download full text (23.9 KiB)

Reviewed: https://review.openstack.org/246547
Committed: https://git.openstack.org/cgit/openstack/networking-cisco/commit/?id=7b1eb2b6d5e55563c084f60e44adc1d32706eb17
Submitter: Jenkins
Branch: master

commit d9b9a6421d7ff92e920ed21b01ebc7bf49e38bd6
Author: Sam Betts <email address hidden>
Date: Tue Sep 29 09:18:10 2015 +0100

    Set default branch for stable/kilo

    Change-Id: I31f51ff60f95639f459839f4c7d929d5ec7c458d

commit f08fb31f20c2d8cc1e6b71784cdfd9604895e16d
Author: Rich Curran <email address hidden>
Date: Thu Sep 3 13:23:52 2015 -0400

    ML2 cisco_nexus MD: VLAN not created on switch

    As described in DE588,
    "With neutron multiworkers configured, there is a potential race condition
    issue where some of the VLANs will not be configured on one or more N9k
    switches.

    /etc/neutron/neutron.conf
    -------------------------
    api_workers=3
    rpc_workers=3"

    Fix is to allow the vlan create command to be sent down to a switch
    under most event conditions. Long term fix will be to introduce a new
    column in the port binding DB table that indicates the true state of the
    entry/row.

    Closes-Bug: #1491940
    Change-Id: If1da1fcf16a450c1a4107da9970b18fc64936896
    (cherry picked from commit 0e48a16e77fc5ec5fd485a85f97f3650126fb6fe)

commit d400749e43e9d5a1fc92683b40159afce81edc95
Author: Carol Bouchard <email address hidden>
Date: Thu Sep 3 15:19:48 2015 -0400

    Create knob to prevent caching ssh connection

    Create a new initialization knob named never_cache_ssh_connection.
    This boolean is False by default allowing multiple ssh connections
    to the Nexus switch to be cached as it behaves today. When there
    are multiple neutron processes/controllers and/or non-neutron ssh(xml)
    connections, this is an issue since processes hold onto a connection
    while the Nexus devices supports a maximum of 8 sessions. As a result,
    further ssh connections will fail. In this case, the boolean should be
    set to True causing each connection to be closed when a neutron event
    is complete.

    Change-Id: I61ec303856b757dd8d9d43110fec8e7844ab7c6d
    Closes-bug: #1491108
    (cherry picked from commit 23551a4198c61e2e25a6382f27d47b0665f054b8)

commit 0050ea7f1fb3c22214d7ca49cfe641da86123e2c
Author: Carol Bouchard <email address hidden>
Date: Wed Sep 2 11:10:42 2015 -0400

    Bubble up exceptions when Nexus replay enabled

    There are several changes made surrounding this bug.

    1) When replay is enabled, we should bubble exceptions
       for received port create/update/delete post_commit
       transactions. This was suppressed earlier by
       1422738.

    2) When an exception is encountered during a
       post_commit transaction, the driver will no longer
       mark the switch state to inactive to force a replay.
       This is no longer needed since 1481856 was introduced.
       So from this point on, only the replay thread will
       determine the state of the connection to the switch.

    3) In addition to accommodating 1 & 2 above, more detail
       data verification was added to the test code.

    Change-Id: I97...

Changed in networking-cisco:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.