Comment 4 for bug 1443798

Revision history for this message
watanabe.isao (watanabe.isao) wrote :

Hello, @Jeremy Stanley (fungi)

To other tenants as well.
When re-syncing, something like port create and nova boot will fail.
In a large environment, the re-syncing will last up to 3 or 4 minutes. This means if a re-sync occurred, we will almost not be able to boot any more instances for all tenants.

Hello, @Salvatore Orlando (salvatore-orlando)

Because this is a ordinarily user enabled operation(CLI and API as well), which affects whole system, so I put it as a security problem. If I'm not marking the problem in the right way, please tell me.

Hello, ALL

I will add a patch to this bug report ASAP, which will be well tested in master branch.
The fix is mentioned in the title, which is to add a restrict on netmask of 31 add 32 when IPv4, and 63, 64 when IPv6.
I really need this bug fixed in kilo or stable/kilo.1. If there is any problem with this, please tell me.
Thank you very much.