NFLOGs are added to iptables correctly
Delete log-resource A
=> expect: NFLOGs for ACCEPT disappears
=> Observed: NFLOGs for ACCEPT still remains => Bug
=> NFLOGs are added to iptables correctly
Delete log-resource A
=> expect: NFLOGs for ACCEPT and DROP disappears
=> Observed: NFLOGs for ACCEPT and DROP still remains => Bug
I have tested a logging feature for firewall_group in stable/rocky [1], and found a bug. Please follow the following testcase to reproduce this bug:
Environment:
- Devstack stable/rocky
- Create a router with port-A that attach to fwg1
Testcase 1
----------
Create 2 log-resources:
+ A: {ACCEPT, fwg1, port-A }
+ B : {DROP, fwg1, port-A}
NFLOGs are added to iptables correctly
Delete log-resource A
=> expect: NFLOGs for ACCEPT disappears
=> Observed: NFLOGs for ACCEPT still remains => Bug
Testcase 2
----------
Create 2 log-resources
+ A: {ALL, fwg1, port-A }
+ B : {ACCEPT, fwg1, port-A}
=> NFLOGs are added to iptables correctly
Delete log-resource A
=> expect: NFLOGs for ACCEPT and DROP disappears
=> Observed: NFLOGs for ACCEPT and DROP still remains => Bug
References: /docs.openstack .org/neutron/ latest/ admin/config- logging. html#service- workflow- for-operator
[1] https:/