Skip to content

CLOUDSTACK-9811: fixed an issue if the dev is not in the databag - #2003

Merged
asfgit merged 2 commits into
apache:masterfrom
swill:cs_ip_fix
Mar 23, 2017
Merged

CLOUDSTACK-9811: fixed an issue if the dev is not in the databag#2003
asfgit merged 2 commits into
apache:masterfrom
swill:cs_ip_fix

Conversation

@swill

Copy link
Copy Markdown
Contributor

Defend against the specified dev not being in the databag.

@borisstoyanov

Copy link
Copy Markdown
Contributor

Thanks for this fix @swill
@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@borisstoyanov a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result: ✔centos6 ✔centos7 ✔debian. JID-591

@borisstoyanov

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@borisstoyanov a Trillian-Jenkins test job (centos7 mgmt + kvm-centos7) has been kicked to run smoke tests

@karuturi

Copy link
Copy Markdown
Member

Thanks Will. Can you please add bug id(CLOUDSTACK-9811) to the PR and commit message?

@blueorangutan

Copy link
Copy Markdown

Trillian test result (tid-954)
Environment: kvm-centos7 (x2), Advanced Networking with Mgmt server 7
Total time taken: 33186 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr2003-t954-kvm-centos7.zip
Intermitten failure detected: /marvin/tests/smoke/test_network.py
Intermitten failure detected: /marvin/tests/smoke/test_privategw_acl.py
Intermitten failure detected: /marvin/tests/smoke/test_snapshots.py
Intermitten failure detected: /marvin/tests/smoke/test_vpc_redundant.py
Test completed. 45 look ok, 4 have error(s)

TestResultTime (s)Test File
test_05_rvpc_multi_tiersFailure197.06test_vpc_redundant.py
test_04_rvpc_network_garbage_collector_nicsFailure1226.73test_vpc_redundant.py
test_01_create_redundant_VPC_2tiers_4VMs_4IPs_4PF_ACLFailure367.39test_vpc_redundant.py
test_04_rvpc_privategw_static_routesFailure308.87test_privategw_acl.py
test_network_rules_acquired_public_ip_3_Load_Balancer_RuleFailure41.60test_network.py
test_network_rules_acquired_public_ip_2_nat_ruleFailure31.61test_network.py
test_network_rules_acquired_public_ip_1_static_nat_ruleFailure93.45test_network.py
test_02_list_snapshots_with_removed_data_storeError0.03test_snapshots.py
test_01_vpc_site2site_vpnSuccess154.57test_vpc_vpn.py
test_01_vpc_remote_access_vpnSuccess60.82test_vpc_vpn.py
test_01_redundant_vpc_site2site_vpnSuccess245.94test_vpc_vpn.py
test_02_VPC_default_routesSuccess275.74test_vpc_router_nics.py
test_01_VPC_nics_after_destroySuccess501.27test_vpc_router_nics.py
test_03_create_redundant_VPC_1tier_2VMs_2IPs_2PF_ACL_reboot_routersSuccess541.72test_vpc_redundant.py
test_02_redundant_VPC_default_routesSuccess742.74test_vpc_redundant.py
test_09_delete_detached_volumeSuccess151.17test_volumes.py
test_08_resize_volumeSuccess156.07test_volumes.py
test_07_resize_failSuccess161.42test_volumes.py
test_06_download_detached_volumeSuccess156.57test_volumes.py
test_05_detach_volumeSuccess155.55test_volumes.py
test_04_delete_attached_volumeSuccess151.12test_volumes.py
test_03_download_attached_volumeSuccess156.10test_volumes.py
test_02_attach_volumeSuccess89.55test_volumes.py
test_01_create_volumeSuccess710.80test_volumes.py
test_03_delete_vm_snapshotsSuccess275.19test_vm_snapshots.py
test_02_revert_vm_snapshotsSuccess95.66test_vm_snapshots.py
test_01_create_vm_snapshotsSuccess159.69test_vm_snapshots.py
test_deploy_vm_multipleSuccess256.90test_vm_life_cycle.py
test_deploy_vmSuccess0.02test_vm_life_cycle.py
test_advZoneVirtualRouterSuccess0.02test_vm_life_cycle.py
test_10_attachAndDetach_isoSuccess26.48test_vm_life_cycle.py
test_09_expunge_vmSuccess125.15test_vm_life_cycle.py
test_08_migrate_vmSuccess30.59test_vm_life_cycle.py
test_07_restore_vmSuccess0.09test_vm_life_cycle.py
test_06_destroy_vmSuccess130.63test_vm_life_cycle.py
test_03_reboot_vmSuccess125.63test_vm_life_cycle.py
test_02_start_vmSuccess10.12test_vm_life_cycle.py
test_01_stop_vmSuccess40.24test_vm_life_cycle.py
test_CreateTemplateWithDuplicateNameSuccess50.38test_templates.py
test_08_list_system_templatesSuccess0.02test_templates.py
test_07_list_public_templatesSuccess0.03test_templates.py
test_05_template_permissionsSuccess0.04test_templates.py
test_04_extract_templateSuccess5.11test_templates.py
test_03_delete_templateSuccess5.08test_templates.py
test_02_edit_templateSuccess90.16test_templates.py
test_01_create_templateSuccess20.24test_templates.py
test_10_destroy_cpvmSuccess161.54test_ssvm.py
test_09_destroy_ssvmSuccess138.36test_ssvm.py
test_08_reboot_cpvmSuccess101.44test_ssvm.py
test_07_reboot_ssvmSuccess133.44test_ssvm.py
test_06_stop_cpvmSuccess132.03test_ssvm.py
test_05_stop_ssvmSuccess163.51test_ssvm.py
test_04_cpvm_internalsSuccess1.15test_ssvm.py
test_03_ssvm_internalsSuccess3.27test_ssvm.py
test_02_list_cpvm_vmSuccess0.08test_ssvm.py
test_01_list_sec_storage_vmSuccess0.09test_ssvm.py
test_01_snapshot_root_diskSuccess10.92test_snapshots.py
test_04_change_offering_smallSuccess234.25test_service_offerings.py
test_03_delete_service_offeringSuccess0.03test_service_offerings.py
test_02_edit_service_offeringSuccess0.04test_service_offerings.py
test_01_create_service_offeringSuccess0.07test_service_offerings.py
test_02_sys_template_readySuccess0.09test_secondary_storage.py
test_01_sys_vm_startSuccess0.12test_secondary_storage.py
test_09_reboot_routerSuccess40.25test_routers.py
test_08_start_routerSuccess30.20test_routers.py
test_07_stop_routerSuccess10.12test_routers.py
test_06_router_advancedSuccess0.04test_routers.py
test_05_router_basicSuccess0.03test_routers.py
test_04_restart_network_wo_cleanupSuccess5.65test_routers.py
test_03_restart_network_cleanupSuccess60.39test_routers.py
test_02_router_internal_advSuccess1.04test_routers.py
test_01_router_internal_basicSuccess0.56test_routers.py
test_router_dns_guestipquerySuccess76.67test_router_dns.py
test_router_dns_externalipquerySuccess0.06test_router_dns.py
test_router_dhcphostsSuccess286.44test_router_dhcphosts.py
test_router_dhcp_optsSuccess21.51test_router_dhcphosts.py
test_01_updatevolumedetailSuccess0.05test_resource_detail.py
test_01_reset_vm_on_rebootSuccess145.83test_reset_vm_on_reboot.py
test_createRegionSuccess0.03test_regions.py
test_create_pvlan_networkSuccess5.14test_pvlan.py
test_dedicatePublicIpRangeSuccess0.30test_public_ip_range.py
test_03_vpc_privategw_restart_vpc_cleanupSuccess473.19test_privategw_acl.py
test_02_vpc_privategw_static_routesSuccess348.33test_privategw_acl.py
test_01_vpc_privategw_aclSuccess81.51test_privategw_acl.py
test_01_primary_storage_nfsSuccess35.65test_primary_storage.py
test_createPortablePublicIPRangeSuccess15.14test_portable_publicip.py
test_createPortablePublicIPAcquireSuccess15.40test_portable_publicip.py
test_isolate_network_password_serverSuccess90.19test_password_server.py
test_UpdateStorageOverProvisioningFactorSuccess0.10test_over_provisioning.py
test_oobm_zchange_passwordSuccess25.44test_outofbandmanagement.py
test_oobm_multiple_mgmt_server_ownershipSuccess16.27test_outofbandmanagement.py
test_oobm_issue_power_statusSuccess10.18test_outofbandmanagement.py
test_oobm_issue_power_softSuccess10.22test_outofbandmanagement.py
test_oobm_issue_power_resetSuccess15.38test_outofbandmanagement.py
test_oobm_issue_power_onSuccess15.24test_outofbandmanagement.py
test_oobm_issue_power_offSuccess10.22test_outofbandmanagement.py
test_oobm_issue_power_cycleSuccess15.24test_outofbandmanagement.py
test_oobm_enabledisable_across_clusterzonesSuccess87.20test_outofbandmanagement.py
test_oobm_enable_feature_validSuccess5.12test_outofbandmanagement.py
test_oobm_enable_feature_invalidSuccess0.26test_outofbandmanagement.py
test_oobm_disable_feature_validSuccess5.13test_outofbandmanagement.py
test_oobm_disable_feature_invalidSuccess0.07test_outofbandmanagement.py
test_oobm_configure_invalid_driverSuccess0.06test_outofbandmanagement.py
test_oobm_configure_default_driverSuccess0.05test_outofbandmanagement.py
test_oobm_background_powerstate_syncSuccess23.29test_outofbandmanagement.py
test_extendPhysicalNetworkVlanSuccess15.41test_non_contigiousvlan.py
test_01_nicSuccess553.91test_nic.py
test_releaseIPSuccess252.16test_network.py
test_reboot_routerSuccess397.49test_network.py
test_public_ip_user_accountSuccess10.19test_network.py
test_public_ip_admin_accountSuccess40.22test_network.py
test_delete_accountSuccess281.99test_network.py
test_02_port_fwd_on_non_src_natSuccess55.46test_network.py
test_01_port_fwd_on_src_natSuccess111.57test_network.py
test_nic_secondaryip_add_removeSuccess216.96test_multipleips_per_nic.py
login_test_saml_userSuccess17.82test_login.py
test_assign_and_removal_lbSuccess148.45test_loadbalance.py
test_02_create_lb_rule_non_natSuccess202.12test_loadbalance.py
test_01_create_lb_rule_src_natSuccess218.04test_loadbalance.py
test_03_list_snapshotsSuccess0.04test_list_ids_parameter.py
test_02_list_templatesSuccess0.03test_list_ids_parameter.py
test_01_list_volumesSuccess0.02test_list_ids_parameter.py
test_07_list_default_isoSuccess0.04test_iso.py
test_05_iso_permissionsSuccess0.04test_iso.py
test_04_extract_IsoSuccess5.11test_iso.py
test_03_delete_isoSuccess95.11test_iso.py
test_02_edit_isoSuccess0.04test_iso.py
test_01_create_isoSuccess20.70test_iso.py
test_04_rvpc_internallb_haproxy_stats_on_all_interfacesSuccess197.91test_internal_lb.py
test_03_vpc_internallb_haproxy_stats_on_all_interfacesSuccess137.18test_internal_lb.py
test_02_internallb_roundrobin_1RVPC_3VM_HTTP_port80Success536.15test_internal_lb.py
test_01_internallb_roundrobin_1VPC_3VM_HTTP_port80Success439.18test_internal_lb.py
test_dedicateGuestVlanRangeSuccess10.19test_guest_vlan_range.py
test_UpdateConfigParamWithScopeSuccess0.10test_global_settings.py
test_rolepermission_lifecycle_updateSuccess5.79test_dynamicroles.py
test_rolepermission_lifecycle_listSuccess5.68test_dynamicroles.py
test_rolepermission_lifecycle_deleteSuccess5.58test_dynamicroles.py
test_rolepermission_lifecycle_createSuccess5.60test_dynamicroles.py
test_rolepermission_lifecycle_concurrent_updatesSuccess5.69test_dynamicroles.py
test_role_lifecycle_update_role_inuseSuccess5.61test_dynamicroles.py
test_role_lifecycle_updateSuccess10.67test_dynamicroles.py
test_role_lifecycle_listSuccess5.61test_dynamicroles.py
test_role_lifecycle_deleteSuccess10.63test_dynamicroles.py
test_role_lifecycle_createSuccess5.62test_dynamicroles.py
test_role_inuse_deletionSuccess5.59test_dynamicroles.py
test_role_account_acls_multiple_mgmt_serversSuccess7.03test_dynamicroles.py
test_role_account_aclsSuccess7.06test_dynamicroles.py
test_default_role_deletionSuccess5.65test_dynamicroles.py
test_04_create_fat_type_disk_offeringSuccess0.05test_disk_offerings.py
test_03_delete_disk_offeringSuccess0.03test_disk_offerings.py
test_02_edit_disk_offeringSuccess0.04test_disk_offerings.py
test_02_create_sparse_type_disk_offeringSuccess0.05test_disk_offerings.py
test_01_create_disk_offeringSuccess0.07test_disk_offerings.py
test_deployvm_userdispersingSuccess20.40test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_userconcentratedSuccess20.40test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_firstfitSuccess60.49test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_userdata_postSuccess10.31test_deploy_vm_with_userdata.py
test_deployvm_userdataSuccess60.59test_deploy_vm_with_userdata.py
test_02_deploy_vm_root_resizeSuccess5.66test_deploy_vm_root_resize.py
test_01_deploy_vm_root_resizeSuccess5.66test_deploy_vm_root_resize.py
test_00_deploy_vm_root_resizeSuccess206.73test_deploy_vm_root_resize.py
test_deploy_vm_from_isoSuccess206.85test_deploy_vm_iso.py
test_DeployVmAntiAffinityGroupSuccess60.74test_affinity_groups.py
test_change_service_offering_for_vm_with_snapshotsSkipped0.00test_vm_snapshots.py
test_01_test_vm_volume_snapshotSkipped0.00test_vm_snapshots.py
test_06_copy_templateSkipped0.00test_templates.py
test_static_role_account_aclsSkipped0.01test_staticroles.py
test_11_ss_nfs_version_on_ssvmSkipped0.02test_ssvm.py
test_01_scale_vmSkipped0.00test_scale_vm.py
test_01_primary_storage_iscsiSkipped0.03test_primary_storage.py
test_nested_virtualization_vmwareSkipped0.00test_nested_virtualization.py
test_06_copy_isoSkipped0.00test_iso.py
test_deploy_vgpu_enabled_vmSkipped0.02test_deploy_vgpu_enabled_vm.py
test_3d_gpu_supportSkipped0.02test_deploy_vgpu_enabled_vm.py

@ustcweizhou

Copy link
Copy Markdown
Contributor

not tested it. but it seems the 'else' part also need to be changed.

@borisstoyanovborisstoyanov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've tested the changes and the VR does come up now, but I'm really concerned from the test failures we're getting

@swillswill changed the title fixed an issue if the dev is not in the databagCLOUDSTACK-9811: fixed an issue if the dev is not in the databagMar 14, 2017
@swill

Copy link
Copy Markdown
ContributorAuthor

@ustcweizhou the else case did not change from the original code: https://github.com/apache/cloudstack/pull/1741/files#diff-a7d6f7150cca74029f23c19b72ad0622L49

@karuturi I have updated the PR title and I updated the commit message to include the jira ticket.

@borisstoyanov do we have a run of these tests just against master recently to review the difference in output?

@ustcweizhou

Copy link
Copy Markdown
Contributor

@swill what I mean is , if you do not want to change the logic, do you need to change 'else:' to 'elif index == -1:' ?

@swill

Copy link
Copy Markdown
ContributorAuthor

I have to admit, I am not sure how the IP was found when looping through the list initially, but then when trying to update the index for the IP that was found, it is not there. The only way I can think of that would cause this is if the IP <-> dev mapping is broken somehow. It found the matching IP, but apparently that IP is not on the dev defined by the nic_dev_id (which comes from either: nic_dev_id = address['nic_dev_id'] (from the databag), which can then be overridden by nic_dev_id = ip['nic_dev_id'] (from the passed in IP) ).

Yes, I think you are right that the else case does not work right now. This is because we are appending the IP to this dev, but we never removed it from the other dev it was apparently found in. This logic is SUPPOSED to find the existing IP's index and then if found, update that index with the updated info.

The old logic which just removed all "found" IPs and then re-added them, did not preserve the order, so the source nat IP could get reconfigured as a secondary IP on a nic instead of it being primary. This reordering of the IPs on VR reboot caused the VPN to fail because the source nat IP was no longer the primary IP.

So we know that removing all found IPs and then adding them does not work because it changes the order of the IPs causing the source nat IP to become a secondary IP on the nic.

The error described in CLOUDSTACK-9811 seems to be a situation where the IP is found on one nic, but then for some reason the dev which the IP is associated with is changed (I don't know why this would be happening), causing the index where the IP was found to not be valid because the IP is actually on a different dev.

To know how to fix this correctly, we need to understand why/how an IP can be associated with one dev (index found) and then get changed to be associated with a different dev.

We need to find a way to preserve IP order while being able to update the IP configurations.

@remibergsma do you have any ideas on this? Anyone else have ideas here?

@swill

Copy link
Copy Markdown
ContributorAuthor

On the Jira ticket, Wei Zhou mentioned that this could potentially happen if you have two different public IP ranges. So if you associate a public IP which is in a different range than the source nat, a new nic will be created. If you disassociate it, that nic will be removed.

I guess my question is. Why is it not on thedbagvariable then associated with that dev? I think Wei is probably right in terms of context, but I am not sure how exactly to solve this yet.

@borisstoyanov can you confirm that you have two different public IP ranges in your setup?

@borisstoyanov

Copy link
Copy Markdown
Contributor

@swill we're using one IP range for the physical guest public network. I think we could set this up if required?

@ustcweizhou

Copy link
Copy Markdown
Contributor

@borisstoyanov are you using vpc ?

@swill

Copy link
Copy Markdown
ContributorAuthor

@borisstoyanov we are still trying to understand how the IP was found when looping through the dbag but it is not associated with the expected dev when we try to update the index which it was found on. The only way I can see this could happen is if the dev requested it be configured on is different from the dev it is actually configured on. I still have not figured out how that case exists.

@ustcweizhou has some good ideas on this front, but I don't think we have gotten to a point where we understand how this problem is happening.

@borisstoyanov is there a chance you can post the ips.json and ip_association.json files in your environment so we can start to understand what the config is that is causing this?

@borisstoyanov

Copy link
Copy Markdown
Contributor

@swill thanks, I found the ips.json, but I couldn't find the ip_association.json on the VR. I guess it's not processed yet. Can you advise how to force it to generate? Hope this helps.
ips.txt

@borisstoyanov

Copy link
Copy Markdown
Contributor

@ustcweizhou no VPC

@swill

Copy link
Copy Markdown
ContributorAuthor

@borisstoyanov I have a suspicion that the ip_association.json is a transient file which may be short lived. I am not sure because I have not seen it either, but it was the file being processed when you had your original error.

I will review your ips.json and see what I can find.

@swill

Copy link
Copy Markdown
ContributorAuthor

This ips.json file confuses the hell out of me. From what I can tell both eth2 and eth3 both have the ip 10.1.35.83 twice for each (for a total of the IP being configured 4 times over two interfaces).

How was this IP configured?

 "eth2": [
{
"add": true,
"broadcast": "10.1.63.255",
"cidr": "10.1.35.83/19",
"device": "eth2",
"gateway": "10.1.63.254",
"netmask": "255.255.224.0",
"network": "10.1.32.0/19",
"nic_dev_id": "2",
"nw_type": "public",
"one_to_one_nat": false,
"public_ip": "10.1.35.83",
"size": "19",
"source_nat": false
},
{
"add": true,
"broadcast": "10.1.63.255",
"cidr": "10.1.35.83/19",
"device": "eth2",
"gateway": "10.1.63.254",
"netmask": "255.255.224.0",
"network": "10.1.32.0/19",
"nic_dev_id": "2",
"nw_type": "public",
"one_to_one_nat": false,
"public_ip": "10.1.35.83",
"size": "19",
"source_nat": false
}
],
"eth3": [
{
"add": true,
"broadcast": "10.1.63.255",
"cidr": "10.1.35.83/19",
"device": "eth3",
"first_i_p": true,
"gateway": "10.1.63.254",
"netmask": "255.255.224.0",
"network": "10.1.32.0/19",
"new_nic": true,
"nic_dev_id": 3,
"nw_type": "public",
"one_to_one_nat": false,
"public_ip": "10.1.35.83",
"size": "19",
"source_nat": true,
"vif_mac_address": "06:ee:46:00:00:03"
},
{
"add": true,
"broadcast": "10.1.63.255",
"cidr": "10.1.35.83/19",
"device": "eth3",
"first_i_p": true,
"gateway": "10.1.63.254",
"netmask": "255.255.224.0",
"network": "10.1.32.0/19",
"new_nic": true,
"nic_dev_id": 3,
"nw_type": "public",
"one_to_one_nat": false,
"public_ip": "10.1.35.83",
"size": "19",
"source_nat": true,
"vif_mac_address": "06:a4:80:00:00:03"
}
],

I will see if I can get to the bottom of this, but this is pretty confusing. Do you have a sequence of events which produced this configuration?

@swill

Copy link
Copy Markdown
ContributorAuthor

So... Looking at this with a different perspective. If there is a bug elsewhere which would cause an IP to be duplicated in the dbag, the old implementation would have cleaned up this bug and would have removed all the duplicates (including the real one) and then would have only added back the real one. My implementation did not assume that I was having to clean up duplicates in the dbag variable and only focused on adding if it didn't exist or updating the existing entry if it did exist. I will have to think about this more...

@ustcweizhou

Copy link
Copy Markdown
Contributor

the ips.json is very very weird

@borisstoyanov

Copy link
Copy Markdown
Contributor

yes, agree with you @swill, it seems eth3 is duplicated eth2. The VR we're trying to bring up isn't supposed to have eth3 at all...

@ustcweizhou

Copy link
Copy Markdown
Contributor

it seems nicDevId is not set correctly in java code.

@ustcweizhou

Copy link
Copy Markdown
Contributor

@borisstoyanov what's the last commit in your code ?
could you check how many nics attached to the VR in database, select * from nics where instance_id= ?

@swill

Copy link
Copy Markdown
ContributorAuthor

Ya, I am not sure where the problem is stemming from. The fact that my code is not defensive around this problem is a problem. That is for sure. But given my understanding of the moving parts here, I feel like there is something else going on as well. I will see if I can get an environment up and running tomorrow so I can do some more testing on this.

@ustcweizhou

Copy link
Copy Markdown
Contributor

@borisstoyanov moreover, can you please restart the network with cleanup, to see if the new VRs can start ?

@swill

Copy link
Copy Markdown
ContributorAuthor

I am considering changing my implementation to be the same as the old implementation (which removed the IP from the dbag in the initial loop of the merge), but if source_nat is present and it is true and the len(dbag[ip['device']]) > 0 (with all the checking required), then prepend else append. This should ensure that the source nat ip is the primary ip on the nic which the StrongSwan feature depends on.

If I do this and there is a bug elsewhere that will duplicate the IPs in the databag, then this will clean that up (as I assume it was doing before).

Not sure this will fix @borisstoyanov's current problem, but I think it is probably a safer implementation to keep the source nat IP as the first IP.

I will update this PR with that change later today...

@borisstoyanov

Copy link
Copy Markdown
Contributor

Hi @swill, could you please let us know when do you expect to address the changes you have mentioned, so I could schedule the testing accordingly. Thanks.

@ustcweizhou

Copy link
Copy Markdown
Contributor

@borisstoyanov could you please test with my suggestion? I think it should fix the duplicated nics in VR.

@remibergsma

Copy link
Copy Markdown
Contributor

@swill FYI if you look for first_i_p as seen in the json on the Python side, then on the Java side it's called firstIP, as the gson lib replaces every capital with an underscore and then the lowercase letter.

@swill

Copy link
Copy Markdown
ContributorAuthor

Thanks @remibergsma. I am going to use source_nat as it better represents what it is I am trying to establish and it seems to always be in the object where first_i_p does not always seem to be present (look at @borisstoyanov's output above for example).

@borisstoyanov I will work on getting you the new implementation today.

@swill

Copy link
Copy Markdown
ContributorAuthor

@borisstoyanov alright, this is ready for you to start testing. Can you kick off CI on this as well?

I will be doing testing of this locally as well.

This implementation is very similar to how it was implemented before my original change. See: https://github.com/apache/cloudstack/pull/1741/files#diff-a7d6f7150cca74029f23c19b72ad0622L19

The only change from the original was that if the IP is a source_nat IP and there are already IPs associated with that dev, it will prepend instead of append so the source nat ip is set as the primary ip on the nic (required for VPN).

@borisstoyanov

Copy link
Copy Markdown
Contributor

not sure about the CI tests @swill, I think the easiest way to kick Travis tests is the close/reopen the PR.
I'll pick it up as soon as possible. I'll rebuild and run the smoketests.
@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@borisstoyanov a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result: ✔centos6 ✔centos7 ✔debian. JID-594

@borisstoyanov

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@borisstoyanov a Trillian-Jenkins test job (centos7 mgmt + kvm-centos7) has been kicked to run smoke tests

@swill

Copy link
Copy Markdown
ContributorAuthor

thank you sir. :)

@borisstoyanov

Copy link
Copy Markdown
Contributor

@blueorangutan test

@blueorangutan

Copy link
Copy Markdown

@borisstoyanov a Trillian-Jenkins test job (centos7 mgmt + kvm-centos7) has been kicked to run smoke tests

@blueorangutan

Copy link
Copy Markdown

Trillian test result (tid-958)
Environment: kvm-centos7 (x2), Advanced Networking with Mgmt server 7
Total time taken: 31840 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr2003-t958-kvm-centos7.zip
Intermitten failure detected: /marvin/tests/smoke/test_privategw_acl.py
Intermitten failure detected: /marvin/tests/smoke/test_snapshots.py
Intermitten failure detected: /marvin/tests/smoke/test_vpc_redundant.py
Test completed. 46 look ok, 3 have error(s)

TestResultTime (s)Test File
test_01_create_redundant_VPC_2tiers_4VMs_4IPs_4PF_ACLFailure369.05test_vpc_redundant.py
test_04_rvpc_privategw_static_routesFailure335.61test_privategw_acl.py
test_02_list_snapshots_with_removed_data_storeError0.04test_snapshots.py
test_01_vpc_site2site_vpnSuccess145.03test_vpc_vpn.py
test_01_vpc_remote_access_vpnSuccess66.12test_vpc_vpn.py
test_01_redundant_vpc_site2site_vpnSuccess250.53test_vpc_vpn.py
test_02_VPC_default_routesSuccess275.54test_vpc_router_nics.py
test_01_VPC_nics_after_destroySuccess547.92test_vpc_router_nics.py
test_05_rvpc_multi_tiersSuccess508.38test_vpc_redundant.py
test_04_rvpc_network_garbage_collector_nicsSuccess1403.12test_vpc_redundant.py
test_03_create_redundant_VPC_1tier_2VMs_2IPs_2PF_ACL_reboot_routersSuccess543.21test_vpc_redundant.py
test_02_redundant_VPC_default_routesSuccess750.68test_vpc_redundant.py
test_09_delete_detached_volumeSuccess156.45test_volumes.py
test_08_resize_volumeSuccess156.39test_volumes.py
test_07_resize_failSuccess161.50test_volumes.py
test_06_download_detached_volumeSuccess156.27test_volumes.py
test_05_detach_volumeSuccess150.72test_volumes.py
test_04_delete_attached_volumeSuccess151.19test_volumes.py
test_03_download_attached_volumeSuccess156.32test_volumes.py
test_02_attach_volumeSuccess94.54test_volumes.py
test_01_create_volumeSuccess711.06test_volumes.py
test_03_delete_vm_snapshotsSuccess275.20test_vm_snapshots.py
test_02_revert_vm_snapshotsSuccess95.66test_vm_snapshots.py
test_01_create_vm_snapshotsSuccess163.76test_vm_snapshots.py
test_deploy_vm_multipleSuccess247.58test_vm_life_cycle.py
test_deploy_vmSuccess0.03test_vm_life_cycle.py
test_advZoneVirtualRouterSuccess0.02test_vm_life_cycle.py
test_10_attachAndDetach_isoSuccess26.64test_vm_life_cycle.py
test_09_expunge_vmSuccess125.24test_vm_life_cycle.py
test_08_migrate_vmSuccess45.95test_vm_life_cycle.py
test_07_restore_vmSuccess0.15test_vm_life_cycle.py
test_06_destroy_vmSuccess125.83test_vm_life_cycle.py
test_03_reboot_vmSuccess125.85test_vm_life_cycle.py
test_02_start_vmSuccess10.16test_vm_life_cycle.py
test_01_stop_vmSuccess40.31test_vm_life_cycle.py
test_CreateTemplateWithDuplicateNameSuccess30.38test_templates.py
test_08_list_system_templatesSuccess0.03test_templates.py
test_07_list_public_templatesSuccess0.04test_templates.py
test_05_template_permissionsSuccess0.06test_templates.py
test_04_extract_templateSuccess5.13test_templates.py
test_03_delete_templateSuccess5.13test_templates.py
test_02_edit_templateSuccess90.17test_templates.py
test_01_create_templateSuccess25.33test_templates.py
test_10_destroy_cpvmSuccess161.59test_ssvm.py
test_09_destroy_ssvmSuccess163.56test_ssvm.py
test_08_reboot_cpvmSuccess101.50test_ssvm.py
test_07_reboot_ssvmSuccess133.54test_ssvm.py
test_06_stop_cpvmSuccess131.72test_ssvm.py
test_05_stop_ssvmSuccess193.66test_ssvm.py
test_04_cpvm_internalsSuccess1.22test_ssvm.py
test_03_ssvm_internalsSuccess3.25test_ssvm.py
test_02_list_cpvm_vmSuccess0.12test_ssvm.py
test_01_list_sec_storage_vmSuccess0.13test_ssvm.py
test_01_snapshot_root_diskSuccess11.12test_snapshots.py
test_04_change_offering_smallSuccess239.60test_service_offerings.py
test_03_delete_service_offeringSuccess0.04test_service_offerings.py
test_02_edit_service_offeringSuccess0.05test_service_offerings.py
test_01_create_service_offeringSuccess0.11test_service_offerings.py
test_02_sys_template_readySuccess0.12test_secondary_storage.py
test_01_sys_vm_startSuccess0.18test_secondary_storage.py
test_09_reboot_routerSuccess35.33test_routers.py
test_08_start_routerSuccess30.27test_routers.py
test_07_stop_routerSuccess10.16test_routers.py
test_06_router_advancedSuccess0.06test_routers.py
test_05_router_basicSuccess0.04test_routers.py
test_04_restart_network_wo_cleanupSuccess5.69test_routers.py
test_03_restart_network_cleanupSuccess55.48test_routers.py
test_02_router_internal_advSuccess1.06test_routers.py
test_01_router_internal_basicSuccess0.57test_routers.py
test_router_dns_guestipquerySuccess76.73test_router_dns.py
test_router_dns_externalipquerySuccess0.08test_router_dns.py
test_router_dhcphostsSuccess277.82test_router_dhcphosts.py
test_router_dhcp_optsSuccess21.71test_router_dhcphosts.py
test_01_updatevolumedetailSuccess0.07test_resource_detail.py
test_01_reset_vm_on_rebootSuccess130.88test_reset_vm_on_reboot.py
test_createRegionSuccess0.04test_regions.py
test_create_pvlan_networkSuccess5.22test_pvlan.py
test_dedicatePublicIpRangeSuccess0.41test_public_ip_range.py
test_03_vpc_privategw_restart_vpc_cleanupSuccess479.72test_privategw_acl.py
test_02_vpc_privategw_static_routesSuccess370.17test_privategw_acl.py
test_01_vpc_privategw_aclSuccess87.09test_privategw_acl.py
test_01_primary_storage_nfsSuccess35.81test_primary_storage.py
test_createPortablePublicIPRangeSuccess15.18test_portable_publicip.py
test_createPortablePublicIPAcquireSuccess15.42test_portable_publicip.py
test_isolate_network_password_serverSuccess89.31test_password_server.py
test_UpdateStorageOverProvisioningFactorSuccess0.13test_over_provisioning.py
test_oobm_zchange_passwordSuccess30.64test_outofbandmanagement.py
test_oobm_multiple_mgmt_server_ownershipSuccess16.34test_outofbandmanagement.py
test_oobm_issue_power_statusSuccess10.25test_outofbandmanagement.py
test_oobm_issue_power_softSuccess15.32test_outofbandmanagement.py
test_oobm_issue_power_resetSuccess15.31test_outofbandmanagement.py
test_oobm_issue_power_onSuccess15.32test_outofbandmanagement.py
test_oobm_issue_power_offSuccess15.34test_outofbandmanagement.py
test_oobm_issue_power_cycleSuccess15.35test_outofbandmanagement.py
test_oobm_enabledisable_across_clusterzonesSuccess82.49test_outofbandmanagement.py
test_oobm_enable_feature_validSuccess5.15test_outofbandmanagement.py
test_oobm_enable_feature_invalidSuccess0.09test_outofbandmanagement.py
test_oobm_disable_feature_validSuccess5.17test_outofbandmanagement.py
test_oobm_disable_feature_invalidSuccess0.10test_outofbandmanagement.py
test_oobm_configure_invalid_driverSuccess0.08test_outofbandmanagement.py
test_oobm_configure_default_driverSuccess0.07test_outofbandmanagement.py
test_oobm_background_powerstate_syncSuccess23.39test_outofbandmanagement.py
test_extendPhysicalNetworkVlanSuccess15.31test_non_contigiousvlan.py
test_01_nicSuccess419.21test_nic.py
test_releaseIPSuccess257.96test_network.py
test_reboot_routerSuccess413.50test_network.py
test_public_ip_user_accountSuccess10.25test_network.py
test_public_ip_admin_accountSuccess40.27test_network.py
test_network_rules_acquired_public_ip_3_Load_Balancer_RuleSuccess66.91test_network.py
test_network_rules_acquired_public_ip_2_nat_ruleSuccess61.69test_network.py
test_network_rules_acquired_public_ip_1_static_nat_ruleSuccess123.73test_network.py
test_delete_accountSuccess287.98test_network.py
test_02_port_fwd_on_non_src_natSuccess55.76test_network.py
test_01_port_fwd_on_src_natSuccess111.70test_network.py
test_nic_secondaryip_add_removeSuccess202.47test_multipleips_per_nic.py
login_test_saml_userSuccess19.25test_login.py
test_assign_and_removal_lbSuccess133.35test_loadbalance.py
test_02_create_lb_rule_non_natSuccess187.33test_loadbalance.py
test_01_create_lb_rule_src_natSuccess218.95test_loadbalance.py
test_03_list_snapshotsSuccess0.06test_list_ids_parameter.py
test_02_list_templatesSuccess0.04test_list_ids_parameter.py
test_01_list_volumesSuccess0.03test_list_ids_parameter.py
test_07_list_default_isoSuccess0.06test_iso.py
test_05_iso_permissionsSuccess0.06test_iso.py
test_04_extract_IsoSuccess5.14test_iso.py
test_03_delete_isoSuccess95.19test_iso.py
test_02_edit_isoSuccess0.05test_iso.py
test_01_create_isoSuccess21.01test_iso.py
test_04_rvpc_internallb_haproxy_stats_on_all_interfacesSuccess198.50test_internal_lb.py
test_03_vpc_internallb_haproxy_stats_on_all_interfacesSuccess147.65test_internal_lb.py
test_02_internallb_roundrobin_1RVPC_3VM_HTTP_port80Success495.73test_internal_lb.py
test_01_internallb_roundrobin_1VPC_3VM_HTTP_port80Success430.60test_internal_lb.py
test_dedicateGuestVlanRangeSuccess10.26test_guest_vlan_range.py
test_UpdateConfigParamWithScopeSuccess0.14test_global_settings.py
test_rolepermission_lifecycle_updateSuccess6.17test_dynamicroles.py
test_rolepermission_lifecycle_listSuccess5.98test_dynamicroles.py
test_rolepermission_lifecycle_deleteSuccess5.87test_dynamicroles.py
test_rolepermission_lifecycle_createSuccess5.89test_dynamicroles.py
test_rolepermission_lifecycle_concurrent_updatesSuccess6.00test_dynamicroles.py
test_role_lifecycle_update_role_inuseSuccess5.90test_dynamicroles.py
test_role_lifecycle_updateSuccess10.98test_dynamicroles.py
test_role_lifecycle_listSuccess5.90test_dynamicroles.py
test_role_lifecycle_deleteSuccess10.93test_dynamicroles.py
test_role_lifecycle_createSuccess5.89test_dynamicroles.py
test_role_inuse_deletionSuccess5.86test_dynamicroles.py
test_role_account_acls_multiple_mgmt_serversSuccess8.14test_dynamicroles.py
test_role_account_aclsSuccess8.20test_dynamicroles.py
test_default_role_deletionSuccess5.97test_dynamicroles.py
test_04_create_fat_type_disk_offeringSuccess0.06test_disk_offerings.py
test_03_delete_disk_offeringSuccess0.04test_disk_offerings.py
test_02_edit_disk_offeringSuccess0.05test_disk_offerings.py
test_02_create_sparse_type_disk_offeringSuccess0.07test_disk_offerings.py
test_01_create_disk_offeringSuccess0.10test_disk_offerings.py
test_deployvm_userdispersingSuccess20.56test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_userconcentratedSuccess30.65test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_firstfitSuccess50.63test_deploy_vms_with_varied_deploymentplanners.py
test_deployvm_userdata_postSuccess10.48test_deploy_vm_with_userdata.py
test_deployvm_userdataSuccess50.78test_deploy_vm_with_userdata.py
test_02_deploy_vm_root_resizeSuccess5.97test_deploy_vm_root_resize.py
test_01_deploy_vm_root_resizeSuccess5.99test_deploy_vm_root_resize.py
test_00_deploy_vm_root_resizeSuccess207.53test_deploy_vm_root_resize.py
test_deploy_vm_from_isoSuccess207.46test_deploy_vm_iso.py
test_DeployVmAntiAffinityGroupSuccess60.88test_affinity_groups.py
test_change_service_offering_for_vm_with_snapshotsSkipped0.00test_vm_snapshots.py
test_01_test_vm_volume_snapshotSkipped0.00test_vm_snapshots.py
test_06_copy_templateSkipped0.00test_templates.py
test_static_role_account_aclsSkipped0.02test_staticroles.py
test_11_ss_nfs_version_on_ssvmSkipped0.02test_ssvm.py
test_01_scale_vmSkipped0.00test_scale_vm.py
test_01_primary_storage_iscsiSkipped0.04test_primary_storage.py
test_nested_virtualization_vmwareSkipped0.00test_nested_virtualization.py
test_06_copy_isoSkipped0.00test_iso.py
test_deploy_vgpu_enabled_vmSkipped0.03test_deploy_vgpu_enabled_vm.py
test_3d_gpu_supportSkipped0.03test_deploy_vgpu_enabled_vm.py

@borisstoyanovborisstoyanov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the fix @swill, tests are looking good, I've manually confirmed VR is coming up.
LGTM

@borisstoyanov

Copy link
Copy Markdown
Contributor

ping @rhtyd @DaanHoogland@abhinandanprateek@PaulAngus for review.

@DaanHoogland

Copy link
Copy Markdown
Contributor

code LGTM but @ustcweizhou 's patch still makes sense to me. Maybe you can add that separately? travis still fails!

@borisstoyanov

Copy link
Copy Markdown
Contributor

@DaanHoogland you could review it as well it addressed in https://github.com/apache/cloudstack/pull/2011/files

@karuturi

Copy link
Copy Markdown
Member

@ustcweizhou can you also review this fix? Is pr #2011 still required?

@yadvr

Copy link
Copy Markdown
Member

LGTM, does this affect 4.9 as well @swill ? /cc @borisstoyanov

@borisstoyanov

Copy link
Copy Markdown
Contributor

@rhtyd I think this was introduced with the StrongSwan implementation which was 4.10 I think.

@ustcweizhou

Copy link
Copy Markdown
Contributor

@karuturi to be honest, I think PR#2011 fixes the issue, not this one.

@swill

swill commented Mar 22, 2017

Copy link
Copy Markdown
ContributorAuthor

I think #2011 fixes the observed issue, but this PR improves the IP ordering fix originally added to the strongswan pr. This implementation ensures (again) that duplicate public ips will not be saved to the data bag while ensuring the source nat ip is primary on its nic.

In short, I think both PRs are worth merging.

@borisstoyanov

Copy link
Copy Markdown
Contributor

@karuturi we have 3 LGTMs, I think we're good to merge this.
tag:mergeready

@karuturi

Copy link
Copy Markdown
Member

ok. Thanks everyone. I am merging this.

@asfgit
asfgit merged commit bb40877 into apache:masterMar 23, 2017
asfgit pushed a commit that referenced this pull request Mar 23, 2017
CLOUDSTACK-9811: fixed an issue if the dev is not in the databagDefend against the specified dev not being in the databag.
* pr/2003:
changed the order fix to be closer to the original code
CLOUDSTACK-9811: fixed an issue if the dev is not in the databag
Signed-off-by: Rajani Karuturi <rajani.karuturi@accelerite.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@swill@borisstoyanov@blueorangutan@karuturi@ustcweizhou@remibergsma@DaanHoogland@yadvr@asfgit