| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2017-08-03 | |||
| 18:11:06 | mriedem | well i see that here https://review.openstack.org/#/c/391113/13/nova/api/openstack/compute/server_groups.py | |
| 18:11:13 | mriedem | it was doing context.can(sg_policies.BASE_POLICY_NAME) | |
| 18:11:21 | edmondsw | originally there was only rule:os_compute_api:os-server-groups and for backward compat we wanted whatever someone had for that to still be what they got if they used the new rules | |
| 18:11:25 | mriedem | and the rule for that was | |
| 18:11:26 | mriedem | check_str=base.RULE_ADMIN_OR_OWNER), | |
| 18:11:26 | mriedem | name=BASE_POLICY_NAME, | |
| 18:11:26 | mriedem | policy.RuleDefault( | |
| 18:11:49 | mriedem | it was using rule:admin_or_owner before | |
| 18:11:58 | mriedem | i don't see where rule:os_compute_api:os-server-groups came from | |
| 18:13:49 | edmondsw | tat is rule:os_compute_api:os-server-groups that you just pasted | |
| 18:14:21 | edmondsw | BASE_POLICY_NAME = os_compute_api:os-server-groups | |
| 18:14:44 | edmondsw | so in order for the the new rules to default to whatever you have set for that old rule, we pointed them to the old rule... rule:os_compute_api:os-server-groups | |
| 18:14:49 | edmondsw | mriedem make sense? | |
| 18:15:08 | edmondsw | backward compat and policy are a nightmare... | |
| 18:15:19 | edmondsw | one of the things we want to talk about fixing at the PTG | |
| 18:18:06 | mriedem | so context.can(sg_policies.BASE_POLICY_NAME) turns that into rule:os_compute_api:os-server-groups ? | |
| 18:18:09 | mriedem | in oslo.context? | |
| 18:18:12 | mriedem | or oslo.policy | |
| 18:18:39 | mriedem | isn't context.can just looking up the action? | |
| 18:18:44 | mriedem | which was os_compute_api:os-server-groups | |
| 18:18:51 | mriedem | and in the before times, that mapped to rule:admin_or_owner | |
| 18:18:53 | mriedem | not rule:os_compute_api:os-server-groups | |
| 18:19:33 | mriedem | dansmith: i left some random thoughts in your cells v2 docs patch | |
| 18:19:43 | mriedem | fighting with over/under doc'ing | |
| 18:20:04 | mriedem | edmondsw: yeah here https://docs.openstack.org/nova/latest/configuration/sample-policy.html | |
| 18:20:08 | dansmith | mriedem: I was leaving the console thing to melwitt | |
| 18:20:09 | mriedem | #"os_compute_api:os-server-groups": "rule:admin_or_owner" | |
| 18:20:11 | mriedem | was the old thing | |
| 18:20:18 | mriedem | and was changed to | |
| 18:20:19 | mriedem | #"os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups" | |
| 18:20:44 | mriedem | which is exactly backward incompatible | |
| 18:22:37 | mriedem | edmondsw: also going back to mitaka before policy in code https://github.com/openstack/nova/blob/mitaka-eol/etc/nova/policy.json#L445 | |
| 18:25:26 | openstackgerrit | Ed Leafe proposed openstack/nova master: Handle ironicclient failures in Ironic driver https://review.openstack.org/487925 | |
| 18:27:24 | openstack | Launchpad bug 1708508 in OpenStack Compute (nova) "os-server-groups policy rules are wrong" [Undecided,New] | |
| 18:27:24 | mriedem | edmondsw: https://bugs.launchpad.net/nova/+bug/1708508 | |
| 18:27:45 | mriedem | lbragstad: what happens if you define a policy action to have a rule which is not actually defined? | |
| 18:27:50 | mriedem | does it just default to the default rule? | |
| 18:28:18 | lbragstad | mriedem: i would assume that to error | |
| 18:28:20 | lbragstad | i can test though | |
| 18:28:27 | mriedem | lbragstad: like say i define "os_compute_api:os-server-groups:create": "rule:doesnotexist", | |
| 18:28:31 | mriedem | and there is no rule for doesnotexist | |
| 18:28:46 | edmondsw | mriedem os_compute_api:os-server-groups is a rule... the value for that rule is by default "rule:admin_or_owner" because there's another rule called admin_or_owner, and then you look at the value for admin_or_owner... they chain | |
| 18:28:53 | edmondsw | so what we did here was add another level to that chain | |
| 18:29:06 | edmondsw | when you use a rule as a value, you need to prefix "rule:" | |
| 18:29:14 | edmondsw | make sense? | |
| 18:29:22 | mriedem | no | |
| 18:29:24 | mriedem | looking at https://docs.openstack.org/nova/latest/configuration/sample-policy.html | |
| 18:29:34 | mriedem | #"admin_or_owner": "is_admin:True or project_id:%(project_id)s" | |
| 18:29:34 | mriedem | i see | |
| 18:29:42 | mriedem | defining the policy for the admin_or_owner rule | |
| 18:29:50 | edmondsw | take "os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups" for example | |
| 18:29:56 | mriedem | oh shit | |
| 18:29:57 | mriedem | #"os_compute_api:os-server-groups": "rule:admin_or_owner" | |
| 18:29:57 | mriedem | i get it now | |
| 18:30:00 | mriedem | gdi | |
| 18:30:00 | edmondsw | :) | |
| 18:30:15 | mriedem | #"os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups" | |
| 18:30:26 | mriedem | #"os_compute_api:os-server-groups": "rule:admin_or_owner" | |
| 18:30:26 | mriedem | points to | |
| 18:30:30 | edmondsw | yep | |
| 18:30:34 | mriedem | my god | |
| 18:30:52 | mriedem | lbragstad: nvm | |
| 18:31:12 | edmondsw | so when we remove os_compute_api:os-server-groups we have to also, at the same time, update the defaults for the other rules to go straight to admin_or_owner instead of via the removed rule | |
| 18:33:08 | openstackgerrit | Stephen Finucane proposed openstack/nova master: doc: Import administration guide https://review.openstack.org/477497 | |
| 18:33:08 | openstackgerrit | Stephen Finucane proposed openstack/nova master: doc: Import installation guide https://review.openstack.org/477488 | |
| 18:33:09 | openstackgerrit | Stephen Finucane proposed openstack/nova master: doc: Rework index page per new sections https://review.openstack.org/478485 | |
| 18:33:21 | mriedem | yup | |
| 18:33:25 | mriedem | and we can do that in queens i guess | |
| 18:34:37 | openstackgerrit | Dan Smith proposed openstack/nova master: Add a caveat section about cellsv2 upcalls https://review.openstack.org/490612 | |
| 18:35:01 | mriedem | edmondsw: thanks for holding my hand | |
| 18:35:06 | mriedem | policy is a scary neighborhood | |
| 18:35:25 | mriedem | like TMNT lane that dan lives on | |
| 18:35:49 | edmondsw | mriedem np... policy will drive you nuts | |
| 18:37:27 | lbragstad | fact | |
| 18:40:08 | dansmith | mriedem: heh | |
| 18:40:40 | openstackgerrit | Jay Pipes proposed openstack/nova master: remove provider allocs in confirm/revert resize https://review.openstack.org/488510 | |
| 18:40:41 | openstackgerrit | Jay Pipes proposed openstack/nova master: Add resource utilities to scheduler utils https://review.openstack.org/490514 | |
| 18:41:06 | jaypipes | dansmith: ok, so I'm still stumped on that ocata to pike ironic failure. everything else is passing. | |
| 18:41:23 | jaypipes | dansmith: hoping you might put some fresh eyes on that, since I need to run soon. | |
| 18:41:53 | mriedem | melwitt: you want to look at this additional cells v2 multi-cell doc goody? https://review.openstack.org/#/c/490612/ | |
| 18:41:57 | jaypipes | dansmith: I suspect it might have something to do with the new resources extra specs processing thing, but honestly I'm not positive. | |
| 18:42:10 | dansmith | jaypipes: yeah. should we slam in mriedem's single node patch at the bttom before you go? | |
| 18:42:30 | jaypipes | dansmith: I hadn't seen that, but I trust you whatever you want sure | |
| 18:42:33 | dansmith | oh wait | |
| 18:42:41 | dansmith | er, cancel that wait | |
| 18:42:57 | dansmith | jaypipes: this guy: https://review.openstack.org/#/c/490085/7 | |
| 18:42:57 | jaypipes | heh | |
| 18:43:22 | openstackgerrit | Stephen Finucane proposed openstack/nova master: nova-manage: Deprecate '--version' parameters https://review.openstack.org/453808 | |
| 18:43:30 | jaypipes | dansmith: ah, yeah, totes. I didn't touch that guy | |
| 18:43:43 | openstackgerrit | Stephen Finucane proposed openstack/nova master: nova-manage: Deprecate '--version' parameters https://review.openstack.org/453808 | |
| 18:43:44 | dansmith | yeah | |
| 18:43:45 | jaypipes | dansmith: +2 from me. | |
| 18:43:52 | dansmith | mriedem: you okay with me +2ing that even though I did the test bit? | |
| 18:45:22 | mriedem | for my change? | |
| 18:45:23 | mriedem | sure | |
| 18:45:28 | dansmith | yeah | |
| 18:45:30 | mriedem | it wasn't much - just removing TODOs | |
| 18:46:00 | mriedem | not to make your contribution to the change seem small or otherwise unimportant, of course :) | |
| 18:47:57 | dansmith | jaypipes: just unit tests I need to look at right? functional all work? | |
| 18:48:24 | jaypipes | dansmith: nope, all units should work fine. it's one functional test in tests/functional/compute/test_resource_tracker.py. | |