)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"e9aa0268b3e5f4f4a97ff12d6c02087ffb85666e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"cd21d2c2_af14af46","updated":"2026-07-24 10:48:01.000000000","message":"The spec looks OK. -1 just for visibility, questions inline.","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"7c1c94de1f89e4c259bf2e5cc45c1889ccc3b183","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"511394ab_774b1bb7","updated":"2026-07-30 11:04:03.000000000","message":"All the issues and questions that I raised are answered.","commit_id":"465be3f94c96845575d43bdfcbb8636b22603345"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"958273349d4e89c53034ec3ec8a1d6680d675626","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"c1bc9409_60b63eb3","updated":"2026-07-31 14:58:49.000000000","message":"thanks, finally I got back to this spec","commit_id":"465be3f94c96845575d43bdfcbb8636b22603345"}],"specs/2026.2/indirect-floating-ip-router-selection.rst":[{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"f6185f78859cf18f5fb19eba3f37253bc8143d13","unresolved":true,"context_lines":[{"line_number":296,"context_line":"   * - Change static routes on transit routers"},{"line_number":297,"context_line":"     - N/A"},{"line_number":298,"context_line":"     - **Not validated**"},{"line_number":299,"context_line":""},{"line_number":300,"context_line":"This has to be documented in the release notes and admin guide."},{"line_number":301,"context_line":""},{"line_number":302,"context_line":""},{"line_number":303,"context_line":"Alternatives Considered"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c03c9e40_b83ed55f","line":300,"range":{"start_line":299,"start_character":0,"end_line":300,"end_character":63},"updated":"2026-07-09 12:40:43.000000000","message":"+1, this can be something to be used for shooting someone in the foot","commit_id":"2f016abf2b82aaba89eca2f72917213be30ee176"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"f6185f78859cf18f5fb19eba3f37253bc8143d13","unresolved":true,"context_lines":[{"line_number":386,"context_line":"**Cons:**"},{"line_number":387,"context_line":""},{"line_number":388,"context_line":"* **Router discovery problem** — from an inner port alone, finding the"},{"line_number":389,"context_line":"  relevant router may require scanning many routers. "},{"line_number":390,"context_line":"* Poor fit for the two-hop transit topology (routes use IP nexthops, not"},{"line_number":391,"context_line":"  router adjacency)."},{"line_number":392,"context_line":"* Worst-case performance without careful indexing."}],"source_content_type":"text/x-rst","patch_set":1,"id":"3a868e61_5e13b436","line":389,"range":{"start_line":389,"start_character":52,"end_line":389,"end_character":53},"updated":"2026-07-09 12:40:43.000000000","message":"nit: extra space","commit_id":"2f016abf2b82aaba89eca2f72917213be30ee176"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"1948d44cb1df0839fd74b44c35e5ba39b90e03b9","unresolved":false,"context_lines":[{"line_number":386,"context_line":"**Cons:**"},{"line_number":387,"context_line":""},{"line_number":388,"context_line":"* **Router discovery problem** — from an inner port alone, finding the"},{"line_number":389,"context_line":"  relevant router may require scanning many routers. "},{"line_number":390,"context_line":"* Poor fit for the two-hop transit topology (routes use IP nexthops, not"},{"line_number":391,"context_line":"  router adjacency)."},{"line_number":392,"context_line":"* Worst-case performance without careful indexing."}],"source_content_type":"text/x-rst","patch_set":1,"id":"ebb4099a_b60c5896","line":389,"range":{"start_line":389,"start_character":52,"end_line":389,"end_character":53},"in_reply_to":"3a868e61_5e13b436","updated":"2026-07-10 09:07:40.000000000","message":"Done","commit_id":"2f016abf2b82aaba89eca2f72917213be30ee176"},{"author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"change_message_id":"f6185f78859cf18f5fb19eba3f37253bc8143d13","unresolved":true,"context_lines":[{"line_number":400,"context_line":"exists."},{"line_number":401,"context_line":""},{"line_number":402,"context_line":""},{"line_number":403,"context_line":"Security Impact"},{"line_number":404,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":405,"context_line":""},{"line_number":406,"context_line":"* Writable ``router_id`` is gated by new Oslo policy rules:"},{"line_number":407,"context_line":""},{"line_number":408,"context_line":"  * ``create_floatingip:router_id`` — project member or admin (default)."},{"line_number":409,"context_line":"  * ``update_floatingip:router_id`` — project member or admin (default)."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"* By default, project members may set ``router_id`` only to routers visible"},{"line_number":412,"context_line":"  to their project."},{"line_number":413,"context_line":"* Allowing indirect FIPs does not bypass port or network RBAC; it only"},{"line_number":414,"context_line":"  relaxes which router may host NAT for an already-authorized port"},{"line_number":415,"context_line":"  association."},{"line_number":416,"context_line":"* Misconfiguration (wrong ``router_id``) creates a FIP that appears ACTIVE"},{"line_number":417,"context_line":"  but does not forward traffic — an operational risk, not a tenancy bypass."},{"line_number":418,"context_line":""},{"line_number":419,"context_line":""},{"line_number":420,"context_line":"Performance Impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"d7e6414e_095e1e12","line":417,"range":{"start_line":403,"start_character":0,"end_line":417,"end_character":75},"updated":"2026-07-09 12:40:43.000000000","message":"thanks for collecting these","commit_id":"2f016abf2b82aaba89eca2f72917213be30ee176"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"1948d44cb1df0839fd74b44c35e5ba39b90e03b9","unresolved":true,"context_lines":[{"line_number":400,"context_line":"exists."},{"line_number":401,"context_line":""},{"line_number":402,"context_line":""},{"line_number":403,"context_line":"Security Impact"},{"line_number":404,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":405,"context_line":""},{"line_number":406,"context_line":"* Writable ``router_id`` is gated by new Oslo policy rules:"},{"line_number":407,"context_line":""},{"line_number":408,"context_line":"  * ``create_floatingip:router_id`` — project member or admin (default)."},{"line_number":409,"context_line":"  * ``update_floatingip:router_id`` — project member or admin (default)."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"* By default, project members may set ``router_id`` only to routers visible"},{"line_number":412,"context_line":"  to their project."},{"line_number":413,"context_line":"* Allowing indirect FIPs does not bypass port or network RBAC; it only"},{"line_number":414,"context_line":"  relaxes which router may host NAT for an already-authorized port"},{"line_number":415,"context_line":"  association."},{"line_number":416,"context_line":"* Misconfiguration (wrong ``router_id``) creates a FIP that appears ACTIVE"},{"line_number":417,"context_line":"  but does not forward traffic — an operational risk, not a tenancy bypass."},{"line_number":418,"context_line":""},{"line_number":419,"context_line":""},{"line_number":420,"context_line":"Performance Impact"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c132adf7_00aaba9e","line":417,"range":{"start_line":403,"start_character":0,"end_line":417,"end_character":75},"in_reply_to":"d7e6414e_095e1e12","updated":"2026-07-10 09:07:40.000000000","message":"It was actually LLM who initially put it here. I just validated and \"approved\" it 😉","commit_id":"2f016abf2b82aaba89eca2f72917213be30ee176"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"e9aa0268b3e5f4f4a97ff12d6c02087ffb85666e","unresolved":true,"context_lines":[{"line_number":60,"context_line":"which is stricter than what the datapath requires."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Use cases"},{"line_number":64,"context_line":"---------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"Gateway VM with static routes"}],"source_content_type":"text/x-rst","patch_set":2,"id":"87da60e9_31ec8c16","line":63,"range":{"start_line":63,"start_character":0,"end_line":63,"end_character":9},"updated":"2026-07-24 10:48:01.000000000","message":"So, if I\u0027m not wrong, what you propose is two architectures:\n* Connecting the inner private network with the external network with *external* resources (for example, a router VM).\n* Nested Neutron/OVN routers.\n\nIn both cases, it would be able to have inner private \u003c--\u003e external FIP (NAT), right?","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"e9c1084e37e3f747bad173ca00672a722205b45a","unresolved":false,"context_lines":[{"line_number":60,"context_line":"which is stricter than what the datapath requires."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"Use cases"},{"line_number":64,"context_line":"---------"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"Gateway VM with static routes"}],"source_content_type":"text/x-rst","patch_set":2,"id":"f71d7429_2ee5187f","line":63,"range":{"start_line":63,"start_character":0,"end_line":63,"end_character":9},"in_reply_to":"87da60e9_31ec8c16","updated":"2026-07-27 12:39:36.000000000","message":"yes, the solution proposed in this spec should works for both those cases in the same way","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"e9aa0268b3e5f4f4a97ff12d6c02087ffb85666e","unresolved":true,"context_lines":[{"line_number":235,"context_line":"  must SNAT traffic from subnets not directly connected ([927560]_) - to"},{"line_number":236,"context_line":"  make sure this is true, Neutron `ovn-router` service plugin may load new api"},{"line_number":237,"context_line":"  extension `floating-ip-router-writable` only when ``ovn_router_indirect_snat``"},{"line_number":238,"context_line":"  is set to ``True``. We may also consider deprecating ``ovn_router_indirect_snat``"},{"line_number":239,"context_line":"  in favor of new config option named ``ovn_router_indirect_nat`` which would"},{"line_number":240,"context_line":"  cover both SNAT and DNAT (FIP) cases."},{"line_number":241,"context_line":"* **OVN version:** OVN build including the [FDP-744]_ fix where catch-all"}],"source_content_type":"text/x-rst","patch_set":2,"id":"aeac46ec_b4d0db8b","line":238,"range":{"start_line":238,"start_character":22,"end_line":238,"end_character":83},"updated":"2026-07-24 10:48:01.000000000","message":"nit: this is already deprecated","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"e9c1084e37e3f747bad173ca00672a722205b45a","unresolved":false,"context_lines":[{"line_number":235,"context_line":"  must SNAT traffic from subnets not directly connected ([927560]_) - to"},{"line_number":236,"context_line":"  make sure this is true, Neutron `ovn-router` service plugin may load new api"},{"line_number":237,"context_line":"  extension `floating-ip-router-writable` only when ``ovn_router_indirect_snat``"},{"line_number":238,"context_line":"  is set to ``True``. We may also consider deprecating ``ovn_router_indirect_snat``"},{"line_number":239,"context_line":"  in favor of new config option named ``ovn_router_indirect_nat`` which would"},{"line_number":240,"context_line":"  cover both SNAT and DNAT (FIP) cases."},{"line_number":241,"context_line":"* **OVN version:** OVN build including the [FDP-744]_ fix where catch-all"}],"source_content_type":"text/x-rst","patch_set":2,"id":"07f8920e_ddaae0e5","line":238,"range":{"start_line":238,"start_character":22,"end_line":238,"end_character":83},"in_reply_to":"aeac46ec_b4d0db8b","updated":"2026-07-27 12:39:36.000000000","message":"done","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"e9aa0268b3e5f4f4a97ff12d6c02087ffb85666e","unresolved":true,"context_lines":[{"line_number":366,"context_line":"  that subnet also appears in the adjacency graph."},{"line_number":367,"context_line":""},{"line_number":368,"context_line":""},{"line_number":369,"context_line":"Alternative 2: Static route-based validation"},{"line_number":370,"context_line":"--------------------------------------------"},{"line_number":371,"context_line":""},{"line_number":372,"context_line":"This is original proposal from [LP#2072505]_."}],"source_content_type":"text/x-rst","patch_set":2,"id":"f86a171b_0d2b03f3","line":369,"range":{"start_line":369,"start_character":0,"end_line":369,"end_character":2},"updated":"2026-07-24 10:48:01.000000000","message":"I assume that the `Proposed Change` does not make this validation. But, and please correct me if I\u0027m wrong, if we create a NAT register linking a inner IP with a external IP (FIP), OVN will SNAT this traffic always, regardless if the inner IP is connected or not to a router or if this inner IP has the correct routes.","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"b3f926476dc1012bc6f4b4b471750227a382f8ae","unresolved":false,"context_lines":[{"line_number":366,"context_line":"  that subnet also appears in the adjacency graph."},{"line_number":367,"context_line":""},{"line_number":368,"context_line":""},{"line_number":369,"context_line":"Alternative 2: Static route-based validation"},{"line_number":370,"context_line":"--------------------------------------------"},{"line_number":371,"context_line":""},{"line_number":372,"context_line":"This is original proposal from [LP#2072505]_."}],"source_content_type":"text/x-rst","patch_set":2,"id":"ebbedf75_1bb2757b","line":369,"range":{"start_line":369,"start_character":0,"end_line":369,"end_character":2},"in_reply_to":"1c47ed91_d7eca62e","updated":"2026-07-29 13:29:59.000000000","message":"Done","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"5f4b44d14bf5aeef871d0bb97e7a41db78d56c4e","unresolved":true,"context_lines":[{"line_number":366,"context_line":"  that subnet also appears in the adjacency graph."},{"line_number":367,"context_line":""},{"line_number":368,"context_line":""},{"line_number":369,"context_line":"Alternative 2: Static route-based validation"},{"line_number":370,"context_line":"--------------------------------------------"},{"line_number":371,"context_line":""},{"line_number":372,"context_line":"This is original proposal from [LP#2072505]_."}],"source_content_type":"text/x-rst","patch_set":2,"id":"1c47ed91_d7eca62e","line":369,"range":{"start_line":369,"start_character":0,"end_line":369,"end_character":2},"in_reply_to":"d4c5e416_72ea7b6a","updated":"2026-07-27 14:18:24.000000000","message":"For the VM-in-the-middle case, I also want to add the following. Checking with Claude, it told me that the DNAT is done in the external router pipeline. So if the traffic reaches the external router, the DNAT will work:\n```\npublic (external)\n  |\next-router (LR, DGP to public, LRP on outer-net, dnat_and_snat for FIP)\n  |\nouter-net (LS)\n  |\ngateway-VM (forwarding VM, ports on outer-net + inner-net)\n  |\ninner-net (LS)\n  |\nworker-VM (inner IP, FIP target)\n```\n\nBut there is an important limitation: it is not possible to have distributed FIP. The traffic of the gateway-VM (that doesn\u0027t have a distributed FIP associated), will use the ext-router pipeline in the GW node. That means `is_chassis_resident` (for distributed FIP) check will fail. In this configuration is not possible to use distributed FIP","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"e9c1084e37e3f747bad173ca00672a722205b45a","unresolved":true,"context_lines":[{"line_number":366,"context_line":"  that subnet also appears in the adjacency graph."},{"line_number":367,"context_line":""},{"line_number":368,"context_line":""},{"line_number":369,"context_line":"Alternative 2: Static route-based validation"},{"line_number":370,"context_line":"--------------------------------------------"},{"line_number":371,"context_line":""},{"line_number":372,"context_line":"This is original proposal from [LP#2072505]_."}],"source_content_type":"text/x-rst","patch_set":2,"id":"d4c5e416_72ea7b6a","line":369,"range":{"start_line":369,"start_character":0,"end_line":369,"end_character":2},"in_reply_to":"f86a171b_0d2b03f3","updated":"2026-07-27 12:39:36.000000000","message":"so far I\u0027ve only checked the case with additional router in the middle as this was our \"main\" use case downstream. I think it should works but I will for sure check also the case with a VM in the middle. If that won\u0027t work we will need to document that use case as not supported probably, at least in the initial version of this feature.","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"change_message_id":"4626e6e3863e84b9a10de8f739f97dbc87871413","unresolved":true,"context_lines":[{"line_number":456,"context_line":"  - Two-router transit topology (analogous to ext-router /"},{"line_number":457,"context_line":"    internal-router lab setup)."},{"line_number":458,"context_line":"  - Negative: gateway router without external network on FIP\u0027s network."},{"line_number":459,"context_line":"  - Negative: strict mode without ``router_id`` still returns 404."},{"line_number":460,"context_line":""},{"line_number":461,"context_line":"* Document ML2/OVS/DVR test gaps or exclusions explicitly in test suite"},{"line_number":462,"context_line":"  configuration."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7caf9dfa_23dee241","line":459,"updated":"2026-07-10 13:34:27.000000000","message":"Just something I thought about during discussion - should test that a VM on an isolated network (no router) does not work, it might already be covered.","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"e9c1084e37e3f747bad173ca00672a722205b45a","unresolved":false,"context_lines":[{"line_number":456,"context_line":"  - Two-router transit topology (analogous to ext-router /"},{"line_number":457,"context_line":"    internal-router lab setup)."},{"line_number":458,"context_line":"  - Negative: gateway router without external network on FIP\u0027s network."},{"line_number":459,"context_line":"  - Negative: strict mode without ``router_id`` still returns 404."},{"line_number":460,"context_line":""},{"line_number":461,"context_line":"* Document ML2/OVS/DVR test gaps or exclusions explicitly in test suite"},{"line_number":462,"context_line":"  configuration."}],"source_content_type":"text/x-rst","patch_set":2,"id":"a778c6f3_6cf74382","line":459,"in_reply_to":"7caf9dfa_23dee241","updated":"2026-07-27 12:39:36.000000000","message":"Done","commit_id":"e643293284569a80bc421822d2385e4065b3a8f4"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"7c1c94de1f89e4c259bf2e5cc45c1889ccc3b183","unresolved":false,"context_lines":[{"line_number":262,"context_line":"configuration: the gateway VM\u0027s traffic (without a distributed FIP of its"},{"line_number":263,"context_line":"own) traverses the ext-router pipeline on the gateway chassis node, so the"},{"line_number":264,"context_line":"``is_chassis_resident`` check used for distributed FIP will fail. Indirect"},{"line_number":265,"context_line":"FIPs in the gateway-VM topology therefore operate in **centralised mode"},{"line_number":266,"context_line":"only**."},{"line_number":267,"context_line":"This limitation will have to be well documented."},{"line_number":268,"context_line":""},{"line_number":269,"context_line":"ML2/OVS without DVR"}],"source_content_type":"text/x-rst","patch_set":4,"id":"930dd801_1668bd8b","line":266,"range":{"start_line":265,"start_character":0,"end_line":266,"end_character":7},"updated":"2026-07-30 11:04:03.000000000","message":"+1","commit_id":"465be3f94c96845575d43bdfcbb8636b22603345"}]}
