nagaboinaramgopal opened a new pull request, #14037:
URL: https://github.com/apache/cloudstack/pull/14037

   ### Description
   
   When a security group rule references another security group, each member VM
   should be authorized as an exact host. The IPv4 address is correctly pinned 
to a
   /32, but the IPv6 address was expanded to /64, opening the whole subnet the
   member sits in rather than just that member. This silently broadens the rule 
to
   every address in the member's /64.
   
   Pin the IPv6 member to /128 to match the IPv4 behaviour.
   
   ### Types of changes
   
   - [x] Bug fix (non-breaking change which fixes an issue)
   
   ### Feature/Enhancement Scale or Bug Severity
   
   #### Bug Severity
   
   - [x] Minor
   
   ### How Has This Been Tested?
   
   Added a unit test asserting an IPv6 security-group member is authorized as a 
/128
   host and not the whole /64. Also built the standard packages and deployed on 
a KVM
   advanced zone.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to