wido commented on PR #14037: URL: https://github.com/apache/cloudstack/pull/14037#issuecomment-6020772166
@DaanHoogland done. I verified this PR with Claude Fable and ran the unit tests locally on the PR branch. Findings: - Both `/64` call sites are fixed. `SecurityGroupManagerImpl2` is the bean wired in Spring, so the second commit is the one that actually matters in production. Good catch @weizhouapache. - The KVM agent passes the CIDR unchanged to `ip6tables -s`, and Python's `ip_network(cidr, False)` silently masks `2001:db8::5/64` to the whole `/64`. With `/128` it is exactly one host. XenServer drops all IPv6 in ebtables, so KVM is the only affected hypervisor. - The new tests pass. I also reverted both lines to `/64` and reran them, both fail as expected, so they really guard the fix. - The `/64` came in with #11243 and shipped in 4.20.2.0 onwards. It is on the 4.19 branch as well but no 4.19 release contains it. Not tested on a live KVM host, the Trillian run covers that. LGTM. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
