Skip to content

server: scope IPv6 security group member rules to the exact host - #14037

Open
nagaboinaramgopal wants to merge 1 commit into
apache:mainfrom
nagaboinaramgopal:fix/secgroup-ipv6-host-cidr
Open

server: scope IPv6 security group member rules to the exact host#14037
nagaboinaramgopal wants to merge 1 commit into
apache:mainfrom
nagaboinaramgopal:fix/secgroup-ipv6-host-cidr

Conversation

@nagaboinaramgopal

Copy link
Copy Markdown

Description

When a security group rule references another security group, each member VM
should be authorized as an exact host. The IPv4 address is correctly pinned to a
/32, but the IPv6 address was expanded to /64, opening the whole subnet the
member sits in rather than just that member. This silently broadens the rule to
every address in the member's /64.

Pin the IPv6 member to /128 to match the IPv4 behaviour.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)

Feature/Enhancement Scale or Bug Severity

Bug Severity

  • Minor

How Has This Been Tested?

Added a unit test asserting an IPv6 security-group member is authorized as a /128
host and not the whole /64. Also built the standard packages and deployed on a KVM
advanced zone.

When a security group rule references another security group, each member VM
should be authorized as an exact host. The IPv4 address is correctly pinned to
a /32, but the IPv6 address was expanded to /64, opening the whole subnet the
member sits in rather than just that member. Pin the IPv6 member to /128 to
match the IPv4 behaviour.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant