Page MenuHomePhabricator
Paste P60929

Masterwork From Distant Lands
ActivePublic

Authored by ProdPasteBot on Apr 18 2024, 1:31 PM.
Tags
None
Referenced Files
F47337195: Masterwork From Distant Lands
Apr 18 2024, 1:31 PM
Subscribers
None
Apr 18 13:28:10 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:10.576 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:377 started
Apr 18 13:28:10 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:10.579 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:377 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:12 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:12.577 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:378 started
Apr 18 13:28:12 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:12.580 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:378 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:14 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:14.579 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:379 started
Apr 18 13:28:14 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:14.582 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:379 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:16 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:16.581 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:380 started
Apr 18 13:28:16 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:16.584 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:380 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:18 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:18.582 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:381 started
Apr 18 13:28:18 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:18.585 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:381 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:20 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:20.585 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:382 started
Apr 18 13:28:20 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:20.588 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:382 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.003
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: /usr/lib/python3/dist-packages/oslo_policy/policy.py:722: UserWarning: Policy "admin_or_owner":"is_admin:True or project_id:%(project_id)s" was deprecated for removal in 21.0.0. Reason:
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: Nova API policies are introducing new default roles with scope_type
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: capabilities. Old policies are deprecated and silently going to be ignored
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: in nova 23.0.0 release.
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: . Its value may be silently ignored in the future.
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: warnings.warn(
Apr 18 13:28:21 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:21.766 8372 INFO neutron.agent.securitygroups_rpc [req-8f728cad-9a67-4a34-9244-bdf98d5ab80e req-54d5d0b1-588d-45ef-aa09-8b9082137d75 novaadmin taavitestproject - - default default] Security group member updated {'4c29a64f-b883-4622-893c-eb3fd78b0b7f'}
Apr 18 13:28:22 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:22.586 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:383 started
Apr 18 13:28:22 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:22.589 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:383 - starting polling. Elapsed:0.003
Apr 18 13:28:22 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:22.591 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:383 - port information retrieved. Elapsed:0.005
Apr 18 13:28:22 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:22.592 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:383 completed. Processed ports statistics: {'regular': {'added': 0, 'updated': 0, 'removed': 0}}. Elapsed:0.006
Apr 18 13:28:23 cloudvirt2001-dev nova-compute[1374]: 2024-04-18 13:28:23.702 1374 INFO os_vif [None req-8f728cad-9a67-4a34-9244-bdf98d5ab80e novaadmin taavitestproject - - default default] Successfully plugged vif VIFOpenVSwitch(active=False,address=fa:16:3e:07:c5:cb,bridge_name='br-int',has_traffic_filtering=True,id=de8355ee-9aee-4de4-9df9-513d9d62c08c,network=Network(e40a1c9f-cc09-4751-a6b8-0469a52318b7),plugin='ovs',port_profile=VIFPortProfileOpenVSwitch,preserve_on_delete=False,vif_name='tapde8355ee-9a')
Apr 18 13:28:23 cloudvirt2001-dev kernel: device tapde8355ee-9a entered promiscuous mode
Apr 18 13:28:23 cloudvirt2001-dev systemd-machined[949]: New machine qemu-4-i-0002c362.
Apr 18 13:28:23 cloudvirt2001-dev systemd[1]: Started machine-qemu\x2d4\x2di\x2d0002c362.scope - Virtual Machine qemu-4-i-0002c362.
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.588 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:384 started
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.591 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:384 - starting polling. Elapsed:0.003
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.593 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:384 - port information retrieved. Elapsed:0.006
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.595 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0bfd010>, 'local_vlan': None}
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.596 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Assigning 2 as local vlan for net-id=e40a1c9f-cc09-4751-a6b8-0469a52318b7, seg-id=8
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.613 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:384 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.019
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.614 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.670 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.680 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:384 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.092
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.589 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:385 started
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.593 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:385 - starting polling. Elapsed:0.004
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.594 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.597 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:385 - port information retrieved. Elapsed:0.008
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.599 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0041b10>, 'local_vlan': 2}
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.605 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:385 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.606 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.623 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.632 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:385 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.043
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.591 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:386 started
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.594 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:386 - starting polling. Elapsed:0.003
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.595 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.597 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:386 - port information retrieved. Elapsed:0.007
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.599 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a00fdcd0>, 'local_vlan': 2}
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.606 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:386 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.008
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.607 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.626 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.635 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:386 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.044
Apr 18 13:28:29 cloudvirt2001-dev sudo[14284]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/bmc-info --config-file /tmp/ipmi_exporter-8cdfae4a066f76bfd6e94a194553e5a3
Apr 18 13:28:29 cloudvirt2001-dev sudo[14284]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:29 cloudvirt2001-dev sudo[14284]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:29 cloudvirt2001-dev sudo[14287]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmimonitoring -Q --ignore-unrecognized-events --comma-separated-output --no-header-output --sdr-cache-recreate --output-event-bitmask --output-sensor-state --config-file /tmp/ipmi_exporter-b3536e56554f7cb002766f7d11231ea7
Apr 18 13:28:29 cloudvirt2001-dev sudo[14287]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.592 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:387 started
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.596 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:387 - starting polling. Elapsed:0.003
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.596 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.599 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:387 - port information retrieved. Elapsed:0.007
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.601 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a02797d0>, 'local_vlan': 2}
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.607 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:387 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.608 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.627 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.636 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:387 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.044
Apr 18 13:28:30 cloudvirt2001-dev sudo[14287]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:30 cloudvirt2001-dev sudo[14295]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-chassis --get-chassis-status --config-file /tmp/ipmi_exporter-9690c5f49381594901921565260923f1
Apr 18 13:28:30 cloudvirt2001-dev sudo[14295]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:30 cloudvirt2001-dev sudo[14295]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:30 cloudvirt2001-dev sudo[14297]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-dcmi --get-system-power-statistics --config-file /tmp/ipmi_exporter-b67f5a2d0525979a95dd0173c75ee1d6
Apr 18 13:28:30 cloudvirt2001-dev sudo[14297]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:30 cloudvirt2001-dev sudo[14297]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:30 cloudvirt2001-dev sudo[14299]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-sel --info --config-file /tmp/ipmi_exporter-ba4c183c147809bb1b6f93f7281bf088
Apr 18 13:28:30 cloudvirt2001-dev sudo[14299]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:30 cloudvirt2001-dev sudo[14299]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.594 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:388 started
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.597 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:388 - starting polling. Elapsed:0.003
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.598 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.602 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:388 - port information retrieved. Elapsed:0.008
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.604 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0b85b10>, 'local_vlan': 2}
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.609 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:388 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.610 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.628 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.636 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:388 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.042
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.596 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:389 started
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.599 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:389 - starting polling. Elapsed:0.003
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.600 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.601 8372 WARNING neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Clearing cache of registered ports, retries to resync were > 5
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.604 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:389 - port information retrieved. Elapsed:0.008
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.606 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0082d90>, 'local_vlan': 2}
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.611 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:389 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.612 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.630 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.637 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:389 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.041
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.598 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:390 started
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.601 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:390 - starting polling. Elapsed:0.003
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.602 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.605 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:390 - port information retrieved. Elapsed:0.007
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.607 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0f5b950>, 'local_vlan': 2}
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.612 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:390 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.006
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.612 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.629 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.636 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:390 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.039
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.599 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:391 started
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.602 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:391 - starting polling. Elapsed:0.003
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.603 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.606 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:391 - port information retrieved. Elapsed:0.007
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.608 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb69bf2ecd0>, 'local_vlan': 2}
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:391 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.615 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.631 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.638 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:391 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.039
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.601 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:392 started
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.604 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:392 - starting polling. Elapsed:0.003
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.605 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.608 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:392 - port information retrieved. Elapsed:0.007
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.610 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb69bf4bc50>, 'local_vlan': 2}
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.615 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:392 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.616 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.633 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.641 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:392 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.040
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.603 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:393 started
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.606 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:393 - starting polling. Elapsed:0.003
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.606 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.609 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:393 - port information retrieved. Elapsed:0.007
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.611 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0233ad0>, 'local_vlan': 2}
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.617 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:393 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.618 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.635 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.643 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:393 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.041
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.604 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:394 started
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.607 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:394 - starting polling. Elapsed:0.003
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.608 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.609 8372 WARNING neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Clearing cache of registered ports, retries to resync were > 5
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.612 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:394 - port information retrieved. Elapsed:0.008
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0157a90>, 'local_vlan': 2}
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.620 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:394 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.008
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.621 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.638 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.646 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:394 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.042
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.605 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:395 started
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.608 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:395 - starting polling. Elapsed:0.003
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.609 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.612 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:395 - port information retrieved. Elapsed:0.007
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a000d650>, 'local_vlan': 2}
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.621 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:395 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.008
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.621 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.639 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.648 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:395 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.043
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.607 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:396 started
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.610 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:396 - starting polling. Elapsed:0.003
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.611 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:396 - port information retrieved. Elapsed:0.007
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.616 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0279250>, 'local_vlan': 2}
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.623 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:396 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.008
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.623 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.641 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.649 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:396 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.043
Apr 18 13:28:48 cloudvirt2001-dev sshd[14345]: Connection from 208.80.153.84 port 42640 on 10.192.20.5 port 22 rdomain ""
Apr 18 13:28:48 cloudvirt2001-dev sshd[14345]: Connection closed by 208.80.153.84 port 42640 [preauth]
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.608 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:397 started
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.612 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:397 - starting polling. Elapsed:0.003
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.613 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.615 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:397 - port information retrieved. Elapsed:0.007
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.617 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb69bf2e150>, 'local_vlan': 2}
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.624 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:397 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.008
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.625 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.643 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.653 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:397 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.044
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.610 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:398 started
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.613 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:398 - starting polling. Elapsed:0.003
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.617 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:398 - port information retrieved. Elapsed:0.007
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.619 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a00fdcd0>, 'local_vlan': 2}
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.625 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:398 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.626 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.644 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.653 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:398 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.043
Apr 18 13:28:52 cloudvirt2001-dev sudo[14361]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/bmc-info --config-file /tmp/ipmi_exporter-2a82c03faddae3e45662cb6f427a819b
Apr 18 13:28:52 cloudvirt2001-dev sudo[14361]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:53 cloudvirt2001-dev sudo[14361]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:53 cloudvirt2001-dev sudo[14368]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmimonitoring -Q --ignore-unrecognized-events --comma-separated-output --no-header-output --sdr-cache-recreate --output-event-bitmask --output-sensor-state --config-file /tmp/ipmi_exporter-d0f821fcdbc9b411726d003e14e96e33
Apr 18 13:28:53 cloudvirt2001-dev sudo[14368]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:54 cloudvirt2001-dev sudo[14368]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:54 cloudvirt2001-dev sudo[14370]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-chassis --get-chassis-status --config-file /tmp/ipmi_exporter-0f8a77bd47225650c314ace60ab3fb86
Apr 18 13:28:54 cloudvirt2001-dev sudo[14370]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:54 cloudvirt2001-dev sudo[14370]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:54 cloudvirt2001-dev sudo[14372]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-dcmi --get-system-power-statistics --config-file /tmp/ipmi_exporter-8a8f6c89b0b1382ff589b9382da53cb4
Apr 18 13:28:54 cloudvirt2001-dev systemd-journald[577]: Data hash table of /var/log/journal/62693336befd45e4abc6fcb349d9135e/system.journal has a fill level at 75.0 (174763 of 233016 items, 67108864 file size, 383 bytes per hash table item), suggesting rotation.
Apr 18 13:28:54 cloudvirt2001-dev systemd-journald[577]: /var/log/journal/62693336befd45e4abc6fcb349d9135e/system.journal: Journal header limits reached or header out-of-date, rotating.
Apr 18 13:28:54 cloudvirt2001-dev sudo[14372]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:54 cloudvirt2001-dev sudo[14372]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:54 cloudvirt2001-dev sudo[14375]: prometheus : PWD=/ ; USER=root ; COMMAND=/usr/sbin/ipmi-sel --info --config-file /tmp/ipmi_exporter-7098f0b8b4d4289ecf013debdf783036
Apr 18 13:28:54 cloudvirt2001-dev sudo[14375]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=106)
Apr 18 13:28:54 cloudvirt2001-dev sudo[14375]: pam_unix(sudo:session): session closed for user root
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.611 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:399 started
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:399 - starting polling. Elapsed:0.003
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.615 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.616 8372 WARNING neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Clearing cache of registered ports, retries to resync were > 5
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.618 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:399 - port information retrieved. Elapsed:0.007
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.620 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0040710>, 'local_vlan': 2}
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.626 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:399 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.006
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.627 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.648 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.658 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:399 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.047
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.613 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:400 started
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.616 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:400 - starting polling. Elapsed:0.003
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.617 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.620 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:400 - port information retrieved. Elapsed:0.007
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.622 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb69bf7fb50>, 'local_vlan': 2}
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.627 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:400 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.006
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.627 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.646 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.652 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:400 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.039
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.614 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:401 started
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.617 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:401 - starting polling. Elapsed:0.003
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.618 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.621 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:401 - port information retrieved. Elapsed:0.007
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.623 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0c234d0>, 'local_vlan': 2}
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.629 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:401 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.629 8372 INFO neutron.agent.securitygroups_rpc [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Preparing filters for devices {'de8355ee-9aee-4de4-9df9-513d9d62c08c'}
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.647 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
12. -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
13. -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
14. -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
17. -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
18. -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
19. -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
20. -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
36. COMMIT
37. # Completed by iptables_manager
38.
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Error while processing VIF ports: neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
*filter
:neutron-openvswi-i355ee-9aee - [0:0]
:neutron-openvswi-o355ee-9aee - [0:0]
:neutron-openvswi-s355ee-9aee - [0:0]
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
-I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
-I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2860, in rpc_loop
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent failed_devices = self.process_network_ports(
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/plugins/ml2/drivers/openvswitch/agent/ovs_neutron_agent.py", line 2278, in process_network_ports
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.sg_agent.setup_port_filters(added_to_datapath,
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 292, in setup_port_filters
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.prepare_devices_filter(new_devices)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 143, in decorated_function
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, # pylint: disable=not-callable
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 156, in prepare_devices_filter
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply_port_filter(device_ids)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 107, in decorated_function
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent return func(self, *args, **kwargs)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/securitygroups_rpc.py", line 172, in _apply_port_filter
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent with self.firewall.defer_apply():
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3.11/contextlib.py", line 144, in __exit__
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent next(self.gen)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/firewall.py", line 140, in defer_apply
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.filter_defer_apply_off()
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_firewall.py", line 1007, in filter_defer_apply_off
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self.iptables.defer_apply_off()
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 446, in defer_apply_off
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent self._apply()
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 464, in _apply
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent first = self._apply_synchronized()
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ^^^^^^^^^^^^^^^^^^^^^^^^^^
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 628, in _apply_synchronized
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise err
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/iptables_manager.py", line 518, in _do_run_restore
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent linux_utils.execute(args, process_input='\n'.join(commands),
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent File "/usr/lib/python3/dist-packages/neutron/agent/linux/utils.py", line 156, in execute
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent raise exceptions.ProcessExecutionError(msg,
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent neutron_lib.exceptions.ProcessExecutionError: Exit code: 2; Cmd: ['iptables-restore', '-n']; Stdin: # Generated by iptables_manager
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *filter
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-i355ee-9aee - [0:0]
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-o355ee-9aee - [0:0]
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent :neutron-openvswi-s355ee-9aee - [0:0]
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 2 -d 172.16.129.142/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 3 -d 255.255.255.255/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 1 -s 0.0.0.0/32 -d 255.255.255.255/32 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 2 -j neutron-openvswi-s355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 3 -p udp -m udp --sport 68 --dport 67 -m comment --comment "Allow DHCP client traffic." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 4 -p udp -m udp --sport 67 --dport 68 -m comment --comment "Prevent DHCP Spoofing by VM." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 6 -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Generated by iptables_manager
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent *raw
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent COMMIT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.653 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:401 completed. Processed ports statistics: {'regular': {'added': 1, 'updated': 1, 'removed': 0}}. Elapsed:0.039
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.616 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:402 started
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.619 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:402 - starting polling. Elapsed:0.003
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.620 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent out of sync with plugin!
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.622 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Agent rpc_loop - iteration:402 - port information retrieved. Elapsed:0.007
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.624 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] Port de8355ee-9aee-4de4-9df9-513d9d62c08c updated. Details: {'device': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'device_id': 'eba48442-8c83-4541-8a9f-d97a9ab57493', 'network_id': 'e40a1c9f-cc09-4751-a6b8-0469a52318b7', 'port_id': 'de8355ee-9aee-4de4-9df9-513d9d62c08c', 'mac_address': 'fa:16:3e:07:c5:cb', 'admin_state_up': True, 'status': 'DOWN', 'network_type': 'vxlan', 'segmentation_id': 8, 'physical_network': None, 'fixed_ips': [{'subnet_id': 'c2868c65-9af2-4ecb-96af-8de1aa54f530', 'ip_address': '172.16.129.142'}], 'device_owner': 'compute:nova', 'allowed_address_pairs': [], 'port_security_enabled': True, 'qos_policy_id': None, 'qos_network_policy_id': None, 'profile': {}, 'vif_type': 'ovs', 'vnic_type': 'normal', 'security_groups': ['4c29a64f-b883-4622-893c-eb3fd78b0b7f'], 'migrating_to': None, 'hints': None, 'vif_port': <neutron.agent.common.ovs_lib.VifPort object at 0x7fb6a0267690>, 'local_vlan': 2}
Apr 18 13:29:00 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:29:00.630 8372 INFO neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] process_network_ports - iteration:402 - treat_devices_added_or_updated completed. Skipped 0 and no activated binding devices 0 of 1 devices currently available. Time elapsed: 0.007

Event Timeline

ProdPasteBot changed the title of this paste from untitled to Masterwork From Distant Lands.