<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On 5 August 2016 at 13:05, Dan Smith <span dir="ltr"><<a href="mailto:dms@danplanet.com" target="_blank">dms@danplanet.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">> I haven't been able to reproduce it either, but it's unclear how packets<br>
> would get into a VM on an island since there is no router interface, and<br>
> the VM can't respond even if it did get it.<br>
><br>
> I do see outbound pings from the connected VM get to eth0, hit the<br>
> masquerade rule, and continue on their way.  But those packets get<br>
> dropped at my ISP since they're in the 10/8 range, so perhaps something<br>
> in the datacenter where this is running is responding?  Grasping at<br>
> straws is right until we see the results of Armando's test patch.<br>
<br>
</span>Right, that's what I was thinking when I said "something with the<br>
provider" in my other reply. A provider could potentially always reflect<br>
10/8 back at you to eliminate the possibility of ever escaping like<br>
that, which would presumably come back, hit the 10.1/20 route that we<br>
have and continue on in. I'm not entirely sure why that's not being hit<br>
right now (i.e. before this change), but I'm less familiar with the<br>
current state of the art than I am this patch.<br></blockquote><div><br></div><div>Still digging but we have a clean pass in [0]. The multinode setup involves br-ex [1,2], I am not quite sure how changing iptables rules fiddles with it, if at all.</div><div><br></div><div>[0] <a href="http://logs.openstack.org/76/351876/1/experimental/gate-tempest-dsvm-neutron-dvr-multinode-full/3a81575/logs/testr_results.html.gz">http://logs.openstack.org/76/351876/1/experimental/gate-tempest-dsvm-neutron-dvr-multinode-full/3a81575/logs/testr_results.html.gz</a></div><div>[1] <a href="https://github.com/openstack-infra/devstack-gate/blob/master/functions.sh#L1108">https://github.com/openstack-infra/devstack-gate/blob/master/functions.sh#L1108</a><br></div><div>[2] <a href="https://github.com/openstack-infra/devstack-gate/blob/master/devstack-vm-gate.sh#L130">https://github.com/openstack-infra/devstack-gate/blob/master/devstack-vm-gate.sh#L130</a></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<span class=""><font color="#888888"><br>
--Dan<br>
</font></span><div class=""><div class="h5"><br>
______________________________<wbr>______________________________<wbr>______________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" rel="noreferrer" target="_blank">OpenStack-dev-request@lists.<wbr>openstack.org?subject:<wbr>unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" rel="noreferrer" target="_blank">http://lists.openstack.org/<wbr>cgi-bin/mailman/listinfo/<wbr>openstack-dev</a><br>
</div></div></blockquote></div><br></div></div>