[neutron] [dev] ml2plugin doesn't use new security group rpc api

Just FooBar just.foobar42 at gmail.com
Fri Mar 8 15:12:39 UTC 2019

Hello everyone,

I'm having problems with Security Group Rule updates not being applied to
vms on hypervisors and I think I know why this is happening.

I see that there's already a bug about that:
https://bugs.launchpad.net/neutron/+bug/1814209 but there isn't much action
going on there. In my case, neutron-server is also using the queue
q-agent-notifier-security_group-update (as seen from neutron-server logs in
debug mode). The neutron version is the same, 12.0.4.

I went to check the code for my version 12.0.4 and I've found some
suspicious part which might be the cause of this bug. Let me explain my
understanding of the situation.

I started with ovs agent code and found that it is using
SecurityGroupServerAPIShim (
class for, well, Security Group RPC.

Comments in this class definition (
explain that it is a replacement for an older interface,
SecurityGroupServerAPIShim inherits from SecurityGroupInfoAPIMixin (
which is also a parent of the server side Ml2Plugin (
>From this I make a conclusion that Ml2Plugin was also switched to the new
SG RPC interface.

Now, there are other details that suggest that Ml2Plugin wasn't switched to
the new interface entirely and continues to use the old-style SG RPC

There's a class AgentNotifierApi (
used by neutron-server's Ml2Plugin (
to send notifications (to agents, I suppose). It inherits from the class
SecurityGroupAgentRpcApiMixin (
which has been marked for removal starting from Pike 3 years ago in this
This AgentNotifierApi class wasn't switched to a new Shim RPC interface for
SG (as it was done for the ovs agent and Ml2Plugin itself).

All previous links are for 12.0.4 version, the one used in my system
And here's the same class AgentNotifierApi from the Rocky release:
. As you can see, it still inherits from the class marked for removal and
isn't using new style SG RPC API.

>From all this I conclude that until AgentNotifierApi is using new style API
or the way that Ml2Plugin is sending notifications isn't changed, the bug
will still be present.

Please let me know if I'm getting this wrong. If I'm right, I'm interested
in helping to fix the bug.

Thank you for your attention!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-discuss/attachments/20190308/e9352346/attachment-0001.html>

More information about the openstack-discuss mailing list