*** macz_ has joined #openstack-neutron | 00:00 | |
*** macz_ has quit IRC | 00:04 | |
*** zzzeek has quit IRC | 00:04 | |
*** zzzeek has joined #openstack-neutron | 00:05 | |
*** nplanel has quit IRC | 00:15 | |
*** nplanel has joined #openstack-neutron | 00:15 | |
*** yamamoto has joined #openstack-neutron | 00:37 | |
*** ociuhandu has joined #openstack-neutron | 00:42 | |
*** ociuhandu has quit IRC | 00:46 | |
*** zhanglong has joined #openstack-neutron | 00:47 | |
*** sapd1 has joined #openstack-neutron | 00:53 | |
*** sapd1 has quit IRC | 01:01 | |
*** sapd1 has joined #openstack-neutron | 01:02 | |
openstackgerrit | Miguel Lavalle proposed openstack/neutron-tempest-plugin master: Add tempest API tests for address groups RBAC https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/773274 | 01:06 |
---|---|---|
*** spatel has joined #openstack-neutron | 01:28 | |
*** spatel has quit IRC | 01:28 | |
*** congnt95 has joined #openstack-neutron | 01:33 | |
*** sapd1 has quit IRC | 01:42 | |
openstackgerrit | Kieran Spear proposed openstack/neutron master: Fix misleading doc re: secgroup rule quota https://review.opendev.org/c/openstack/neutron/+/773275 | 01:45 |
*** sapd1 has joined #openstack-neutron | 01:47 | |
*** macz_ has joined #openstack-neutron | 02:01 | |
*** baojg has joined #openstack-neutron | 02:03 | |
*** macz_ has quit IRC | 02:06 | |
*** zhanglong has quit IRC | 02:13 | |
*** rcernin has quit IRC | 02:21 | |
*** ociuhandu has joined #openstack-neutron | 02:30 | |
*** ociuhandu has quit IRC | 02:35 | |
*** rcernin has joined #openstack-neutron | 02:36 | |
*** yamamoto has quit IRC | 02:38 | |
*** yamamoto has joined #openstack-neutron | 02:39 | |
*** rcernin has quit IRC | 02:45 | |
*** rcernin has joined #openstack-neutron | 02:45 | |
*** yamamoto has quit IRC | 03:07 | |
*** yamamoto_ has joined #openstack-neutron | 03:07 | |
*** manpreet has joined #openstack-neutron | 03:09 | |
*** ociuhandu has joined #openstack-neutron | 03:22 | |
*** ociuhandu has quit IRC | 03:26 | |
*** zhanglong has joined #openstack-neutron | 03:35 | |
openstackgerrit | liuyulong proposed openstack/neutron master: Config option to disable the DHCP functions https://review.opendev.org/c/openstack/neutron/+/772255 | 03:37 |
openstackgerrit | liuyulong proposed openstack/neutron master: Add the base class DHCPResponder https://review.opendev.org/c/openstack/neutron/+/773281 | 03:37 |
openstackgerrit | liuyulong proposed openstack/neutron master: Add the DHCPReponder for IPv4 https://review.opendev.org/c/openstack/neutron/+/773282 | 03:37 |
openstackgerrit | liuyulong proposed openstack/neutron master: Add the DHCPReponder for IPv6 https://review.opendev.org/c/openstack/neutron/+/773283 | 03:37 |
*** zhanglong has quit IRC | 03:45 | |
*** rcernin has quit IRC | 04:00 | |
*** rcernin has joined #openstack-neutron | 04:02 | |
*** jfan has joined #openstack-neutron | 04:15 | |
*** ociuhandu has joined #openstack-neutron | 04:23 | |
*** rcernin has quit IRC | 04:27 | |
*** ociuhandu has quit IRC | 04:29 | |
*** rcernin has joined #openstack-neutron | 04:35 | |
*** lajoskatona has joined #openstack-neutron | 05:07 | |
*** ratailor has joined #openstack-neutron | 05:15 | |
*** lajoskatona has quit IRC | 05:20 | |
*** ociuhandu has joined #openstack-neutron | 05:30 | |
*** sapd1 has quit IRC | 05:32 | |
*** yamamoto_ has quit IRC | 05:33 | |
*** ociuhandu has quit IRC | 05:34 | |
*** lajoskatona has joined #openstack-neutron | 05:35 | |
*** yamamoto has joined #openstack-neutron | 05:36 | |
*** zhanglong has joined #openstack-neutron | 05:57 | |
openstackgerrit | liuyulong proposed openstack/neutron-specs master: Add spec for Distributed DHCP https://review.opendev.org/c/openstack/neutron-specs/+/768588 | 06:20 |
*** gcheresh has joined #openstack-neutron | 06:38 | |
*** hemanth_n has joined #openstack-neutron | 06:38 | |
*** TheJulia has quit IRC | 06:44 | |
*** masayukig has quit IRC | 06:44 | |
*** TheJulia has joined #openstack-neutron | 06:45 | |
*** yonglihe has quit IRC | 06:45 | |
*** gmann has quit IRC | 06:45 | |
*** jungleboyj has quit IRC | 06:45 | |
*** jungleboyj has joined #openstack-neutron | 06:46 | |
*** gmann has joined #openstack-neutron | 06:46 | |
*** masayukig has joined #openstack-neutron | 06:47 | |
*** yonglihe has joined #openstack-neutron | 06:48 | |
*** ksambor has joined #openstack-neutron | 06:54 | |
*** ociuhandu has joined #openstack-neutron | 07:02 | |
*** ociuhandu has quit IRC | 07:06 | |
*** ccamposr__ has joined #openstack-neutron | 07:08 | |
*** sapd1 has joined #openstack-neutron | 07:09 | |
*** ccamposr has quit IRC | 07:10 | |
*** rcernin has quit IRC | 07:25 | |
*** ralonsoh has joined #openstack-neutron | 07:26 | |
*** ratailor has quit IRC | 07:44 | |
*** zhanglong has quit IRC | 07:47 | |
*** tmorin has joined #openstack-neutron | 07:55 | |
*** slaweq has joined #openstack-neutron | 07:59 | |
*** rcernin has joined #openstack-neutron | 08:07 | |
*** tesseract has joined #openstack-neutron | 08:09 | |
*** rpittau|afk is now known as rpittau | 08:11 | |
openstackgerrit | Slawek Kaplonski proposed openstack/neutron master: Temporary make rally job non-voting https://review.opendev.org/c/openstack/neutron/+/773297 | 08:12 |
*** bengates has joined #openstack-neutron | 08:18 | |
ralonsoh | slaweq, so you need help with rally? | 08:21 |
slaweq | ralonsoh: I don't think so, but thx | 08:21 |
ralonsoh | I think you didn't find the root of the problem | 08:21 |
slaweq | not root cause yet | 08:22 |
ralonsoh | ok, ping me if needed | 08:22 |
slaweq | but lbragstad did some investigation there also | 08:22 |
slaweq | I will sync with him later today | 08:22 |
slaweq | thx a lot | 08:22 |
*** rcernin has quit IRC | 08:24 | |
*** tmorin has quit IRC | 08:24 | |
*** rcernin has joined #openstack-neutron | 08:26 | |
*** waleedm has joined #openstack-neutron | 08:27 | |
*** zhanglong has joined #openstack-neutron | 08:27 | |
*** bengates has quit IRC | 08:29 | |
*** bengates has joined #openstack-neutron | 08:30 | |
*** rcernin has quit IRC | 08:31 | |
slaweq | ralonsoh: and how it's going with the dhcp race? | 08:36 |
slaweq | do You need any help with that? | 08:36 |
ralonsoh | slaweq, I think the patch is working | 08:36 |
ralonsoh | let me check the py36 erros | 08:36 |
slaweq | but is it in gerrit already? | 08:36 |
ralonsoh | but I tested it manually and seems to work | 08:36 |
ralonsoh | yes, one sec | 08:36 |
slaweq | great | 08:36 |
ralonsoh | slaweq, https://review.opendev.org/c/openstack/neutron/+/773160 | 08:37 |
*** rcernin has joined #openstack-neutron | 08:37 | |
slaweq | I will take a look at it in few minutes | 08:37 |
openstackgerrit | Merged openstack/neutron master: Fix misleading doc re: secgroup rule quota https://review.opendev.org/c/openstack/neutron/+/773275 | 08:39 |
*** ociuhandu has joined #openstack-neutron | 08:45 | |
*** ociuhandu has quit IRC | 08:45 | |
*** ociuhandu has joined #openstack-neutron | 08:45 | |
*** jlibosva has joined #openstack-neutron | 08:49 | |
*** ociuhandu has quit IRC | 08:49 | |
*** elvira has joined #openstack-neutron | 08:50 | |
*** lucasagomes has joined #openstack-neutron | 08:50 | |
*** jpena|off is now known as jpena | 08:58 | |
*** ociuhandu has joined #openstack-neutron | 09:00 | |
*** xarlos has joined #openstack-neutron | 09:17 | |
*** zhanglong has quit IRC | 09:20 | |
*** rcernin has quit IRC | 09:27 | |
*** benj_ has quit IRC | 09:28 | |
*** benj_ has joined #openstack-neutron | 09:30 | |
lucasagomes | ralonsoh, hi there, quick q, do we need these backports: https://review.opendev.org/c/openstack/tripleo-heat-templates/+/773298 ? | 09:32 |
lucasagomes | ralonsoh, I think IGMP in networking-ovn is stable/train minimun | 09:33 |
ralonsoh | lucasagomes, hey, maybe the name is not valid before Train | 09:34 |
ralonsoh | but we need those patches because this config parameter is also valid for OVS | 09:35 |
*** ociuhandu has quit IRC | 09:36 | |
ralonsoh | lucasagomes, ok, I see now, we need this parameter but only in OVS... | 09:37 |
*** rcernin has joined #openstack-neutron | 09:39 | |
lucasagomes | ralonsoh, ah fair enough yes | 09:42 |
lucasagomes | since we use the same | 09:42 |
lucasagomes | ralonsoh, the only problem is the release note, it says OVN there | 09:42 |
ralonsoh | lucasagomes, yeah, I need to refactor those patches | 09:42 |
lucasagomes | ack | 09:42 |
*** zhanglong has joined #openstack-neutron | 09:45 | |
*** ociuhandu has joined #openstack-neutron | 10:01 | |
*** rcernin has quit IRC | 10:06 | |
*** ratailor has joined #openstack-neutron | 10:08 | |
*** baojg has quit IRC | 10:09 | |
*** baojg has joined #openstack-neutron | 10:10 | |
*** baojg has quit IRC | 10:10 | |
*** baojg has joined #openstack-neutron | 10:10 | |
*** baojg has quit IRC | 10:11 | |
*** baojg has joined #openstack-neutron | 10:11 | |
*** baojg has quit IRC | 10:11 | |
*** baojg has joined #openstack-neutron | 10:12 | |
*** baojg has quit IRC | 10:12 | |
*** baojg has joined #openstack-neutron | 10:13 | |
*** baojg has quit IRC | 10:13 | |
*** baojg has joined #openstack-neutron | 10:13 | |
*** bengates has quit IRC | 10:14 | |
*** baojg has quit IRC | 10:14 | |
*** baojg has joined #openstack-neutron | 10:14 | |
*** bengates has joined #openstack-neutron | 10:14 | |
openstackgerrit | Arkady Shtempler proposed openstack/neutron-tempest-plugin master: Delete router test - API scenario https://review.opendev.org/c/openstack/neutron-tempest-plugin/+/763072 | 10:14 |
*** baojg has quit IRC | 10:15 | |
*** baojg has joined #openstack-neutron | 10:15 | |
*** baojg has quit IRC | 10:15 | |
*** baojg has joined #openstack-neutron | 10:16 | |
*** baojg has quit IRC | 10:16 | |
*** bengates has quit IRC | 10:17 | |
*** bengates has joined #openstack-neutron | 10:18 | |
*** bengates has quit IRC | 10:22 | |
*** bengates has joined #openstack-neutron | 10:23 | |
*** bengates has quit IRC | 10:30 | |
*** bengates has joined #openstack-neutron | 10:31 | |
*** dtantsur|afk is now known as dtantsur | 10:54 | |
*** zhanglong has quit IRC | 10:57 | |
openstackgerrit | Stephen Finucane proposed openstack/os-vif master: Drop use of deprecated collections classes https://review.opendev.org/c/openstack/os-vif/+/773360 | 11:04 |
*** sapd1 has quit IRC | 11:04 | |
*** dviroel has joined #openstack-neutron | 11:07 | |
*** rcernin has joined #openstack-neutron | 11:16 | |
*** sapd1 has joined #openstack-neutron | 11:17 | |
openstackgerrit | liuyulong proposed openstack/neutron-specs master: Add spec for Distributed DHCP https://review.opendev.org/c/openstack/neutron-specs/+/768588 | 11:20 |
openstackgerrit | Rodolfo Alonso proposed openstack/neutron master: Process DHCP events in order if related https://review.opendev.org/c/openstack/neutron/+/773160 | 11:20 |
*** sapd1 has quit IRC | 11:25 | |
*** ociuhandu has quit IRC | 11:30 | |
*** ociuhandu has joined #openstack-neutron | 11:30 | |
openstackgerrit | Rodolfo Alonso proposed openstack/neutron master: Process DHCP events in order if related https://review.opendev.org/c/openstack/neutron/+/773160 | 11:34 |
*** ociuhandu has quit IRC | 11:36 | |
*** sapd1 has joined #openstack-neutron | 11:39 | |
*** jangutter has joined #openstack-neutron | 11:40 | |
ralonsoh | lucasagomes, https://review.opendev.org/c/openstack/puppet-neutron/+/715890 | 11:52 |
ralonsoh | I will need to backport this too | 11:52 |
ralonsoh | right? | 11:52 |
lucasagomes | ralonsoh, yes | 11:52 |
lucasagomes | that should work for both drivers | 11:52 |
ralonsoh | lucasagomes, thanks!! | 11:52 |
lucasagomes | o/ thank u! | 11:52 |
lucasagomes | ralonsoh, I should have backported it at the time but, in my mind I was mostly thinking of OVN (which is only stable/train) | 11:53 |
lucasagomes | idk why I didn't question the fact that these options weren't there for OVS too | 11:53 |
lucasagomes | sorry for that | 11:53 |
ralonsoh | lucasagomes, that should be fast to backport | 11:54 |
lucasagomes | right on | 11:54 |
*** sapd1 has quit IRC | 11:55 | |
*** bengates_ has joined #openstack-neutron | 12:03 | |
*** bengates has quit IRC | 12:04 | |
openstackgerrit | Merged openstack/neutron master: Temporary make rally job non-voting https://review.opendev.org/c/openstack/neutron/+/773297 | 12:15 |
*** yamamoto has quit IRC | 12:16 | |
*** ilush has joined #openstack-neutron | 12:22 | |
*** jpena is now known as jpena|lunch | 12:30 | |
*** rcernin has quit IRC | 12:33 | |
ralonsoh | lucasagomes, actually, I realize that there is no THT configuration parameter for OVS agent | 12:36 |
ralonsoh | https://review.opendev.org/c/openstack/tripleo-heat-templates/+/714462 allows to configure the Neutron API and the OVN container | 12:37 |
ralonsoh | but never the OVS.igmp_snooping_enable parameter | 12:37 |
ralonsoh | Am I correct? | 12:38 |
ralonsoh | (btw, I'm going for lunch, I'll read you later) | 12:38 |
*** sapd1 has joined #openstack-neutron | 12:40 | |
*** Luzi has joined #openstack-neutron | 12:43 | |
*** yamamoto has joined #openstack-neutron | 12:44 | |
*** ociuhandu has joined #openstack-neutron | 12:45 | |
*** ociuhandu has quit IRC | 12:46 | |
*** ociuhandu has joined #openstack-neutron | 12:47 | |
*** rcernin has joined #openstack-neutron | 12:47 | |
*** bengates has joined #openstack-neutron | 12:58 | |
*** bengates_ has quit IRC | 13:01 | |
*** ratailor has quit IRC | 13:03 | |
*** ratailor_ has joined #openstack-neutron | 13:03 | |
*** EmilienM has joined #openstack-neutron | 13:04 | |
lucasagomes | ralonsoh, yeah apparently there wasn't any before | 13:14 |
lucasagomes | ralonsoh, ohhh I see what u mean | 13:15 |
lucasagomes | maybe the patch is wrong then ? We should also have included this for the agent | 13:15 |
lucasagomes | not wrong but, not complete | 13:16 |
lucasagomes | which makes sense cause again, when we sent those we had mostly OVN in mind | 13:16 |
*** yamamoto has quit IRC | 13:23 | |
*** jpena|lunch is now known as jpena | 13:24 | |
ralonsoh | lucasagomes, yeah, I'll add a patch from master to queens to add the support for OVS | 13:27 |
lucasagomes | ralonsoh++ | 13:29 |
*** jangutter has quit IRC | 13:36 | |
*** jangutter has joined #openstack-neutron | 13:37 | |
*** rcernin has quit IRC | 13:38 | |
*** yamamoto has joined #openstack-neutron | 13:54 | |
*** ratailor_ has quit IRC | 13:54 | |
*** ociuhandu has quit IRC | 13:55 | |
*** ociuhandu has joined #openstack-neutron | 13:56 | |
*** Luzi has quit IRC | 13:59 | |
*** yamamoto has quit IRC | 14:05 | |
*** jangutter_ has joined #openstack-neutron | 14:08 | |
*** lbragstad has joined #openstack-neutron | 14:09 | |
*** jangutter has quit IRC | 14:11 | |
*** hemanth_n has quit IRC | 14:12 | |
mgariepy | ralonsoh, can you take a quick look at this one it has passed CI but i'd like to have your opinion on it: https://review.opendev.org/c/openstack/neutron/+/773165/ | 14:12 |
ralonsoh | mgariepy, give me some time, I'll check it later this afternoon | 14:12 |
mgariepy | ok perfect thanks | 14:12 |
*** lbragstad has quit IRC | 14:16 | |
*** ociuhandu has quit IRC | 14:19 | |
openstackgerrit | Lajos Katona proposed openstack/neutron master: [unittest]: mock _is_keepalived_use_no_track_supported https://review.opendev.org/c/openstack/neutron/+/773401 | 14:19 |
*** ociuhandu has joined #openstack-neutron | 14:19 | |
*** bengates has quit IRC | 14:20 | |
*** Yarboa has quit IRC | 14:22 | |
*** lbragstad has joined #openstack-neutron | 14:22 | |
*** bengates has joined #openstack-neutron | 14:22 | |
*** tmorin has joined #openstack-neutron | 14:23 | |
*** ociuhandu has quit IRC | 14:29 | |
*** ociuhandu has joined #openstack-neutron | 14:30 | |
openstackgerrit | Lajos Katona proposed openstack/networking-odl master: Fix master of networking-odl https://review.opendev.org/c/openstack/networking-odl/+/769877 | 14:35 |
*** ociuhandu has quit IRC | 14:35 | |
*** Yarboa has joined #openstack-neutron | 14:36 | |
*** waleedm has quit IRC | 14:37 | |
*** ociuhandu has joined #openstack-neutron | 14:37 | |
*** ociuhandu has quit IRC | 14:39 | |
*** ociuhandu has joined #openstack-neutron | 14:39 | |
*** ilush has quit IRC | 15:16 | |
*** kevko has joined #openstack-neutron | 15:23 | |
openstackgerrit | Rodolfo Alonso proposed openstack/neutron master: Process DHCP events in order if related https://review.opendev.org/c/openstack/neutron/+/773160 | 15:24 |
openstackgerrit | Lajos Katona proposed openstack/networking-bgpvpn master: Make lower-constraints job non-voting https://review.opendev.org/c/openstack/networking-bgpvpn/+/771219 | 15:29 |
slaweq | lbragstad: gmann: hi | 15:30 |
slaweq | how are You? | 15:30 |
lbragstad | slaweq o/ | 15:30 |
slaweq | lbragstad: gmann: can You take a look at https://review.opendev.org/c/openstack/oslo.policy/+/773414 and tell me if that makes any sense for You? with that patch I have locally same api times as without secure-rbac in Neutron | 15:30 |
lbragstad | slaweq awesome - i can test it out | 15:31 |
slaweq | lbragstad: but I don't know oslo policy code much so maybe that isn't good aproach at all | 15:31 |
slaweq | ralonsoh: maybe also You want to take a look ^^ :) | 15:32 |
ralonsoh | slaweq, sure | 15:33 |
slaweq | thx | 15:33 |
lbragstad | ok - so it's adding multiple rules together since neutron enforces policies several times | 15:33 |
slaweq | lbragstad: generally, what I found is that neutron is calling policy.check() method A LOT | 15:33 |
slaweq | see my comment https://bugs.launchpad.net/neutron/+bug/1913718/comments/4 | 15:33 |
openstack | Launchpad bug 1913718 in neutron "rally ci job is unstable - port list takes very long time" [Critical,Confirmed] - Assigned to Slawek Kaplonski (slaweq) | 15:33 |
lbragstad | yea - it looks like it calls it on every resource in the response? | 15:34 |
slaweq | but that was the same before secure rbac | 15:34 |
slaweq | it call it for every attribute for every resource in the response | 15:34 |
slaweq | so e.g. when I have 4k ports to list, it calls it about 120k times :/ | 15:34 |
lbragstad | dang... | 15:34 |
slaweq | but, as I said, it was like that before | 15:34 |
lbragstad | right | 15:34 |
gmann | oh | 15:35 |
slaweq | the only difference now is this call to _handle_deprecated_rule() | 15:35 |
slaweq | and it calls it every time, when policy.check() is called | 15:35 |
slaweq | so my idea was to call this _handle_deprecated_rule only once for each rule, as later it already have that "OrCheck()" prepared | 15:36 |
lbragstad | yeah | 15:36 |
gmann | slaweq: lbragstad but it is called in load_rules | 15:37 |
slaweq | on neutron side the problem is that our policies allows to specify what attributes are available for some users | 15:37 |
lbragstad | load_rules is called from enforce() | 15:37 |
slaweq | lbragstad: yes, it is | 15:37 |
gmann | ah yeah | 15:37 |
lbragstad | https://opendev.org/openstack/oslo.policy/src/branch/master/oslo_policy/policy.py#L948 | 15:38 |
gmann | should not we load only in init() ? | 15:38 |
slaweq | so I'm not sure if we can do some optimisation on neutron's side there as we need to e.g. check for each port in the list if we can return some attribute | 15:38 |
lbragstad | i think we do that so we can pickup rule changes without having to reload the service | 15:38 |
lbragstad | (or instantiate a new Enforcer) | 15:38 |
openstackgerrit | Lajos Katona proposed openstack/os-ken master: DNM: test os_ken master https://review.opendev.org/c/openstack/os-ken/+/773438 | 15:38 |
gmann | humm | 15:39 |
lbragstad | anther thing we could do require oslo.policy to make a copy of the rules passed in before modifying them with an OrCheck | 15:39 |
lbragstad | we could do is require* | 15:40 |
gmann | lbragstad: but if change in policy file we expect service to be restarted | 15:40 |
lbragstad | hmm | 15:40 |
lbragstad | then i wonder why load_rules is called from enforce() | 15:40 |
gmann | yeah me too | 15:40 |
gmann | lbragstad: see this is what we found in json->yaml migration https://review.opendev.org/c/openstack/nova/+/773192 | 15:41 |
lbragstad | we expect users to register rules after they initialize an enforcer | 15:41 |
gmann | in this https://review.opendev.org/c/openstack/glance/+/772912/5 | 15:41 |
gmann | if file is created/modified then policy init() file will not (if new file ) be picked rightly | 15:42 |
lbragstad | ok - interesting... | 15:43 |
gmann | lbragstad: and and load rule also in init - https://github.com/openstack/nova/blob/master/nova/policy.py#L93 | 15:43 |
lbragstad | here i thought the main reason we had load_rules() called from enforce() was because we wanted to check rule changes | 15:43 |
slaweq | gmann: lbragstad: but can't we e.g. move the _handle_deprecated_rule() to the Rule object even, to write warning only once, during the initialization? and to prepare correct check then only once? | 15:43 |
slaweq | then we still can have load_rules() called in enforce() method but there will be less warnings logged | 15:44 |
slaweq | and it will be faster in case of neutron | 15:44 |
gmann | slaweq: but still it will load from file and iterate over all the registered rule | 15:44 |
gmann | i think that is heavy thing for each check | 15:44 |
*** jangutter has joined #openstack-neutron | 15:46 | |
slaweq | yes, it iterates | 15:46 |
slaweq | but from my tests it didn't looked like very heavy | 15:46 |
slaweq | according to times it spends in that method with and without deprecated rule set | 15:47 |
gmann | policy file load https://opendev.org/openstack/oslo.policy/src/branch/master/oslo_policy/policy.py#L614 | 15:48 |
*** jangutter_ has quit IRC | 15:48 | |
gmann | lbragstad: this one. self.policy_file is used and not detected again so i feel we can consider modifying policy file also as a 'restart your service to policy re-init' https://opendev.org/openstack/oslo.policy/src/branch/master/oslo_policy/policy.py#L604 | 15:49 |
lbragstad | i think we should figure out if oslo.policy is going to load rules on enforcement, and if so make sure it actually does it without restarting the service, or we should remove it from the enforce method | 15:49 |
gmann | yeah, | 15:50 |
gmann | may be we can get some operator feedback on this if they change rule in file then they restart service or not | 15:51 |
lbragstad | additionally, we might want to think about stephenfin's comment about ensuring the Enforcer only modifies objects it has control over (instead of modifying rules that are passed in) | 15:51 |
gmann | yeah that too | 15:52 |
slaweq | lbragstad: gmann: so do You think we should remove load_rules() from enforce() method? and call it only during initialization of the Enforcer object? | 15:52 |
slaweq | is my understanding correct? | 15:52 |
lbragstad | that's one possible option - because it does actually reload the rules according to what gmann found in glance | 15:53 |
lbragstad | so - even if you wanted to have rules loaded without restarting the service, it wouldn't work (iiuc) | 15:53 |
slaweq | lbragstad: gmann will You propose such patch or do You want me to send it? | 15:53 |
slaweq | for us it is critical to fix that issue | 15:54 |
gmann | for no policy file case, then we can do that without any issue(it would not break anyone) but for policy file case we need to think that how we can break existing operator if they do not expect service restart on file modification | 15:54 |
lbragstad | ok - so it does work, but only if a policy file is on disk? | 15:54 |
gmann | slaweq: it can break operator with policy file ^^. may be we need to do it very carefully | 15:54 |
lbragstad | ok - so i'm less inclined to remove load_rules() from enforce() now :) | 15:55 |
gmann | lbragstad: you mean without restarting service? | 15:55 |
lbragstad | right | 15:55 |
gmann | no it would not work for that case right? policy engine will have previous loaded rule? | 15:56 |
slaweq | but what do You think about moving handle_deprecated_rule to the Rule object itself? and to call it just once for each rule? | 15:56 |
slaweq | IMHO it could be less invasive change which would unblock neutron at least :) | 15:56 |
gmann | slaweq: I think we can do that and think on load_rule() with more feedback and thought like in PTG or so? | 15:58 |
gmann | lbragstad: ^^ what you say? | 15:58 |
lbragstad | yeah | 16:00 |
slaweq | gmann: lbragstad, thx guys, I have to leave now but tomorrow morning I will update my patch to make it "properly" | 16:01 |
slaweq | I will ping You tomorrow to review it | 16:01 |
gmann | slaweq: thanks. have a good night | 16:01 |
gmann | lbragstad: while json->yaml migration I found we mostly test policy-in-code and not with policy file or so (except neutron policy file). may be we should add some generic job on devstack/oslo.policy side withpolicy file too to avoid any regression | 16:03 |
*** Madkiss has quit IRC | 16:08 | |
*** macz_ has joined #openstack-neutron | 16:11 | |
*** _mlavalle_1 has quit IRC | 16:12 | |
*** mlavalle has joined #openstack-neutron | 16:18 | |
*** jangutter_ has joined #openstack-neutron | 16:25 | |
*** jangutter has quit IRC | 16:28 | |
*** ociuhandu_ has joined #openstack-neutron | 16:36 | |
*** ociuhandu has quit IRC | 16:39 | |
*** ociuhandu_ has quit IRC | 16:40 | |
*** Yarboa has quit IRC | 16:43 | |
*** ociuhandu has joined #openstack-neutron | 16:46 | |
*** sapd1 has quit IRC | 16:48 | |
*** ociuhandu has quit IRC | 16:51 | |
*** dtantsur is now known as dtantsur|afk | 17:00 | |
openstackgerrit | Rodolfo Alonso proposed openstack/neutron master: Remove rootwrap execution (2) https://review.opendev.org/c/openstack/neutron/+/772068 | 17:01 |
*** lucasagomes has quit IRC | 17:02 | |
*** rpittau is now known as rpittau|afk | 17:21 | |
*** tesseract has quit IRC | 17:40 | |
openstackgerrit | Brian Haley proposed openstack/networking-ovn stable/train: ovn: Always use UTC for Hash ring timestamps https://review.opendev.org/c/openstack/networking-ovn/+/752945 | 17:47 |
*** tesseract has joined #openstack-neutron | 17:48 | |
*** ralonsoh has quit IRC | 17:50 | |
*** bengates has quit IRC | 17:58 | |
*** yamamoto has joined #openstack-neutron | 18:02 | |
*** jpena is now known as jpena|off | 18:04 | |
*** yamamoto has quit IRC | 18:07 | |
*** rm_work has quit IRC | 18:10 | |
*** jlibosva has quit IRC | 18:12 | |
*** rm_work has joined #openstack-neutron | 18:23 | |
*** rm_work has quit IRC | 18:23 | |
*** rm_work has joined #openstack-neutron | 18:25 | |
*** rm_work has quit IRC | 18:25 | |
*** rm_work has joined #openstack-neutron | 18:26 | |
*** rm_work has quit IRC | 18:26 | |
*** rm_work has joined #openstack-neutron | 18:27 | |
*** rm_work has quit IRC | 18:27 | |
*** Yarboa has joined #openstack-neutron | 18:28 | |
*** rm_work has joined #openstack-neutron | 18:28 | |
*** rm_work has quit IRC | 18:28 | |
*** rm_work has joined #openstack-neutron | 18:32 | |
*** rm_work has quit IRC | 18:32 | |
*** rm_work has joined #openstack-neutron | 18:39 | |
*** rm_work has quit IRC | 18:39 | |
*** dsneddon has joined #openstack-neutron | 18:42 | |
*** hamalq has joined #openstack-neutron | 18:46 | |
*** rm_work has joined #openstack-neutron | 18:50 | |
*** rm_work has quit IRC | 18:50 | |
*** elvira has quit IRC | 18:53 | |
*** rm_work has joined #openstack-neutron | 18:54 | |
*** rm_work has quit IRC | 18:54 | |
*** gcheresh has quit IRC | 18:54 | |
*** mchc has joined #openstack-neutron | 19:00 | |
*** rm_work has joined #openstack-neutron | 19:01 | |
*** rm_work has quit IRC | 19:01 | |
mchc | can some one help me, I am having troubles connecting an external network with a physical one | 19:02 |
*** rm_work has joined #openstack-neutron | 19:04 | |
*** rm_work has quit IRC | 19:04 | |
*** gcheresh has joined #openstack-neutron | 19:10 | |
*** kevko has quit IRC | 19:14 | |
*** tesseract has quit IRC | 19:15 | |
*** rm_work has joined #openstack-neutron | 19:15 | |
*** rm_work has quit IRC | 19:15 | |
mgariepy | ralonsoh, are you testing on ovn or ovs directly ? | 19:21 |
mgariepy | with ovs, my change does change the cookie for some theses flows (but i'm not quite sure what is the implication of this) | 19:21 |
*** rm_work has joined #openstack-neutron | 19:22 | |
*** rm_work has quit IRC | 19:22 | |
*** rm_work has joined #openstack-neutron | 19:47 | |
*** Yarboa has quit IRC | 19:54 | |
*** lajoskatona has quit IRC | 19:57 | |
openstackgerrit | Brian Haley proposed openstack/ovn-octavia-provider master: Change to build OVN from source https://review.opendev.org/c/openstack/ovn-octavia-provider/+/771889 | 20:14 |
openstackgerrit | Merged openstack/networking-ovn stable/train: Ensure ovsdb_probe_interval set before connect() https://review.opendev.org/c/openstack/networking-ovn/+/765896 | 20:15 |
*** knikolla_ has joined #openstack-neutron | 20:18 | |
*** jrosser_ has joined #openstack-neutron | 20:18 | |
*** fyx_ has joined #openstack-neutron | 20:18 | |
*** guilhermesp__ has joined #openstack-neutron | 20:18 | |
*** janno_ has joined #openstack-neutron | 20:20 | |
*** rm_work has joined #openstack-neutron | 20:23 | |
*** andy__ has joined #openstack-neutron | 20:23 | |
*** f0o|away has joined #openstack-neutron | 20:25 | |
*** jrosser has quit IRC | 20:26 | |
*** knikolla has quit IRC | 20:26 | |
*** guilhermesp has quit IRC | 20:26 | |
*** fyx has quit IRC | 20:26 | |
*** f0o has quit IRC | 20:26 | |
*** andy_ has quit IRC | 20:26 | |
*** janno has quit IRC | 20:26 | |
*** zigo has quit IRC | 20:26 | |
*** sorrison has quit IRC | 20:26 | |
*** knikolla_ is now known as knikolla | 20:26 | |
*** andy__ is now known as andy_ | 20:26 | |
*** f0o|away is now known as f0o | 20:26 | |
*** jrosser_ is now known as jrosser | 20:26 | |
*** guilhermesp__ is now known as guilhermesp | 20:26 | |
*** fyx_ is now known as fyx | 20:26 | |
*** hack-char has quit IRC | 20:28 | |
*** hack-char has joined #openstack-neutron | 20:32 | |
*** zigo has joined #openstack-neutron | 20:33 | |
*** kevko has joined #openstack-neutron | 20:37 | |
*** hamalq has quit IRC | 20:43 | |
*** hamalq has joined #openstack-neutron | 20:43 | |
openstackgerrit | Brian Haley proposed openstack/ovn-octavia-provider master: Correctly set member operating status https://review.opendev.org/c/openstack/ovn-octavia-provider/+/765213 | 21:02 |
openstackgerrit | Brian Haley proposed openstack/ovn-octavia-provider master: Start running the tempest API tests https://review.opendev.org/c/openstack/ovn-octavia-provider/+/752558 | 21:02 |
*** dsneddon has quit IRC | 21:15 | |
*** manpreet has quit IRC | 21:24 | |
*** nplanel has quit IRC | 21:25 | |
*** nplanel has joined #openstack-neutron | 21:27 | |
*** Yarboa has joined #openstack-neutron | 21:36 | |
*** tmorin has quit IRC | 21:38 | |
*** ccamposr has joined #openstack-neutron | 21:45 | |
*** ccamposr__ has quit IRC | 21:48 | |
*** gcheresh has quit IRC | 21:49 | |
*** yamamoto has joined #openstack-neutron | 22:10 | |
*** Underknowledge has joined #openstack-neutron | 22:17 | |
*** kevko has quit IRC | 22:17 | |
*** yonglihe has quit IRC | 22:17 | |
*** yamamoto has quit IRC | 22:17 | |
*** rcernin has joined #openstack-neutron | 22:20 | |
*** kevko has joined #openstack-neutron | 22:26 | |
*** kevko has quit IRC | 22:31 | |
slaweq | lbragstad: thx for update oslo.policy patch | 22:39 |
slaweq | lbragstad: FYI, I just proposed new release with this fix https://review.opendev.org/c/openstack/releases/+/773535 | 22:39 |
lbragstad | slaweq excellent - thanks for proposing that | 22:42 |
*** yumiriam has joined #openstack-neutron | 22:42 | |
*** dsneddon has joined #openstack-neutron | 22:46 | |
*** Underknowledge has quit IRC | 22:47 | |
*** Underknowledge has joined #openstack-neutron | 22:47 | |
openstackgerrit | Lance Bragstad proposed openstack/neutron master: Bump oslo.policy to 3.6.1 https://review.opendev.org/c/openstack/neutron/+/773537 | 22:53 |
lbragstad | slaweq ^ that should get the rally gates passing again, but it might not pass fully until we have an actual release (the depends on is only for tracking purposes) | 22:54 |
slaweq | lbragstad: thx a lot | 22:54 |
lbragstad | no problem - i only did the easy bits, nice find | 22:55 |
openstackgerrit | Slawek Kaplonski proposed openstack/neutron master: Revert "Temporary make rally job non-voting" https://review.opendev.org/c/openstack/neutron/+/773422 | 22:56 |
openstackgerrit | Slawek Kaplonski proposed openstack/neutron master: Revert "Temporary make rally job non-voting" https://review.opendev.org/c/openstack/neutron/+/773422 | 22:56 |
slaweq | thx | 22:57 |
slaweq | I'm done for today, good night :) | 22:57 |
slaweq | and thx a lot for all help with that lbragstad | 22:57 |
*** slaweq has quit IRC | 23:01 | |
openstackgerrit | Flavio Fernandes proposed openstack/neutron master: [DNM] [WIP] Please ignore -- [OVN] security group logging support https://review.opendev.org/c/openstack/neutron/+/768129 | 23:09 |
*** mchlumsky has quit IRC | 23:55 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!