- Issued:
- 2017-03-30
- Updated:
- 2017-03-30
RHBA-2017:0856 - Bug Fix Advisory
Synopsis
openstack-neutron bug fix advisory
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated OpenStack Networking packages that resolve various issues are now
available for Red Hat OpenStack Platform 9.0 (Mitaka) for RHEL 7.
Description
Red Hat OpenStack Platform provides the facilities for building a private
or public infrastructure-as-a-service (IaaS) cloud running on commonly
available physical hardware. This advisory includes packages for:
- OpenStack Networking service
OpenStack Networking (neutron) is a virtual network service for OpenStack.
Just as OpenStack Compute (nova) provides an API to dynamically request and
configure virtual servers, OpenStack Networking provides an API to
dynamically request and configure virtual networks. These networks connect
'interfaces' from other OpenStack services (e.g. virtual NICs from Compute
VMs). The OpenStack Networking API supports extensions to provide advanced
network capabilities (e.g. QoS, ACLs, network monitoring, etc.)
This update addresses the following issues:
- Previously, when ports were created with port_security disabled, the explicit iptables rules were not applied to allow the traffic. This resulted in packets hitting a default REJECT rule, and all traffic was blocked.
With this fix, firewall rules are correctly installed on ports with port_security disabled and traffic is allowed.
- Previously, because of the way the initial sync was done after starting the DHCP agent, periodic reports were not sent until the sync completed. In large environments this can be a lengthy process, and the lack of status reports during this process caused the agent to be marked as DOWN. This fix allows periodic reports to be sent during the DHCP agent initial sync, so it won't be marked as DOWN. It also addresses a bug which caused the initial sync to be performed twice, so the setup time has been halved.
Solution
Before applying this update, ensure all previously released errata relevant
to your system have been applied.
Red Hat OpenStack Platform 9 runs on Red Hat Enterprise Linux 7.3.
The Red Hat OpenStack Platform 9 Release Notes contain the following:
- An explanation of the way in which the provided components interact to
form a working cloud computing environment.
- Technology Previews, Recommended Practices, and Known Issues.
- The channels required for Red Hat OpenStack Platform 9, including which
channels need to be enabled and disabled.
The Release Notes are available at:
https://access.redhat.com/documentation/en/red-hat-openstack-platform/9/paged/release-notes
This update is available through 'yum update' on systems registered through
Red Hat Subscription Manager. For more information about Red Hat
Subscription Manager, see:
https://access.redhat.com/documentation/en-US/Red_Hat_Subscription_Management/1/html/RHSM/index.html
Affected Products
- Red Hat OpenStack 9 x86_64
Fixes
- BZ - 1429331 - iptables rule blocks traffic even with port_security_enabled set to False
- BZ - 1433255 - Restarting dhcp-agent in large environment causes the agent to report down for extended time while namespaces are being re-manageed
CVEs
(none)
References
(none)
Red Hat OpenStack 9
| SRPM | |
|---|---|
| openstack-neutron-8.3.0-5.el7ost.src.rpm | SHA-256: 7744973de2de7b5e7f10fce488b687557b667384873c6233d4bee58f6df8fe99 |
| x86_64 | |
| openstack-neutron-8.3.0-5.el7ost.noarch.rpm | SHA-256: a8e2d4b2584133b4a1aeb78a9de2dc1dcd3391d3236701e412dcfbe41bab0f17 |
| openstack-neutron-bgp-dragent-8.3.0-5.el7ost.noarch.rpm | SHA-256: 82f6fb59843d13f5169994c55bb928620eae2aa6453d52892486d747df739e8c |
| openstack-neutron-common-8.3.0-5.el7ost.noarch.rpm | SHA-256: 79fc3bcb5e15ff09075b98d0a5681da5be441577bc245e33e9d9debeebc0644d |
| openstack-neutron-linuxbridge-8.3.0-5.el7ost.noarch.rpm | SHA-256: 4103470f355d7dc7efeab45d8411b98d4756c0ed6448b43ea7d28b08fdad32c4 |
| openstack-neutron-macvtap-agent-8.3.0-5.el7ost.noarch.rpm | SHA-256: c684347f8bf3777ff27eeac404a32a1a8149ecd5ee161505a46e345174444cc4 |
| openstack-neutron-metering-agent-8.3.0-5.el7ost.noarch.rpm | SHA-256: 1f2c0350a55340471e9b3aba6bb6a1cb7db978bd82c3b382dcbca48cfd5bf2ba |
| openstack-neutron-ml2-8.3.0-5.el7ost.noarch.rpm | SHA-256: 9a29b3df3efb233376dcf484a2faf82d3b3633d6a43a908512b17484f0f990fd |
| openstack-neutron-openvswitch-8.3.0-5.el7ost.noarch.rpm | SHA-256: ffd906287091b765e9f791552dcc4fb19dafe918ab247b7b7b141b9f93003e8b |
| openstack-neutron-rpc-server-8.3.0-5.el7ost.noarch.rpm | SHA-256: 8cc6c367be690e825e2656479bc4e289620f1347239e86c69ccc85afdc319324 |
| openstack-neutron-sriov-nic-agent-8.3.0-5.el7ost.noarch.rpm | SHA-256: fdab7af26d6071e62173e6a401779a5e0ae716011f47bb4507a727d8eeaab41a |
| python-neutron-8.3.0-5.el7ost.noarch.rpm | SHA-256: bc8da29fb676290091215f9546262e328c4b881b79a3f5f9b6122f1f236d41ac |
| python-neutron-tests-8.3.0-5.el7ost.noarch.rpm | SHA-256: 17794809879969eda5844a40746eca8a8ff2008ad018b7e499d103586b03e5cc |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.