Clarify ACL-Rule Behaviour for TCP/UDP-Protocol without start- and endport
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
### Discussed in https://github.com/apache/cloudstack/discussions/13113
Originally posted by **mwaag** May 7, 2026
Hi,
we noticed cloudstack let you successfully define ACL-Ingress-Rules for TCP (and UDP) without setting a start- and endport.
Many of our users (even we) assumed, that it stands for 'all ports'. But instead the router keeps on blocking traffic.
(We didn't test this on UDP explicitly)
We know, we can workaround this with just setting start- and endports or use protocol: All
Is this expected behaviour or should this be handled as a bug?
(We probably would suggest to either restrict defining rules without setting start- and endports at all or treat this kind of rules as "all ports" - rule)
Tested Versions are:
4.18.2.4
4.20.3.0
コントリビューションガイド
調査の方向性
https://github.com/apache/cloudstack/discussions/13113 のリンク先の議論から始め、CloudStack 4.18.2.4 および 4.20.3.0 で報告されている挙動も確認してください。ソースファイルやテストは指定されていないため、開始ポートまたは終了ポートのない TCP および UDP ルールに対する ACL ingress の処理を特定してください。完了条件は、その挙動が明示的に定義され、制限されるか、すべてのポートを対象とするルールとして一貫して処理され、両方のプロトコルがカバーされていることです。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- networking
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100