)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"471fc52407c5d8bea06ea65f037ffd1ad83e982b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"aa21566f_d88bc14e","updated":"2026-06-03 12:30:16.000000000","message":"You have to address comments from other reviewers but I am generally ok with the idea of this proposal","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"7054b2359d744c41db0a3b01d3cfb4cbdd95a29c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"3a2d1646_a6a334bc","updated":"2026-06-24 08:44:08.000000000","message":"one last thing to address IMHO and LGTM for me then","commit_id":"d93a07b32a776f6f61c895a910d691492c249cff"}],"specs/2026.2/port-groups-for-security-group-rules.rst":[{"author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"change_message_id":"ace2ed7c451fb9c3f4e4e1ccd85eb88b536d27a8","unresolved":true,"context_lines":[{"line_number":25,"context_line":"Neutron security group rules currently support only:"},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"* A single port (e.g., port 80)"},{"line_number":28,"context_line":"* A continuous port range (e.g., ports 500-600)"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"To allow traffic on multiple non-contiguous ports (e.g., TCP ports 80, 443,"},{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"}],"source_content_type":"text/x-rst","patch_set":2,"id":"9543d5c9_9d04fda3","line":28,"range":{"start_line":28,"start_character":4,"end_line":28,"end_character":14},"updated":"2026-05-27 00:17:42.000000000","message":"nit: s/contiguous","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":25,"context_line":"Neutron security group rules currently support only:"},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"* A single port (e.g., port 80)"},{"line_number":28,"context_line":"* A continuous port range (e.g., ports 500-600)"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"To allow traffic on multiple non-contiguous ports (e.g., TCP ports 80, 443,"},{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bba363a0_e78d83cc","line":28,"range":{"start_line":28,"start_character":4,"end_line":28,"end_character":14},"in_reply_to":"9543d5c9_9d04fda3","updated":"2026-06-04 12:51:35.000000000","message":"Fixed in Patchset 3. Thank you for catching this.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3b454277_6ff93a6b","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"updated":"2026-05-13 12:10:43.000000000","message":"I have one consideration here. With your proposal we\u0027ll have just one SG rule but multiple \"SG port ranges\". I see no benefit in terms of number of registers.\n\nIf the problem is to represent all the port ranges associated to the same protocol or traffic type, that could be handled in the CLI, for example.\n\nTo be honest, I don\u0027t really see any improvement here. Actually, with your DB change, it will be needed to refactor the existing implementations for other mech drivers (ML2/OVS, for example).\n\nI see the performance improvement we can achieve in ML2/OVN, grouping the same traffic rule ports in one single ACL. But this could be done inside the Neutron API.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"365390671cab3faf8e031e14a101b8fa6b9a38b8","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a06dfded_180df081","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"0c5204b4_72be7a37","updated":"2026-06-04 11:27:19.000000000","message":"This spec was discussed during the last Neutron meeting [1].\n\nIt was agreed to have this `PortGroup` implementation.\n\n[1]https://meetings.opendev.org/meetings/networking/2026/networking.2026-06-02-13.00.log.html#l-54","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"8b37693d23ca48a5292762684f0b6ebb7c2755ec","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4e117bd4_5c7ade9d","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"3b454277_6ff93a6b","updated":"2026-05-14 10:15:56.000000000","message":"Thank you for the feedback.\n\nThe main value of this proposal is to reduce the number of security group rules users need to manage.\n\nFor example, allowing ports 80, 443, and 8080:\n- Current: Users manage 3 separate rules\n- Port Group: Users manage only 1 rule\n\nAdditionally, Port Groups can be reused across multiple security groups, providing further benefits when the same port combinations are needed in different contexts.\n\nRegarding your comment that \"that could be handled in the CLI\",\nI\u0027d like to clarify: Does it mean accepting comma-separated port lists (e.g., `--port 80,443,8080`) and automatically creating multiple security group rules?\n(If it is right, I think this should be added to both CLI and REST API for consistency.)\n\nI\u0027d appreciate your thoughts on this trade-off.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"change_message_id":"ace2ed7c451fb9c3f4e4e1ccd85eb88b536d27a8","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"855dfc74_aebfe3ce","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"4b43cbd7_04cf7bfc","updated":"2026-05-27 00:17:42.000000000","message":"I\u0027m having a hard time understanding the conversation here.\n\nRodolfo - based on the below comments, I\u0027m guessing you are Ok with the port-group concept for the API and DB table? But you want a SG \u0027list\u0027 operation to show all the ports. That kind-of implies you should be able to specify all the ports in a SG \u0027create\u0027 call.\n\nMaybe if you walked through an example of what the CLI would look like it would make sense. Thanks.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"effa0412467169063a6ec9f30731ee873164dd3e","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4b43cbd7_04cf7bfc","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"4e117bd4_5c7ade9d","updated":"2026-05-21 09:56:17.000000000","message":"No, what I\u0027m saying is that we can combine the `openstack security group rule list` depending on the protocol, direction, etc, and provide a single line with multiple ports.\n\nTo be honest, I would implement the OVN part but I would leave the Neutron DB change. If needed, if the problem is the user experience, I would try my suggestion, merging several related rules in one line.\n\nI would like other reviewers to think about this idea.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"0fcffdae878edfc79341c8e892939dfc4187ad2b","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"f558c274_d67ba5e7","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"855dfc74_aebfe3ce","updated":"2026-05-27 07:11:20.000000000","message":"I don\u0027t want any DB change related to this spec. The rationale behind this change is the user experience: it is hard to read the SG rules associated to a protocol and direction if several ports and port ranges are associated to it.\n\nSo my proposal is to aggregate it in the CLI. For example, in a SG with 4 rules related to (TCP,ingress,0.0.0.0/0), with multiple ports and ranges, this is the output: [1 first].\n\nThe idea is to group all these ports and ranges in the ouput: [1 second]. But this could be done by the CLI, keeping the Neutron DB untouched.\n\nThis proposal have a problem: the ID of the rule is not correct and cannot list the independent rules to delete them. To be honest, [1 first], ordering by \"Port Range\", something that can be done today, is good enough for me.\n\n[1]https://paste.opendev.org/show/bhTSGHX5kS9L8jXppqJW/","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"a3853263d7b59debd945378bfb9d76d1eabee71d","unresolved":false,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7187720f_9bb7392f","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"a06dfded_180df081","updated":"2026-06-04 12:55:10.000000000","message":"Thanks for the constructive discussion and reaching consensus on the approach.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"471fc52407c5d8bea06ea65f037ffd1ad83e982b","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"0c5204b4_72be7a37","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"abd9c197_a6e7b273","updated":"2026-06-03 12:30:16.000000000","message":"For me introducing new API resourse `PortGroup` as is proposed here is fine. This can be improvement of the user experience indeed. We already have very similar concept for IP Addresses (AddressGroup) so why not for ports.\nI don\u0027t think the goal of this spec is (and ever have been) to improve backend implementations. I see this proposal only as improvement for user experience.\nAnd I don\u0027t really think that this can be solved on the client side. As Brian alreadh mentioned, even if you could potentially improve how SGs are represented and combine some ports there, it will not solve the creation of many SG rules.\n\nNow lets imagine the case: there is openstack cloud on top of which users have k8s clusters installed. Cloud admin can define port group named e.g. \"kubernetes tcp ports\" where there will be defined all ports used by different parts of k8s, like e.g. 6643 (API Server), 10250 (kubelet API), etc.\nThat Port group can be then shared for all tenants and all tenants can use it in their own security groups.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"change_message_id":"17ab06bfcab8465e30488875dae101191dde36c4","unresolved":true,"context_lines":[{"line_number":31,"context_line":"and 500-600), users must create separate security group rules for each port"},{"line_number":32,"context_line":"or port range."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"This limitation results in:"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"* Increased number of security group rules to manage"},{"line_number":37,"context_line":"* More complex security group configurations"},{"line_number":38,"context_line":"* Difficulty in managing large-scale deployments with thousands of rules"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Use Cases"},{"line_number":41,"context_line":"---------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"abd9c197_a6e7b273","line":38,"range":{"start_line":34,"start_character":0,"end_line":38,"end_character":72},"in_reply_to":"f558c274_d67ba5e7","updated":"2026-05-28 03:51:27.000000000","message":"Ok, so I think I understand better, but what about SG rule create? Would we change create with multiple ports to create multiple rules but \u0027list\u0027 only shows one? That doesn\u0027t seem right, since how do we delete one port out of the list without the SG rule ID associated with it?\n\nUnless there is a new CLI option to compress the rules when listing?\n\nIt would be great to not change the DB at all, I just don\u0027t know how to do it yet.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":154,"context_line":"            \"direction\": \"ingress\","},{"line_number":155,"context_line":"            \"ethertype\": \"IPv4\","},{"line_number":156,"context_line":"            \"protocol\": \"tcp\","},{"line_number":157,"context_line":"            \"remote_port_group_id\": \"port-group-uuid\","},{"line_number":158,"context_line":"            \"security_group_id\": \"sg-uuid\""},{"line_number":159,"context_line":"        }"},{"line_number":160,"context_line":"    }"}],"source_content_type":"text/x-rst","patch_set":2,"id":"d049becf_102d3a56","line":157,"range":{"start_line":157,"start_character":13,"end_line":157,"end_character":33},"updated":"2026-05-13 12:10:43.000000000","message":"I would avoid the prefix `remote` here. This is just a `port_group`","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":154,"context_line":"            \"direction\": \"ingress\","},{"line_number":155,"context_line":"            \"ethertype\": \"IPv4\","},{"line_number":156,"context_line":"            \"protocol\": \"tcp\","},{"line_number":157,"context_line":"            \"remote_port_group_id\": \"port-group-uuid\","},{"line_number":158,"context_line":"            \"security_group_id\": \"sg-uuid\""},{"line_number":159,"context_line":"        }"},{"line_number":160,"context_line":"    }"}],"source_content_type":"text/x-rst","patch_set":2,"id":"1ab18f24_954a19bd","line":157,"range":{"start_line":157,"start_character":13,"end_line":157,"end_character":33},"in_reply_to":"c1d5d2ec_70986963","updated":"2026-06-04 12:51:35.000000000","message":"Renamed in Patchset3. Thank you.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"471fc52407c5d8bea06ea65f037ffd1ad83e982b","unresolved":true,"context_lines":[{"line_number":154,"context_line":"            \"direction\": \"ingress\","},{"line_number":155,"context_line":"            \"ethertype\": \"IPv4\","},{"line_number":156,"context_line":"            \"protocol\": \"tcp\","},{"line_number":157,"context_line":"            \"remote_port_group_id\": \"port-group-uuid\","},{"line_number":158,"context_line":"            \"security_group_id\": \"sg-uuid\""},{"line_number":159,"context_line":"        }"},{"line_number":160,"context_line":"    }"}],"source_content_type":"text/x-rst","patch_set":2,"id":"c1d5d2ec_70986963","line":157,"range":{"start_line":157,"start_character":13,"end_line":157,"end_character":33},"in_reply_to":"d049becf_102d3a56","updated":"2026-06-03 12:30:16.000000000","message":"+1","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":159,"context_line":"        }"},{"line_number":160,"context_line":"    }"},{"line_number":161,"context_line":""},{"line_number":162,"context_line":"DB Impact"},{"line_number":163,"context_line":"---------"},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"New Tables"}],"source_content_type":"text/x-rst","patch_set":2,"id":"564bfc32_b7a80d73","line":162,"range":{"start_line":162,"start_character":0,"end_line":162,"end_character":2},"updated":"2026-05-13 12:10:43.000000000","message":"Please use this example [1] to create this section.\n\n[1]https://github.com/openstack/neutron-specs/blob/master/specs/2023.2/configurable-default-sg-rules.rst#db-impact","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":159,"context_line":"        }"},{"line_number":160,"context_line":"    }"},{"line_number":161,"context_line":""},{"line_number":162,"context_line":"DB Impact"},{"line_number":163,"context_line":"---------"},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"New Tables"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a6c5e2d7_fdfc669d","line":162,"range":{"start_line":162,"start_character":0,"end_line":162,"end_character":2},"in_reply_to":"564bfc32_b7a80d73","updated":"2026-06-04 12:51:35.000000000","message":"Updated to table format as suggested in Patchset 3. Thanks.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":165,"context_line":"New Tables"},{"line_number":166,"context_line":"~~~~~~~~~~"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"* **port_groups**: Stores port group definitions"},{"line_number":169,"context_line":"* **port_associations**: Stores individual port_range_min / port_range_max entries for each port group"},{"line_number":170,"context_line":""},{"line_number":171,"context_line":"Schema Changes"}],"source_content_type":"text/x-rst","patch_set":2,"id":"1ce43d8b_d52abb8e","line":168,"range":{"start_line":168,"start_character":4,"end_line":168,"end_character":15},"updated":"2026-05-13 12:10:43.000000000","message":"I would require feedback from other reviewers. But if these tables are associated to the security groups, I would name both as:\n`security_groups_port_groups`\n`security_groups_port_ranges`\n\nThe `Port Group` is an OVN concept, we should avoid this ambiguity.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":165,"context_line":"New Tables"},{"line_number":166,"context_line":"~~~~~~~~~~"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"* **port_groups**: Stores port group definitions"},{"line_number":169,"context_line":"* **port_associations**: Stores individual port_range_min / port_range_max entries for each port group"},{"line_number":170,"context_line":""},{"line_number":171,"context_line":"Schema Changes"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4601b942_5b9fb0a1","line":168,"range":{"start_line":168,"start_character":4,"end_line":168,"end_character":15},"in_reply_to":"1ce43d8b_d52abb8e","updated":"2026-06-04 12:51:35.000000000","message":"Renamed to security_groups_port_groups and security_groups_port_ranges in Patchset 3.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":188,"context_line":""},{"line_number":189,"context_line":"* ``remote_port_group_id``: UUID (foreign key to port_groups, nullable)"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Backend Implementation"},{"line_number":192,"context_line":"----------------------"},{"line_number":193,"context_line":""},{"line_number":194,"context_line":"ML2/OVN Backend"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a28261f4_902e2c96","line":191,"range":{"start_line":191,"start_character":0,"end_line":191,"end_character":7},"updated":"2026-05-13 12:10:43.000000000","message":"Mechanism driver","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":188,"context_line":""},{"line_number":189,"context_line":"* ``remote_port_group_id``: UUID (foreign key to port_groups, nullable)"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Backend Implementation"},{"line_number":192,"context_line":"----------------------"},{"line_number":193,"context_line":""},{"line_number":194,"context_line":"ML2/OVN Backend"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a5dacdde_b75482fb","line":191,"range":{"start_line":191,"start_character":0,"end_line":191,"end_character":7},"in_reply_to":"a28261f4_902e2c96","updated":"2026-06-04 12:51:35.000000000","message":"Fixed in Patchset 3. Thanks.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":191,"context_line":"Backend Implementation"},{"line_number":192,"context_line":"----------------------"},{"line_number":193,"context_line":""},{"line_number":194,"context_line":"ML2/OVN Backend"},{"line_number":195,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":196,"context_line":""},{"line_number":197,"context_line":"For ML2/OVN backend, Port Groups will be translated to OVN ACL match"}],"source_content_type":"text/x-rst","patch_set":2,"id":"6845e4f5_7d9f5590","line":194,"range":{"start_line":194,"start_character":8,"end_line":194,"end_character":15},"updated":"2026-05-13 12:10:43.000000000","message":"mechanism driver","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":191,"context_line":"Backend Implementation"},{"line_number":192,"context_line":"----------------------"},{"line_number":193,"context_line":""},{"line_number":194,"context_line":"ML2/OVN Backend"},{"line_number":195,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":196,"context_line":""},{"line_number":197,"context_line":"For ML2/OVN backend, Port Groups will be translated to OVN ACL match"}],"source_content_type":"text/x-rst","patch_set":2,"id":"63cef4a3_1fbdf24a","line":194,"range":{"start_line":194,"start_character":8,"end_line":194,"end_character":15},"in_reply_to":"6845e4f5_7d9f5590","updated":"2026-06-04 12:51:35.000000000","message":"Fixed in Patchset 3. Thanks.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"f9a9a5a6ac5ac2451739d977b8d49517dc0b2f73","unresolved":true,"context_lines":[{"line_number":202,"context_line":""},{"line_number":203,"context_line":"This leverages the existing OVN ACL syntax capabilities."},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Other Backends (ML2/OVS, iptables)"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"For backends that do not support multiple ports in a single rule, the Port"}],"source_content_type":"text/x-rst","patch_set":2,"id":"34d70c3b_dac98217","line":205,"range":{"start_line":205,"start_character":25,"end_line":205,"end_character":33},"updated":"2026-05-13 12:10:43.000000000","message":"`iptables` is not a backend but a particular ML2/OVS firewall implementation. This should refer only to mechanism drivers.","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":36716,"name":"Kyuyeong Lee","display_name":"Kyuyeong Lee","email":"kyu0.lee@samsung.com","username":"kyu0"},"change_message_id":"0a77710d31980f636ba5e57d91c4bf1c8cce787b","unresolved":false,"context_lines":[{"line_number":202,"context_line":""},{"line_number":203,"context_line":"This leverages the existing OVN ACL syntax capabilities."},{"line_number":204,"context_line":""},{"line_number":205,"context_line":"Other Backends (ML2/OVS, iptables)"},{"line_number":206,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":207,"context_line":""},{"line_number":208,"context_line":"For backends that do not support multiple ports in a single rule, the Port"}],"source_content_type":"text/x-rst","patch_set":2,"id":"5d170ef7_d196af54","line":205,"range":{"start_line":205,"start_character":25,"end_line":205,"end_character":33},"in_reply_to":"34d70c3b_dac98217","updated":"2026-06-04 12:51:35.000000000","message":"Removed iptables reference in Patchset 3. Thanks","commit_id":"5e1ec3f22f690af54d17908f1f9ea98ff65b2d62"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"7054b2359d744c41db0a3b01d3cfb4cbdd95a29c","unresolved":true,"context_lines":[{"line_number":175,"context_line":"+------------------+---------+------+-------+---------------------------------------------------+"},{"line_number":176,"context_line":"| project_id       | String  | No   | CR    | Project ID that owns the port group.              |"},{"line_number":177,"context_line":"+------------------+---------+------+-------+---------------------------------------------------+"},{"line_number":178,"context_line":"| shared           | Boolean | No   | CRU   | Whether the port group is shared across project.  |"},{"line_number":179,"context_line":"+------------------+---------+------+-------+---------------------------------------------------+"},{"line_number":180,"context_line":"| standard_attr_id | Integer | Yes  | R     | ID of the associated standard attribute record.   |"},{"line_number":181,"context_line":"+------------------+---------+------+-------+---------------------------------------------------+"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c0529e28_5fd146cc","line":178,"updated":"2026-06-24 08:44:08.000000000","message":"instead of just adding ``shared`` flag here and allow to share port group with everyone or not at all, I think it would be better to use RBAC mechanism which we have in neutron and which is used for various resources like e.g. address_groups. You can see for example patch https://github.com/openstack/neutron/commit/8094b524f693180fe9f435ef0d1f23b6a44259ae to check how it is implemented","commit_id":"d93a07b32a776f6f61c895a910d691492c249cff"}]}
