ovsfw doesn't support cidr in allowed_address_pairs

Bug #1669021 reported by Inessa Vasilevskaya
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
neutron
Invalid
High
Inessa Vasilevskaya

Bug Description

Seen on: ocata devstack

Steps to reproduce:

1. update port with allowed_address_pairs as cidr, for example

 neutron port-update 2559e0ff-6a52-4b78-9471-246fecb846c0 --allowed-address-pairs type=dict list=true ip_address=192.168.0.0/30

2. switch to openvswitch firewall
firewall_driver=openvswitch in /etc/neutron/plugins/ml2/ml2_conf.ini

3. observe a bunch of errors in openvswitch-agent log (http://paste.openstack.org/show/600933/)

with ValueError: IPAddress() does not support netmasks or subnet prefixes! See documentation for details.

Tags: ovs-fw
Changed in neutron:
assignee: nobody → Inessa Vasilevskaya (ivasilevskaya)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron (master)

Fix proposed to branch: master
Review: https://review.openstack.org/439651

Changed in neutron:
status: New → In Progress
Changed in neutron:
importance: Undecided → High
tags: added: ovs-fw
Revision history for this message
jazeltq (jazeltq-k) wrote :

magnum use template can not create master for
this bug in neutron.....

no longer affects: magnum
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on neutron (master)

Change abandoned by Inessa Vasilevskaya (<email address hidden>) on branch: master
Review: https://review.openstack.org/439651
Reason: this has been addressed by https://review.openstack.org/#/c/415180/

Revision history for this message
Inessa Vasilevskaya (ivasilevskaya) wrote :

I believe the bug can be closed now

Changed in neutron:
status: In Progress → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.