Earlier  
Posted Nick Remark
#openstack-nova - 2023-01-25
10:50:32 sean-k-mooney yes
10:50:50 sean-k-mooney we have a downstream deadlien ot have that merged internally by next week
10:51:04 gibi and we have downstream proactive backport too ;)
10:51:05 sean-k-mooney but i would prefer to also have it merged upstream
10:51:51 johnthetubaguy I didn't see that one, yes, that should get some love too.
10:51:55 sean-k-mooney if we are doing a release we should ideally include both or do a second release once both are there
10:51:57 bauzas mmm, OK, I only tho see 'in progress' on ossa
10:52:09 bauzas so I guess that one isn't on mitre
10:52:37 bauzas nevermind me, it is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37394
10:52:52 bauzas but yeah, it's a dos
10:53:00 bauzas not a compute exposure
10:53:11 sean-k-mooney preventign the compute agent form stating
10:53:26 bauzas yup, hence the security level
10:53:39 sean-k-mooney from a public cloud perspecivive both are costly in different ways
10:53:55 bauzas we can try to land them at the same pace, but I don't want to wait more than one day if we can't due to them
10:54:29 bauzas sean-k-mooney: I tend to set a different priority on it
10:54:52 gibi I agree to not wait more than a day with a release if the latest cve fix lands
10:54:56 bauzas we're not talking of direct access to the host which could compromize all the dataplane
10:55:21 sean-k-mooney well that not quite what the other cve does
10:55:44 sean-k-mooney it can give you direct access to the file system but not the network
10:56:39 bauzas if you have access to the file system, you can access the network later
10:56:39 sean-k-mooney anyway fine lets continue but before i saw the new cve patches yesterday i had planned to ask use to prioites this older one in the team meeting yesterday
10:56:53 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (objects) https://review.opendev.org/c/openstack/nova/+/839401
10:56:53 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (db) https://review.opendev.org/c/openstack/nova/+/831193
10:56:54 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (drivers and compute manager part) https://review.opendev.org/c/openstack/nova/+/833090
10:56:54 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (manila abstraction) https://review.opendev.org/c/openstack/nova/+/831194
10:56:55 opendevreview ribaudr proposed openstack/nova master: Check shares support https://review.opendev.org/c/openstack/nova/+/850499
10:56:55 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (api) https://review.opendev.org/c/openstack/nova/+/836830
10:56:56 opendevreview ribaudr proposed openstack/nova master: Add metadata for shares https://review.opendev.org/c/openstack/nova/+/850500
10:56:57 opendevreview ribaudr proposed openstack/nova master: Add instance.share_detach notification https://review.opendev.org/c/openstack/nova/+/851028
10:56:57 opendevreview ribaudr proposed openstack/nova master: Add instance.share_attach notification https://review.opendev.org/c/openstack/nova/+/850501
10:56:59 opendevreview ribaudr proposed openstack/nova master: Add helper methods to attach/detach shares https://review.opendev.org/c/openstack/nova/+/852085
10:56:59 opendevreview ribaudr proposed openstack/nova master: Add shares to InstancePayload https://review.opendev.org/c/openstack/nova/+/851029
10:57:01 opendevreview ribaudr proposed openstack/nova master: Add virt/libvirt error test cases https://review.opendev.org/c/openstack/nova/+/852087
10:57:01 opendevreview ribaudr proposed openstack/nova master: Add libvirt test to ensure metadata are working. https://review.opendev.org/c/openstack/nova/+/852086
10:57:03 opendevreview ribaudr proposed openstack/nova master: Support rebooting an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/854824
10:57:03 opendevreview ribaudr proposed openstack/nova master: Add share_info parameter to reboot method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/854823
10:57:05 opendevreview ribaudr proposed openstack/nova master: Add instance.share_detach_error notification https://review.opendev.org/c/openstack/nova/+/860283
10:57:05 opendevreview ribaudr proposed openstack/nova master: Add instance.share_attach_error notification https://review.opendev.org/c/openstack/nova/+/860282
10:57:07 opendevreview ribaudr proposed openstack/nova master: Support resuming an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860285
10:57:07 opendevreview ribaudr proposed openstack/nova master: Add share_info parameter to resume method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/860284
10:57:09 opendevreview ribaudr proposed openstack/nova master: Support rescuing an instance with shares (driver part) https://review.opendev.org/c/openstack/nova/+/860287
10:57:09 opendevreview ribaudr proposed openstack/nova master: Add helper methods to rescue/unrescue shares https://review.opendev.org/c/openstack/nova/+/860286
10:57:11 opendevreview ribaudr proposed openstack/nova master: Change microversion to 2.XX https://review.opendev.org/c/openstack/nova/+/852088
10:57:11 opendevreview ribaudr proposed openstack/nova master: Support rescuing an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860288
10:57:13 opendevreview ribaudr proposed openstack/nova master: Documentation https://review.opendev.org/c/openstack/nova/+/871642
10:57:54 sean-k-mooney bauzas: have they confirmed that raw devices special files are actully usable im not sure file access imples network access
10:58:05 sean-k-mooney it would come down to the speicics of the vmdk impl
10:58:14 sean-k-mooney anyway we dont need to speculate
10:58:16 bauzas sean-k-mooney: I tested it by myself
10:58:29 bauzas and when I say it's nasty, trust me it is
10:58:51 sean-k-mooney ok well since this has been discusled upstream we now also need ot have it downstream by next week at the latest
11:01:42 johnthetubaguy bauzas: escation to something nasty should be assume with these things, for sure. Even if we can't see it yet.
11:02:49 sean-k-mooney johnthetubaguy: i was just thinking that if it was anythin like virtio-fs special files cant be accesed but i trust dan and bauzas when they say it was nasty
11:03:10 bauzas johnthetubaguy: sean-k-mooney: read the bug report
11:03:18 bauzas and the first comments, there is a reproducer
11:03:22 sean-k-mooney i have not reviewed the bug/cve in any detail rather just enduing the patches were moving last night
11:06:25 sean-k-mooney ok so on that reading it does not allow direct network access form the main descrption anyway lets not look for other ways to abuse this
11:06:59 sean-k-mooney if i try hard enough im sure i can come up with ways to make it worse and i really dont want to do that on a public channel
11:09:56 bauzas +1
11:18:32 zigo bauzas: I'll push my patches in a bit...
11:18:39 zigo FYI, I got Stein fixed too... :)
11:18:54 zigo Stein -> Rocky backport seems another tricky one...
12:13:24 priteau Anyone know why grenade keeps failing on stable/wallaby with the vmdk patch?
12:38:07 opendevreview Merged openstack/nova stable/yoga: Reproduce bug 1981813 in func env https://review.opendev.org/c/openstack/nova/+/859312
12:53:29 zigo I also got Rocky in shape! :P
13:15:18 opendevreview Merged openstack/nova stable/yoga: Gracefully ERROR in _init_instance if vnic_type changed https://review.opendev.org/c/openstack/nova/+/859313
13:22:25 bauzas sent the xena patches for ^ to the gate
13:22:43 bauzas passports* even
13:26:56 gibi bauzas: thanks
13:40:51 sahid 0/ bauzas sean-k-mooney https://review.opendev.org/c/openstack/nova/+/858384 when you have a moment if you can double-check the phrasing regarding doc I hope that will be aligned with your thinking
13:41:26 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Dividing global privsep profile https://review.opendev.org/c/openstack/nova/+/871729
13:41:43 sean-k-mooney sahid: sure im on a call but ill check when it wraps
13:42:09 sahid sean-k-mooney: no worries, thanks a lot for your time :-)
13:44:55 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Dividing global privsep profile https://review.opendev.org/c/openstack/nova/+/871729
13:47:56 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Dividing global privsep profile https://review.opendev.org/c/openstack/nova/+/871729
14:04:06 gibi I did a round of rechecks on the vmdk cve
14:16:17 gibi bauzas: bahh, I need to update commit hashes in the https://review.opendev.org/q/topic:bug%252F1981813 series all the way back from xena to train
14:16:25 gibi fun
14:43:25 opendevreview Balazs Gibizer proposed openstack/nova stable/xena: Reproduce bug 1981813 in func env https://review.opendev.org/c/openstack/nova/+/859314
14:43:26 opendevreview Balazs Gibizer proposed openstack/nova stable/xena: Gracefully ERROR in _init_instance if vnic_type changed https://review.opendev.org/c/openstack/nova/+/859315
14:52:18 bauzas gibi: I guess I can review it again ? ^
14:52:46 gibi bauzas: yeah I hope I did not screw up copying hashes
14:53:18 bauzas gibi: you used the merge patch one ?
14:53:24 gibi yes
14:53:32 gibi now it points to the merged one
14:53:38 bauzas should work so
14:53:39 gibi in both xena patch
14:53:41 gibi es
14:53:50 gibi and I have to do it for the rest of the stable branches too
14:56:00 opendevreview Dan Smith proposed openstack/nova master: WIP: Detect host renames and abort startup https://review.opendev.org/c/openstack/nova/+/863920
14:58:32 gibi a recheckd https://review.opendev.org/c/openstack/nova/+/871622 back to the gate it was kicked due to a slow CI node
15:03:06 bauzas gibi: yup, thanks for having rechecked the changes
15:06:20 gibi bauzas: even with trying to land them in parallel I doubt we will land all of them until friday
15:06:33 gibi maybe if the gate is better during the night...
15:06:57 gibi :D
15:23:40 artom 🤞
15:23:40 artom 🤞
15:23:44 artom Hey, it's unicode!
15:38:41 bauzas artom: tss, wanted to avoid it :p

Earlier   Later