Updation of shared firewall-policy with non shared firewall-rule should be restricted

Bug #1699706 reported by Puneet Arora
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
In Progress
Undecided
Unassigned

Bug Description

Using horizon I am able to update/edit shared firewall policy with non-shared firewall-rule which is oppose to behavior when we create firewall-policy of shared mode with firewall-rules of non-shared mode. Because during creation of firewall policy if we create firewall policy with shared mode and add firewall rule which is non-shared then exception raises.
But during updation of firewall policy which is of shared mode with non-shared firewall rule then doesn't raises any exception. This behavior should be restricted.

Steps:-
1) Login to horizon.
2) Goto Project->Network->Firewalls
3) Create firewall rule with non-shared mode:
   e.g: Firewall-rule-1: UDP Allow (Non-shared)

4) Create firewall-policy with shared mode (e.g.: Firewall-policy-1 ) and try to add "Firewall-rule-1" to this policy then exception raises "Operation cannot be performed since Firewall Policy 41995c30-159a-4d18-891e-1bd5cf9e9aef is shared but Firewall Rule fdd19e89-062c-467e-b689-0a07f839663e is not shared"

5) Now again create firewall-policy with shared mode and without any firewall-rule.
6) Edit firewall policy and try to insert firewall-rule created in step3. Now it succeed. This should also be restricted.

Tags: fwaas
Puneet Arora (apuneet)
Changed in python-neutronclient:
status: New → Opinion
Changed in python-neutronclient:
assignee: nobody → Reedip (reedip-banerjee)
affects: python-neutronclient → neutron
tags: added: lbaas
tags: added: fwaas
removed: lbaas
Changed in neutron:
status: Opinion → Confirmed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron-fwaas (master)

Fix proposed to branch: master
Review: https://review.openstack.org/486377

Changed in neutron:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on neutron-fwaas (master)

Change abandoned by Reedip (<email address hidden>) on branch: master
Review: https://review.openstack.org/486377

Revision history for this message
Puneet Arora (apuneet) wrote :

Reedip, are you still looking into issue?

Revision history for this message
Reedip (reedip-banerjee-deactivatedaccount) wrote :
Revision history for this message
Reedip (reedip-banerjee-deactivatedaccount) wrote :
Revision history for this message
Puneet Arora (apuneet) wrote :

Could you please resolve the errors on patch and help in merging of code?

Revision history for this message
Reedip (reedip-banerjee-deactivatedaccount) wrote :

Since I am not active anymore, I would like to remove myself from the assignee. Its open for anyone else to take up.

Changed in neutron:
assignee: Reedip (reedip-banerjee) → nobody
Revision history for this message
OpenStack Infra (hudson-openstack) wrote :

Change abandoned by Slawek Kaplonski (<email address hidden>) on branch: master
Review: https://review.opendev.org/488438
Reason: As we are going to deprecate master branch in this project this patch is not needed anymore.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.