- Issued:
- 2017-09-13
- Updated:
- 2017-09-13
RHBA-2017:2714 - Bug Fix Advisory
Synopsis
openstack-neutron bug fix advisory
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated OpenStack Networking packages that resolve various issues are now
available for Red Hat OpenStack Platform 11.0 (Ocata) for RHEL 7.
Description
Red Hat OpenStack Platform provides the facilities for building, deploying
and monitoring a private or public infrastructure-as-a-service (IaaS) cloud
running on commonly available physical hardware. This advisory includes
packages for:
- OpenStack Networking service
OpenStack Networking (neutron) is a virtual network service for OpenStack.
Just as OpenStack Compute (nova) provides an API to dynamically request and
configure virtual servers, OpenStack Networking provides an API to
dynamically request and configure virtual networks. These networks connect
'interfaces' from other OpenStack services (e.g. virtual NICs from Compute
VMs). The OpenStack Networking API supports extensions to provide advanced
network capabilities (e.g. QoS, ACLs, network monitoring, etc.)
Changes to the openstack-neutron component:
- A high memory consumption was observed, especially in large environments, which often led to out-of-memory issues. The main culprit was neutron-ns-metadata-proxy process, responsible for proxying metadata requests from the VM to Nova.
neutron-ns-metadata-proxy is now replaced by haproxy which has a more lightweight memory footprint. (BZ#1439855)
- Neutron HA backup instances have the same IP/MAC addresses as the master instance and they have IPv6 forwarding enabled by default. This causes them to subscribe to different multicast groups and they may respond to queries coming from the external network. This traffic will make the upstream switch learn the MAC address on a different port, disrupting existing traffic to the master instance.
Disable IPv6 forwarding on backup instances and restore it on failover. Traffic will not leave the backup instance to the upstream switch and will not disrupting existing connections with the master instance. (BZ#1469048)
Solution
Before applying this update, ensure all previously released errata relevant
to your system have been applied.
Red Hat OpenStack Platform 11 runs on Red Hat Enterprise Linux 7.4.
The Red Hat OpenStack Platform 11 Release Notes contain the following:
- An explanation of the way in which the provided components interact to
form a working cloud computing environment.
- Technology Previews, Recommended Practices, and Known Issues.
- The channels required for Red Hat OpenStack Platform 11, including which
channels need to be enabled and disabled.
The Release Notes are available at:
https://access.redhat.com/documentation/en/red-hat-openstack-platform/
This update is available through 'yum update' on systems registered through
Red Hat Subscription Manager. For more information about Red Hat
Subscription Manager, see:
https://access.redhat.com/documentation/en-US/Red_Hat_Subscription_Management/1/html/RHSM/index.html
Affected Products
- Red Hat OpenStack 11 x86_64
Fixes
- BZ - 1439855 - [OSP11] neutron-ns-metadata-proxy has a large memory footprint
- BZ - 1467388 - pep8 job fails in OSP 11 branch
- BZ - 1468630 - Integrated DNS does not work with Cisco ACI due to Neutron bug
- BZ - 1468684 - max_overflow value for sqlalchemy is set to a low value (20) in neutron/common/config.py however default value from oslo.db (50) should be used
- BZ - 1469048 - Backup HA router sending traffic, traffic from switch interrupted
- BZ - 1481420 - Rebase openstack-neutron-lbaas to b3479a1
- BZ - 1481426 - Rebase openstack-octavia to 3e3716c
- BZ - 1481429 - Rebase openstack-octavia to 3e3716c
- BZ - 1481883 - Rebase python-networking-bigswitch to 1bf3d8f
- BZ - 1482141 - Rebase python-networking-cisco to a50f581
- BZ - 1482211 - Rebase openstack-neutron-fwaas to 1f76429
- BZ - 1483153 - Rebase openstack-neutron to 2272a00
- BZ - 1483585 - Rebase python-networking-bigswitch to 1bf3d8f
CVEs
(none)
References
(none)
Red Hat OpenStack 11
SRPM | |
---|---|
openstack-neutron-10.0.2-8.el7ost.src.rpm | SHA-256: a0a0ccff008ed6ffcda73efacfe391a9560e077050694141124651f18cba9cef |
openstack-neutron-fwaas-10.0.1-3.el7ost.src.rpm | SHA-256: 08d4c3840e692e5e4f7298cea51328cf586efc0df2f23e6c5681564d9d26ad6b |
openstack-neutron-lbaas-10.0.1-2.el7ost.src.rpm | SHA-256: 474c9871ca62f039c6b5ba0d1a14a96a9e858354ae0d8b09935907f6e7ab18b7 |
openstack-octavia-0.10.0-9.el7ost.src.rpm | SHA-256: 60469cceb1fa5defe0ea69285b11dd7e21014fbb4d99cb6fcb9d423018200ec8 |
python-networking-bigswitch-10.0.7-2.el7ost.src.rpm | SHA-256: 69e162cc2631550509b361da35cc02d9aab390e615edaaa3775cd9671bfb94bf |
python-networking-cisco-5.1.0-2.el7ost.src.rpm | SHA-256: 9a0153e4d4c3a02c33c45ba980b58c5a4fb528ceda159ec50663a3f722e0b1c2 |
x86_64 | |
openstack-neutron-10.0.2-8.el7ost.noarch.rpm | SHA-256: bd091ae1027dcc65918827b02b622a97fd16dcf606e5c062d54fc05f40ea9695 |
openstack-neutron-bigswitch-agent-10.0.7-2.el7ost.noarch.rpm | SHA-256: 73dc61342b43e320b9e0d596cf527e137a0ed6d8a6f53306d401ae127016bd4f |
openstack-neutron-bigswitch-lldp-10.0.7-2.el7ost.noarch.rpm | SHA-256: 13f714d5a8c3322a9787347f6abfb88e8ebe726e858d949ed493c8610fa912f8 |
openstack-neutron-common-10.0.2-8.el7ost.noarch.rpm | SHA-256: 3fbc029f8611a1bfa83bbb49939fd8fc6e383ff5787d09ad336af17408fbdf20 |
openstack-neutron-fwaas-10.0.1-3.el7ost.noarch.rpm | SHA-256: f475412f20007f89aa74d7001281af18ae11603498713267eac25a6b11062825 |
openstack-neutron-lbaas-10.0.1-2.el7ost.noarch.rpm | SHA-256: 31994852b33c46b495ebc162f0d1bc853685a3c663e3b054aa9ab5fe46276822 |
openstack-neutron-linuxbridge-10.0.2-8.el7ost.noarch.rpm | SHA-256: cff4b5721e584fd76d04b4155211a62ae794885b2886df819cc978051fe0bea3 |
openstack-neutron-macvtap-agent-10.0.2-8.el7ost.noarch.rpm | SHA-256: 3f1b26f42c7016d48fec24c9bf8c12b7cf4cabbe1b718a0431e902f7cdebf2f2 |
openstack-neutron-metering-agent-10.0.2-8.el7ost.noarch.rpm | SHA-256: 6eaa5789f1103d7090c8a477e6cdb4f137f0c9bc9e3591dddb33bbb08874d055 |
openstack-neutron-ml2-10.0.2-8.el7ost.noarch.rpm | SHA-256: 71ce91ede1be9641b37be0e004c3592951a631a96dc25973464d2d788693d477 |
openstack-neutron-openvswitch-10.0.2-8.el7ost.noarch.rpm | SHA-256: 7913d3f2941951e38984927f283d8df4f38b59b45761ca99c565d670476daa2b |
openstack-neutron-rpc-server-10.0.2-8.el7ost.noarch.rpm | SHA-256: 58f751fbc1c8758cf35c10a77a852276709dd8aabd8eafd0e5b02155d1fd4918 |
openstack-neutron-sriov-nic-agent-10.0.2-8.el7ost.noarch.rpm | SHA-256: 0bf2c20a99262f774cf8d92764ca9c3c9b1406e4575e5290b83f385082a69114 |
openstack-octavia-amphora-agent-0.10.0-9.el7ost.noarch.rpm | SHA-256: 84003917ef79eeebcaebf4c4fd9a1571b0287ced9991483b3bd01116e2272e60 |
openstack-octavia-api-0.10.0-9.el7ost.noarch.rpm | SHA-256: c47077452e7b7d0f3121187c773b59cb2480d861045c3d6076da12b7f458761d |
openstack-octavia-common-0.10.0-9.el7ost.noarch.rpm | SHA-256: de4c1aba6c5f230c766ec15d2a90398bcba58c459fefa6a93493d0de66888fb0 |
openstack-octavia-debuginfo-0.10.0-9.el7ost.x86_64.rpm | SHA-256: 9a088d6dea7f1c00e23aea55bc9fa661525530bd3a81660ed5e9eb72775a9633 |
openstack-octavia-diskimage-create-0.10.0-9.el7ost.noarch.rpm | SHA-256: 716f7abd2feecb44516d50d20f459314430d068becd3a51490619d94dddb9439 |
openstack-octavia-health-manager-0.10.0-9.el7ost.noarch.rpm | SHA-256: c6c93294f75d32d87626ea9759446358a1a4905fcb1d4fb1a47f469616425e4c |
openstack-octavia-housekeeping-0.10.0-9.el7ost.noarch.rpm | SHA-256: f5903423a4c8c3f7fefadaae8fc69d3fda26a30e38ecf683657d6bb15f2b19f3 |
openstack-octavia-worker-0.10.0-9.el7ost.noarch.rpm | SHA-256: 9bd8a4d3faf8e79305f04a23ae19f42b05e0e37ffd577e2213053d41c4865ab7 |
python-networking-bigswitch-10.0.7-2.el7ost.noarch.rpm | SHA-256: bbceec768dd00846fd2c2456a30bde90e03c5a91427287110545a20bec27a8d8 |
python-networking-cisco-5.1.0-2.el7ost.noarch.rpm | SHA-256: ca6b1bceb141e4a7075a1c0d08e9782c0b20ef251c528dde8ba4d1a01f3aa267 |
python-neutron-10.0.2-8.el7ost.noarch.rpm | SHA-256: 39bdb2019b61ef7616e2cc4fbdf26305d44fc31af19905249b114309fd48e2fb |
python-neutron-fwaas-10.0.1-3.el7ost.noarch.rpm | SHA-256: f7d4bd6e50ec8d84bf47f29bc29e291eedabf7cbbeba8a3227cc26e23e112a40 |
python-neutron-fwaas-tests-10.0.1-3.el7ost.noarch.rpm | SHA-256: 52085f885989ef80d050405b22f32909f08e3e9c19320302ed9c552d47c5014f |
python-neutron-lbaas-10.0.1-2.el7ost.noarch.rpm | SHA-256: 7f7b4e4cee6470b2ce83de1761b182f44eb70f33179ca27a8fd9152c9b88f438 |
python-neutron-lbaas-tests-10.0.1-2.el7ost.noarch.rpm | SHA-256: 1395387ee05d71b25cda4cb377ce275eb7e82ab075a10e9dcc57d357e6bc17b5 |
python-neutron-tests-10.0.2-8.el7ost.noarch.rpm | SHA-256: 55920db62a7c47dbe67592bc5eaecb843e97389bdb7c1f7bc0cfbad86b5ea04f |
python-octavia-0.10.0-9.el7ost.noarch.rpm | SHA-256: 0c778bc3697c5523f38915dc7bfbd4dc8ba55f9f24e2c243854fcb5e19750d99 |
python-octavia-tests-0.10.0-9.el7ost.noarch.rpm | SHA-256: d50781b74a3b172f6c972823c86a4ebd14c746a7c77c9c9bcd3542795f778e84 |
python-octavia-tests-golang-0.10.0-9.el7ost.x86_64.rpm | SHA-256: 61f9d429c45815a6876fd668107fa01c3068c05a8722d9712f7c5d4d734521c4 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.