generating duplicate LLA iptables rules

Bug #1622938 reported by Kevin Benton
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Fix Released
Medium
Kevin Benton

Bug Description

Spotted in gate. Looks like we are generating duplicate iptables rules for LLA v6 entries.

2016-09-13 08:10:15.769 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:41.844 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sd39667db-b -s fe80::f816:3eff:fe30:7756/128 -m mac --mac-source FA:16:3E:30:77:56 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:41.844 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:55.708 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sd39667db-b -s fe80::f816:3eff:fe30:7756/128 -m mac --mac-source FA:16:3E:30:77:56 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:55.708 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:55.798 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sd39667db-b -s fe80::f816:3eff:fe30:7756/128 -m mac --mac-source FA:16:3E:30:77:56 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:55.798 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:59.713 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sd39667db-b -s fe80::f816:3eff:fe30:7756/128 -m mac --mac-source FA:16:3E:30:77:56 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:10:59.713 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:11:03.825 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sd39667db-b -s fe80::f816:3eff:fe30:7756/128 -m mac --mac-source FA:16:3E:30:77:56 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:11:03.825 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2016-09-13 08:11:09.679 13401 WARNING neutron.agent.linux.iptables_manager [req-4534b4a3-484e-4fc5-8b44-0e91d70feb88 - -] Duplicate iptables rule detected. This may indicate a bug in the the iptables rule generation code. Line: -A neutron-linuxbri-sa16bbb04-2 -s fe80::f816:3eff:fecd:f5b1/128 -m mac --mac-source FA:16:3E:CD:F5:B1 -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN

Tags: logging
Changed in neutron:
assignee: nobody → Kevin Benton (kevinbenton)
milestone: none → newton-rc1
importance: Undecided → Medium
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron (master)

Fix proposed to branch: master
Review: https://review.openstack.org/369269

Changed in neutron:
status: New → In Progress
Revision history for this message
Armando Migliaccio (armando-migliaccio) wrote :

Gate where? What job, etc?

Revision history for this message
Kevin Benton (kevinbenton) wrote :

linux bridge jobs

Revision history for this message
Kevin Benton (kevinbenton) wrote :

dvr jobs

Revision history for this message
Kevin Benton (kevinbenton) wrote :
tags: added: logging
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to neutron (master)

Reviewed: https://review.openstack.org/369269
Committed: https://git.openstack.org/cgit/openstack/neutron/commit/?id=d1b9026729d085a9f986fb6c394a04b9aa5a87f6
Submitter: Jenkins
Branch: master

commit d1b9026729d085a9f986fb6c394a04b9aa5a87f6
Author: Kevin Benton <email address hidden>
Date: Mon Sep 12 23:51:11 2016 -0700

    Prevent duplicate LLA iptables rules

    Check if lla,mac tuple is in pairs before appending
    it again. Otherwise we end up generating duplicate
    iptables rules.

    Closes-Bug: #1622938
    Change-Id: I43658a31f9853cbc94784f497193210990f769dd

Changed in neutron:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/neutron 9.0.0.0rc1

This issue was fixed in the openstack/neutron 9.0.0.0rc1 release candidate.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.