Bug 1205920
Summary: | iptables being overwritten by system-config-firewall | ||
---|---|---|---|
Product: | Red Hat CloudForms Management Engine | Reporter: | Joe Vlcek <jvlcek> |
Component: | Build | Assignee: | Joe Vlcek <jvlcek> |
Status: | CLOSED ERRATA | QA Contact: | Sean Myers <sean.myers> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 5.4.0 | CC: | drieden, jhardy, jrafanie, jvlcek, mpovolny, obarenbo, sean.myers, tcarlin |
Target Milestone: | GA | ||
Target Release: | 5.4.0 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2015-06-16 12:55:23 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Joe Vlcek
2015-03-25 22:56:53 UTC
New commit detected on manageiq/master: https://github.com/ManageIQ/manageiq/commit/e88aadbaa10119646e9b18735d1a8c055da730e9 commit e88aadbaa10119646e9b18735d1a8c055da730e9 Author: Joe VLcek <jvlcek> AuthorDate: Wed Mar 25 18:44:45 2015 -0400 Commit: Joe VLcek <jvlcek> CommitDate: Mon Mar 30 11:58:45 2015 -0400 Incorporate the iptable updates without overwriting installed version https://bugzilla.redhat.com/show_bug.cgi?id=1205920 https://bugzilla.redhat.com/show_bug.cgi?id=1202478 [skip ci] system/COPY/etc/sysconfig/iptables | 22 ---------------------- system/TEMPLATE/etc/sysconfig/iptables | 22 ++++++++++++++++++++++ system/cfme-setup.sh | 7 +++++++ 3 files changed, 29 insertions(+), 22 deletions(-) delete mode 100644 system/COPY/etc/sysconfig/iptables create mode 100644 system/TEMPLATE/etc/sysconfig/iptables Joe, as far as I can tell, /etc/sysconfig/iptables has been overwritten by system-config-firewall as explained in the bug report. I also don't see "/var/www/miq/system/TEMPLATE/etc/sysconfig/iptables" on the filesystem, as indicated in the referenced commit. Has that commit been superseded by something else, or do you have some insight on how I can verify this? Right now it looks like the system-config-firewall rules are still trumping. (In reply to Sean Myers from comment #5) > Joe, as far as I can tell, /etc/sysconfig/iptables has been overwritten by > system-config-firewall as explained in the bug report. I also don't see > "/var/www/miq/system/TEMPLATE/etc/sysconfig/iptables" on the filesystem, as > indicated in the referenced commit. > > Has that commit been superseded by something else, or do you have some > insight on how I can verify this? Right now it looks like the > system-config-firewall rules are still trumping. Sean, Yes a new solution has been implemented. Sorry this bug didn't get updated to indicate that. This commit supersedes the initial solution: https://github.com/ManageIQ/manageiq/commit/cf9f8924d68568e89595cd1156290069114ec878#diff-2dfb25f9c3c8b0ebb13f5329160ed71b I have two suggestions for confirming this: #1 - Confirm ports 5900:5999 are open. Start with" "grep ACCEPT /etc/sysconfig/iptables" and confirm that port range is listed. #2 - By verifying BZ: https://bugzilla.redhat.com/show_bug.cgi?id=1202478 which this BZ enables to work. Verified on 5.4.0.0.25.20150429111523_0455f87 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-1100.html |