| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-cyborg - 2026-06-23 | |||
| 14:16:14 | sean-k-mooney | so this is more or less just paperwork and markign it implemented | |
| 14:16:29 | sean-k-mooney | it was added in 2023.2 | |
| 14:16:45 | sean-k-mooney | the reason i call thi sout is i think we still could do with more tempest testing of this | |
| 14:17:08 | sean-k-mooney | so we may decied to file a tracker bug for the tempst plugin | |
| 14:17:30 | sean-k-mooney | but for all practical cases this is done so i appoved https://review.opendev.org/c/openstack/cyborg-specs/+/896076 to reflect that | |
| 14:18:07 | sean-k-mooney | i think we can move on to reviews | |
| 14:18:52 | sean-k-mooney | #topic reviews | |
| 14:19:01 | sean-k-mooney | ok first one consistent and secure RBAC spec for Cyborg | |
| 14:19:09 | sean-k-mooney | #link https://blueprints.launchpad.net/openstack-cyborg/+spec/consistent-and-secure-rbac | |
| 14:19:15 | sean-k-mooney | #link https://review.opendev.org/q/topic:%22bp/consistent-and-secure-rbac%22 | |
| 14:19:34 | sean-k-mooney | chandankumar: and jgilaber: have reviewd the spec so i approved it to merge this morning | |
| 14:20:00 | sean-k-mooney | i have a complete impleaiton aviable and im hoping to merge that in the next 1-2 weeks. | |
| 14:20:16 | sean-k-mooney | obviously spec freeze has precedence so we should focus on those | |
| 14:20:35 | sean-k-mooney | but if you have extra review bandwith feedback is welcome | |
| 14:21:20 | sean-k-mooney | any questions on the topic of SRBAC that anyone want to ask now? | |
| 14:21:24 | jgilaber | I hope to start reviewing this series this week | |
| 14:22:01 | sean-k-mooney | i kicked of my review ci on it overnight | |
| 14:22:13 | sean-k-mooney | im gogn to go though and triage its fineidng later in the week | |
| 14:22:16 | sean-k-mooney | proably firday | |
| 14:22:25 | opendevreview | Merged openstack/cyborg-specs master: move attribute spec to impletment https://review.opendev.org/c/openstack/cyborg-specs/+/896076 | |
| 14:22:26 | sean-k-mooney | so ill also look at any other feedback | |
| 14:22:41 | sean-k-mooney | i expect at leat one revison in the next week | |
| 14:22:59 | sean-k-mooney | while i belive its mergable as is im sure there are things that can be impvoed | |
| 14:23:13 | sean-k-mooney | one thing ill call out | |
| 14:23:15 | sean-k-mooney | https://review.opendev.org/c/openstack/cyborg/+/992722 | |
| 14:23:34 | sean-k-mooney | the first patch is baisclly dead code removal and a minor bug fix | |
| 14:23:52 | sean-k-mooney | so i pulled that out to the front | |
| 14:24:54 | sean-k-mooney | the rest is the actual srbac implementation | |
| 14:25:09 | sean-k-mooney | i think we can move on ? | |
| 14:25:32 | sean-k-mooney | #topic Add generic NVMe driver spec with secure cleanup | |
| 14:25:36 | sean-k-mooney | #link https://review.opendev.org/c/openstack/cyborg-specs/+/985349/14/specs/2026.2/approved/generic-nvme-driver-with-secure-cleanup.rst | |
| 14:25:57 | sean-k-mooney | this is chandans feature. i hope to do another pass on that on thrusday | |
| 14:26:05 | sean-k-mooney | chandankumar: anything you want to raise on this topic? | |
| 14:26:44 | sean-k-mooney | chandankumar: i dont think you have updated this with the dicussion we had yestready correct? | |
| 14:26:49 | chandankumar | nope, I hope to finish the cleanup rewrite with clear_mode and clear_method by today | |
| 14:27:21 | sean-k-mooney | ack | |
| 14:27:44 | sean-k-mooney | i guess if there are no questions we can move on | |
| 14:27:55 | sean-k-mooney | #topic generic mdev driver | |
| 14:27:59 | sean-k-mooney | #link https://review.opendev.org/c/openstack/cyborg-specs/+/982276 | |
| 14:28:13 | sean-k-mooney | jgilaber: anythign you want to rasie on your spec? | |
| 14:28:24 | sean-k-mooney | im hoping to review that tomorow if its ready for review? | |
| 14:28:43 | opendevreview | chandan kumar proposed openstack/cyborg-specs master: Add generic NVMe driver spec with secure cleanup https://review.opendev.org/c/openstack/cyborg-specs/+/985349 | |
| 14:28:54 | jgilaber | nothing to raise, I think I addressed all comments | |
| 14:29:07 | chandankumar | Ok I have updated it here, But a one more pass on my side before asking for review | |
| 14:29:21 | jgilaber | the only point left I think is how to handle the multiple mdev types with placement | |
| 14:29:34 | sean-k-mooney | ack anythin you want to call out on the nova side? | |
| 14:30:16 | jgilaber | on the nova side the mtty series is close to merge I think | |
| 14:30:20 | jgilaber | it's working well in CI | |
| 14:30:29 | jgilaber | and I pushed a patch for the OWNER_NOVA trait | |
| 14:30:32 | jgilaber | #link https://review.opendev.org/c/openstack/nova/+/994299 | |
| 14:30:54 | jgilaber | on the last one I'm still working on the tests, but hopefully will be ready for review by the end of the week | |
| 14:31:06 | sean-k-mooney | our initall plan was to reused that for the cyborg ci. we may want to revaluate if we will instead port mdev supprot into the pci sim | |
| 14:31:17 | sean-k-mooney | but i think we choudl continue with the inial plan for now | |
| 14:31:49 | sean-k-mooney | ack ill add the owner trait patch to my review list | |
| 14:32:42 | jgilaber | yes, we can evaluate once I'm done with the nova part if we want to use pci sim, but for now using the nova devstack plugin should work and be easy to use | |
| 14:32:52 | sean-k-mooney | we may need to think about the upgrade impact of https://review.opendev.org/c/openstack/nova/+/994299/2/nova/compute/pci_placement_translator.py | |
| 14:33:09 | sean-k-mooney | that likely need to be gated behind a min compute service version check | |
| 14:33:24 | sean-k-mooney | well no | |
| 14:33:28 | sean-k-mooney | that where your addign the trait | |
| 14:33:32 | sean-k-mooney | that proably fine | |
| 14:33:35 | jgilaber | the pre filter is behind a service check | |
| 14:33:51 | jgilaber | adding the trait should be fine I think since it would not prevent any allocation | |
| 14:33:56 | sean-k-mooney | ah yes https://review.opendev.org/c/openstack/nova/+/994299/2/nova/scheduler/request_filter.py | |
| 14:34:36 | sean-k-mooney | ok ill do a proper review later | |
| 14:34:57 | jgilaber | ack, thanks | |
| 14:34:58 | sean-k-mooney | for the prefilter i think we want to add @functools.cache to the min version check | |
| 14:35:31 | sean-k-mooney | an all cell scatter gather on ever schdule is expensive | |
| 14:35:40 | sean-k-mooney | but we can do it once per scdhuler restart | |
| 14:36:01 | sean-k-mooney | we woudl just need to document that in the upgrade release note | |
| 14:36:13 | sean-k-mooney | i.e. that a schduler restart is needed after all compute are upgraded | |
| 14:36:19 | sean-k-mooney | but that kind of needed anyway for other easons | |
| 14:37:00 | sean-k-mooney | im not conviced the prefilter is correct by the way | |
| 14:37:02 | jgilaber | ack, I think I'll need to update the release note for that | |
| 14:37:10 | sean-k-mooney | we can go into this in more detail in teh review | |
| 14:37:16 | jgilaber | sure | |
| 14:37:25 | sean-k-mooney | effectivly you will ned to include the triat request in the request group | |
| 14:37:30 | sean-k-mooney | not just root reqiures | |
| 14:37:47 | sean-k-mooney | but ya lets move to bugs unless there are other questions? | |
| 14:38:11 | sean-k-mooney | melwitt: ^ might be good to get your input on too | |
| 14:38:59 | sean-k-mooney | #topic bugs | |
| 14:39:11 | sean-k-mooney | first one | |
| 14:39:17 | sean-k-mooney | #link https://bugs.launchpad.net/openstack-cyborg/+bug/2157586 | |
| 14:39:22 | sean-k-mooney | Cyborg Device Profile API rejects OWNER_CYBORG trait | |
| 14:39:46 | sean-k-mooney | this came up while reviewing chandands spec i belvie | |
| 14:39:56 | sean-k-mooney | chandankumar: do you want to expand on it | |
| 14:40:23 | chandankumar | it came from here https://review.opendev.org/c/openstack/cyborg-tempest-plugin/+/992210/4//COMMIT_MSG | |
| 14:40:33 | sean-k-mooney | oh yes your right | |
| 14:40:46 | chandankumar | I was adding scenario test for pci driver to create device profile there I found that | |
| 14:40:57 | sean-k-mooney | so the tl;dr is | |
| 14:41:02 | sean-k-mooney | cybrog device profiles | |
| 14:41:10 | sean-k-mooney | cannot currently request any standard traits | |
| 14:41:26 | sean-k-mooney | such as OWNER_CYBORG | |
| 14:41:50 | sean-k-mooney | this is a limitation that we should adress | |
| 14:41:57 | chandankumar | https://github.com/openstack/cyborg/blob/master/cyborg/api/controllers/v2/device_profiles.py#L211 | |
| 14:42:40 | sean-k-mooney | https://docs.openstack.org/api-ref/accelerator/#create-device-profile | |
| 14:42:47 | sean-k-mooney | if we look at the api ref | |
| 14:43:01 | sean-k-mooney | this is the descripton of the group field | |
| 14:43:05 | sean-k-mooney | """This is a list of dictionaries to describe returned accelerator resource by users, where users use keys to describe the resource_classes or traits and values to indicate its quantity or property. This is intentionally similar to extra_specs in nova flavor, and uses the same keywords for resources and traits. The key-value pair can either be a resource/trait or a Cyborg | |
| 14:43:07 | sean-k-mooney | property. Cyborg property is of the form “accel:<key>”: “<value>”. The valid key-value pairs can be found below.""" | |
| 14:43:41 | sean-k-mooney | the grousp is a dict of string key to string value | |