keystonemiddleware audit selects the wrong target service

Bug #1797584 reported by Michael Johnson on 2018-10-12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Michael Johnson

Bug Description

Keystonemiddleware audit support is selecting the wrong "target" service when OpenStack service endpoints are not using unique TCP ports.

The incorrect code is here:

With that code, if the services are not using unique TCP ports for each endpoint, the first endpoint that matches the IP adddress of the request will be selected.

Since most services have moved to not using TCP ports for their endpoints, this needs to be fixed to allow the proper target service to be selected.

Changed in keystonemiddleware:
assignee: nobody → Michael Johnson (johnsom)

Fix proposed to branch: master

Changed in keystonemiddleware:
status: New → In Progress
Changed in keystonemiddleware:
importance: Undecided → Medium

Submitter: Zuul
Branch: master

commit 782729b6e98c1d2857c7e4f24bb69219e43c108f
Author: Michael Johnson <email address hidden>
Date: Fri Oct 12 09:05:10 2018 -0700

    Fix audit target service selection

    The keystonemiddleware audit code would select the wrong OpenStack service
    endpoint for a request if the cloud is not using unique TCP ports for each
    service endpoint. As most services are no longer using a port per service,
    but instead using unique paths, this caused the audit to select the wrong
    target service. This leads to incorrect audit logging due to the wrong
    audit map being used.

    This patch checks the request to see if a TCP port was present in the request,
    and if not, fall back to using the target_endpoint_type configured in the
    audit map file.

    Change-Id: Ie2e0bf74ecca485d599a4041bb770bd6e296bc99
    Closes-bug: 1797584

Changed in keystonemiddleware:
status: In Progress → Fix Released

This issue was fixed in the openstack/keystonemiddleware 6.0.0 release.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers