[Yahoo-eng-team] [Bug 2075539] Re: port-security iptables rules allows rogue DHCP servers to reach instances

2024-08-05 Thread Brian Haley
Hi Arun, While I can't confirm this is still a bug, there are a couple of things to be aware of. 1) Xena is an unsupported release, at this point only 2023.1 (Antelope) and later are actively supported by the upstream community. 2) Linux Bridge is unsupported and considered an "experimental" opt

[Yahoo-eng-team] [Bug 2073745] Re: [eventlet-deprecation] Reduce the ``IpConntrackManager`` process pool to a single thread

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/neutron/+/924582 Committed: https://opendev.org/openstack/neutron/commit/23b9077df53d2d61a3749ea8631ce4c7fe277b35 Submitter: "Zuul (22348)" Branch:master commit 23b9077df53d2d61a3749ea8631ce4c7fe277b35 Author: Rodolfo Alonso Hernandez Date:

[Yahoo-eng-team] [Bug 2075349] Re: JSONDecodeError when OIDCRedirectURI is the same as the Keystone OIDC auth endpoint

2024-08-05 Thread Jadon Naas
** Also affects: keystone Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/2075349 Title: JSONDecodeError when OIDCRedirec

[Yahoo-eng-team] [Bug 2074209] Re: OVN maintenance tasks may be delayed 10 minutes in the podified deployment

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/neutron/+/925194 Committed: https://opendev.org/openstack/neutron/commit/04c217bcd0eda07d52a60121b6f86236ba6e26ee Submitter: "Zuul (22348)" Branch:master commit 04c217bcd0eda07d52a60121b6f86236ba6e26ee Author: Slawek Kaplonski Date: Tue Jul

[Yahoo-eng-team] [Bug 2075955] [NEW] [RFE] Allow binding SecurityGroups to Network

2024-08-05 Thread David Pineau
Public bug reported: In the context of my work, I'm looking to "enforce" some security groups settings onto all ports of a Network. For a bit more context, we're configuring a network as external, so that it may provide network access to a service which is not managed by Openstack. We wanted, t

[Yahoo-eng-team] [Bug 2075539] [NEW] port-security iptables rules allows rogue DHCP servers to reach instances

2024-08-05 Thread Arun Vinod
Public bug reported: High level description: The default iptables rules added by neutron port-security allows the replies from rogue DHCP servers to reach the VM on provider network steps to reproduce- - Create provider network with DHCP enabled - enable port-security - if there is a rogue DHCP

[Yahoo-eng-team] [Bug 2073782] Re: "Tagging" extension does not initialize the policy enforcer

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/neutron/+/924656 Committed: https://opendev.org/openstack/neutron/commit/776178e90763d004ccb595b131cdd4dd617cd34f Submitter: "Zuul (22348)" Branch:master commit 776178e90763d004ccb595b131cdd4dd617cd34f Author: Rodolfo Alonso Hernandez Date:

[Yahoo-eng-team] [Bug 2075958] [NEW] [RFE] Limit who may bind security groups

2024-08-05 Thread David Pineau
Public bug reported: In the context of my work, I'm looking to "enforce" some security groups settings onto all ports of a Network. For a bit more context, we're configuring a network as external, so that it may provide network access to a service which is not managed by Openstack. We wanted, t

[Yahoo-eng-team] [Bug 1759956] Re: [dvr][fast-exit] incorrect policy rules get deleted when a distributed router has ports on multiple tenant networks

2024-08-05 Thread Brian Murray
Ubuntu 17.10 (Artful Aardvark) has reached end of life, so this bug will not be fixed for that specific release. ** Changed in: neutron (Ubuntu Artful) Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscrib

[Yahoo-eng-team] [Bug 2073987] Re: Switch from distributed to centralized Floating IPs breaks connectivity to the existing FIPs

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/neutron/+/925007 Committed: https://opendev.org/openstack/neutron/commit/4b1bfb93e380b8dce78935395b2cda57076e5476 Submitter: "Zuul (22348)" Branch:master commit 4b1bfb93e380b8dce78935395b2cda57076e5476 Author: Slawek Kaplonski Date: Fri Jul

[Yahoo-eng-team] [Bug 2075959] [NEW] NUMATopologyFilter pagesize logs are missleading

2024-08-05 Thread Balazs Gibizer
Public bug reported: When the instance request mem pages via symbolic names (e.g. "large" instead of specifying the exact size) and the instance does not fit to a NUMA cell due to the memory requirements nova logs are confusing: ./nova-scheduler-scheduler.log:2024-07-31 23:37:28.428 1 DEBUG nova.

[Yahoo-eng-team] [Bug 2076089] [NEW] admin cannot force instance launch on disabled host

2024-08-05 Thread Filippo Stenico
Public bug reported: Description === I have a set of disabled nova compute services, with nova compute service up and running, and I would like to force instance creation, as admin, on a disabled conpute node for testing purposes. I added the option --availability-zone nova:$HOST to the

[Yahoo-eng-team] [Bug 2075489] [NEW] The image file will still in stage when using image conversion plugin

2024-08-05 Thread Shisen.Zhang
Public bug reported: Delete an image that is in an importing state, if glance has used the image format conversion plugin, the image file will remain in the stage if the image has been converted. Ideally image file should be deleted from the stage. Environment settings: glance-direct,web-downlo

[Yahoo-eng-team] [Bug 2075529] [NEW] Unable to delete "access_as_shared" RBAC policy

2024-08-05 Thread Anton Kurbatov
Public bug reported: I encounter a very strange behavior when I try to add and delete the "access_as_shared" RBAC policy. I can add it successfully, but the subsequent delete doesn't work: openstack network rbac create ... # SUCCESS openstack network rbac delete $ID # FAIL Pre-requirements:

[Yahoo-eng-team] [Bug 2072483] Re: Revert image status to queued if image conversion fails

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/glance/+/923624 Committed: https://opendev.org/openstack/glance/commit/ea131dd1442861cb5884f99b6bb9e47e397605ce Submitter: "Zuul (22348)" Branch:master commit ea131dd1442861cb5884f99b6bb9e47e397605ce Author: Abhishek Kekane Date: Mon Jul 8

[Yahoo-eng-team] [Bug 2075489] Re: The image file will still in stage when using image conversion plugin

2024-08-05 Thread Abhishek Kekane
We have a cleanup job to delete images from staging area which left orphan there. This will run on service startup where it will check the staging area for any left/partial data files and delete it from there. https://github.com/openstack/glance/blob/master/glance/common/wsgi.py#L467 https://gith

[Yahoo-eng-team] [Bug 1742505] Re: gre_sys set to default 1472 when using path_mtu > 1500 with ovs 2.8.x

2024-08-05 Thread Brian Murray
Ubuntu 17.10 (Artful Aardvark) has reached end of life, so this bug will not be fixed for that specific release. ** Changed in: linux (Ubuntu Artful) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscrib

[Yahoo-eng-team] [Bug 2075723] [NEW] Wrong token expiration time format with expiring application credentials

2024-08-05 Thread Boris Bobrov
Public bug reported: In bug #1992183, token expiration time was limited to the application credentials expiration time. Unfortunately, the format used in the token is not the one specified in api-ref. Steps to reproduce: 1. Create application credentials expiring very soon 2. Issue a token with t

[Yahoo-eng-team] [Bug 2066115] Re: Prevent KeyError getting value of optional data

2024-08-05 Thread OpenStack Infra
Reviewed: https://review.opendev.org/c/openstack/horizon/+/919430 Committed: https://opendev.org/openstack/horizon/commit/fcce68a914f49938137785a4635d781b5a1741df Submitter: "Zuul (22348)" Branch:master commit fcce68a914f49938137785a4635d781b5a1741df Author: MinhNLH2 Date: Sun May 19 20:5

[Yahoo-eng-team] [Bug 2076122] [NEW] dns integration: support multiple domains per instance

2024-08-05 Thread Andrew Bogott
Public bug reported: Right now the designate/dns integration extension only allows specifying a single domain during resource creation, or a single domain to associate with a network. Ideally this would instead support N domains. For instance, I'd like my newly created VMs to have a dns entry tha

[Yahoo-eng-team] [Bug 2075504] [NEW] Unhselve to specific host can fail with oslo_versionedobjects.exception.ObjectActionError: Object action set_defaults failed because: No default set for field node

2024-08-05 Thread Balazs Gibizer
Public bug reported: When a libvirt based VM is unshelved to a ironic compute host then nova does not fail the operation gracefully with NoValidHost, but instead the scheduler fails with a stack trace: 2024-08-01 00:56:36.414 1 ERROR oslo_messaging.rpc.server [None req-a45169a4-4024-48d0-bd04-a0

[Yahoo-eng-team] [Bug 2075559] [NEW] 未经授权:您提出的请求需要身份验证

2024-08-05 Thread sensei
Public bug reported: openstack图形化页面中,创建实例的时候报网页错误,到keystone日志中发现是没有经过授权这个是最主要的错误,openstack的版本是2019年的train 下面是keystone的主要报错日志 keystone.server.flask.application [req-d28c65c7-cfd0-4625-b787-e2657d64fe36 - - - - -] Authorization failed. The request you have made requires authentication. from 192.1