User cannot create HA L3 Router

Bug #1388716 reported by Sachi King on 2014-11-03
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Undecided
Sachi King
Juno
Undecided
Unassigned

Bug Description

Currently, after modifying the policy.json a standard user cannot create a HA L3 router.

This is caused by neutron attempting to create a new network without a tenant under the users context.
All other operations with tenant-less owners performed during the creation of the router will complete successfully.

Sachi King (nakato) on 2014-11-03
Changed in neutron:
assignee: nobody → Sachi King (nakato)

Fix proposed to branch: master
Review: https://review.openstack.org/132533

Changed in neutron:
status: New → In Progress
Assaf Muller (amuller) on 2014-11-09
tags: added: l3-ha
Assaf Muller (amuller) on 2014-11-09
Changed in neutron:
status: In Progress → Incomplete
Assaf Muller (amuller) wrote :

This happens without editing the policy file as well:
I changed l3_ha to True in neutron.conf. I then made sure a regular user (Called demo for these purposes) has no HA network, sourced the demo user, and created a router (Which was by default HA), and the creation of the router failed because the creation of the HA network failed.

Changed in neutron:
status: Incomplete → Confirmed
tags: added: juno-backport-potential
Changed in neutron:
status: Confirmed → In Progress

Reviewed: https://review.openstack.org/132533
Committed: https://git.openstack.org/cgit/openstack/neutron/commit/?id=cc9bc24229f1d79dc99303db1affc03c030c011e
Submitter: Jenkins
Branch: master

commit cc9bc24229f1d79dc99303db1affc03c030c011e
Author: Sachi King <email address hidden>
Date: Mon Nov 3 00:35:51 2014 +1100

    Fix L3 HA network creation to allow user to create router

    Update HA Network creation to use an admin context to allow Neutron
    to create the tenant-less network required for the HA router when
    it does not yet exist and is being created by a non-admin user.

    Neutron creates these resources without a tenant so users cannot see
    or modify the HA network, ports, etc. Port creation and association
    already use elivated admin contexts to allow their function when
    an user attempts to create a HA L3 router.

    Change-Id: I36166158a0970b8d08d6702054b11a43fb684281
    Closes-Bug: #1388716

Changed in neutron:
status: In Progress → Fix Committed

Reviewed: https://review.openstack.org/133689
Committed: https://git.openstack.org/cgit/openstack/neutron/commit/?id=033e1413fa74a12fc4a0601c42e184317b0586c4
Submitter: Jenkins
Branch: stable/juno

commit 033e1413fa74a12fc4a0601c42e184317b0586c4
Author: Sachi King <email address hidden>
Date: Mon Nov 3 00:35:51 2014 +1100

    Fix L3 HA network creation to allow user to create router

    Update HA Network creation to use an admin context to allow Neutron
    to create the tenant-less network required for the HA router when
    it does not yet exist and is being created by a non-admin user.

    Neutron creates these resources without a tenant so users cannot see
    or modify the HA network, ports, etc. Port creation and association
    already use elivated admin contexts to allow their function when
    an user attempts to create a HA L3 router.

    Conflicts:
            neutron/tests/unit/db/test_l3_ha_db.py

    Change-Id: I36166158a0970b8d08d6702054b11a43fb684281
    Closes-Bug: #1388716
    (cherry picked from commit cc9bc24229f1d79dc99303db1affc03c030c011e)

tags: added: in-stable-juno

Change abandoned by Sam Yaple (<email address hidden>) on branch: master
Review: https://review.openstack.org/140598
Reason: Wrong topic

Change abandoned by Sam Yaple (<email address hidden>) on branch: master
Review: https://review.openstack.org/140601

Thierry Carrez (ttx) on 2014-12-18
Changed in neutron:
milestone: none → kilo-1
status: Fix Committed → Fix Released
Thierry Carrez (ttx) on 2015-04-30
Changed in neutron:
milestone: kilo-1 → 2015.1.0
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers