Bug 692587

Summary: RFE: good idea to check for ip_forwading is enabled
Product: [Retired] CloudForms Cloud Engine Reporter: wes hayutin <whayutin>
Component: aeolus-conductorAssignee: Mo Morsi <mmorsi>
Status: CLOSED CURRENTRELEASE QA Contact: wes hayutin <whayutin>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 0.3.1CC: clalance, cpelland, deltacloud-maint, morazi
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-06-14 16:12:24 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description wes hayutin 2011-03-31 15:55:04 UTC
Description of problem:

due to https://bugzilla.redhat.com/show_bug.cgi?id=692558

its possible to have libvirt installed w/o ipforwarding enabled. Since we depend on it for builds now, its probably a good idea to check for it w/ the puppet scripts.


[root@dell-pe2950-01 ~]# cat /proc/sys/net/ipv4/ip_forward
1


found in..

root@dhcp231-29 ~]# rpm -qa | grep aeolus
aeolus-conductor-daemons-0.0.3-0.fc14.20110331142542gitfcf7990.x86_64
aeolus-configure-2.0.0-5.fc14.20110330155142gitecf8f95.noarch
aeolus-conductor-0.0.3-0.fc14.20110331142542gitfcf7990.x86_64
aeolus-conductor-doc-0.0.3-0.fc14.20110331142542gitfcf7990.x86_64
[root@dhcp231-29 ~]#

Comment 1 wes hayutin 2011-03-31 16:27:05 UTC
IMHO
we should bail out of the configure script if its not set to 1.  I doubt we want to configure that for a user.

Comment 2 Chris Lalancette 2011-03-31 20:12:41 UTC
While doing this check during configure time is not a bad idea, it unfortunately doesn't really prevent the issue.  Other process (NetworkManager comes to mind) can and do write to /proc/sys/net/ipv4/ip_forward of their own accord.  What could happen then is that we could check, everything could be fine, and then NetworkManager could come along and undo it.

This is unfortunately not something we can easily fix at our layer.  It is also unfortunately not something that is fixed in later libvirt (at least, not yet).  So we are sort of in a tough situation here.

Chris Lalancette

Comment 3 wes hayutin 2011-12-08 13:46:51 UTC
perm close