14:01:40 #startmeeting fwaas 14:01:40 Meeting started Tue Mar 7 14:01:40 2017 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:42 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:01:44 The meeting name has been set to 'fwaas' 14:01:45 o/ 14:01:53 hi 14:01:59 #chair SridarK 14:01:59 Warning: Nick not in channel: SridarK 14:02:00 Current chairs: SridarK yushiro 14:02:04 ok lets get started 14:02:23 by rotation - i will run the meeting today 14:02:27 #chair xgerman 14:02:36 SridarK_, Yes, please :) 14:02:45 ok 14:02:47 yo 14:03:01 ok we will get this running smooth from now on :-) 14:03:09 next week xgerman will run the mtg 14:03:28 * xgerman needs to make a reminder 14:03:36 :-) 14:03:36 sounds good 14:03:50 Good 14:04:07 ok lets run thru our usual stuff 14:04:15 #topic FWaaSv2 14:04:47 wondering if the bot has some issues 14:05:08 the meeting started, didnt it ? 14:05:25 yushiro: can u pls add SridarK_ to chair 14:05:35 No, I think it didnt, we need to copy the logs at the end 14:05:46 #chair SridarK_ 14:05:47 Current chairs: SridarK SridarK_ yushiro 14:05:59 ok cool now we should be in business :-) 14:06:05 SridarK_, ah, I missed '_'. 14:06:10 lol 14:06:14 no worries 14:06:18 #chair xgerman 14:06:19 Current chairs: SridarK SridarK_ xgerman yushiro 14:06:28 #topic FWaaSv2 14:07:13 yushiro how are things with the L2 agent and Default FWG patches 14:07:59 SridarK_ : I'm sorry I couldn't work last week at all due to other emergency jobs.. 14:08:10 I know that feeling… 14:08:28 oh yes - no worries, 14:08:30 SridarK_, i can work on patches 14:08:43 SridarK_, if there is anythng i can do let me know 14:08:43 a part of how things go on 14:08:49 SridarK_, This week I can do it. So, currenlty add more UTs with Cedric/Paddu. 14:08:59 vks1: great - will take that up in open discussion 14:09:06 SridarK_, thanks 14:09:13 some updates on the OVS changes 14:09:15 vks1, great :) 14:09:39 Jakub was out on PTO and now is back and provided some pointers to get started 14:09:56 #link https://github.com/openstack/neutron/blob/master/doc/source/devref/openvswitch_firewall.rst 14:10:13 #link https://github.com/openstack/neutron/tree/master/neutron/agent/linux/openvswitch_firewall 14:10:31 SridarK_ this is abut the OVS Firewall Driver implementation , right? 14:10:32 chandanc is also out on PTO this week 14:10:41 reedip_1: yes exactly 14:11:06 so i think next week with chandanc back - we can get some discussions started 14:11:14 yeah, so we need to figure out if we use the same tables or add our own 14:11:25 and try to nail down some specifics in a week or so 14:11:32 sounds good 14:12:21 +! 14:12:27 in some sense this will indeed influence the L2 Driver as well the L2 Agent FWaaS patches as well 14:12:45 yeah, we will need OVS versions, too 14:12:46 so we are in a bit of a holding pattern anyways in this area 14:12:54 xgerman: +1 14:13:21 SridarK_, xgerman : sure. 14:14:15 let’s hope this won’t cause too much of. arework/delay 14:14:39 xgerman: exactly this is probab our biggest risk factor 14:15:04 we should plan for having a good "plan" in the next 2 weeks 14:15:12 +1 14:15:18 yes. 14:15:27 yup 14:15:44 then we should be on track for P-1 or very early P-2 (basically before the summit) 14:16:01 +q 14:16:02 +1 14:16:12 also we need to make sure Neutron doesn’t back out 14:16:20 of OVS 14:16:49 xgerman: yes indeed - Kevin was fairly certain - but we need to be sure that there are no shifts in priorites 14:17:06 other important things for FWaaS v2 - were getting better test coverage and Horizon 14:17:27 Sarath was looking into Horizon 14:17:28 I will start the test for Tempest soon, was busy this week with neutronlib 14:17:44 reedip_1: sure - i was going to look into it as well 14:17:50 we can divy up this 14:17:54 yup 14:18:10 lets discuss it in Open Discussion 14:18:21 also we have been getting some good coverage and fixing of scale issues from zzelle and blallau 14:18:37 thanks folks for weeding out some day 1 issues 14:19:04 i guess this is more generic and beyond v2 14:19:11 this one is important too https://review.openstack.org/#/c/426287/ 14:19:54 yeah, indeed 14:19:59 Thanks blallau on it 14:20:13 ok lets move on 14:20:15 @Sridark thank you ;) 14:20:20 blallau, Thank you! 14:20:39 blallau : +1 :) 14:20:42 #topic Stadium Compliance 14:21:07 OSC has been released recently 14:21:08 reedip_1: thanks for stepping here with the neutron lib changes 14:21:17 *stepping in 14:21:17 +1 14:21:33 pls go ahead with things that u are looking at 14:21:33 Next up in my items is the Fullstack and tempest test 14:22:01 reedip_1: how are we with neutron lib are there more things pending 14:22:04 Well I am still having an issue with one patch for migration of neutron-lib ( https://review.openstack.org/421472 ) 14:22:14 yes 14:22:17 SridarK_ : I am looking at the changes from boden 14:22:30 at regular intervals as well as any emails 14:23:02 ok 14:23:08 so if there is something, I am putting that across in neutron-lib in case he is busy, but other wise boden has been taking care of most of the items 14:23:19 yes perfect 14:23:22 so I just pitch in in case of some gate issues etc. 14:23:36 got some last week 14:23:47 and njohnston had put together a punch list for neutron lib 14:24:08 pls feel free to recruit other fwaas folks as well 14:24:11 I dont know about that list SridarK_ 14:24:25 ah ok - let me dig that up 14:24:29 can you share the same here so others can also look it up 14:25:28 #link https://etherpad.openstack.org/p/neutron_lib_fwaas_punchlist 14:25:42 njohnston: thanks as always :-) 14:26:00 obviously quite out of date now 14:26:14 njohnston: no worries - we will work to clean that up 14:26:25 reedip_1: so we could use this as a base 14:26:41 and lets volunteer to get this moving 14:26:51 hi njohnston :) 14:27:10 hi 14:27:19 wow, long list 14:27:32 njohnston, hi :) 14:27:49 hello all :-) 14:27:50 indeed njohnston will be missed very much for all the things he took care of 14:29:05 reedip_1: we can sync up offline to discuss this more and lets make sure that u are not overly burdened 14:29:47 other things we need to discuss here ? 14:30:06 SridarK_ yeah sure ( and no I am not burdened :) ) 14:30:15 nothing more right now 14:30:18 reedip_1: great cool 14:30:52 #topic Performance Improvement (Netlink) 14:30:59 tuhv: pls go ahead 14:31:33 Hi 14:32:12 I have updated my three parts based on Cedric's comments 14:32:42 Hope to see others reviews SridarK_, njohnston, xgemen 14:32:52 tuhv: will do 14:33:24 SridarK_, Also, please review Cedric's first https://review.openstack.org/#/c/434535/11 14:33:38 tuhv, will do in this week. Sorry for late. 14:33:47 tuhv: ok adding to my list 14:34:00 It helps us to grant sudo privilege when we run functional tests 14:34:01 +1 14:34:21 xgerman, SridarK_, we need it for fwass, right? 14:34:47 Also, my functional test is depending-on it :) 14:35:37 https://review.openstack.org/#/c/433598/ helps us to switch between 2 methods: conntrack-tools and netlink 14:35:43 tuhv: ok will take a look 14:35:56 well, with our new OVS agenda… 14:36:28 xgerman, we also still using iptables for L3, right? 14:36:45 tuhv: yes that will not change 14:37:11 So, we need to use conntrack :) 14:37:47 so on that point, on L2 - would this be relevant when we use OVS 14:38:12 OVS handles conntrack differently… 14:38:30 ok 14:38:38 SridarK_, xgerman, May we need a verification for conntrack in OVS, 14:38:57 i know tuhv and hoangcx were also looking to extend Netlink to Sec Groups 14:39:09 “Note: Open vSwitch firewall driver uses register 5 for marking flow related to port and register 6 which defines network and is used for conntrack zones." 14:39:10 so this may need a revisit ? 14:39:10 If ther is a problem, we can fix it 14:39:19 SridarK_, OVS handles conntrack by its flow entries also 14:39:19 #link Note: Open vSwitch firewall driver uses register 5 for marking flow related to port and register 6 which defines network and is used for conntrack zones. 14:39:42 #link https://github.com/openstack/neutron/blob/master/doc/source/devref/openvswitch_firewall.rst 14:39:49 ^^ that link 14:40:19 xgerman, thanks, we will take a look at this 14:40:21 but I am not sure if we won’t need rootwrap to modify those things 14:41:11 xgerman: thx - tuhv - yes u should think about the impact of change to OVS 14:41:50 anyways for L3 being iptables based - this will be relevant 14:42:01 SridarK_ it is easier if we make it configurable (a decouple driver) :) 14:42:03 Yes 14:42:41 tuhv: yes makes sense 14:42:52 If we make conntrack as a decouple driver as https://review.openstack.org/#/c/433598/, we can implement it easier 14:43:23 +1 14:43:29 +1 14:43:42 iptables_fwaas or even OVS if using conntrack driver can use through flush_entries and delete_entries function, I think 14:44:07 we can focus on trying to sort thru Netlink related patches for this week 14:44:15 +1 14:44:29 +1 14:44:39 SridarK, xgerman, yushiro, thanks 14:44:54 thanks tuhv 14:45:08 It's more readable and maintainable now, with keeping it based concept 14:45:15 +1 14:45:30 if nothing else lets move on 14:45:34 #topic bugs 14:46:10 SridarK_ Can we put a link in the etherpad, to see the latest bugs ? That would be easier for everyone , I guess 14:46:26 #link https://bugs.launchpad.net/openstack/+bugs?field.searchtext=fwaas&search=Search&field.status%3Alist=NEW&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INPROGRESS&field.status%3Alist=FIXCOMMITTED&field.assignee=&field.bug_reporter=&field.omit_dupes=on&field.has_patch=&field.has_no_package 14:46:35 this is what i use 14:46:49 perhaps others have better filters 14:47:12 i did not get a chance to triage before the meeting 14:47:21 Oh , I see the shortened filter in etherpad 14:47:38 reedip_1: yes u should use that 14:48:25 reedip_1, : http://urx.blue/BEcs filtered by tag 'fwaas' 14:49:23 thanks yushiro : but I think it has Incomplete ones as well, we may not need them now if we have marked them incomlete and the authoer hasnt changed it back 14:49:37 i am not sure if there is someting critical 14:49:48 lets take an action to scrub the list of bugs 14:50:36 reedip_1, OK. I'll update filteres. 14:50:39 if someone has a bug that they would like to discuss - lets do that 14:51:05 none that I remember right now 14:51:06 #action SridarK_ to take a first pass to scrub existing bugs 14:51:35 ok lets move on 14:51:41 #topic RFE 14:52:33 reedip_1: did u want to discuss more on ur spec 14:53:11 SridarK_ : I havent added anything much right now, I want to look into the OVS Firewall Driver first 14:53:11 #link https://review.openstack.org/#/c/236840/ 14:53:23 before I can work it around for OVS as well as iptables 14:53:44 so that I can ensure that it is easier to propagate it across other drivers 14:53:48 ok cool - u will need iptables for L3 anyways 14:53:57 hmm 14:55:08 but yeah, I would like review comments from others if possible 14:55:44 reedip_1: yes - i think we want this to applied to a Rule in the context of a specific policy 14:56:00 SridarK_ yes 14:56:03 +1 14:56:05 that was my main comment 14:56:16 I changed the spec accordingly, hopefully it is answering the concern now 14:56:37 otherwise i think it is good except for some minor things 14:56:49 ok lets carry on in gerrit 14:56:54 sure 14:56:58 #topic Open Discussion 14:57:10 SridarK_ I would like someone's help in discussion for the FWaaS driver with ODL 14:57:15 vks1: thanks for joining 14:57:23 3 min left 14:57:28 SridarK_, hi 14:57:29 and offer to help 14:57:45 yes i think there are a number of things that u can pick up on 14:58:07 SridarK_, point me and I will look 14:58:08 i know u wanted to also investigate the interaction with SFC 14:58:19 yes, hi vks1 14:58:24 vks1: ok we can look at some things 14:58:29 we wanted to discuss SFC before our PTG 14:58:32 annp is working logging feature with OVS native in Neutron with me. I'll ask some help to him about OVS native firewall driver. 14:58:38 reedip_1, hi 14:58:45 we had a discussion for Common Classifier Model 14:58:55 We wpuld like to know your ideas for SFC 14:59:04 yeah, I keep commenting on CCF 14:59:09 reedip_1: on the ODL changes - isaku and rui are looking at coming up with an ODL agent as the first step 14:59:12 maybe on the mail chain as we do not have time right now ?? :( 14:59:15 reedip_1, sure 14:59:25 SridarK_ : ok, I will look into it with them :) 14:59:30 yes lets start some discussion 14:59:33 offline 14:59:37 we are at time 14:59:37 yushiro, let me know i am up 14:59:47 vks1: great thanks 14:59:54 vks1, Sure 15:00:10 if nothing else thanks for joining and have a great week everyone 15:00:12 ok, I will take leave 15:00:16 #endmeeting fwaas