Repository navigation
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## 4.20 #14325 +/- ##
============================================
- Coverage 16.41% 16.41% -0.01%
+ Complexity 13657 13656 -1
============================================
Files 5669 5669
Lines 501628 501627 -1
Branches 60942 60944 +2
============================================
- Hits 82336 82320 -16
- Misses 410064 410081 +17
+ Partials 9228 9226 -2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@DaanHoogland can you review? Small follow-up to #14037. |
9620a88 to
75c502f
Compare
thanks @wido I just noticed #14037 added two new test classes, any chance to move the new tests in #14037 and this PR into existing SecurityGroupManagerImplTest.java and SecurityGroupManagerImpl2Test.java ? |
DaanHoogland
left a comment
There was a problem hiding this comment.
code looks good, but agree with the move of the tests @weizhouapache proposes
When a security group rule references another security group, the member's IPv4 address is appended with /32 without checking whether the member has one. An IPv6-only member therefore produces the CIDR "null/32" in the generated ruleset. Only add the IPv4 entry when the member has an IPv4 address, in both SecurityGroupManagerImpl and SecurityGroupManagerImpl2. The tests for this and for the /128 member CIDR from apache#14037 now live in SecurityGroupManagerImplTest instead of four standalone test classes. Found while reviewing apache#14037.
75c502f to
93879d0
Compare
|
@weizhouapache done, all four tests are now in |
Description
Found while reviewing #14037. When a security group rule references another security group, both
SecurityGroupManagerImplandSecurityGroupManagerImpl2append/32to the member's IPv4 address without checking it. For a member with an IPv6-only NIC this produces the CIDRnull/32.The KVM agent drops the invalid entry while parsing, but the management server should not generate it. Skip the IPv4 entry when the member has no IPv4 address.
Based on 4.20 on top of #14037.
Types of changes
Feature/Enhancement Scale or Bug Severity
Bug Severity
How Has This Been Tested?
Unit tests for both implementations with an IPv6-only member, added to
SecurityGroupManagerImplTesttogether with the two tests from #14037. They pass with the fix and fail without it.