[Yahoo-eng-team] [Bug 1716401] Re: FWaaS: Ip tables rules do not get updated in case of distributed virtual routers (DVR)

2019-10-01 Thread Swaminathan Vasudevan
*** This bug is a duplicate of bug 1845557 *** https://bugs.launchpad.net/bugs/1845557 This bug is also a duplicate of https://bugs.launchpad.net/neutron/+bug/1845557 ** This bug is no longer a duplicate of bug 1715395 FWaaS: Firewall creation fails in case of distributed routers (Pike) **

[Yahoo-eng-team] [Bug 1845557] [NEW] DVR: FWaaS rules created for a router after the FIP and VM created, not applied to routers rfp port on router-update

2019-09-26 Thread Swaminathan Vasudevan
VM is not protected by the Firewall rules. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: Confirmed ** Tags: fwaas l3-dvr-backlog ** Changed in: neutron Assignee: (unassigned) => Swaminathan Vasudevan (swamina

[Yahoo-eng-team] [Bug 1840979] Re: [L2] [opinion] update the port DB status directly in agent-side

2019-08-22 Thread Swaminathan Vasudevan
** Changed in: neutron Status: New => Opinion ** Changed in: neutron Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1840979 Title: [L2] [opin

[Yahoo-eng-team] [Bug 1824571] Re: l3agent can't create router if there are multiple external networks

2019-07-08 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1824571 Title: l3agent can't create router if there are multiple external n

[Yahoo-eng-team] [Bug 1824566] Re: DVR-Nexthop static routes are not getting configured in FIP Namespace when disassociating and reassociating a FloatingIP in Ocata

2019-07-08 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1824566 Title: DVR-Nexthop static routes are not getting configured in

[Yahoo-eng-team] [Bug 1823314] Re: ha router sometime goes in standby mode in all controllers

2019-07-08 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1823314 Title: ha router sometime goes in standby mode in all controllers

[Yahoo-eng-team] [Bug 1815676] Re: DVR: External process monitor for keepalived should be removed when external gateway is removed for DVR HA routers

2019-05-29 Thread Swaminathan Vasudevan
** Changed in: neutron Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1815676 Title: DVR: External process monitor for keepalived should be removed

[Yahoo-eng-team] [Bug 1824566] [NEW] DVR-Nexthop static routes are not getting configured in FIP Namespace when disassociating and reassociating a FloatingIP in Ocata

2019-04-12 Thread Swaminathan Vasudevan
Public bug reported: Nexthop static routes for external network are not getting configured in the FIP Namespace table, after disassociating and re-associating a FloatingIP. This is seen in Ocata and Newton. Not seen in Pike and later branches. Steps to reproduce this problem. 1. Deploy the devst

[Yahoo-eng-team] [Bug 1821815] [NEW] Gate jobs are failing for stable/ocata

2019-03-26 Thread Swaminathan Vasudevan
Public bug reported: Some Gate jobs are failing for stable/ocata, is there any known issues with the stable/ocata branch. See the patch for details. https://review.openstack.org/#/c/640176/ https://review.openstack.org/#/c/642363/ ** Affects: neutron Importance: Undecided Status: N

[Yahoo-eng-team] [Bug 1816698] [NEW] DVR-HA: Removing a router from an agent, does not clear the namespaces on the agent

2019-02-19 Thread Swaminathan Vasudevan
Public bug reported: Removing an active or a standby ha-router from an agent, does not clear the router namespace and the Snat namespaces. This leads to sometimes having two Active HA routers and two 'ha-interface' in the snat namespace for DVR routers. This can be very easily reproduced. 1. Cr

[Yahoo-eng-team] [Bug 1815676] [NEW] DVR: External process monitor for keepalived should be removed when external gateway is removed for DVR HA routers

2019-02-12 Thread Swaminathan Vasudevan
Public bug reported: External process monitor for keepalived state change should be removed when the External Gateway is removed for DVR HA routers. We have seen under certain conditions when the SNAT namespace is missing, the External process Monitor is try to respawn the keepalived state chang

[Yahoo-eng-team] [Bug 1814002] [NEW] Packets getting lost during SNAT with too many connections using the same source and destination on Network Node

2019-01-30 Thread Swaminathan Vasudevan
Public bug reported: Probably we have a problem with SNAT, with too many connections using the same source / destination, on the network nodes. We have reproduced the bug with DNS requests, but we assume that it affects other packages as well. When we send a lot of DNS requests, we see that

[Yahoo-eng-team] [Bug 1804136] Re: Industry Standard approach for DVR E/W routing issue of port/mac movement by vlan based mac learning

2018-11-19 Thread Swaminathan Vasudevan
So if i understand your recommendation are you suggesting that we completely ignore the HOST MAC change that we make today and just use VLAN+MAC learning, so that the packets will get out of the host with its own MAC. What will happen to the switch learning that would happen in the intermediate ph

[Yahoo-eng-team] [Bug 1606741] Re: Metadata service for instances is unavailable when the l3-agent on the compute host is dvr_snat mode

2018-10-26 Thread Swaminathan Vasudevan
** Changed in: neutron Status: In Progress => Confirmed ** Changed in: neutron Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1606741 Title:

[Yahoo-eng-team] [Bug 1797037] [NEW] Extra routes configured on routers are not set in the router namespace and snat namespace with DVR-HA routers

2018-10-09 Thread Swaminathan Vasudevan
Public bug reported: When DVR routers are configured for HA and if we try to add an extra route to the DVR routers, the extra route is not set in the router namespace or in the snat namespace. Configure for HA and DVR 1. Create Router 2. Attach Interface 3. Try to add an extra route with destinat

[Yahoo-eng-team] [Bug 1716782] Re: DVR multinode job has linuxbridge agent mech driver defined

2018-08-29 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1716782 Title: DVR multinode job has linuxbridge agent mech driver defi

[Yahoo-eng-team] [Bug 1779194] [NEW] neutron-lbaas haproxy agent, when configured with allow_automatic_lbaas_agent_failover = True, after failover, when the failed agent restarts or reconnects to Rabb

2018-06-28 Thread Swaminathan Vasudevan
Public bug reported: When we configure two or more lbaas haproxy agents with high availability by setting the allow_automatic_lbaas_agent_failover to True for failover, then the LBaaS fails over to an available active agent, either when the agent is not responsive or the agent lost connection wit

[Yahoo-eng-team] [Bug 1778643] [NEW] DVR: Fip gateway port is tagged as DEAD port by OVS when external_bridge is configured

2018-06-25 Thread Swaminathan Vasudevan
Public bug reported: When external bridge is configured in Neutron, the FIP Agent Gateway port 'fg-' is tagged as a DEAD port with Vlan id of 4095. This issue is seen in Pike. It seems that there was fix that recently merged in neutron shown below https://review.openstack.org/#/c/564825/10 Base

[Yahoo-eng-team] [Bug 1776984] [NEW] DVR: Self recover from the loss of 'fg' ports in FIP Namespace

2018-06-14 Thread Swaminathan Vasudevan
Public bug reported: Sometimes we have seen the 'fg' ports within the fip-namespace either goes down, not created in time or getting deleted due to some race conditions. When this happens, the code tries to recover itself after couple of exceptions when there is a router_update message. But aft

[Yahoo-eng-team] [Bug 1776566] [NEW] DVR: FloatingIP create throws an error if the L3 agent is not running in the given host

2018-06-12 Thread Swaminathan Vasudevan
Public bug reported: FloatingIP create throws an error if the L3 agent is not running on the given host for DVR Routers. This can be reproduced by 1. Configure the global router settings to be 'Legacy' CVR routers. 2. Then configure a DVR Router by manually setting '--distributed = True' from CL

[Yahoo-eng-team] [Bug 1774463] [NEW] RFE: Add support for IPv6 on DVR Routers for the Fast-path exit

2018-05-31 Thread Swaminathan Vasudevan
Public bug reported: This RFE is to add support for IPv6 on DVR Routers for the Fast-Path-Exit. Today DVR support Fast-Path-Exit through the FIP Namespace, but FIP Namespace does not support IPv6 addresses for the Link local address and also we don't have any ra proxy enabled in the FIP Namespac

[Yahoo-eng-team] [Bug 1774459] [NEW] RFE: Update permanent ARP entries for allowed_address_pair IPs in DVR Routers

2018-05-31 Thread Swaminathan Vasudevan
Public bug reported: We have a long term issue with Allowed_address_pairs IP which associated with unbound ports and DVR routers. The ARP entry for the allowed_address_pair IP does not change based on the GARP issued by any keepalived instance. Since DVR does the ARP table update through the co

[Yahoo-eng-team] [Bug 1768919] [NEW] PCI-Passthrough fails when we have Flavor configured and provide a port with vnic_type=direct-physical

2018-05-03 Thread Swaminathan Vasudevan
Public bug reported: PCI-Passthrough of a NIC device to the VM fails, when we have both the Flavor configured with Alias and also provide a network port with 'vnic_type=direct-physical'. The comment shown in the source code shown below, https://github.com/openstack/nova/blob/644ac5ec37903b0a088

[Yahoo-eng-team] [Bug 1768917] [NEW] PCI-Passthrough documentation is incorrect while trying to pass through a NIC

2018-05-03 Thread Swaminathan Vasudevan
Public bug reported: As per the documentation shown below https://docs.openstack.org/nova/pike/admin/pci-passthrough.html In order to achieve PCI passthrough of a network device, it states that we should create a 'flavor' based on the alias and then associate a flavor to the server create functi

[Yahoo-eng-team] [Bug 1761260] [NEW] DVR: Add a check for the item_allocator IP before trying to release it, since we see a KeyError sometimes, when the item is not there anymore.

2018-04-04 Thread Swaminathan Vasudevan
Public bug reported: We have seen this Traceback in Pike based installation, while trying to cleanup a gateway with DVR routers. 2018-04-03 20:30:10.081 9672 DEBUG neutron.agent.l3.dvr_fip_ns [-] Delete FIP link interfaces for router: e415276a-4f37-4ee0-ba48-12d3909153c7 delete_rtr_2_fip_link

[Yahoo-eng-team] [Bug 1759694] Re: DHCP agent doesn't respawn metadata when enable_isolated_metadata and gateway removed

2018-03-28 Thread Swaminathan Vasudevan
*** This bug is a duplicate of bug 1753540 *** https://bugs.launchpad.net/bugs/1753540 Cherry-picked to stable/pike https://review.openstack.org/#/c/557536/ ** This bug has been marked a duplicate of bug 1753540 When isolated metadata is enabled, metadata proxy doesn't get automatically s

[Yahoo-eng-team] [Bug 1758093] [NEW] DVR: RPC error handling missing for get_network_info_for_id

2018-03-22 Thread Swaminathan Vasudevan
Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1758093 Title: DVR:

[Yahoo-eng-team] [Bug 1757188] Re: some L3 HA routers does not work

2018-03-22 Thread Swaminathan Vasudevan
** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1757188 Title: some L3 HA routers does not work Status in neutron: Invalid Bug des

[Yahoo-eng-team] [Bug 1757495] Re: Using dvr and centralized routers in same network fails

2018-03-22 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Incomplete => Invalid ** Changed in: neutron Status: Invalid => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1757495 Title: Using

[Yahoo-eng-team] [Bug 1756406] [NEW] DVR: Fix dvr mac address format to be backward compatible with non native openflow interface

2018-03-16 Thread Swaminathan Vasudevan
ed to add a patch to change the format of the MAC before it is handed over to the openflow interface driver. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog -- You received this

[Yahoo-eng-team] [Bug 1657981] Re: FloatingIPs not reachable after restart of compute node (DVR)

2018-03-12 Thread Swaminathan Vasudevan
** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1657981 Title: FloatingIPs not reachable after restart of compute node (DVR) Status i

[Yahoo-eng-team] [Bug 1716194] Re: IPTables rules are not updated if there is a change in the FWaaS rules when FWaaS is deployed in DVR mode

2018-03-12 Thread Swaminathan Vasudevan
*** This bug is a duplicate of bug 1715395 *** https://bugs.launchpad.net/bugs/1715395 ** This bug is no longer a duplicate of bug 1716401 FWaaS: Ip tables rules do not get updated in case of distributed virtual routers (DVR) ** This bug has been marked a duplicate of bug 1715395 FWaaS:

[Yahoo-eng-team] [Bug 1751396] [NEW] DVR: Inter Tenant Traffic between two networks and connected through a shared network not reachable with DVR routers

2018-02-23 Thread Swaminathan Vasudevan
Public bug reported: Inter Tenant Traffic between Two Tenants on two different private networks connected through a common shared network (created by Admin) is not route able through DVR routers Steps to reproduce it: (NOTE: No external, just shared network) This is only reproducable in Multinod

[Yahoo-eng-team] [Bug 1749577] Re: DVR: Static routes are not configured in snat-namespase for DVR Routers

2018-02-14 Thread Swaminathan Vasudevan
User error. ** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1749577 Title: DVR: Static routes are not configured in snat-namespase fo

[Yahoo-eng-team] [Bug 1749577] [NEW] DVR: Static routes are not configured in snat-namespase for DVR Routers

2018-02-14 Thread Swaminathan Vasudevan
Public bug reported: Static routes are not configured in snat-namespace for DVR routers. Steps to reproduce: 1. Create Network 2. Create Subnet 3. Create Router 4. Add interface to Router 5. Set gateway for the Router 6. Add a static route (next hop to the Router) 7. Go check the 'snat-namespace'

[Yahoo-eng-team] [Bug 1667877] Re: [RFE] Allow DVR for E/W while leaving N/S centralized

2017-10-04 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1667877 Title: [RFE] Allow DVR for E/W while leaving N/S centralized S

[Yahoo-eng-team] [Bug 1635554] Re: Delete Router / race condition

2017-10-03 Thread Swaminathan Vasudevan
In that case we should close this bug. ** Changed in: neutron Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1635554 Title: Delete Router / race co

[Yahoo-eng-team] [Bug 1712795] Re: Fail to startup neutron-l3-agent

2017-10-03 Thread Swaminathan Vasudevan
Right now there is no bug fixes are support for mitaka branch. Since this bug is not seen in the current master and stable branch, so I would close this bug. ** Changed in: neutron Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engin

[Yahoo-eng-team] [Bug 1718788] [NEW] DVR: Migrate centralized unbound floatingip to the respective host when the port is bound

2017-09-21 Thread Swaminathan Vasudevan
is not seen on the host where the VM resides. Theoretically the FloatingIP should be migrated to the host where it is currently bound. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: Confirmed ** Tags: l3-dvr-backlog

[Yahoo-eng-team] [Bug 1718585] Re: set floatingip status to DOWN during creation

2017-09-21 Thread Swaminathan Vasudevan
** Changed in: neutron Status: New => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1718585 Title: set floatingip status to DOWN during creation Status in neutron: Opi

[Yahoo-eng-team] [Bug 1717302] [NEW] Tempest floatingip scenario tests failing on DVR Multinode setup with HA

2017-09-14 Thread Swaminathan Vasudevan
Public bug reported: neutron.tests.tempest.scenario.test_floatingip.FloatingIpSameNetwork and neutron.tests.tempest.scenario.test_floatingip.FloatingIpSeparateNetwork are failing on every patch. This trace is seen on the node-2 l3-agent. Sep 13 07:16:43.404250 ubuntu-xenial-2-node-rax-dfw-10909

[Yahoo-eng-team] [Bug 1716829] [NEW] Centralized floatingips not configured right with DVR and HA

2017-09-12 Thread Swaminathan Vasudevan
ecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog ** Changed in: neutron Status: New => Confirmed -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subsc

[Yahoo-eng-team] [Bug 1712728] [NEW] DVR: get_router_cidrs in dvr_edge_router not returning the centralized_floating_ip cidr

2017-08-23 Thread Swaminathan Vasudevan
Public bug reported: get_router_cidrs over-ridden in dvr_edge_router is not returing the centralized_floating_ip cidrs. So the consequence is the DNAT rules are left over in the snat namespace when the centralized_floating_ips are removed. ** Affects: neutron Importance: Undecided

[Yahoo-eng-team] [Bug 1702790] [NEW] DVR Router update task fails when agent restarts

2017-07-06 Thread Swaminathan Vasudevan
Public bug reported: When there is a DVR router with gateway enabled, and if the agent restarts, then the router_update fails and you can see Error log in the l3_agent.log. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status

[Yahoo-eng-team] [Bug 1702769] [NEW] Binding info for DVR port not found error seen when notify_l2pop_port_wiring is called with DVR routers

2017-07-06 Thread Swaminathan Vasudevan
the error. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: Confirmed ** Tags: l3-dvr-backlog ** Changed in: neutron Assignee: (unassigned) => Swaminathan Vasudevan (swaminathan-vasudevan) ** Changed in: neutron

[Yahoo-eng-team] [Bug 1701288] [NEW] In scale testing RPC timeout error seen in the ovs_neutron_agent when update_device_list is called with DVR routers

2017-06-29 Thread Swaminathan Vasudevan
Public bug reported: At large scale testing when trying to deploy around 8000 VMs with DVR routers, we are seeing an RPC Timeout error in ovs_neutron_agent. This RPC Timeout error occurs when the ovs_neutron_agent tries to bind the vif port. On further analysis it seems that the update_port_stat

[Yahoo-eng-team] [Bug 1695101] [NEW] DVR Router ports and gateway ports are not bound to any host and no snat namespace created

2017-06-01 Thread Swaminathan Vasudevan
em. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: Confirmed ** Tags: l3-dvr-backlog ** Tags added: l3-dvr-backlog ** Changed in: neutron Assignee: (unassigned) => Swaminathan Vasudevan (swaminathan-vasudevan)

[Yahoo-eng-team] [Bug 1667877] [NEW] [RFE] DVR support for Configuring Floatingips in Network Node or in the Compute Node based on Config option.

2017-02-24 Thread Swaminathan Vasudevan
Public bug reported: Provide a Configurable option to configure Floatingips for DVR based routers to reside on Compute Node or on Network Node. Also proactively check the status of the agent on the destination node and if the agent health is down, then configure the Floatingip on the Network Nod

[Yahoo-eng-team] [Bug 1524020] Re: DVRImpact: dvr_vmarp_table_update and dvr_update_router_add_vm is called for every port update instead of only when host binding or mac-address changes occur

2017-01-11 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1524020 Title: DVRImpact: dvr_vmarp_table_update and dvr_update_router

[Yahoo-eng-team] [Bug 1554876] Re: router not found warning logs in the L3 agent

2017-01-11 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1554876 Title: router not found warning logs in the L3 agent Status in

[Yahoo-eng-team] [Bug 1631513] [NEW] DVR: Fix race conditions when trying to add default gateway for fip gateway port.

2016-10-07 Thread Swaminathan Vasudevan
Public bug reported: There seems to be a race condition when trying to add default gateway route in fip namespace for the fip agent gateway port. The way it happens is at high scale testing, when there is a router update that is currently happening for the Router-A which has a floatingip, a fip n

[Yahoo-eng-team] [Bug 1593354] Re: SNAT HA failed because of missing nat rule in snat namespace iptable

2016-10-06 Thread Swaminathan Vasudevan
I did verify it in Mitaka and I don't see any issues with the 'sg' port and related rules with respect to failover. So we can close this issue as we discussed last week. ** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo!

[Yahoo-eng-team] [Bug 1476469] Re: with DVR, a VM can't use floatingIP and VPN at the same time

2016-09-28 Thread Swaminathan Vasudevan
VPN is a centralized service and not distributed one. The VPN service is only running in the SNAT Namespace and not on the router or fip namespace. So the fip traffic flowing through the fip namespace or router namespace may not go through the IPsec driver that is running in SNAT Namespace. This

[Yahoo-eng-team] [Bug 1609217] Re: DVR: dvr router should not exist in not-binded network node

2016-08-31 Thread Swaminathan Vasudevan
** Changed in: neutron Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1609217 Title: DVR: dvr router should not exist in not-binded network node St

[Yahoo-eng-team] [Bug 1614337] Re: L3 agent fails on FIP when DVR and HA both enabled in router

2016-08-29 Thread Swaminathan Vasudevan
** Changed in: neutron Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1614337 Title: L3 agent fails on FIP when DVR and HA both enabled in router Sta

[Yahoo-eng-team] [Bug 1611964] [NEW] SNAT redirect rules should be removed only on Gateway clear.

2016-08-10 Thread Swaminathan Vasudevan
Public bug reported: SNAT redirect rules should be removed only on Gateway clear and not for a gateway move or gateway reschedule. This would cause the snat_node unreachable by the dvr service ports on the originating node. How to reproduce it. 1. Create a two network node setup (dvr_snat) 2.

[Yahoo-eng-team] [Bug 1611513] [NEW] ip_lib: Add support for 'Flush' command in iproute

2016-08-09 Thread Swaminathan Vasudevan
Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog ** Summary changed: - ip_lib: Add support for 'Flush' command for iproute + ip_lib: Add support for 'Flush' command in iproute -- You received thi

[Yahoo-eng-team] [Bug 1599287] [NEW] Cleanup snat redirect rules when agent restarts after stale snat namespace is cleaned.

2016-07-05 Thread Swaminathan Vasudevan
the local file system and reused later when necessary. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog ** Tags added: l3-dvr-backlog -- You received this bug notification because

[Yahoo-eng-team] [Bug 1583694] [NEW] [RFE] DVR support for Allowed_address_pair port that are bound to multiple ACTIVE VM ports used by Octavia

2016-05-19 Thread Swaminathan Vasudevan
Public bug reported: DVR support for Allowed_address_pair ports with FloatingIP that are unbound and assgined to Multiple VMs that are active. Problem Statement: When FloatingIP is asssigned to Allowed_address_pair port and assigned to multiple VMs that are ACTIVE and connected to DVR (Distribu

[Yahoo-eng-team] [Bug 1578866] Re: test_user_update_own_password failing intermittently

2016-05-11 Thread Swaminathan Vasudevan
** Also affects: neutron Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1578866 Title: test_user_update_own_password failing intermittently S

[Yahoo-eng-team] [Bug 1569918] [NEW] Allowed_address_pair fixed_ip configured with FloatingIP after getting associated with a VM port does not work with DVR routers

2016-04-13 Thread Swaminathan Vasudevan
Public bug reported: Allowed_address_pair fixed_ip when configured with FloatingIP after the port is associated with the VM port is not reachable from DVR router. The current code only supports adding in the proper ARP update and port host binding inheritence for the Allowed_address_pair port onl

[Yahoo-eng-team] [Bug 1566046] [NEW] Fix TypeError when trying to update an arp entry for ports with allowed_address_pairs on DVR router

2016-04-04 Thread Swaminathan Vasudevan
see this in the neutron-server logs. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: New ** Tags: l3-dvr-backlog ** Changed in: neutron Assignee: (unassigned) => Swaminathan Vasudevan (swaminathan-vasu

[Yahoo-eng-team] [Bug 1564776] [NEW] DVR l3 agent should check for snat namespace existence before adding or deleting anything from the namespace

2016-04-01 Thread Swaminathan Vasudevan
Public bug reported: Check for snat_namespace existence in the node before any operation in the namespace. Today we check the self.snatnamespace which may or may not reflect the exact state of the system. If the snat_namespace is accidentally deleted and if we try to remove t

[Yahoo-eng-team] [Bug 1564575] [NEW] DVR router namespaces are deleted when we manually move a DVR router from one SNAT_node to another SNAT_node even though there are active VMs in the node

2016-03-31 Thread Swaminathan Vasudevan
Public bug reported: DVR router namespaces are deleted when we manually move the router from on dvr_snat node to another dvr_snat node. It should be only deleting the snat_namespace and not the router_namespace, since there are 'dhcp' ports and 'vm' ports still serviced by DVR. How to reproduce:

[Yahoo-eng-team] [Bug 1563879] [NEW] [RFE] DVR should route packets to Instances behind the L2 Gateway

2016-03-30 Thread Swaminathan Vasudevan
Public bug reported: L2 Gateway bridges the neutron network with the hardware based VxLAN gateways. The DVR routers in neutron could not forward traffic to an instance that is behind the VxLAN gateways since it could not 'ARP' for those instances. DVR currently has prepopulated ARP entries for al

[Yahoo-eng-team] [Bug 1562110] [NEW] link-lock-address allocater for DVR has a limit of 256 address pairs per node

2016-03-25 Thread Swaminathan Vasudevan
Public bug reported: The current 'link-lock-address allocator for DVR routers has a limit fo 256 routers per node. This should be configurable and not just limit to 256 routers per node. ** Affects: neutron Importance: Undecided Status: Confirmed ** Tags: l3-dvr-backlog ** Chang

[Yahoo-eng-team] [Bug 1499045] Re: get_snat_port_for_internal_port called twice when an interface is added or removed by the l3 agent in the case of DVR routers.

2016-03-22 Thread Swaminathan Vasudevan
** Changed in: neutron Status: In Progress => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1499045 Title: get_snat_port_for_internal_port called twice when an interface

[Yahoo-eng-team] [Bug 1538369] Re: re factor add_router_interface in l3_dvr_db.py

2016-03-22 Thread Swaminathan Vasudevan
** Changed in: neutron Status: New => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1538369 Title: re factor add_router_interface in l3_dvr_db.py Status in neutron: Op

[Yahoo-eng-team] [Bug 1558097] [NEW] DVR SNAT HA - Documentation for Networking guide

2016-03-18 Thread Swaminathan Vasudevan
Public bug reported: DVR SNAT HA - Documentation for Networking guide for Mitaka. ** Affects: neutron Importance: Undecided Status: New ** Tags: l3-dvr-backlog -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutr

[Yahoo-eng-team] [Bug 1554392] Re: Set extra route for DVR might cause error

2016-03-08 Thread Swaminathan Vasudevan
This is a known issue, since the router does not have an external network interface in the router namespace and if you try to configure an extra route pointing to the next hop which does not have a corresponding interface in the router namespace. This was a descision that we made since we don't wa

[Yahoo-eng-team] [Bug 1549511] [NEW] "test_volume_backed_live_migration" test failures seen in the gate

2016-02-24 Thread Swaminathan Vasudevan
Public bug reported: Recently we have seen the "Test_volume_backed_live_migration" fail with Multinode gate setup. This test failure is seen in nova/neutron etc., http://logs.openstack.org/17/258417/6/check/gate-tempest-dsvm-multinode- full/0d516d3/console.html#_2016-02-24_17_43_48_123 ** Affec

[Yahoo-eng-team] [Bug 1541714] Re: DVR routers are not created on a compute node that runs agent in 'dvr' mode

2016-02-04 Thread Swaminathan Vasudevan
It was an invalid user configuration. The "dvr"node was not configured with the right agent mode, and so this issue was seen. Please ignore this bug. ** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team,

[Yahoo-eng-team] [Bug 1541714] [NEW] DVR routers are not created on a compute node that runs agent in 'dvr' mode

2016-02-03 Thread Swaminathan Vasudevan
Public bug reported: DVR routers are not created on a compute node that is running L3 agent in "dvr" mode. This might have been introduced by the latest patch that changed the scheduling behavior. https://review.openstack.org/#/c/254837/ Steps to reproduce: 1. Stack up two nodes. ( dvr_snat no

[Yahoo-eng-team] [Bug 1535928] [NEW] Duplicate IPtables rule detected warning message seen in L3 agent

2016-01-19 Thread Swaminathan Vasudevan
Public bug reported: In recent L3 agent logs in the gate we have been seeing this warning message associated with the DVR router jobs. Right now none of the jobs are failing, but we need to see why this warning message is showing up in the logs or it might be due to some hidden issues. http://

[Yahoo-eng-team] [Bug 1524020] [NEW] DVRImpact: dvr_vmarp_table_update and dvr_update_router_add_vm is called for every port update instead of only when host binding or mac-address changes occur

2015-12-08 Thread Swaminathan Vasudevan
Public bug reported: DVR arp update (dvr_vmarp_table_update) and dvr_update_router_add_vm called for every update_port if the mac_address changes or when update_devic_up is true. These functions should be called from _notify_l3_agent_port_update, only when a host binding for a service port change

[Yahoo-eng-team] [Bug 1515360] [NEW] Add more verbose to Tempest Test Errors that causes "SSHTimeout" seen in CVR and DVR

2015-11-11 Thread Swaminathan Vasudevan
Public bug reported: Today "SSHTimeout" Errors are seen both in CVR ( Centralized Virtual Routers) and DVR ( Distributed Virtual Routers). The frequency of occurence is more on DVR than the CVR. But the problem here, is the error statement that is returned and the data that is dumped. SSHTimeou

[Yahoo-eng-team] [Bug 1513678] [NEW] At scale router scheduling takes a long time with DVR routers with multiple compute nodes hosting thousands of VMs

2015-11-05 Thread Swaminathan Vasudevan
might be taking lot more time. So we need to figure out the issue and reduce the time taken for the scheduling. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog -- You received this bug

[Yahoo-eng-team] [Bug 1512199] Re: change vm fixed ips will cause unable to communicate to vm in other network

2015-11-03 Thread Swaminathan Vasudevan
Not able to reproduce I could see the arp table update on the router namespaces on both nodes. I tried to modify the ports on both the subnet 10.2.0.X and 10.0.0.X. In this example I have change the 10.2.0.4 to 10.2.0.25 and 10.0.0.8 10.0.0.20. In both cases I saw that the arp entry was updated.

[Yahoo-eng-team] [Bug 1509004] [NEW] "test_dualnet_dhcp6_stateless_from_os" failures seen in the gate

2015-10-22 Thread Swaminathan Vasudevan
Public bug reported: "test_dualnet_dhcp6_stateless_from_os" - This test fails in the gate randomly both with DVR and non-DVR routers. http://logs.openstack.org/79/230079/27/check/gate-tempest-dsvm-neutron- full/1caed8b/logs/testr_results.html.gz http://logs.openstack.org/85/238485/1/check/gate-t

[Yahoo-eng-team] [Bug 1503847] [NEW] Python34 test failures in gate - Logging Error

2015-10-07 Thread Swaminathan Vasudevan
Public bug reported: I am seeing "gate-neutron-python34" test failures again in neutron. http://logs.openstack.org/82/228582/13/check/gate-neutron- python34/5b36c34/console.html http://logs.openstack.org/82/228582/13/check/gate-neutron- python34/5b36c34/console.html#_2015-10-07_17_36_06_987 **

[Yahoo-eng-team] [Bug 1501873] [NEW] FIP Namespace add/delete race condition seen in DVR router log

2015-10-01 Thread Swaminathan Vasudevan
te_dvr_fip_interfaces /opt/stack/new/neutron/neutron/agent/l3/dvr_local_router.py:427 2015-09-29 21:10:34.043 DEBUG neutron.agent.l3.dvr_fip_ns [req-33413b07-784c-469e-8a35-0e20312a157e None None] add fip-namespace(fip-31689320-95d7-44f9-932a-cc82c1bca2b4) create /opt/stack/new/neutron/neutron

[Yahoo-eng-team] [Bug 1501086] [NEW] ARP entries dropped by DVR routers when the qr device is not ready or present

2015-09-29 Thread Swaminathan Vasudevan
22e4-5fef-4889-9372-8cf1218522a2 None None] adding internal network: prefix(qr-), port(b672ffde-cd80-49eb-9817-58436fa8e8fd) _internal_network_added /opt/stack/new/neutron/neutron/agent/l3/router_info.py:300 ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swami

[Yahoo-eng-team] [Bug 1499787] [NEW] Static routes are attempted to add to SNAT Namespace of DVR routers without checking for Router Gateway.

2015-09-25 Thread Swaminathan Vasudevan
Public bug reported: In DVR routers static routes are now only added to snat namespace. But before adding to snat namespace, the routers are not checked for the existence of gateway. ** Affects: neutron Importance: Undecided Status: New ** Tags: l3-dvr-backlog -- You received t

[Yahoo-eng-team] [Bug 1499785] [NEW] Static routes are not added to the qrouter namespace for DVR routers

2015-09-25 Thread Swaminathan Vasudevan
Public bug reported: Static routes are not added to the qrouter namespace when routers are added. Initially it used to be configuring the routes in the qrouter namespace but not in the SNAT namespace. A recent patch caused this regression in moving the routes from qrouter namespace to SNAT name

[Yahoo-eng-team] [Bug 1499045] [NEW] get_snat_port_for_internal_port called twice when an interface is added or removed by the l3 agent in the case of DVR routers.

2015-09-23 Thread Swaminathan Vasudevan
' and again it is called by the 'dvr_edge_router.py'. This can be reduced to a single call to improve the controll plane performance. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress **

[Yahoo-eng-team] [Bug 1419175] Re: Cannot find device "qr-" error message found in logtrace with DVR routers while trying to update arp entry

2015-09-21 Thread Swaminathan Vasudevan
: (unassigned) => Swaminathan Vasudevan (swaminathan-vasudevan) ** Tags added: l3-dvr-backlog -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1419175 Title: Cannot find device "qr-" error

[Yahoo-eng-team] [Bug 1496578] [NEW] SNAT port not found for the given internal port error message seen when gateway is removed for DVR routers.

2015-09-16 Thread Swaminathan Vasudevan
failure it seems when a gateway is removed, the "get_snat_port_for_internal_port" is called without the cache value. This bug was introduced by the patch shown below. Icc099c1a97e3e68eeaf4690bc83167ba30d8099a ** Affects: neutron Importance: Undecided Assignee: Swaminathan Va

[Yahoo-eng-team] [Bug 1493524] [NEW] IPv6 support for DVR routers

2015-09-08 Thread Swaminathan Vasudevan
Public bug reported: This bug would capture all the IPv6 related work on DVR routers going forward. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: In Progress ** Tags: l3-dvr-backlog -- You received this bug

[Yahoo-eng-team] [Bug 1475011] [NEW] FloatingIPsTestJson tests fail with DVR routers

2015-07-15 Thread Swaminathan Vasudevan
uot; when trying to delete the "floatingip_agent_gateway_port". "Floatingip_agent_gateway_port" calls "_delete_port" and so the "ML2PLugin" throws attribute not found error with recent changes. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan

[Yahoo-eng-team] [Bug 1456755] Re: Could not retrieve gateway port for subnet

2015-06-23 Thread Swaminathan Vasudevan
*** This bug is a duplicate of bug 1404823 *** https://bugs.launchpad.net/bugs/1404823 ** This bug is no longer a duplicate of bug 1456756 Could not retrieve gateway port for subnet ** This bug has been marked a duplicate of bug 1404823 router-interface-add port succeed but does not add

[Yahoo-eng-team] [Bug 1468007] [NEW] Delete the FloatingIP Agent Gateway Port only when External Network is deleted and also delete the port based on Agents decision.

2015-06-23 Thread Swaminathan Vasudevan
Public bug reported: FloatingIP Agent Gateway port is created on the nodes to substitute for the Gateway port, since gateway port is currently residing on the Network Node. So it makes sense for the server to delete the FloatingIP Agent Gateway Port only when the External Gateway Port is deleted

[Yahoo-eng-team] [Bug 1465434] [NEW] DVR issues with supporting multiple subnets per network on DVR routers

2015-06-15 Thread Swaminathan Vasudevan
Public bug reported: DVR today has issues with supporting multiple subnets per network on its routers. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: New ** Tags: l3-dvr-backlog -- You received this bug

[Yahoo-eng-team] [Bug 1426165] Re: DVR: "Device or resource busy" error seen when fip namespace is being deleted

2015-04-10 Thread Swaminathan Vasudevan
Let us go ahead and close this bug. ** Changed in: neutron Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1426165 Title: DVR: "Device or resource busy" err

[Yahoo-eng-team] [Bug 1398446] Re: Nova compute failed to delete VM port with DVR

2015-03-31 Thread Swaminathan Vasudevan
** Changed in: neutron Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1398446 Title: Nova compute failed to delete VM port with DVR Status in OpenS

[Yahoo-eng-team] [Bug 1431077] [NEW] TRACE: attribute error when trying to fetch the router.snat_namespace.name

2015-03-11 Thread Swaminathan Vasudevan
Public bug reported: TRACE seen in the vpn-agent log when configured with DVR router. A recent refactoring to the agent have introduced this problem. http://logs.openstack.org/71/130471/6/check/check-tempest-dsvm-neutron- dvr/10208dc/logs/screen-q-vpn.txt.gz?level=TRACE 2015-03-11 14:09:03.570

[Yahoo-eng-team] [Bug 1423422] [NEW] FloatingIP Agent Gateway Port is created for Non-DVR Routers

2015-02-18 Thread Swaminathan Vasudevan
FloatingIP Agent Gateway Ports for Legacy routers which are not utilized. Only DVR routers require L3 agent to be present in the Compute Node. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan-vasudevan) Status: New ** Tags: l3-dvr-backlog

[Yahoo-eng-team] [Bug 1421886] [NEW] FloatingIP agent gateway port should delete the FIP Agent gateway port based on the host and the external network id when there are multiple external networks.

2015-02-13 Thread Swaminathan Vasudevan
Public bug reported: FloatingIP Agent Gateway port should be deleted based on the host and also based on the External network id. In the Multiple external network scenario what happens is there might be more than one FloatingIP Agent Gateway Port on the same host and so it has to be deleted based

[Yahoo-eng-team] [Bug 1421497] [NEW] Gateway clear generates a TRACE - AttributeError in get_int_device_name in DVR routers

2015-02-12 Thread Swaminathan Vasudevan
Public bug reported: A recent change in the agent code have introduced this problem. When a Gateway is cleared from the router, even though there are no existing floating IPs, the "external_gateway_removed" function in "agent.py" is calling "process_floatingips". That may be the reason for thi

[Yahoo-eng-team] [Bug 1421011] [NEW] Remove unused RPC methods from the L3_rpc

2015-02-11 Thread Swaminathan Vasudevan
Public bug reported: Remove unsued RPC methods from the L3_rpc. The "get_snat_router_interface_ports" is defined but not currently used by any agents. So it need to be cleaned. ** Affects: neutron Importance: Undecided Assignee: Swaminathan Vasudevan (swaminathan

[Yahoo-eng-team] [Bug 1417386] [NEW] AttributeError: _oslo_messaging_localcontext errors found in neutron l3-agent logs

2015-02-02 Thread Swaminathan Vasudevan
Public bug reported: This TRACE is seen in many places in the neutron l3-agent logs from the jenkins logs. 2015-02-02 23:29:13.916 ERROR oslo_messaging.rpc.dispatcher [req-ce57a6b0-04fc-41dd-a114-5b69c0ebcf6d FloatingIPsNegativeTestJSON-267704990 FloatingIPsNegativeTestJSON-594738290] Exception

  1   2   >