Earlier  
Posted Nick Remark
#openstack-nova - 2017-08-03
18:14:49 edmondsw mriedem make sense?
18:15:08 edmondsw backward compat and policy are a nightmare...
18:15:19 edmondsw one of the things we want to talk about fixing at the PTG
18:18:06 mriedem so context.can(sg_policies.BASE_POLICY_NAME) turns that into rule:os_compute_api:os-server-groups ?
18:18:09 mriedem in oslo.context?
18:18:12 mriedem or oslo.policy
18:18:39 mriedem isn't context.can just looking up the action?
18:18:44 mriedem which was os_compute_api:os-server-groups
18:18:51 mriedem and in the before times, that mapped to rule:admin_or_owner
18:18:53 mriedem not rule:os_compute_api:os-server-groups
18:19:33 mriedem dansmith: i left some random thoughts in your cells v2 docs patch
18:19:43 mriedem fighting with over/under doc'ing
18:20:04 mriedem edmondsw: yeah here https://docs.openstack.org/nova/latest/configuration/sample-policy.html
18:20:08 dansmith mriedem: I was leaving the console thing to melwitt
18:20:09 mriedem #"os_compute_api:os-server-groups": "rule:admin_or_owner"
18:20:11 mriedem was the old thing
18:20:18 mriedem and was changed to
18:20:19 mriedem #"os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups"
18:20:44 mriedem which is exactly backward incompatible
18:22:37 mriedem edmondsw: also going back to mitaka before policy in code https://github.com/openstack/nova/blob/mitaka-eol/etc/nova/policy.json#L445
18:25:26 openstackgerrit Ed Leafe proposed openstack/nova master: Handle ironicclient failures in Ironic driver https://review.openstack.org/487925
18:27:24 openstack Launchpad bug 1708508 in OpenStack Compute (nova) "os-server-groups policy rules are wrong" [Undecided,New]
18:27:24 mriedem edmondsw: https://bugs.launchpad.net/nova/+bug/1708508
18:27:45 mriedem lbragstad: what happens if you define a policy action to have a rule which is not actually defined?
18:27:50 mriedem does it just default to the default rule?
18:28:18 lbragstad mriedem: i would assume that to error
18:28:20 lbragstad i can test though
18:28:27 mriedem lbragstad: like say i define "os_compute_api:os-server-groups:create": "rule:doesnotexist",
18:28:31 mriedem and there is no rule for doesnotexist
18:28:46 edmondsw mriedem os_compute_api:os-server-groups is a rule... the value for that rule is by default "rule:admin_or_owner" because there's another rule called admin_or_owner, and then you look at the value for admin_or_owner... they chain
18:28:53 edmondsw so what we did here was add another level to that chain
18:29:06 edmondsw when you use a rule as a value, you need to prefix "rule:"
18:29:14 edmondsw make sense?
18:29:22 mriedem no
18:29:24 mriedem looking at https://docs.openstack.org/nova/latest/configuration/sample-policy.html
18:29:34 mriedem #"admin_or_owner": "is_admin:True or project_id:%(project_id)s"
18:29:34 mriedem i see
18:29:42 mriedem defining the policy for the admin_or_owner rule
18:29:50 edmondsw take "os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups" for example
18:29:56 mriedem oh shit
18:29:57 mriedem #"os_compute_api:os-server-groups": "rule:admin_or_owner"
18:29:57 mriedem i get it now
18:30:00 mriedem gdi
18:30:00 edmondsw :)
18:30:15 mriedem #"os_compute_api:os-server-groups:create": "rule:os_compute_api:os-server-groups"
18:30:26 mriedem #"os_compute_api:os-server-groups": "rule:admin_or_owner"
18:30:26 mriedem points to
18:30:30 edmondsw yep
18:30:34 mriedem my god
18:30:52 mriedem lbragstad: nvm
18:31:12 edmondsw so when we remove os_compute_api:os-server-groups we have to also, at the same time, update the defaults for the other rules to go straight to admin_or_owner instead of via the removed rule
18:33:08 openstackgerrit Stephen Finucane proposed openstack/nova master: doc: Import administration guide https://review.openstack.org/477497
18:33:08 openstackgerrit Stephen Finucane proposed openstack/nova master: doc: Import installation guide https://review.openstack.org/477488
18:33:09 openstackgerrit Stephen Finucane proposed openstack/nova master: doc: Rework index page per new sections https://review.openstack.org/478485
18:33:21 mriedem yup
18:33:25 mriedem and we can do that in queens i guess
18:34:37 openstackgerrit Dan Smith proposed openstack/nova master: Add a caveat section about cellsv2 upcalls https://review.openstack.org/490612
18:35:01 mriedem edmondsw: thanks for holding my hand
18:35:06 mriedem policy is a scary neighborhood
18:35:25 mriedem like TMNT lane that dan lives on
18:35:49 edmondsw mriedem np... policy will drive you nuts
18:37:27 lbragstad fact
18:40:08 dansmith mriedem: heh
18:40:40 openstackgerrit Jay Pipes proposed openstack/nova master: remove provider allocs in confirm/revert resize https://review.openstack.org/488510
18:40:41 openstackgerrit Jay Pipes proposed openstack/nova master: Add resource utilities to scheduler utils https://review.openstack.org/490514
18:41:06 jaypipes dansmith: ok, so I'm still stumped on that ocata to pike ironic failure. everything else is passing.
18:41:23 jaypipes dansmith: hoping you might put some fresh eyes on that, since I need to run soon.
18:41:53 mriedem melwitt: you want to look at this additional cells v2 multi-cell doc goody? https://review.openstack.org/#/c/490612/
18:41:57 jaypipes dansmith: I suspect it might have something to do with the new resources extra specs processing thing, but honestly I'm not positive.
18:42:10 dansmith jaypipes: yeah. should we slam in mriedem's single node patch at the bttom before you go?
18:42:30 jaypipes dansmith: I hadn't seen that, but I trust you whatever you want sure
18:42:33 dansmith oh wait
18:42:41 dansmith er, cancel that wait
18:42:57 dansmith jaypipes: this guy: https://review.openstack.org/#/c/490085/7
18:42:57 jaypipes heh
18:43:22 openstackgerrit Stephen Finucane proposed openstack/nova master: nova-manage: Deprecate '--version' parameters https://review.openstack.org/453808
18:43:30 jaypipes dansmith: ah, yeah, totes. I didn't touch that guy
18:43:43 openstackgerrit Stephen Finucane proposed openstack/nova master: nova-manage: Deprecate '--version' parameters https://review.openstack.org/453808
18:43:44 dansmith yeah
18:43:45 jaypipes dansmith: +2 from me.
18:43:52 dansmith mriedem: you okay with me +2ing that even though I did the test bit?
18:45:22 mriedem for my change?
18:45:23 mriedem sure
18:45:28 dansmith yeah
18:45:30 mriedem it wasn't much - just removing TODOs
18:46:00 mriedem not to make your contribution to the change seem small or otherwise unimportant, of course :)
18:47:57 dansmith jaypipes: just unit tests I need to look at right? functional all work?
18:48:24 jaypipes dansmith: nope, all units should work fine. it's one functional test in tests/functional/compute/test_resource_tracker.py.
18:48:32 dansmith oh okay
18:48:55 jaypipes dansmith: it's expecting instance_claim() to have written allocation records for an ironic instance but it's not writing those allocations for some reason.
18:49:06 dansmith okay
18:49:14 jaypipes dansmith: and if I had to guess, maybe something to do with how we're pulling resources now with extra specs?
18:49:36 dansmith yeah found it
18:49:40 dansmith the test I mean
18:50:36 prashkre mriedem: Hi. Have you created a LP bug for issue with patch in https://review.openstack.org/#/c/391113/?
18:52:12 mriedem prashkre: i did but invalidated it once i understood how the policy rules were being linked
18:54:28 openstackgerrit Matt Riedemann proposed openstack/nova master: Add track_instance_changes note in disable_group_policy_check_upcall https://review.openstack.org/490627
18:56:31 prashkre mriedem: I got confused with your query, now I got it why we had made it like that. due to compatablitiy with people who already started using that rule, it was made like that..
18:58:28 mriedem melwitt: L35 in here about cell caches https://etherpad.openstack.org/p/nova-pike-cells-v2-todos - i think we have that covered in the FAQs page
18:58:35 mriedem but let me know if you were thinking of something else

Earlier   Later