| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2021-02-18 | |||
| 15:13:02 | sean-k-mooney | https://bugs.launchpad.net/nova/+bug/1798904 might be mitgated by the patches for https://bugs.launchpad.net/neutron/+bug/1734320 the last of which is https://review.opendev.org/c/openstack/nova/+/602432 | |
| 15:13:05 | openstack | Launchpad bug 1798904 in os-vif "tenant isolation is bypassed if port admin-state-up=false" [Critical,Confirmed] - Assigned to sean mooney (sean-k-mooney) | |
| 15:13:06 | openstack | Launchpad bug 1734320 in os-vif "Eavesdropping private traffic" [High,Fix released] - Assigned to sean mooney (sean-k-mooney) | |
| 15:13:25 | openstackgerrit | Stephen Finucane proposed openstack/nova master: Use neutronclient's port binding APIs https://review.opendev.org/c/openstack/nova/+/706295 | |
| 15:13:27 | sean-k-mooney | https://bugs.launchpad.net/nova/+bug/1552042 im not familar with | |
| 15:13:28 | openstack | Launchpad bug 1552042 in OpenStack Compute (nova) "Host data corruption through nova inject_key feature" [Medium,In progress] - Assigned to Matt Riedemann (mriedem) | |
| 15:14:34 | openstackgerrit | Sylvain Bauza proposed openstack/nova master: Add net & utils methods for routed nets & segments https://review.opendev.org/c/openstack/nova/+/773976 | |
| 15:14:43 | sean-k-mooney | looks like mriedem was trying to remove the file injefction feature with https://review.opendev.org/c/openstack/nova/+/324720/ | |
| 15:14:45 | openstackgerrit | Sylvain Bauza proposed openstack/nova master: Add a routed networks scheduler pre-filter https://review.opendev.org/c/openstack/nova/+/749068 | |
| 15:20:02 | gibi | artom: lol | |
| 15:34:07 | sean-k-mooney | gibi: fyi just updated https://bugs.launchpad.net/nova/+bug/1798904 with my current understanding perhapes we shoudl review https://bugs.launchpad.net/nova/+bug/1552042 in the team call | |
| 15:34:09 | openstack | Launchpad bug 1798904 in os-vif "tenant isolation is bypassed if port admin-state-up=false" [Critical,Confirmed] - Assigned to sean mooney (sean-k-mooney) | |
| 15:34:10 | openstack | Launchpad bug 1552042 in OpenStack Compute (nova) "Host data corruption through nova inject_key feature" [Medium,In progress] - Assigned to Matt Riedemann (mriedem) | |
| 15:34:31 | sean-k-mooney | by which i mean nova meeting | |
| 15:36:49 | sean-k-mooney | stephenfin: have we removed file injection yet? | |
| 15:37:57 | stephenfin | I don't think so | |
| 15:38:04 | stephenfin | From nova, you mean? | |
| 15:38:09 | sean-k-mooney | ya | |
| 15:38:15 | sean-k-mooney | we deprecated it queens for removal | |
| 15:38:15 | stephenfin | I don't think we can without bumping out minimum API microversion | |
| 15:38:17 | stephenfin | *our | |
| 15:38:20 | stephenfin | Right? | |
| 15:38:34 | sean-k-mooney | well you just deleted half of the hyperviors api | |
| 15:38:43 | sean-k-mooney | and remove xen specifc ones last cycle | |
| 15:38:55 | sean-k-mooney | so we could | |
| 15:39:07 | stephenfin | That's different though | |
| 15:39:22 | sean-k-mooney | how | |
| 15:39:52 | sean-k-mooney | you flat out removed api with no fallback | |
| 15:40:24 | stephenfin | Right, but this would involve suggested removing certain microversions and keeping the rest of the API | |
| 15:40:33 | sean-k-mooney | we partly have doe this by the way in https://github.com/openstack/nova/blob/e6f5e814050a19d6f027037424556b2889514ec3/nova/api/openstack/compute/rest_api_version_history.rst#257 | |
| 15:40:45 | stephenfin | Or at least having those microversions behave differently on one server than another | |
| 15:40:59 | stephenfin | which is arguably worse, depending on how much of a purist you are | |
| 15:41:14 | sean-k-mooney | yep thats what will happen with the xenapis or hyperviors | |
| 15:41:26 | sean-k-mooney | or any other api wehre we now return a 404 and removed the code | |
| 15:42:22 | stephenfin | not realllly | |
| 15:42:37 | sean-k-mooney | im really not seeing why it is not | |
| 15:42:53 | stephenfin | we've never (knowingly) changed behavior of an existing microversion | |
| 15:42:59 | stephenfin | except where it was returning a 5xx error | |
| 15:43:03 | stephenfin | right? | |
| 15:43:10 | sean-k-mooney | sure we have | |
| 15:43:22 | sean-k-mooney | you jsut did it with the hyperviors stats api | |
| 15:43:47 | sean-k-mooney | you cant use the old microverion and get that back right? | |
| 15:43:52 | stephenfin | No, you can | |
| 15:44:08 | sean-k-mooney | really i though you were killing the code | |
| 15:44:15 | stephenfin | 2.87 and boom, you're back to the bad old world full of lies and deceit | |
| 15:44:17 | stephenfin | nope | |
| 15:44:21 | stephenfin | cos we don't do that | |
| 15:44:28 | stephenfin | unless we have no choice | |
| 15:44:29 | sean-k-mooney | well you did kill the code for xen | |
| 15:44:42 | stephenfin | yes, we had no choice there. The APIs didn't work without it | |
| 15:44:51 | sean-k-mooney | and we have killed the code for nova networks and cells v1 | |
| 15:45:17 | stephenfin | but we never had a release where 2.N still existed but gave different responses to previous releases | |
| 15:45:44 | sean-k-mooney | im not sure about that | |
| 15:46:12 | stephenfin | 2.N should yield consistent behaviour until we reach the point where we can no longer support it, in which case it'll return 404 or 410 for all microversions | |
| 15:46:17 | sean-k-mooney | do we still have the code for the xen specific console server action | |
| 15:46:45 | stephenfin | I think that's a HTTP 410 now | |
| 15:46:51 | stephenfin | Or 404, I don't recall | |
| 15:47:07 | sean-k-mooney | so there is a case where its go. | |
| 15:47:22 | sean-k-mooney | your conserned that we woudl be breaking server cretae for those that use file injection | |
| 15:47:29 | sean-k-mooney | usign the old microverion | |
| 15:47:34 | stephenfin | yeah, exactly | |
| 15:47:47 | sean-k-mooney | right im suggesting its been deprecated for remval since queens | |
| 15:47:51 | sean-k-mooney | and we shoudl actully remove it | |
| 15:48:05 | stephenfin | We don't think anyone was using the Xen stuff, and we know they couldn't use the nova-network stuff | |
| 15:48:19 | stephenfin | You'd only know that if you used a newer microversion though | |
| 15:48:26 | stephenfin | and if you're using OSC, you're probably using 2.1 | |
| 15:48:33 | stephenfin | for now - we're working on it | |
| 15:48:38 | sean-k-mooney | yep probably | |
| 15:48:46 | stephenfin | this really feels like a PTG discussion | |
| 15:48:50 | stephenfin | or at least openstack-discuss | |
| 15:48:56 | sean-k-mooney | well its a long standing public security bug | |
| 15:49:05 | stephenfin | since you and I can't decide this unilaterally | |
| 15:49:06 | sean-k-mooney | we can fix it other ways too | |
| 15:49:28 | stephenfin | yup, aware there are attenuating circumstances here | |
| 15:49:32 | sean-k-mooney | i just dont want us to keep putting of fixing the secuity bug | |
| 15:50:55 | sean-k-mooney | deprecation happend via this spec by the way minimum supported microversion in the distant future. | |
| 15:50:58 | sean-k-mooney | .... | |
| 15:51:03 | sean-k-mooney | https://specs.openstack.org/openstack/nova-specs/specs/queens/implemented/deprecate-file-injection.html#rest-api-impact | |
| 15:51:23 | stephenfin | now bumping the API minimum is something I could get behind | |
| 15:51:30 | stephenfin | we're coming close to 3 digit microversions... | |
| 15:51:51 | stephenfin | that's _definitely_ a PTG discussion though :-D | |
| 15:51:51 | sean-k-mooney | yep | |
| 15:51:56 | openstackgerrit | Lucas Alvares Gomes proposed openstack/nova master: [OVN] Adapt the live-migration job scripts to work with OVN https://review.opendev.org/c/openstack/nova/+/776419 | |
| 15:51:59 | sean-k-mooney | and we called that out in the spec by the way | |
| 15:52:02 | sean-k-mooney | " The point of this microversion is really to signal that users should not be using this legacy part of the compute API, and to set a timer on when it could be removed if nova ever starts requiring a higher minimum supported microversion in the distant future." | |
| 15:52:46 | sean-k-mooney | gibi: is there an etherpad for the xena ptg? | |
| 15:53:09 | sean-k-mooney | gibi: part of me really wants to declare xena a tech debt removal cycle | |
| 15:54:02 | sean-k-mooney | but i do think discussing raising the min microverion may be somethign we shoudl discuss or a differnt path to removing long deperecated apis | |
| 15:54:16 | gibi | sean-k-mooney: good point I should have start a xena ptg pad | |
| 15:54:40 | sean-k-mooney | gibi: ya that getting worringly close... | |
| 15:55:07 | gibi | sean-k-mooney: I've just read back, if you want to discuss the unembargoed security bug on the meeting then please bring it up :) either in the bug section or in the OpenDiscussion | |
| 15:56:02 | sean-k-mooney | an sure i thin the networking one im goign to fix via other work so ill just add it to the things i test | |
| 15:56:17 | gibi | ok | |
| 16:00:55 | gibi | sean-k-mooney: xena ptg etherpad https://etherpad.opendev.org/p/nova-xena-ptg | |
| 16:01:19 | sean-k-mooney | gibi: thanks im going to try and avoid adding too much to it if i can :) | |
| 16:01:43 | gibi | sean-k-mooney: do not limit yourself, we can always remove things later :) | |
| 16:01:52 | sean-k-mooney | oh you already have the do not translate message nice | |
| 16:02:41 | gibi | carried over from the wallaby pad :) | |
| 16:02:45 | sean-k-mooney | ya i guess i just havent done my onw retro on how things have gone over the last 6-12 monts and what did/didnt get done | |
| 16:03:03 | gibi | sean-k-mooney: btw team meeting is ongoing :) | |