- Issued:
- 2018-08-20
- Updated:
- 2018-08-20
RHBA-2018:2514 - Bug Fix Advisory
Synopsis
openstack-neutron bug fix advisory
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated OpenStack Networking packages that resolve various issues are now
available for Red Hat OpenStack Platform 12.0 (Pike) for RHEL 7.
Description
Red Hat OpenStack Platform provides the facilities for building, deploying
and monitoring a private or public infrastructure-as-a-service (IaaS) cloud
running on commonly available physical hardware. This advisory includes
packages for:
- OpenStack Networking service
OpenStack Networking (neutron) is a virtual network service for OpenStack.
Just as OpenStack Compute (nova) provides an API to dynamically request and
configure virtual servers, OpenStack Networking provides an API to
dynamically request and configure virtual networks. These networks connect
'interfaces' from other OpenStack services (e.g. virtual NICs from Compute
VMs). The OpenStack Networking API supports extensions to provide advanced
network capabilities (e.g. QoS, ACLs, network monitoring, etc.).
Changes to the openstack-neutron component:
- A new configuration option called bridge_mac_table_size has been added for the neutron OVS agent. This value is set on every Open vSwitch bridge managed by the openvswitch-neutron-agent. The value controls the maximum number of MAC addresses that can be learned on a bridge. The default value for this new option is 50,000, which should be enough for most systems. Values outside a reasonable range (10 to 1,000,000) might be overridden by Open vSwitch. (BZ#1591204)
- neutron-ovs-cleanup exceeded the three hour timeout on large OVS databases. This left the OVS database only partially cleaned. This fix changes how the cleanup function looks up ports on an OVS bridge. This significantly reduces the time needed to clean the database. (BZ#1541494)
- When an interface was added/removed to/from a router and isolated metadata was enabled on the DHCP Agent, the metadata proxy for that network was not updated. As a result, instances on a network not connected to a router could not fetch metadata.
We now update metadata proxies when a router interface is added/removed, and instances can fetch metadata from the DHCP namespace when their networks become isolated. (BZ#1552103)
- To reduce the time spent processing security group updates in the L2 agent, conntrack deletion is now performed in a set of worker threads instead of the main agent thread. (BZ#1558148)
Solution
Before applying this update, ensure all previously released errata relevant
to your system have been applied.
Red Hat OpenStack Platform 12 runs on Red Hat Enterprise Linux 7.4.
The Red Hat OpenStack Platform 12 Release Notes contain the following:
- An explanation of the way in which the provided components interact to
form a working cloud computing environment.
- Technology Previews, Recommended Practices, and Known Issues.
- The channels required for Red Hat OpenStack Platform 12, including which
channels need to be enabled and disabled.
The Release Notes are available at:
https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/12/
This update is available through 'yum update' on systems registered through
Red Hat Subscription Manager. For more information about Red Hat
Subscription Manager, see:
https://access.redhat.com/documentation/en-US/Red_Hat_Subscription_Management/1/html/RHSM/index.html
Affected Products
- Red Hat OpenStack for IBM Power 12 ppc64le
- Red Hat OpenStack 12 x86_64
Fixes
- BZ - 1541494 - neutron-ovs-cleanup failing when there are too many ports
- BZ - 1547660 - openstack-neutron DHCP agent requires dnsmasq-utils 2.76
- BZ - 1552103 - neutron-ns-metadata-proxy disappeared
- BZ - 1557940 - Can't create Octavia Loadbalancer when firewall_driver = openvswitch
- BZ - 1558090 - router port binding fails with dvr and service subnets
- BZ - 1565615 - Sometimes dhcp_release packet isn't reaching dnsmasq process because it's being reloaded
- BZ - 1568978 - [Tests] PEP8 is broken
- BZ - 1569062 - ovs-fw does not reinstate GRE conntrack entry
- BZ - 1569067 - OVS firewall should drop iptables rules if it detects a bridge
- BZ - 1569070 - Security group updates fail when port hasn't been initialized yet
- BZ - 1570911 - Cannot set --no-share on shared network that has floating_ip, gateway AND a tenant port
- BZ - 1576284 - neutron-openvswitch-agent cleans up stale flows months after they were created but it does not recreated correct flows and bridge configuration
- BZ - 1579502 - Packet loss during standby L3 agent restart
- BZ - 1582646 - Rebase openstack-neutron-fwaas to d02659f
- BZ - 1588544 - Rebase python-networking-odl to 01f7636
- BZ - 1589935 - Rebase python-networking-vmware-nsx to 7481a77
- BZ - 1590020 - Rebase openstack-neutron-lbaas-ui to 98c7d38
- BZ - 1590026 - Rebase openstack-octavia to 90599da
- BZ - 1590458 - Backport support for specifying security group protocol numbers
- BZ - 1590530 - Rebase openstack-neutron-lbaas to d52ad67
- BZ - 1590872 - Rebase openstack-neutron to 466cb9a
- BZ - 1591204 - The mac table size of neutron bridges (br-tun, br-int, br-*) is too small by default and eventually makes openvswitch explode
- BZ - 1592423 - Rebase python-networking-ovn to 54740d9
CVEs
(none)
References
(none)
Red Hat OpenStack for IBM Power 12
| SRPM | |
|---|---|
| openstack-neutron-11.0.4-2.el7ost.src.rpm | SHA-256: 989189375e82af99062d7746084789a0db776c93d881d2d2cd8386be6ebabfcf |
| openstack-neutron-fwaas-11.0.1-4.el7ost.src.rpm | SHA-256: dd68a4e06b7a4c714833e57f168eafb9fe0d45dcbcda5033aecf4becb0aaafac |
| openstack-neutron-lbaas-11.0.3-1.el7ost.src.rpm | SHA-256: 3992bf0189be3f2c3e199ee26bd500c96976a96c8e26d04319c50df9043f4de8 |
| openstack-neutron-lbaas-ui-3.0.2-1.el7ost.src.rpm | SHA-256: a1440e0d05baae7c7dad2e06d8a0210c7943cf4f64826a049b13d865431e8c9b |
| python-networking-odl-11.0.0-4.el7ost.src.rpm | SHA-256: 10df0c60df88d04cab61b67d358de9eeef92f9567009f33c60f917dfc2cb148c |
| python-networking-ovn-3.0.1-2.el7ost.src.rpm | SHA-256: 709b0fe2df96c9c1ae76cf6f1d94fbae4d2e1c4f64b396479509e687d59b7f14 |
| python-networking-vmware-nsx-11.0.2-1.el7ost.src.rpm | SHA-256: 837808c6a2b368e408b0296658f71178b97695f7a8d16dc5f1c947f13cb3acbd |
| ppc64le | |
| openstack-neutron-11.0.4-2.el7ost.noarch.rpm | SHA-256: 9ac19a3cfdb50f28d059722dc0f56daf65f6b2c8a15c57885121f0512ef968e4 |
| openstack-neutron-common-11.0.4-2.el7ost.noarch.rpm | SHA-256: 2cab21b7546c69fe854687c450cef4dfd983becd988b99e49d5f7599b45c0626 |
| openstack-neutron-fwaas-11.0.1-4.el7ost.noarch.rpm | SHA-256: c5fc66fc568804748c75875193ab649c12c199d4dc602e71c56580c63f8ffd46 |
| openstack-neutron-lbaas-11.0.3-1.el7ost.noarch.rpm | SHA-256: 7e5000a70504f8221e895100699c2e32119bbf96c286a35db75cf23ac4b98f70 |
| openstack-neutron-lbaas-ui-3.0.2-1.el7ost.noarch.rpm | SHA-256: 6429da598ec71ed8de2c3c9b69e9e61b389e8eca347549feb827d4336f12927f |
| openstack-neutron-linuxbridge-11.0.4-2.el7ost.noarch.rpm | SHA-256: c7202060274567dadea51e2f0ebcf6e7a333861ef6e02b2f6457a28b9c3acfb7 |
| openstack-neutron-macvtap-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: c160f1504507d9390f04fa86f6de202257061cc799321bf70fc037481583ce35 |
| openstack-neutron-metering-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: 43fe5e7152801e4fb438aa5133f5b52f3370c76041a892526d276aa12e4e65e4 |
| openstack-neutron-ml2-11.0.4-2.el7ost.noarch.rpm | SHA-256: bce29c33a9a2f78218fabae937efbe2dac7a440c986cf21533c0585e14ff629d |
| openstack-neutron-openvswitch-11.0.4-2.el7ost.noarch.rpm | SHA-256: a67e769d384fa557a285217637e2fc39d5f0a5f04bbe00459dd8ab51af01fc64 |
| openstack-neutron-rpc-server-11.0.4-2.el7ost.noarch.rpm | SHA-256: e13db429bb0bbb5961f84bdeafc39755e49d13b7196dfd4f3812520ab639223c |
| openstack-neutron-sriov-nic-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: c51b1ddeed8fdfdebfd5febd40e652881735786a356be1c3e142d0ed8ae71c25 |
| openstack-octavia-amphora-agent-1.0.2-1.el7ost.noarch.rpm | SHA-256: 8a159aca78237cb4a196a088fa80334d6818a235dfe317a224663db40842ee2d |
| openstack-octavia-api-1.0.2-1.el7ost.noarch.rpm | SHA-256: f131c01e45b6d7d7fd7b0afa763a71342ee724b3bb4aa774395ddb63389335e3 |
| openstack-octavia-common-1.0.2-1.el7ost.noarch.rpm | SHA-256: f6bf8e26894a3383af660afb3d4e045af79377695de9c04d963f9a9417addae0 |
| openstack-octavia-debuginfo-1.0.2-1.el7ost.ppc64le.rpm | SHA-256: 01f7c7f7040bcfb82f6488c6c88e38a37fdf10f01a52edb83eacec9eb3fed084 |
| openstack-octavia-diskimage-create-1.0.2-1.el7ost.noarch.rpm | SHA-256: 89a77317fc179c3cc618301cfb2fb49e231b7685128c52102f495f6cae187fb1 |
| openstack-octavia-health-manager-1.0.2-1.el7ost.noarch.rpm | SHA-256: 300849b9a6e5feb83598ff3c47b9c0a607759278c70ada5889440b9c549f76d0 |
| openstack-octavia-housekeeping-1.0.2-1.el7ost.noarch.rpm | SHA-256: 4403ee3f482ec8c28584177708d59f2cc8b85661b27de5f60ca07183ccb75b68 |
| openstack-octavia-worker-1.0.2-1.el7ost.noarch.rpm | SHA-256: b98790424582d6c3f581d0cc61bc3cb860933c7becaecfa2752e93139b139e98 |
| python-networking-odl-11.0.0-4.el7ost.noarch.rpm | SHA-256: 8fd1818f5873da9859089e6e62bbecd246e5b028aad42327d7923a4b3c075f45 |
| python-networking-ovn-3.0.1-2.el7ost.noarch.rpm | SHA-256: c4b48e7d3389cb27a3b2105658af58ea55de94daf3f40cac22d92d8d410ff356 |
| python-networking-vmware-nsx-11.0.2-1.el7ost.noarch.rpm | SHA-256: 92172e884cd38396509ff8d613066ded327c65ef00f57970f5e61de6a1aef0bc |
| python-neutron-11.0.4-2.el7ost.noarch.rpm | SHA-256: 8295b4f4e2327d473b9167e430c4c57ad7e1f781bd71b1b8483c8afab262aa69 |
| python-neutron-fwaas-11.0.1-4.el7ost.noarch.rpm | SHA-256: 5c482d5cf58ac68ffb7d4b1b48b72f5f114d9e48563c9ca850d0901f4cdc4b5a |
| python-neutron-fwaas-tests-11.0.1-4.el7ost.noarch.rpm | SHA-256: e8f0c5c9b6302868c051f8224cceacfcc39de64a0dc84fd7472939aa4b310d60 |
| python-neutron-lbaas-11.0.3-1.el7ost.noarch.rpm | SHA-256: e436b0586277ff1a4365b45bbdfef2cc3e33be3c7f7dea8ac2669dc401476af7 |
| python-neutron-lbaas-tests-11.0.3-1.el7ost.noarch.rpm | SHA-256: 64f21a8dc354181ecaf46197b7782b9d52e96af2ff752ee6aa2a15b4347cc81c |
| python-neutron-tests-11.0.4-2.el7ost.noarch.rpm | SHA-256: 3cacfcc890b2493a99f5a629559b6a36e56b62de675f6ac50271c837ce645732 |
| python-octavia-1.0.2-1.el7ost.noarch.rpm | SHA-256: f961634af94ece8a000919fa60bdda30794efd1afc6923fe41494a3a7ec0b369 |
| python-octavia-tests-1.0.2-1.el7ost.noarch.rpm | SHA-256: 638ad2905328f525c265a3239ee4f36a755df4f06903c33bfb5448c2ee5cff70 |
| python-octavia-tests-golang-1.0.2-1.el7ost.ppc64le.rpm | SHA-256: 95b864b10f61cc0e4a47220c7c72ee5cf5d9031fe8236a3f8268844b2325a5f1 |
Red Hat OpenStack 12
| SRPM | |
|---|---|
| openstack-neutron-11.0.4-2.el7ost.src.rpm | SHA-256: 989189375e82af99062d7746084789a0db776c93d881d2d2cd8386be6ebabfcf |
| openstack-neutron-fwaas-11.0.1-4.el7ost.src.rpm | SHA-256: dd68a4e06b7a4c714833e57f168eafb9fe0d45dcbcda5033aecf4becb0aaafac |
| openstack-neutron-lbaas-11.0.3-1.el7ost.src.rpm | SHA-256: 3992bf0189be3f2c3e199ee26bd500c96976a96c8e26d04319c50df9043f4de8 |
| openstack-neutron-lbaas-ui-3.0.2-1.el7ost.src.rpm | SHA-256: a1440e0d05baae7c7dad2e06d8a0210c7943cf4f64826a049b13d865431e8c9b |
| openstack-octavia-1.0.2-1.el7ost.src.rpm | SHA-256: 11883525534e3a44bfe27ac9c104b67c74dfefa9848e5b4559c84f0d15990eff |
| python-networking-odl-11.0.0-4.el7ost.src.rpm | SHA-256: 10df0c60df88d04cab61b67d358de9eeef92f9567009f33c60f917dfc2cb148c |
| python-networking-ovn-3.0.1-2.el7ost.src.rpm | SHA-256: 709b0fe2df96c9c1ae76cf6f1d94fbae4d2e1c4f64b396479509e687d59b7f14 |
| python-networking-vmware-nsx-11.0.2-1.el7ost.src.rpm | SHA-256: 837808c6a2b368e408b0296658f71178b97695f7a8d16dc5f1c947f13cb3acbd |
| x86_64 | |
| openstack-neutron-11.0.4-2.el7ost.noarch.rpm | SHA-256: 9ac19a3cfdb50f28d059722dc0f56daf65f6b2c8a15c57885121f0512ef968e4 |
| openstack-neutron-common-11.0.4-2.el7ost.noarch.rpm | SHA-256: 2cab21b7546c69fe854687c450cef4dfd983becd988b99e49d5f7599b45c0626 |
| openstack-neutron-fwaas-11.0.1-4.el7ost.noarch.rpm | SHA-256: c5fc66fc568804748c75875193ab649c12c199d4dc602e71c56580c63f8ffd46 |
| openstack-neutron-lbaas-11.0.3-1.el7ost.noarch.rpm | SHA-256: 7e5000a70504f8221e895100699c2e32119bbf96c286a35db75cf23ac4b98f70 |
| openstack-neutron-lbaas-ui-3.0.2-1.el7ost.noarch.rpm | SHA-256: 6429da598ec71ed8de2c3c9b69e9e61b389e8eca347549feb827d4336f12927f |
| openstack-neutron-linuxbridge-11.0.4-2.el7ost.noarch.rpm | SHA-256: c7202060274567dadea51e2f0ebcf6e7a333861ef6e02b2f6457a28b9c3acfb7 |
| openstack-neutron-macvtap-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: c160f1504507d9390f04fa86f6de202257061cc799321bf70fc037481583ce35 |
| openstack-neutron-metering-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: 43fe5e7152801e4fb438aa5133f5b52f3370c76041a892526d276aa12e4e65e4 |
| openstack-neutron-ml2-11.0.4-2.el7ost.noarch.rpm | SHA-256: bce29c33a9a2f78218fabae937efbe2dac7a440c986cf21533c0585e14ff629d |
| openstack-neutron-openvswitch-11.0.4-2.el7ost.noarch.rpm | SHA-256: a67e769d384fa557a285217637e2fc39d5f0a5f04bbe00459dd8ab51af01fc64 |
| openstack-neutron-rpc-server-11.0.4-2.el7ost.noarch.rpm | SHA-256: e13db429bb0bbb5961f84bdeafc39755e49d13b7196dfd4f3812520ab639223c |
| openstack-neutron-sriov-nic-agent-11.0.4-2.el7ost.noarch.rpm | SHA-256: c51b1ddeed8fdfdebfd5febd40e652881735786a356be1c3e142d0ed8ae71c25 |
| openstack-octavia-amphora-agent-1.0.2-1.el7ost.noarch.rpm | SHA-256: 8a159aca78237cb4a196a088fa80334d6818a235dfe317a224663db40842ee2d |
| openstack-octavia-api-1.0.2-1.el7ost.noarch.rpm | SHA-256: f131c01e45b6d7d7fd7b0afa763a71342ee724b3bb4aa774395ddb63389335e3 |
| openstack-octavia-common-1.0.2-1.el7ost.noarch.rpm | SHA-256: f6bf8e26894a3383af660afb3d4e045af79377695de9c04d963f9a9417addae0 |
| openstack-octavia-debuginfo-1.0.2-1.el7ost.x86_64.rpm | SHA-256: ccf0e4b7930308a82f5822f58114b664467b234075ead3cfe86978c3a3f94071 |
| openstack-octavia-diskimage-create-1.0.2-1.el7ost.noarch.rpm | SHA-256: 89a77317fc179c3cc618301cfb2fb49e231b7685128c52102f495f6cae187fb1 |
| openstack-octavia-health-manager-1.0.2-1.el7ost.noarch.rpm | SHA-256: 300849b9a6e5feb83598ff3c47b9c0a607759278c70ada5889440b9c549f76d0 |
| openstack-octavia-housekeeping-1.0.2-1.el7ost.noarch.rpm | SHA-256: 4403ee3f482ec8c28584177708d59f2cc8b85661b27de5f60ca07183ccb75b68 |
| openstack-octavia-worker-1.0.2-1.el7ost.noarch.rpm | SHA-256: b98790424582d6c3f581d0cc61bc3cb860933c7becaecfa2752e93139b139e98 |
| python-networking-odl-11.0.0-4.el7ost.noarch.rpm | SHA-256: 8fd1818f5873da9859089e6e62bbecd246e5b028aad42327d7923a4b3c075f45 |
| python-networking-ovn-3.0.1-2.el7ost.noarch.rpm | SHA-256: c4b48e7d3389cb27a3b2105658af58ea55de94daf3f40cac22d92d8d410ff356 |
| python-networking-vmware-nsx-11.0.2-1.el7ost.noarch.rpm | SHA-256: 92172e884cd38396509ff8d613066ded327c65ef00f57970f5e61de6a1aef0bc |
| python-neutron-11.0.4-2.el7ost.noarch.rpm | SHA-256: 8295b4f4e2327d473b9167e430c4c57ad7e1f781bd71b1b8483c8afab262aa69 |
| python-neutron-fwaas-11.0.1-4.el7ost.noarch.rpm | SHA-256: 5c482d5cf58ac68ffb7d4b1b48b72f5f114d9e48563c9ca850d0901f4cdc4b5a |
| python-neutron-fwaas-tests-11.0.1-4.el7ost.noarch.rpm | SHA-256: e8f0c5c9b6302868c051f8224cceacfcc39de64a0dc84fd7472939aa4b310d60 |
| python-neutron-lbaas-11.0.3-1.el7ost.noarch.rpm | SHA-256: e436b0586277ff1a4365b45bbdfef2cc3e33be3c7f7dea8ac2669dc401476af7 |
| python-neutron-lbaas-tests-11.0.3-1.el7ost.noarch.rpm | SHA-256: 64f21a8dc354181ecaf46197b7782b9d52e96af2ff752ee6aa2a15b4347cc81c |
| python-neutron-tests-11.0.4-2.el7ost.noarch.rpm | SHA-256: 3cacfcc890b2493a99f5a629559b6a36e56b62de675f6ac50271c837ce645732 |
| python-octavia-1.0.2-1.el7ost.noarch.rpm | SHA-256: f961634af94ece8a000919fa60bdda30794efd1afc6923fe41494a3a7ec0b369 |
| python-octavia-tests-1.0.2-1.el7ost.noarch.rpm | SHA-256: 638ad2905328f525c265a3239ee4f36a755df4f06903c33bfb5448c2ee5cff70 |
| python-octavia-tests-golang-1.0.2-1.el7ost.x86_64.rpm | SHA-256: 92a741c8bf657fc6abcd709a6e0b5aa62bc74ba5c7fa85fbcef28a8922ac2054 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.