neutron should validate gateway_ip is in subnet
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned | ||
neutron |
Fix Released
|
Undecided
|
Assaf Muller | ||
Havana |
Won't Fix
|
Undecided
|
Unassigned | ||
Icehouse |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
I don't believe this is actually a valid network configuration:
arosen@
+------
| Field | Value |
+------
| allocation_pools | {"start": "10.11.12.1", "end": "10.11.12.254"} |
| cidr | 10.11.12.0/24 |
| dns_nameservers | |
| enable_dhcp | True |
| gateway_ip | 10.0.0.1 |
| host_routes | |
| id | be0a602b-
| ip_version | 4 |
| name | private-subnet |
| network_id | 53ec3eac-
| tenant_id | f2d9c1726aa940d
+------
Changed in neutron: | |
assignee: | nobody → Assaf Muller (amuller) |
Changed in neutron: | |
milestone: | none → juno-3 |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | juno-3 → 2014.2 |
I think this is config controlled right now with cfg.CONF. force_gateway_ on_subnet.
https:/ /github. com/openstack/ neutron/ blob/master/ neutron/ db/db_base_ plugin_ v2.py#L1068