[staging ]Firewall vulnerability detected. Unused port 9696/tcp can be accessed on slave-03_compute (node-3) node.

Bug #1524864 reported by Anastasia Kuznetsova
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Fix Released
High
Stanislaw Bogatkin

Bug Description

https://old-stable-ci.infra.mirantis.net/view/Staging/job/5.0.3.staging.centos.bvt_1/361/console

ERROR: Deploy cluster in simple mode with Neutron GRE
----------------------------------------------------------------------
Traceback (most recent call last):
  File "/home/jenkins/venv-nailgun-tests/local/lib/python2.7/site-packages/proboscis/case.py", line 296, in testng_method_mistake_capture_func
    compatability.capture_type_error(s_func)
  File "/home/jenkins/venv-nailgun-tests/local/lib/python2.7/site-packages/proboscis/compatability/exceptions_2_6.py", line 27, in capture_type_error
    func()
  File "/home/jenkins/venv-nailgun-tests/local/lib/python2.7/site-packages/proboscis/case.py", line 350, in func
    func(test_case.state.get_state())
  File "/home/jenkins/workspace/5.0.3.staging.centos.bvt_1/fuelweb_test/helpers/decorators.py", line 50, in wrapper
    return func(*args, **kwagrs)
  File "/home/jenkins/workspace/5.0.3.staging.centos.bvt_1/fuelweb_test/tests/test_neutron.py", line 78, in deploy_neutron_gre
    self.fuel_web.security.verify_firewall(cluster_id)
  File "/home/jenkins/workspace/5.0.3.staging.centos.bvt_1/fuelweb_test/__init__.py", line 48, in wrapped
    result = func(*args, **kwargs)
  File "/home/jenkins/workspace/5.0.3.staging.centos.bvt_1/fuelweb_test/helpers/security.py", line 110, in verify_firewall
    node['id']))
Exception: Firewall vulnerability detected. Unused port 9696/tcp can be accessed on slave-03_compute (node-3) node.

summary: - Firewall vulnerability detected. Unused port 9696/tcp can be accessed on
- slave-03_compute (node-3) node.
+ [staging ]Firewall vulnerability detected. Unused port 9696/tcp can be
+ accessed on slave-03_compute (node-3) node.
Revision history for this message
Roman Prykhodchenko (romcheg) wrote :

Is this bug related to this one https://bugs.launchpad.net/fuel/+bug/1524750 ?

Changed in fuel:
status: New → Confirmed
tags: added: area-library
Changed in fuel:
assignee: nobody → Fuel Library Team (fuel-library)
milestone: none → 8.0
tags: added: team-bugfix
Changed in fuel:
assignee: Fuel Library Team (fuel-library) → Stanislaw Bogatkin (sbogatkin)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to fuel-library (master)

Fix proposed to branch: master
Review: https://review.openstack.org/258050

Changed in fuel:
status: Confirmed → In Progress
tags: added: tech-debt
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to fuel-library (master)

Reviewed: https://review.openstack.org/258050
Committed: https://git.openstack.org/cgit/openstack/fuel-library/commit/?id=102ec8466c70cebe12d283beab7110cc8e60d8d7
Submitter: Jenkins
Branch: master

commit 102ec8466c70cebe12d283beab7110cc8e60d8d7
Author: Stanislaw Bogatkin <email address hidden>
Date: Tue Dec 15 21:12:28 2015 +0300

    Separate firewall rules per role

    Apply different rules per different roles, as some nodes should not have
    some rules. Also delete some old unused rules.

    Change-Id: Ic862f083d76a8d624a52dde83bc048b6ed9aaf93
    Closes-Bug: #1524864

Changed in fuel:
status: In Progress → Fix Committed
Revision history for this message
Timur Nurlygayanov (tnurlygayanov) wrote :

So, it looks like the issue was fixed.

Status changed to Fix Released.

Please change the status if issue will be reproduced again.

Changed in fuel:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.