*** reedip has quit IRC | 00:25 | |
*** hoangcx has joined #openstack-fwaas | 00:45 | |
*** cuongnv has joined #openstack-fwaas | 01:09 | |
*** amotoki has joined #openstack-fwaas | 01:46 | |
*** amotoki has quit IRC | 01:58 | |
*** yamamoto has joined #openstack-fwaas | 02:29 | |
*** reedip has joined #openstack-fwaas | 02:31 | |
*** yamamoto has quit IRC | 02:33 | |
*** amotoki has joined #openstack-fwaas | 03:00 | |
*** yushiro has joined #openstack-fwaas | 04:02 | |
*** vks1 has joined #openstack-fwaas | 04:15 | |
*** vks1 has left #openstack-fwaas | 04:16 | |
*** reedip has quit IRC | 04:17 | |
*** vks1 has joined #openstack-fwaas | 04:17 | |
*** reedip has joined #openstack-fwaas | 04:19 | |
*** vks1 has quit IRC | 04:55 | |
*** obre_ has joined #openstack-fwaas | 05:06 | |
*** obre has quit IRC | 05:07 | |
reedip | vks1 , yushiro : http://paste.openstack.org/show/604610/ | 05:07 |
---|---|---|
reedip | I would like to take up neutron-lib | 05:08 |
reedip | yushiro : maybe you can take neutronclient , if you like , and maybe vks1 can take neutron-fwaas | 05:08 |
yushiro | reedip, sure. | 05:08 |
yushiro | reedip: neutron-lib, vks1: neutron-fwaas, yushiro: python-neutronclient | 05:09 |
reedip | vks1 : let us know in case of any issues | 05:09 |
reedip | :) | 05:09 |
yushiro | Thanks for your summary! | 05:09 |
reedip | It was nothing, and maybe I missed something... which I guess you would find | 05:10 |
reedip | yushiro , vks1 : BTW as neutron-fwaas scnearios can fail if we directly change public to shared | 05:10 |
reedip | therefore I propose first adding shared as an attribute | 05:10 |
reedip | in neutron-lib and fwaas | 05:11 |
*** vks1 has joined #openstack-fwaas | 05:11 | |
reedip | and then removing public from fwaas first and then from neutron-lib | 05:11 |
vks1 | hi | 05:13 |
yushiro | reedip, Sure. all of these patch should be named 'bug/1676922' for https://bugs.launchpad.net/neutron/+bug/1676922 | 05:14 |
openstack | Launchpad bug 1676922 in neutron "changing Public attribute in FWaaS" [Medium,New] - Assigned to Reedip (reedip-banerjee) | 05:14 |
reedip | agreed | 05:14 |
reedip | vks1 : any suggestions ? | 05:16 |
vks1 | reedip I just got last 3 lines of conversation :) | 05:17 |
reedip | <reedip> vks1 , yushiro : http://paste.openstack.org/show/604610/ | 05:17 |
reedip | <reedip> I would like to take up neutron-lib | 05:17 |
reedip | <reedip> yushiro : maybe you can take neutronclient , if you like , and maybe vks1 can take neutron-fwaas | 05:17 |
reedip | <yushiro> reedip, sure. | 05:17 |
reedip | <yushiro> reedip: neutron-lib, vks1: neutron-fwaas, yushiro: python-neutronclient | 05:17 |
reedip | <reedip> vks1 : let us know in case of any issues | 05:17 |
reedip | <reedip> :) | 05:17 |
reedip | <yushiro> Thanks for your summary! | 05:17 |
reedip | <reedip> It was nothing, and maybe I missed something... which I guess you would find | 05:17 |
reedip | <reedip> yushiro , vks1 : BTW as neutron-fwaas scnearios can fail if we directly change public to shared | 05:17 |
reedip | <reedip> therefore I propose first adding shared as an attribute | 05:17 |
reedip | <reedip> in neutron-lib and fwaas | 05:17 |
yushiro | reedip, Regarding neutron-lib and python-neutronclient, let's add 'Depends-On: <change-id>' in commit message. | 05:17 |
reedip | <reedip> and then removing public from fwaas first and then from neutron-lib | 05:17 |
reedip | <vks1> hi | 05:17 |
reedip | <yushiro> reedip, Sure. all of these patch should be named 'bug/1676922' for https://bugs.launchpad.net/neutron/+bug/1676922 | 05:17 |
openstack | Launchpad bug 1676922 in neutron "changing Public attribute in FWaaS" [Medium,New] - Assigned to Reedip (reedip-banerjee) | 05:17 |
reedip | <openstack> Launchpad bug 1676922 in neutron "changing Public attribute in FWaaS" [Medium,New] - Assigned to Reedip (reedip-banerjee) | 05:17 |
reedip | There ^^ | 05:17 |
reedip | yushiro : yes , agreed | 05:17 |
vks1 | reedip yeah | 05:17 |
yushiro | :) | 05:18 |
vks1 | reedip ok so I will start adding 'shared' attribute . this is 'boolean' attr ? | 05:19 |
reedip | vks1 : yes , just like Public | 05:19 |
reedip | in clearer terms, you need to migrate the Public Attribute to Shared Attribute | 05:19 |
vks1 | reedip ok | 05:20 |
vks1 | this will be only for v2 or v1 also ?? | 05:20 |
reedip | vks1 : only v2 | 05:24 |
reedip | v1 will be deprecated so no point of moving forward on that right now | 05:24 |
vks1 | ok | 05:24 |
reedip | yushiro : this might impact midonet implementation, so I will drop a small mail on the ML to inform that FWaaS would be moving from Public Attribute to Shared attribute | 05:24 |
reedip | for v2 | 05:24 |
yushiro | reedip, thanks. | 05:28 |
reedip | yushiro : glad to help :) | 05:29 |
yushiro | In order to handle networking-midonet behavior, I'll push noop patch into networking-midonet. | 05:29 |
yushiro | sorry, s/handle/realize | 05:30 |
reedip | ok yushiro :) | 05:32 |
*** yamamoto has joined #openstack-fwaas | 05:35 | |
*** yamamoto has quit IRC | 05:40 | |
*** reedip has quit IRC | 05:54 | |
*** reedip has joined #openstack-fwaas | 06:01 | |
cuongnv | reedip, remember my error yesterday? it's happening on gate now | 06:20 |
cuongnv | http://logs.openstack.org/45/438445/7/check/gate-neutron-fwaas-python27-ubuntu-xenial/c7a0fa7/console.html this one for my ps | 06:21 |
reedip | umm WHAT | 06:22 |
reedip | link | 06:22 |
reedip | thanks, lemme look at it | 06:22 |
cuongnv | same with ps of Cedric https://review.openstack.org/#/c/449610/ | 06:22 |
reedip | were you able to solve it? | 06:22 |
cuongnv | nope | 06:23 |
* cuongnv reading this https://review.openstack.org/#/c/450923/ | 06:23 | |
reedip | Okay checking | 06:23 |
cuongnv | seems related | 06:23 |
reedip | probably | 06:24 |
reedip | taking it up | 06:25 |
cuongnv | cool | 06:28 |
reedip | thanks for the infor cuongnv | 06:28 |
reedip | i think 450923 should be sufficient to fix this | 06:29 |
reedip | lets wait for that patch to merge and then rebase 438445 | 06:29 |
cuongnv | yeah, let's see | 06:29 |
*** yamamoto has joined #openstack-fwaas | 06:41 | |
*** yamamoto has quit IRC | 06:47 | |
reedip | vks1 , yushiro : please add me in your code commits for the migration | 07:34 |
reedip | I havedropped the email on the ML | 07:34 |
yushiro | reedip, sure. I'll add you as 'co-authored-by' | 07:35 |
reedip | noooo ... I am not the author .. you are :) Just add me as a reviewer .... if I actually change that patch with something constructive, then it can be co-authoered by ... but if I am not working on that patch, it doesnt make much sense :) | 07:36 |
*** yamamoto has joined #openstack-fwaas | 07:43 | |
reedip | yushiro, vks1 : https://review.openstack.org/451229 | 07:46 |
reedip | putting -1 and awaiting changes in neutron-fwaas | 07:47 |
yushiro | reedip, amazing speed :) | 07:47 |
reedip | naah, grep -rl and sed :) | 07:47 |
yushiro | aha :) | 07:47 |
*** yamamoto has quit IRC | 07:48 | |
reedip | can work in lib, and aybe in other places | 07:48 |
reedip | grep -rl "public" DIR | xargs sed 's/public/shared/g' | 07:48 |
*** mickeys has quit IRC | 07:59 | |
bbbzhao | Hi guys, is there any case that set the ingress fw_policy and egress fw_policy with the same fw_policy ? deny any? :) | 08:45 |
*** yamamoto has joined #openstack-fwaas | 08:45 | |
*** yamamoto has quit IRC | 08:50 | |
reedip | means | 08:53 |
bbbzhao | I found fw_group can be set like that. I'm not sure it's a vaild operation or any use cases about that. | 08:58 |
reedip | bbbzhao ; they can, cant they ? | 08:59 |
reedip | why cant it be valid :) | 08:59 |
*** mickeys has joined #openstack-fwaas | 08:59 | |
reedip | so you are creating one filrewall policy as deny IPv4, and then associate it with ingress and egress | 09:00 |
reedip | or a better example bbbzhao : suppose you want to schedule the firewalls :D | 09:00 |
reedip | so you want complete access to , say , facebook from 12:00 PM to 1:00 PM everyday | 09:01 |
reedip | but you dont want any external machine to access your VM | 09:01 |
reedip | then the Ingress and Egress policies would be DENY for 1:00 PM to 12:00 PM next day, and from 12:00 PM to 1:00 PM it would be DENY Ingress, Allow Egress :) | 09:01 |
bbbzhao | reedip, cause it contain the same fw_rule..The rule like src X.X.X.X access in ingress traffic, in egress traffic also.. I just think the deny action is OK. But others ..hm I'm not sure. | 09:02 |
reedip | but I think the Source is optional, isnt it ? | 09:03 |
bbbzhao | Yeah. But we cannot control users to not set them. | 09:03 |
bbbzhao | I mean if there is a rule like that .. | 09:04 |
*** mickeys has quit IRC | 09:04 | |
bbbzhao | reedip, just a question about that. :). You said the deny action case is make sense. | 09:12 |
reedip | makes sense to for now | 09:15 |
*** vks1 has quit IRC | 09:16 | |
*** vks1 has joined #openstack-fwaas | 09:16 | |
*** reedip has quit IRC | 09:34 | |
*** vks1 has quit IRC | 09:36 | |
*** reedip has joined #openstack-fwaas | 09:37 | |
*** amotoki has quit IRC | 09:40 | |
*** reedip has quit IRC | 09:43 | |
*** yamamoto has joined #openstack-fwaas | 09:46 | |
*** reedip has joined #openstack-fwaas | 09:48 | |
*** vks1 has joined #openstack-fwaas | 09:51 | |
*** yamamoto has quit IRC | 09:52 | |
*** mickeys has joined #openstack-fwaas | 10:00 | |
*** reedip has quit IRC | 10:01 | |
*** mickeys has quit IRC | 10:04 | |
*** amotoki has joined #openstack-fwaas | 10:16 | |
*** amotoki has quit IRC | 10:17 | |
*** cuongnv has quit IRC | 10:21 | |
*** amotoki has joined #openstack-fwaas | 10:31 | |
*** amotoki has quit IRC | 10:40 | |
*** hoangcx has quit IRC | 10:43 | |
*** yamamoto has joined #openstack-fwaas | 10:48 | |
*** yamamoto has quit IRC | 10:54 | |
*** reedip has joined #openstack-fwaas | 10:58 | |
*** mickeys has joined #openstack-fwaas | 11:01 | |
*** mickeys has quit IRC | 11:05 | |
*** yamamoto has joined #openstack-fwaas | 11:09 | |
*** amotoki has joined #openstack-fwaas | 11:11 | |
*** yamamoto has quit IRC | 11:19 | |
*** vks1 has quit IRC | 11:42 | |
*** yamamoto has joined #openstack-fwaas | 12:20 | |
*** yamamoto has quit IRC | 12:25 | |
*** reedip has quit IRC | 12:52 | |
*** mickeys has joined #openstack-fwaas | 12:58 | |
*** mickeys has quit IRC | 13:02 | |
*** yamamoto has joined #openstack-fwaas | 13:22 | |
*** yamamoto has quit IRC | 13:28 | |
*** vks1 has joined #openstack-fwaas | 13:34 | |
*** vks1 has quit IRC | 13:40 | |
*** vks1 has joined #openstack-fwaas | 13:55 | |
*** reedip has joined #openstack-fwaas | 14:00 | |
*** yamamoto has joined #openstack-fwaas | 14:24 | |
*** yamamoto has quit IRC | 14:29 | |
xgerman | very happy that the public/shared has been worked out ;-) | 14:36 |
*** amotoki has quit IRC | 14:56 | |
*** mickeys has joined #openstack-fwaas | 15:18 | |
*** mickeys_ has joined #openstack-fwaas | 15:22 | |
*** mickeys has quit IRC | 15:23 | |
*** yamamoto has joined #openstack-fwaas | 15:26 | |
*** yamamoto has quit IRC | 15:31 | |
reedip | :) | 15:40 |
*** amotoki has joined #openstack-fwaas | 15:57 | |
*** amotoki has quit IRC | 16:03 | |
*** yamamoto has joined #openstack-fwaas | 16:27 | |
*** yamamoto has quit IRC | 16:33 | |
*** mickeys_ has quit IRC | 16:51 | |
*** amotoki has joined #openstack-fwaas | 16:59 | |
*** amotoki has quit IRC | 17:04 | |
*** mickeys has joined #openstack-fwaas | 17:23 | |
*** yamamoto has joined #openstack-fwaas | 17:29 | |
*** vks1 has quit IRC | 17:30 | |
*** yamamoto has quit IRC | 17:35 | |
*** vishwanathj has joined #openstack-fwaas | 17:58 | |
*** amotoki has joined #openstack-fwaas | 18:00 | |
*** amotoki has quit IRC | 18:05 | |
*** yamamoto has joined #openstack-fwaas | 18:31 | |
*** yamamoto has quit IRC | 18:36 | |
*** openstackstatus has joined #openstack-fwaas | 18:44 | |
*** ChanServ sets mode: +v openstackstatus | 18:44 | |
*** amotoki has joined #openstack-fwaas | 19:01 | |
*** amotoki has quit IRC | 19:05 | |
*** yamamoto has joined #openstack-fwaas | 19:32 | |
*** yamamoto has quit IRC | 19:38 | |
*** amotoki has joined #openstack-fwaas | 20:02 | |
*** amotoki has quit IRC | 20:06 | |
*** yamamoto has joined #openstack-fwaas | 20:34 | |
*** yamamoto has quit IRC | 20:40 | |
*** amotoki has joined #openstack-fwaas | 21:02 | |
*** amotoki has quit IRC | 21:07 | |
*** yamamoto has joined #openstack-fwaas | 21:36 | |
*** yamamoto has quit IRC | 21:42 | |
*** amotoki has joined #openstack-fwaas | 22:03 | |
*** amotoki has quit IRC | 22:08 | |
*** yamamoto has joined #openstack-fwaas | 22:38 | |
*** yamamoto has quit IRC | 22:42 | |
*** reedip has quit IRC | 22:51 | |
*** amotoki has joined #openstack-fwaas | 23:04 | |
*** amotoki has quit IRC | 23:09 | |
*** reedip has joined #openstack-fwaas | 23:26 | |
*** reedip has quit IRC | 23:31 | |
*** yamamoto has joined #openstack-fwaas | 23:39 | |
*** yamamoto has quit IRC | 23:44 | |
*** reedip has joined #openstack-fwaas | 23:45 | |
*** reedip has quit IRC | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!