Bug 1967132

Summary: [4.7] ipBlock ignoring all other cidr's apart from the last one specified
Product: OpenShift Container Platform Reporter: Dan Winship <danw>
Component: NetworkingAssignee: Dan Winship <danw>
Networking sub component: ovn-kubernetes QA Contact: huirwang
Status: CLOSED ERRATA Docs Contact:
Severity: high    
Priority: urgent CC: aconstan, andbartl, astoycos, bbennett, bjarolim, bverschu, danw, huirwang, openshift-bugs-escalate, zzhao
Version: 4.6   
Target Milestone: ---   
Target Release: 4.7.z   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Cause: ovn-kubernetes handled some NetworkPolicies with multiple ipBlocks incorrectly Consequence: The ipBlocks after the first one would be ignored, resulting in pods not being able to reach all of the IPs they were supposed to be able to reach. Fix: Fixed the code for generating OVN ACLs from kubernetes NetworkPolicies Result: Policies with multiple ipBlocks work correctly
Story Points: ---
Clone Of: 1953680 Environment:
Last Closed: 2021-08-17 12:12:09 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1953680    
Bug Blocks:    

Comment 5 errata-xmlrpc 2021-08-17 12:12:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.7.24 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:3032