Deleting 'default' security group of a non-admin tenant by admin is not working

Bug #1398732 reported by Babu Shanmugam
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Juniper Openstack
Fix Committed
Undecided
Babu Shanmugam
OpenContrail
Fix Committed
Undecided
Babu Shanmugam

Bug Description

There are some contradictory behaviour of the 'default' security group created for each tenant when compared with OVS neutron plugin. With OVS plugin, the admin user can delete the 'default' SG of any tenant except its own. Where as, contrail does not allow for the admin user to delete the default SG of other tenants.
After deleting the 'default' SG by admin, following scenarios were observed.

1. Create a new SG with name 'default' - Denied with reason "Default security group already exists."
2. Show 'default' SG - Shows a newly created 'default' SG details
3. List SGs - List result includes newly created 'default' SG
4. Update 'default' SG - Updates a newly created SG
5. SG rule-list - Does not include the rules that belonged to 'default' group
6. SG rule-create - Creates a rule and adds to the newly created 'default' SG group's rules.

Tags: config
tags: added: config
Babu Shanmugam (anbu-p)
Changed in opencontrail:
assignee: nobody → Babu Shanmugam (anbu-p)
Sachin Bansal (sbansal)
Changed in juniperopenstack:
assignee: nobody → Babu Shanmugam (anbu-p)
Revision history for this message
OpenContrail Admin (ci-admin-f) wrote : A change has been merged

Reviewed: https://review.opencontrail.org/5189
Committed: http://github.org/Juniper/contrail-controller/commit/50e23cb8af5f0cccf50dfb82fbb936d732c1a78e
Submitter: Zuul
Branch: master

commit 50e23cb8af5f0cccf50dfb82fbb936d732c1a78e
Author: Babu Shanmugam <email address hidden>
Date: Wed Dec 3 08:31:43 2014 +0000

Fix contradictory behaviour of default security group

Closes-Bug: #1398732

Change-Id: I0f0fb12aa3e65fb38d0237ba349075f3e802ee6f

Changed in juniperopenstack:
status: New → Fix Committed
Changed in opencontrail:
status: New → Fix Committed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.