]> review.fuel-infra Code Review - openstack-build/neutron-build.git/commit
Improve handling of security group updates
authorSalvatore Orlando <salv.orlando@gmail.com>
Thu, 19 Dec 2013 08:26:38 +0000 (00:26 -0800)
committerSalvatore Orlando <salv.orlando@gmail.com>
Sun, 9 Feb 2014 10:29:04 +0000 (02:29 -0800)
commit3046c4ae22b10f9e4fa83a47bfe089554d4a4681
tree465b2306c60349dc3042b7427a9853fb6f232002
parent6df373d9c09c1b4eb258027e052ad2a5acde4bc8
Improve handling of security group updates

Currently updates to security group rules or membership
are handled by immediately triggering a call to refresh_firewall.
This call is quite expensive, and it is often executed with a
very high frequency.

With this patch, the notification handler simply adds devices for
which the firewall should be refreshed to a set, which will then
be processed in another routine. The latter is supposed to
be called in the main agent loop.

This patch for 'provider updates' simply sets a flag for refreshing
the firewall for all devices.

In order to avoid breaking other agents leveraging the security
group RPC mixin, the reactive behaviour is still available, and is
still the default way of handling security group updates.

Partial-Bug: #1253993
Partially implements blueprint: neutron-tempest-parallel

Change-Id: I1574544734865506ff5383404516cc9349c16ec4
neutron/agent/securitygroups_rpc.py
neutron/plugins/openvswitch/agent/ovs_neutron_agent.py
neutron/tests/unit/openvswitch/test_ovs_neutron_agent.py
neutron/tests/unit/test_security_groups_rpc.py