← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1269448] [NEW] VC driver lacks support for secgroups

 

Public bug reported:

Issuing
[root@jhenner-node ~(keystone_admin)]# nova secgroup-add-rule  default tcp 33 33 0.0.0.0/0
+-------------+-----------+---------+-----------+--------------+
| IP Protocol | From Port | To Port | IP Range  | Source Group |
+-------------+-----------+---------+-----------+--------------+
| tcp         | 33        | 33      | 0.0.0.0/0 |              |
+-------------+-----------+---------+-----------+--------------+

causes:
[root@jhenner-node ~(keystone_admin)]# tail -f /var/log/nova/compute.log | grep -v DEBUG
2014-01-15 14:43:33.040 19359 ERROR nova.openstack.common.rpc.amqp [req-8273843f-cf2f-4638-8e41-ad7b5278773b c617ab6c5a9c45ac97d59b3d799e431e 89cec4e2039c4344b30e74575444afd1] Exception during message handling
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp Traceback (most recent call last):
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/rpc/amqp.py", line 461, in _process_data
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     **args)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/rpc/dispatcher.py", line 172, in dispatch
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     result = getattr(proxyobj, method)(ctxt, **kwargs)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/exception.py", line 90, in wrapped
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     payload)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/exception.py", line 73, in wrapped
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(self, context, *args, **kw)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/compute/manager.py", line 857, in refresh_instance_security_rules
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return _sync_refresh()
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 246, in inner
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(*args, **kwargs)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib64/python2.6/contextlib.py", line 34, in __exit__
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     self.gen.throw(type, value, traceback)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 210, in lock
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     yield sem
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 246, in inner
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(*args, **kwargs)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/compute/manager.py", line 856, in _sync_refresh
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return self.driver.refresh_instance_security_rules(instance)
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp AttributeError: 'VMwareVCDriver' object has no attribute 'refresh_instance_security_rules'
2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp 

The secgroups seems to be ineffective, there seems to be no firewalling.

** Affects: nova
     Importance: Undecided
         Status: New


** Tags: vmware

** Tags added: vmware

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1269448

Title:
  VC driver lacks support for secgroups

Status in OpenStack Compute (Nova):
  New

Bug description:
  Issuing
  [root@jhenner-node ~(keystone_admin)]# nova secgroup-add-rule  default tcp 33 33 0.0.0.0/0
  +-------------+-----------+---------+-----------+--------------+
  | IP Protocol | From Port | To Port | IP Range  | Source Group |
  +-------------+-----------+---------+-----------+--------------+
  | tcp         | 33        | 33      | 0.0.0.0/0 |              |
  +-------------+-----------+---------+-----------+--------------+

  causes:
  [root@jhenner-node ~(keystone_admin)]# tail -f /var/log/nova/compute.log | grep -v DEBUG
  2014-01-15 14:43:33.040 19359 ERROR nova.openstack.common.rpc.amqp [req-8273843f-cf2f-4638-8e41-ad7b5278773b c617ab6c5a9c45ac97d59b3d799e431e 89cec4e2039c4344b30e74575444afd1] Exception during message handling
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp Traceback (most recent call last):
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/rpc/amqp.py", line 461, in _process_data
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     **args)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/rpc/dispatcher.py", line 172, in dispatch
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     result = getattr(proxyobj, method)(ctxt, **kwargs)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/exception.py", line 90, in wrapped
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     payload)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/exception.py", line 73, in wrapped
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(self, context, *args, **kw)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/compute/manager.py", line 857, in refresh_instance_security_rules
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return _sync_refresh()
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 246, in inner
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(*args, **kwargs)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib64/python2.6/contextlib.py", line 34, in __exit__
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     self.gen.throw(type, value, traceback)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 210, in lock
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     yield sem
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/openstack/common/lockutils.py", line 246, in inner
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return f(*args, **kwargs)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp   File "/usr/lib/python2.6/site-packages/nova/compute/manager.py", line 856, in _sync_refresh
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp     return self.driver.refresh_instance_security_rules(instance)
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp AttributeError: 'VMwareVCDriver' object has no attribute 'refresh_instance_security_rules'
  2014-01-15 14:43:33.040 19359 TRACE nova.openstack.common.rpc.amqp 

  The secgroups seems to be ineffective, there seems to be no
  firewalling.

To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1269448/+subscriptions


Follow ups

References