[Yahoo-eng-team] [Bug 1427539] [NEW] lbaasv2 old synchronous driver import fails to redirect to new path

2015-03-02 Thread Brandon Logan
Public bug reported: recently all v2 drivers were moved to the neutron_lbaas.drivers package from the neutron_lbaas.services.loadbalancer.drivers package. To maintain backwards compatibility with some of them, redirect of imports was implemented for configs that have not updated to the new paths.

[Yahoo-eng-team] [Bug 1427522] [NEW] affinity server group is limited on one host

2015-03-02 Thread neil nie
Public bug reported: In OpenStack Configuration Reference section scheduling, it states following: Are in a set of group hosts (if requested) (ServerGroupAffinityFilter). It looks like affinity server group can be placed on multiple hosts, but after some trials and investigation, the affinity ser

[Yahoo-eng-team] [Bug 1427521] [NEW] client side filter is missing in vpn tables

2015-03-02 Thread Masco Kaliyamoorthy
Public bug reported: client side filter option is missing in vpn tables ** Affects: horizon Importance: Undecided Assignee: Masco Kaliyamoorthy (masco) Status: New ** Changed in: horizon Assignee: (unassigned) => Masco Kaliyamoorthy (masco) -- You received this bug noti

[Yahoo-eng-team] [Bug 1427520] [NEW] Language change option is not working new panels

2015-03-02 Thread Sudheer Kalla
Public bug reported: In horizon i have added a new panel "My Panel" ,which consists of table and table action to upload a file , After this i navigated to settings and changed the preferred language(to Hindhi) , I noticed that all the panel are affected with new language(Hindhi) but "My Panel" i

[Yahoo-eng-team] [Bug 1427517] [NEW] client side filter is missing in firewall tables

2015-03-02 Thread Masco Kaliyamoorthy
Public bug reported: client side filter option is missing in all the firewall tables ** Affects: horizon Importance: Undecided Assignee: Masco Kaliyamoorthy (masco) Status: In Progress ** Changed in: horizon Assignee: (unassigned) => Masco Kaliyamoorthy (masco) -- You r

[Yahoo-eng-team] [Bug 1427509] [NEW] add oauth and federation authentication to config file

2015-03-02 Thread Steve Martinelli
Public bug reported: Recently federation and oauth support are no longer optional features. In the [auth] section of the keystone config file, they should be indicated as valid options for authentication. But perhaps now included in the default 'methods' option. ** Affects: keystone Importan

[Yahoo-eng-team] [Bug 1427485] [NEW] Fernet tokens contain a version identifier that is not integrity verified

2015-03-02 Thread Dolph Mathews
Public bug reported: Fernet tokens all start with a plaintext string of either "F00" or "F01" indicating either "version 0" (normal unscoped and scoped tokens) or "version 1" (trust-based tokens). That versioning lies outside of the integrity-verified portion of the token, and is thus susceptible

[Yahoo-eng-team] [Bug 1043886] Re: Firewall rules are not updated if you restart nova-compute

2015-03-02 Thread Brian Shang
** Changed in: nova Status: Triaged => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1043886 Title: Firewall rules are not updated if you restart no

[Yahoo-eng-team] [Bug 1427474] [NEW] IPv6 SLAAC subnet create should update ports on net

2015-03-02 Thread Dane LeBlanc
Public bug reported: If ports are first created on a network, and then an IPv6 SLAAC or DHCPv6-stateless subnet is created on that network, then the ports created prior to the subnet create are not getting automatically updated (associated) with addresses for the SLAAC/DHCPv6-stateless subnet, as

[Yahoo-eng-team] [Bug 1427467] [NEW] Oversight when copying configdrive during live migration on Hyperv

2015-03-02 Thread Adelina Tuvenie
Public bug reported: When fixing bug https://launchpad.net/bugs/1322096 there was an oversight. When copying the iso we check if the instance requires a config drive and if that config drive is a iso, by checking the value "config_drive_cdrom" from the conf. This value can change and thus, even i

[Yahoo-eng-team] [Bug 1427465] [NEW] vArmour fwaas agent broken, unit tests skipped, CI not running

2015-03-02 Thread Assaf Muller
Public bug reported: https://github.com/openstack/neutron- fwaas/blob/master/neutron_fwaas/services/firewall/agents/varmour/varmour_router.py#L64 vArmour L3 agent _router_added is calling neutron.agent.l3.router_info.RouterInfo__init__ and its not passing mandatory parameters (interface_driver, a

[Yahoo-eng-team] [Bug 1427459] [NEW] Pools are retrieved for monitors detail even there are no pool association

2015-03-02 Thread Liyingjun
Public bug reported: $ neutron lb-healthmonitor-show e1dbcea5-0028-4d78-a378-339b70e0d315 ++--+ | Field | Value| ++--+ | admin_state_up | True

[Yahoo-eng-team] [Bug 1427440] [NEW] V2 only keystone wont start - revoke not in loaded backends

2015-03-02 Thread Jamie Lennox
Public bug reported: 2015-03-03 00:22:25.674809 mod_wsgi (pid=10468): Target WSGI script '/var/www/keystone/main' cannot be loaded as Python module. 2015-03-03 00:22:25.674835 mod_wsgi (pid=10468): Exception occurred processing WSGI script '/var/www/keystone/main'. 2015-03-03 00:22:25.674856 Tra

[Yahoo-eng-team] [Bug 1427437] [NEW] LDAP debug logging during unit tests brings us close to causing jenkins to fail our tests

2015-03-02 Thread Henry Nash
Public bug reported: The Jenkins runs of our unit tests have a cap of 50Mb of log output..if we generate more than that, then it will fail out tests on the assumption that something is wrong. Our full run of our tests brings us perilously close already to this limit - primarily due to LDAP debug

[Yahoo-eng-team] [Bug 1427432] [NEW] lbaas related(?) check-grenade-dsvm-neutron failure

2015-03-02 Thread YAMAMOTO Takashi
Public bug reported: https://review.openstack.org/#/c/160523/ (purely doc-only change) http://logs.openstack.org/23/160523/2/check/check-grenade-dsvm-neutron/6f82325/logs/new/screen-q-svc.txt.gz#_2015-03-02_23_28_04_319 2015-03-02 23:28:04.319 15268 TRACE neutron.common.config cls._instance

[Yahoo-eng-team] [Bug 1427396] [NEW] lbaasv2 pool list not returning all data

2015-03-02 Thread Phillip Toohill
Public bug reported: Each pool returned by the API on a request to list pools should include all relevant data, such as, session persistence and listeners. ** Affects: neutron Importance: Undecided Assignee: Phillip Toohill (phillip-toohill) Status: New ** Tags: lbaas ** Cha

[Yahoo-eng-team] [Bug 1427391] [NEW] Serial console "cannot find instance"

2015-03-02 Thread Randy Bertram
Public bug reported: In some configurations, Serial Console says that instance cannot be found for the giving id, even though the instance is available. It seems to work fine in development environment, but not on system z server. ** Affects: horizon Importance: Undecided Assignee: Rand

[Yahoo-eng-team] [Bug 1420942] Re: noVNC insecure cookie allows session hijacking

2015-03-02 Thread Nathan Kinder
This has been published as OSSN-0044: https://wiki.openstack.org/wiki/OSSN/OSSN-0044 ** Changed in: ossn Status: New => Fix Released ** Changed in: ossn Assignee: (unassigned) => Paul McMillan (paul-mcmillan) -- You received this bug notification because you are a member of Yahoo

[Yahoo-eng-team] [Bug 1420942] Re: noVNC insecure cookie allows session hijacking

2015-03-02 Thread Nathan Kinder
This should be marked as public now. As Tritan mentioned in comment#8, it's already been disclosed (not to mention that we already wrote and published an OSSN). ** Information type changed from Private Security to Public Security ** Also affects: ossn Importance: Undecided Status: New

[Yahoo-eng-team] [Bug 1427379] [NEW] AttributeError: 'Assignment' object has no attribute 'get_domain_by_name'

2015-03-02 Thread Matthew Edmonds
Public bug reported: 2015-03-02 13:16:45.493 19248 CRITICAL keystone [-] AttributeError: 'Assignment' object has no attribute 'get_domain_by_name' 2015-03-02 13:16:45.493 19248 TRACE keystone Traceback (most recent call last): 2015-03-02 13:16:45.493 19248 TRACE keystone File "/usr/bin/keystone-m

[Yahoo-eng-team] [Bug 1427365] [NEW] openvswitch-agent init script does not source /etc/sysconfig/neutron

2015-03-02 Thread Tom Helander
Public bug reported: The init script '/etc/init.d/openstack-neutron-openvswitch-agent' does not source /etc/sysconfig/neutron, causing the ml2 plugin configuration to not be read as the default value for NEUTRON_PLUGIN_CONF in the init script is '/etc/neutron/plugins/openvswitch/ovs_neutron_plugin

[Yahoo-eng-team] [Bug 1424576] Re: RuntimeError: Unable to find group for option fatal_deprecations, maybe it's defined twice in the same group?

2015-03-02 Thread Doug Hellmann
The config generator from the incubator is deprecated in favor of the new approach in oslo.config. ** Changed in: oslo-incubator Status: New => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (no

[Yahoo-eng-team] [Bug 1427351] [NEW] cells: hypervisor API extension can't find compute_node services

2015-03-02 Thread Andrew Laski
Public bug reported: After the conversion to use Service objects in the hypervisor API extension the lookups for services are happening in the parent cell, not the child cells. This is due to cells redirects not being implemented in the Service object. ** Affects: nova Importance: Undecided

[Yahoo-eng-team] [Bug 1427343] [NEW] missing entry point for cisco apic topology agent

2015-03-02 Thread Ivar Lazzaro
Public bug reported: Cisco APIC topology agent [0] is missing the entry point. [0] neutron.plugins.ml2.drivers.cisco.apic.apic_topology.ApicTopologyService ** Affects: neutron Importance: Undecided Assignee: Ivar Lazzaro (mmaleckk) Status: In Progress ** Changed in: neutron

[Yahoo-eng-team] [Bug 1427328] [NEW] [sahara] The mechanism used to avoid duplicate script names in jobs binaries is fragile

2015-03-02 Thread Luigi Toscano
Public bug reported: Create a Job Binary in the internal db, with a specific script name (for example, "script_name"). If the user creates another job binary with the same script name, a unique UUID is added so that the name is unique. But, if the script name is long, the addition of the UUID c

[Yahoo-eng-team] [Bug 1426544] Re: Nova switching to oslo_log blows up instance object repr in logs

2015-03-02 Thread Doug Hellmann
** Changed in: oslo.log Status: Fix Committed => Fix Released ** Changed in: oslo.log Milestone: None => 0.4.0 ** Changed in: oslo.log Importance: Undecided => Critical -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed t

[Yahoo-eng-team] [Bug 1427317] [NEW] Defunct plug-in configuration files

2015-03-02 Thread Matt Kassawara
Public bug reported: After ML2, the Open vSwitch and Linux Bridge plug-ins became mechanisms/agents. However, the configuration files for these agents, particularly OVS with ovs_neutron_plugin.ini, generates confusion. Furthermore, distributions that package OpenStack take different routes for con

[Yahoo-eng-team] [Bug 1427304] [NEW] [sahara] When the job binary creating fails, the job binary data is created anyway

2015-03-02 Thread Luigi Toscano
Public bug reported: If the user tries to create a Job Binary using the internal db as storage, and the creating fails for a validation error, the job binary data is created anyway. The job data creation code should be executed at the same time/in the same transaction of the job binary creation (

[Yahoo-eng-team] [Bug 1427295] [NEW] nova-network with multi-host and update_dns_entries crashes during instance termination

2015-03-02 Thread Calvin Walton
Public bug reported: I have Openstack Nova set up using nova-network in multi-host mode. I wanted all instances to be able to resolve each-other via dns, so I enabled update_dns_entries=True in nova.conf Upon terminating an instance, I get the following traceback in nova- compute.log on the compu

[Yahoo-eng-team] [Bug 1427291] [NEW] ML2 hierarchical port binding needs additional tests

2015-03-02 Thread Robert Kukura
Public bug reported: Although the current unit tests cover the hierarchical port binding code reasonably well, additional tests are needed that verify the following: * Binding loops are properly avoided * Binding limit is detected * Dead-end binding attempts are handled properly ** Affects: neut

[Yahoo-eng-team] [Bug 1427289] [NEW] [sahara] Back trace when a job binary is created using an existing script

2015-03-02 Thread Luigi Toscano
Public bug reported: >From "Create Job Binary", add a valid name, "storage type" internal, and choose an existing job binary (neither "upload...", nor "create..." in the "Internal Binary" box. The following backtrace can be seen in Horizon logs: [02/Mar/2015 16:24:14] "POST /project/data_process

[Yahoo-eng-team] [Bug 1427277] [NEW] [sahara] Detailed error on job binary creation is not shown

2015-03-02 Thread Luigi Toscano
Public bug reported: When a job binary with an invalid name is created (for example: too long, like currently test_script_name_a5a330ee-bce0-11e4-beaf-3c970e1836cf), Sahara returns an well-defined exception, from the logs: DEBUG sahara.utils.api [-] Validation Error occurred: error_code=400, er

[Yahoo-eng-team] [Bug 1423695] Re: gate-devstack-dsvm-cells fails attaching volume

2015-03-02 Thread Matt Riedemann
Released in 2.22.0. ** Changed in: python-novaclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1423695 Title: gate-dev

[Yahoo-eng-team] [Bug 1427261] [NEW] Improve create instance without volume service

2015-03-02 Thread Cedric Brandily
Public bug reported: Currently an error notification is raised when creating an instance on an OpenStack deployment without volume service. This change avoids the error notification as volume service is not required to boot an instance. ** Affects: horizon Importance: Undecided A

[Yahoo-eng-team] [Bug 1419577] Re: when live-migrate failed, lun-id couldn't be rollback in havana

2015-03-02 Thread Thierry Carrez
Agree that it's a vulnerability in Havana (since live-migration fails so often there). I wouldn't consider it a vulnerability in Icehouse/Juno, since you can't trigger live migration failure without administrative or physical access to the machines. It is a bug with security consequences there, an

[Yahoo-eng-team] [Bug 1384112] Re: endpoint, service, region can not be updated when using kvs driver

2015-03-02 Thread Dolph Mathews
** Also affects: keystone/juno Importance: Undecided Status: New ** Changed in: keystone/juno Assignee: (unassigned) => wanghong (w-wanghong) ** Changed in: keystone/juno Status: New => In Progress ** Changed in: keystone/juno Importance: Undecided => Low -- You receiv

[Yahoo-eng-team] [Bug 1411478] Re: Any attribute that is equal to 'TRUE' or 'FALSE' is treated as boolean by LDAP drivers

2015-03-02 Thread Dolph Mathews
Before we backport this to stable/juno, are there any legitimate use cases where people would be depending on the old behavior? Just want to ensure there's no risk to backporting. ** Also affects: keystone/juno Importance: Undecided Status: New ** Changed in: keystone/juno Status

[Yahoo-eng-team] [Bug 1419577] [NEW] when live-migrate failed, lun-id couldn't be rollback in havana

2015-03-02 Thread Launchpad Bug Tracker
*** This bug is a security vulnerability *** You have been subscribed to a public security bug: Hi, guys When live-migrate failed with error, lun-id of connection_info column in Nova's block_deivce_mapping table couldn't be rollback. and failed VM can have others volume. my test environment is

[Yahoo-eng-team] [Bug 1427209] Re: oslo.log doesn't log request_id, project_id, user_id in nova

2015-03-02 Thread Davanum Srinivas (DIMS)
** Changed in: oslo.log Assignee: (unassigned) => Davanum Srinivas (DIMS) (dims-v) ** Changed in: oslo.log Status: New => Confirmed ** Also affects: nova Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering

[Yahoo-eng-team] [Bug 1427158] Re: Rest call for group and user list is not working without domain_id

2015-03-02 Thread Sourav Biswas
** Description changed: - In older build in PowerVC to get the group / user, we had used the following rest calls: - https://9.114.226.100/powervc/openstack/admin/v3/users - https://9.114.226.100/powervc/openstack/admin/v3/groups + To get the group / user, we had used the following rest calls: v

[Yahoo-eng-team] [Bug 1424900] Re: Bootstrapping Vivid: ERROR failed to bootstrap environment, Permission denied (publickey), ci-info: no authorized ssh keys fingerprints found for user ubuntu

2015-03-02 Thread Scott Moser
this was fixed in 0.7.7~bzr1067-0ubuntu1 uploaded to vivid 2015-02-26. ** Changed in: cloud-init Status: Confirmed => Fix Released ** Also affects: cloud-init (Ubuntu) Importance: Undecided Status: New ** Changed in: cloud-init Status: Fix Released => Fix Committed ** C

[Yahoo-eng-team] [Bug 1427228] [NEW] Allow to run neutron-ns-metadata-proxy as nobody

2015-03-02 Thread Cedric Brandily
Public bug reported: Currently neutron-ns-metadata-proxy runs with neutron user/group permissions on l3-agent but we should allow to run it with less permissions as neutron user is allowed to run neutron-rootwrap. We should restrict as much as possible neutron-ns-metadata-proxy permissions as it's

[Yahoo-eng-team] [Bug 1400966] Re: [OSSA-2014-041] Glance allows users to download and delete any file in glance-api server (CVE-2014-9493)

2015-03-02 Thread Darren Birkett
** Changed in: openstack-ansible/icehouse Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Glance. https://bugs.launchpad.net/bugs/1400966 Title: [OSSA-2014-041] Glance allows users to

[Yahoo-eng-team] [Bug 1426524] Re: race condition prevents intance deletion

2015-03-02 Thread Evgeniy Afonichev
couldn't reproduce. Also I suspect that volume attach/detach led to db inconsistencies ** Changed in: nova Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs

[Yahoo-eng-team] [Bug 1427179] [NEW] boot from volume instance failed, because when reschedule delete the volume

2015-03-02 Thread YaoZheng_ZTE
Public bug reported: 1. Create a volume "nova volume-create --display-name test_volume 1" [root@controller51 nova(keystone_admin)]# nova volume-list +--+---+-+--+-+-

[Yahoo-eng-team] [Bug 1427165] Re: unittest2 deprecated in Django

2015-03-02 Thread Matthias Runge
already fixed with commit https://github.com/openstack/horizon/commit/8e8c084847280f3f8e975910b498ed9fbb3a69c8 ** Changed in: horizon Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboa

[Yahoo-eng-team] [Bug 1427165] [NEW] unittest2 deprecated in Django

2015-03-02 Thread Matthias Runge
Public bug reported: https://docs.djangoproject.com/en/1.7/topics/testing/overview/#writing- tests Python 2.7 introduced some major changes to the unittest library, adding some extremely useful features. To ensure that every Django project could benefit from these new features, Django used to shi

[Yahoo-eng-team] [Bug 1380238] Re: Instances won't obtain IPv6 address if they have additional IPv4 interface

2015-03-02 Thread Sergey Belous
@Ihar, I checked this for ubuntu: http://paste.openstack.org/show/184928/ and all works fine. ** Changed in: neutron Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchp

[Yahoo-eng-team] [Bug 977192] Re: Error message not user friendly while creating security group

2015-03-02 Thread OpenStack Infra
** Changed in: python-novaclient Status: Invalid => In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/977192 Title: Error message not user friendly while

[Yahoo-eng-team] [Bug 1424597] Re: Obscure 'No valid hosts found' if no free fixed IPs left in the network

2015-03-02 Thread Alvaro Lopez
*** This bug is a duplicate of bug 1394268 *** https://bugs.launchpad.net/bugs/1394268 ** This bug has been marked a duplicate of bug 1394268 wrong error message when no IP addresses are available -- You received this bug notification because you are a member of Yahoo! Engineering Team, w

[Yahoo-eng-team] [Bug 1427158] [NEW] Rest call for group and user list is not working without domain_id

2015-03-02 Thread Sourav Biswas
Public bug reported: In older build in PowerVC to get the group / user, we had used the following rest calls: https://9.114.226.100/powervc/openstack/admin/v3/users https://9.114.226.100/powervc/openstack/admin/v3/groups For the recent builds, we are seeing the above command is not working and

[Yahoo-eng-team] [Bug 1365727] Re: N1kv tenant able to create networks for non-shared network profiles of other N1kv tenants

2015-03-02 Thread Ihar Hrachyshka
I wonder whether the bug should have been handled by vulnerability team. It looks like a privilege escalation problem. ** Also affects: ossa Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed

[Yahoo-eng-team] [Bug 1427148] [NEW] optparse.OptionConflictError: option -v/--verbose: conflicting option string(s): -v

2015-03-02 Thread Matthias Runge
Public bug reported: [mrunge@turing horizon (django18)]$ ./run_tests.sh -N -P Running Horizon application tests Traceback (most recent call last): File "/home/mrunge/work/horizon/manage.py", line 23, in execute_from_command_line(sys.argv) File "/usr/lib/python2.7/site-packages/django/core

[Yahoo-eng-team] [Bug 1427141] [NEW] console auth token timeout has no impact

2015-03-02 Thread Markus Zoeller
Public bug reported: Issue = The console feature (VNC, SERIAL, ...) returns a connection with an auth token. This connection *never* times out. Steps to reproduce == The steps below are suitable for testing with the serial console but the behavior is the same with VNC. * ena

[Yahoo-eng-team] [Bug 1427135] [NEW] Neutron API reflects JavaScript/any input in error message

2015-03-02 Thread Adam Heczko
Public bug reported: During security scan of Neutron API, Nessus raises the following security alert about reflected XSS: REQUEST: cross_site_scripting.nasl API RESPONSE : HTTP/1.1 500 Internal Server Error Content-Type: text/plain Content-Length: 596 Date: Mon, 29 Dec 2014 09:50:52 GMT Connecti

[Yahoo-eng-team] [Bug 1427122] [NEW] dvr case with 1 subnet attaches multi routers, fail to create router netns

2015-03-02 Thread ZongKai LI
Public bug reported: Environment 1+2 env with DVR enabled, l3agent on all these nodes are configured with "router_delete_namespaces = True". Create router R1, subnet sn1 and sn2, attach sn1 and sn4 to router R1. Create router R2, subnet sn3 and sn4, attach sn3 and sn4 to router R2. Boot

[Yahoo-eng-team] [Bug 1417515] Re: Horizon Input fields swapped when tried to Launch Stack with invalid name

2015-03-02 Thread Thierry Carrez
Please do not set to FixReleased until the fix is released in a milestone. ** Changed in: horizon Status: Fix Released => Fix Committed -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://

[Yahoo-eng-team] [Bug 1427098] [NEW] create server ignore parameters whether match hypervisor

2015-03-02 Thread LiangChen
Public bug reported: I'm test create server in Juno RDO environment, and I check the code of Kilo version. In a environment with different hypervisor, such as QEMU, docker and Xen etc, Create server is not check the hypervisor type with some import parameters. For example, there is two compute

[Yahoo-eng-team] [Bug 1427097] [NEW] Test case to create provider network

2015-03-02 Thread Wu Hong Guang
Public bug reported: Provider networks are created by the admin and map directly to an existing physical network in the data center. Useful network types in this category are flat (untagged) and VLAN (802.1Q tagged). It is possible to allow provider networks to be shared among tenants as part o