14:01:45 #startmeeting fwaas 14:01:45 Meeting started Thu Nov 30 14:01:45 2017 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:46 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 14:01:48 The meeting name has been set to 'fwaas' 14:01:55 Hello 14:02:03 #chair xgerman_ yushiro 14:02:04 Current chairs: xgerman_ yushiro 14:02:17 chandanc, hi, long time no see :) 14:02:28 Hello yushiro 14:02:53 SridarK, Hi! 14:02:53 Hi All 14:02:58 #chair SridarK 14:02:59 Current chairs: SridarK xgerman_ yushiro 14:03:15 OK, we just started now. Good timing :) 14:03:18 I think according to our etherpad - today is my turn 14:03:48 Ah, OK SridarK and sorry I was absent last meeting. 14:03:49 but yushiro if u have started running already 14:04:00 pls go ahead 14:04:04 Sure 14:04:06 #topic Queens 14:04:10 yushiro: yes no worries 14:04:33 1. l2-agent 14:05:07 oops, 1. l2-agent 2.OVS firewall 3. co-existing Now we are talking about '1.' 14:05:20 #link https://review.openstack.org/#/c/323971/ 14:05:46 annp: i think ur last update on PS77 14:06:02 SridarK, yes. 14:06:07 Now, this patch is independent and annp added 'sg_enabled' flag on it. 14:06:10 took care of checking the enable flag 14:06:17 yes 14:07:00 I am checking that and can do a +2 soon 14:07:21 SridarK, Good. In my point of view, there is no issue now. 14:07:30 yushiro: +1 14:07:46 +1 yushiro 14:07:48 annp, if you feel there is no issue, plz put +1 :) 14:08:08 yushiro Sure. :) 14:08:26 hoangcx, I'd like to ask you to check this patch either. 14:08:34 yushiro, Done. 14:09:18 OK, I'll check it again and start updating 'auto-association default fwg patch'. 14:09:39 yushiro: sounds good 14:09:58 OK, let's move next patch. 14:10:00 [1. l2-agent **2.OVS firewall 3. co-existing] 14:10:13 #link https://review.openstack.org/#/c/447251/54 14:10:46 chandanc, and annp has updated. Could you tell me some updates? 14:11:01 s/me/us 14:11:33 regarding to ovs firewall driver patch: i added handling for port no security group in standalone mode of fwg 14:11:37 annp did most of the update on OVS patch, the only change i proposed was to move the sg_enabled detection logic to the agent 14:12:02 chandanc, yes. 14:12:31 chandanc, annp OK, I see. Thanks for your update :) 14:12:40 I also added explicit drop flows for deny and reject rules 14:13:51 finally, I added generating flow's priority for each fwg rule to respect rule ordering. 14:14:55 annp: so on a FWaaS deny we will drop at this table 14:15:14 and on FWaaS permit - if SG is enabled then we will punt to SG 14:15:43 SridarK: yes. 14:16:40 annp, In order to transit fwg to sg, we need https://review.openstack.org/#/c/515368/12 ? 14:16:48 annp: on drops there is only one caveat that SG logging will miss it 14:17:24 yushiro, yes. we need co-existence patch for co-existence mode. 14:17:39 if SG was also enabled once we have SG logging 14:18:24 SridarK: yes, security group logging will miss drop packets. I think it should be documented in case co-existence 14:18:27 SridarK, ah, yes. 14:18:50 annp: yushiro: yes that is a caveat we can fix with documentation 14:19:13 ok we are on the same page 14:19:23 sorry facing connection issue 14:19:39 Or can we add more validation to handle it? 14:19:59 chandanc, NP. I hope your connection become stable :) 14:20:10 hoangcx_: what do you mean? validation? 14:20:19 hoangcx_: are u asking on the logging issue ? 14:20:25 thanks yushiro :) 14:20:35 Sorry, it will not work. I think documentation is better. 14:20:54 hoangcx_: +1 14:21:02 if so we want the logging stats to reflect - we will incur a performance penalty too 14:21:08 yes doc is better 14:21:16 SridarK: +1 14:21:55 anyways we will support Logging on FWaaS too once SG is done 14:22:02 So, we should implement fwaas logging ASAP :) 14:22:09 :-) 14:22:10 Aha, SridarK +1 14:22:12 SridarK: yeah. +1 14:22:18 sure 14:23:24 annp, Your co-existing patch is 'PoC'. I haven't tested this patch yet. Is it work now? 14:23:38 yushiro, yes, It work fine now. 14:23:53 yes i could do some tests 14:23:54 annp, If it works correctly, could you remove 'PoC' from commit msg? 14:24:06 chandanc, OK, sounds good. 14:24:08 Regarding to co-existing patch, chandanc: do you want to update? 14:24:33 annp: i dont think i will be updating it for now 14:24:38 yushiro, Sure, I will remove that. 14:24:50 will have to wait for feedback 14:25:22 I have update the ppt to the latest implementation 14:25:23 https://docs.google.com/presentation/d/1tRf-JQQiF0v_BdJahDjraxSEgz3c41YGdzHj3ui1C0Q/edit#slide=id.g29cfa03b8a_0_56 14:25:39 1 feedback for this patch. Please write releasenote about an effect for logging feature. 14:25:48 chandanc, I think so too. We are waiting feedback from yushiro, SridarK, xgerman_, ... for that 14:26:01 I'll comment on it. 14:26:06 after this meeting. 14:26:13 o/ 14:26:18 annp: will do 14:26:47 SridarK, Yushiro, xgerman_: Thanks :) 14:27:25 OK, Q-2 is only 4 days or ... We'll do our best. 14:27:46 Anything else for this topic? 14:28:22 that's all from me 14:28:26 OK, let's move on next topic. 14:28:41 #topic Horizon support 14:29:19 chandanc, Do you know Sarath today? 14:29:55 #link https://bugs.launchpad.net/neutron-fwaas-dashboard 14:30:21 All of bugs or backlog were listed on launchpad now. 14:30:22 not sure about him, he got into some office work 14:30:31 chandanc, OK, thank you. 14:31:12 I think we had a few minor issues and will be good to be ready with L2 support 14:31:46 yes, I think it was mostly good 14:32:45 Yeah. I think this is worth to fix it: 'ip_version' doesn't exist in detail firewall rule view' - https://bugs.launchpad.net/neutron-fwaas-dashboard/+bug/1728838 14:32:45 Launchpad bug 1728838 in Neutron FWaaS dashboard "'ip_version' doesn't exist in detail firewall rule view" [Undecided,New] 14:33:23 if you need to be a bug supervisor, feel free to request to join a team. 14:33:39 we need to expand the bug team 14:34:45 amotoki, Thanks. 14:34:52 +1 14:35:10 amotoki, you mean $B!H(BNeutron FWaaS dashboard Driver Team$B!I(B team ? 14:35:26 ah, duplicated 'team' :) 14:35:58 some japanese chars are included???? 14:36:36 yushiro: yes, neutron-fwaas-dashboard is a separate launchpad project, so it has a separate team. 14:36:58 if you are okay, I can add neutron-bugs team to the neutron-fwaas-dashboard bug team in launchpad 14:37:19 it might be more reasonable solution 14:37:29 Ah, I think it's OK. How about you, SridarK and xgerman_ ? 14:37:46 +1 14:37:52 yes i think tht works 14:37:59 we are part of the community 14:38:12 thanks. I will update it soon 14:38:28 Yes (^_^)v 14:38:50 ah, i noticed a better approach. I can set neutron-bugs team as the bug supervisor of neutron-fwaas-dashboard :) 14:39:11 done 14:39:27 amotoki, Thanks for your quick update 14:39:35 +1 14:39:50 yes thx amotoki 14:40:21 OK, let's move next topic. 14:40:34 #topic Stadium Compliance 14:40:45 Is reedip here? 14:41:54 OK, maybe today he is off I think. 14:42:38 OK, let's move on next topic. 14:42:49 #topic bugs 14:42:57 #link http://urx2.nu/C7UI 14:44:32 we need to classify the undecided ones 14:45:24 yes. 14:45:50 I'll check it after this meeting. 14:46:06 thanks — I can go through them as well 14:46:14 xgerman_, NP :) 14:46:15 lets maybe meet for 30 mins on Mon or Tue and run thru them ? 14:46:27 ok, works for me 14:46:38 Sure. 14:46:43 We can look thru and decide amongst us quickly 14:46:50 +1 14:46:54 +1+1 14:47:15 We can meet during yushiro's day time 14:47:28 will make it easier on xgerman_ and myself 14:47:33 as well 14:47:41 will be our evening 14:47:46 Wow, thanks :) I think it's ok for same time for this meeting. 14:48:03 #topic Open Discussion 14:48:18 doude: i have not got to ur changes yes 14:48:20 *yet 14:48:35 as soon as L2 is done i can start looking 14:48:43 Hi 14:48:55 ok I'm waiting lé merge 14:49:02 s/lé/l2 14:49:03 doude: yes 14:49:10 doude, Hi. since Sydney :) 14:49:19 I"m in starting blocks 14:49:23 Hi yushiro 14:49:58 Just an announcement: PTG will be held in Dublin at Feb. https://www.openstack.org/ptg/ 14:50:55 Also there is Travel Support Program here: https://www.openstack.org/ptg/#tab_travel 14:51:09 ok, I have plane tickets ;-) 14:51:18 January 4, 2018: Deadline to submit applications for Round One approvals 14:51:24 k 14:51:30 January 25, 2018: Deadline to submit applications for Round Two approvals 14:52:08 I strongly hope to meet members in Dublin :) Of course, I'll register TSP! 14:52:08 i am not sure yet 14:52:32 not sure yet also 14:53:05 haha, me too :) I'll try it. 14:55:05 Q-2 is Dec 04 - Dec 08. 14:56:02 FWaaS team can help each other and I believe we can do it :) 14:56:07 yeah, we *really* need to get L2 in by then 14:56:24 +1 14:56:44 +1 14:56:56 yushiro do you recall if we ever officially release the V2 API? 14:58:40 xgerman_, let me see.. I think no need to do that because we don't change V2 API. 14:58:57 I want to change V2 ;-) 14:59:07 I am adding remote fwg 14:59:16 with remote fgw? 14:59:22 yes 14:59:32 Ah, like SG 'remote_group_id'. 14:59:40 yep, was in our spec 14:59:56 now I am wondering if I need an Extension or not 15:00:04 if we never released Not… 15:01:03 I think it's OK to add with reno. 15:01:10 Oh, it's over time :) 15:01:13 #endmeeting