Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions neutron/agent/linux/iptables_firewall.py
Original file line number Diff line number Diff line change
Expand Up @@ -775,6 +775,14 @@ def _protocol_name_map(self):
if not self._iptables_protocol_name_map:
tmp_map = constants.IPTABLES_PROTOCOL_NAME_MAP.copy()
tmp_map.update(self._local_protocol_name_map())
# iptables-save uses different strings for 'ipip' (protocol 4)
# depending on the distro, which corresponds to the entry for
# '4' in /etc/protocols. For example:
# - 'ipencap' in Ubuntu
# - 'ipv4' in CentOS/Fedora
# For this reason, we need to map the string for 'ipip' to the
# system-dependent string for '4', see bug #2054324.
tmp_map[constants.PROTO_NAME_IPIP] = tmp_map['4']
self._iptables_protocol_name_map = tmp_map
return self._iptables_protocol_name_map

Expand Down
42 changes: 42 additions & 0 deletions neutron/tests/unit/agent/linux/test_iptables_firewall.py
Original file line number Diff line number Diff line change
Expand Up @@ -489,6 +489,48 @@ def test_filter_ipv4_ingress_protocol_encap_by_num(self):
egress = None
self._test_prepare_port_filter(rule, ingress, egress)

def test_filter_ipv4_ingress_protocol_ipip(self):
# We want to use what the system-dependent string here is for 'ipip',
# as it could be 'ipencap' or 'ipv4' depending on the distro.
# See bug #2054324.
rule = {'ethertype': 'IPv4',
'direction': 'ingress',
'protocol': 'ipip'}
expected_proto_name = self.firewall._iptables_protocol_name('ipip')
ingress = mock.call.add_rule('ifake_dev',
'-p %s -j RETURN' % expected_proto_name,
top=False, comment=None)
egress = None
self._test_prepare_port_filter(rule, ingress, egress)

def test_filter_ipv4_ingress_protocol_4(self):
# We want to use what the system-dependent string here is for '4',
# as it could be 'ipencap' or 'ipv4' depending on the distro.
# See bug #2054324.
rule = {'ethertype': 'IPv4',
'direction': 'ingress',
'protocol': '4'}
expected_proto_name = self.firewall._iptables_protocol_name('4')
ingress = mock.call.add_rule('ifake_dev',
'-p %s -j RETURN' % expected_proto_name,
top=False, comment=None)
egress = None
self._test_prepare_port_filter(rule, ingress, egress)

def test_filter_ipv4_ingress_protocol_94(self):
# We want to use what the system-dependent string here is for '94',
# as it could be 'ipip' or something else depending on the distro.
# See bug #2054324.
rule = {'ethertype': 'IPv4',
'direction': 'ingress',
'protocol': '94'}
expected_proto_name = self.firewall._iptables_protocol_name('94')
ingress = mock.call.add_rule('ifake_dev',
'-p %s -j RETURN' % expected_proto_name,
top=False, comment=None)
egress = None
self._test_prepare_port_filter(rule, ingress, egress)

def test_filter_ipv4_ingress_protocol_999_local(self):
# There is no protocol 999, so let's return a mapping
# that says there is and make sure the rule is created
Expand Down