commit 558a977902c9e83aabaefe67333aee544aa86585
Author: Doug Wiegley <email address hidden>
Date: Sat Mar 2 22:35:52 2019 -0700
When converting sg rules to iptables, do not emit dport if not supported
Since iptables-restore doesn't support --dport with protocol vrrp,
it errors out setting the security groups on the hypervisor.
Marking this a partial fix, since we need a change to prevent
adding those incompatible rules in the first place, but this
patch will stop the bleeding.
Change-Id: If5e557a8e61c3aa364ba1e2c60be4cbe74c1ec8f
Partial-Bug: #1818385
(cherry picked from commit 8c213e45902e21d2fe00639ef7d92b35304bde82)
Reviewed: https:/ /review. openstack. org/640685 /git.openstack. org/cgit/ openstack/ neutron/ commit/ ?id=558a977902c 9e83aabaefe6733 3aee544aa86585
Committed: https:/
Submitter: Zuul
Branch: stable/rocky
commit 558a977902c9e83 aabaefe67333aee 544aa86585
Author: Doug Wiegley <email address hidden>
Date: Sat Mar 2 22:35:52 2019 -0700
When converting sg rules to iptables, do not emit dport if not supported
Since iptables-restore doesn't support --dport with protocol vrrp,
it errors out setting the security groups on the hypervisor.
Marking this a partial fix, since we need a change to prevent
adding those incompatible rules in the first place, but this
patch will stop the bleeding.
Change-Id: If5e557a8e61c3a a364ba1e2c60be4 cbe74c1ec8f 2fe00639ef7d92b 35304bde82)
Partial-Bug: #1818385
(cherry picked from commit 8c213e45902e21d