| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2023-03-01 | |||
| 18:03:43 | sean-k-mooney | instead of hacking in the old key type which wont | |
| 18:05:33 | clarkb | and if anyone can grok the openssh code better than I a PR to default to rsa + sha2 as teh fallback might generate interesting conversations | |
| 18:05:34 | sean-k-mooney | so we should just replace https://github.com/openstack/grenade/blob/master/projects/70_cinder/resources.sh#L121 | |
| 18:05:46 | sean-k-mooney | with a call to ssh-keygen | |
| 18:05:50 | clarkb | the rfc suggests this happen eventually but as far as I can tell it hasn't happened yet which leads to annoying failures n a lot of cases | |
| 18:06:51 | bauzas | sean-k-mooney: patch is up to change grenade https://review.opendev.org/c/openstack/grenade/+/875940/ | |
| 18:07:09 | sean-k-mooney | cool | |
| 18:07:18 | sean-k-mooney | so ye were just discussing why this is needed | |
| 18:07:24 | bauzas | yeah | |
| 18:07:25 | sean-k-mooney | rahter then trying to find a solution | |
| 18:07:27 | sean-k-mooney | ok | |
| 18:07:29 | dansmith | yeah because I definitely didn't | |
| 18:07:30 | bauzas | well | |
| 18:07:47 | bauzas | we are trying to untangle the oddness of ssh negociation | |
| 18:07:48 | dansmith | and I have a bunch of hacks in my own ssh_config that probably need revisiting now that more of my systems are upgraded | |
| 18:07:56 | bauzas | me too | |
| 18:08:10 | bauzas | this discussion is half-workwise, halp-personalwise | |
| 18:08:14 | sean-k-mooney | ok i got burned by this years ago and have helped other fix it in the past so i mostly just accpet it at this point | |
| 18:08:36 | bauzas | I just shamelessly tuned the signature negociation on the fly with my ssh_config | |
| 18:09:04 | bauzas | as I didn't wanted to generate a new pair of ECDSA or something else keys | |
| 18:09:15 | sean-k-mooney | ya i still have PubkeyAcceptedKeyTypes +ssh-rsa for one site in my config | |
| 18:09:20 | sean-k-mooney | but i think thats offline | |
| 18:09:41 | bauzas | but now if I understand correctly, I could rather continue to use my RSA keys but ask for a different signature | |
| 18:09:58 | sean-k-mooney | i also still have | |
| 18:10:01 | bauzas | using rsa-sha2 | |
| 18:10:01 | sean-k-mooney | host review.opendev.org | |
| 18:10:03 | sean-k-mooney | HostKeyAlgorithms ssh-rsa | |
| 18:10:05 | sean-k-mooney | KexAlgorithms +diffie-hellman-group1-sha1 | |
| 18:10:07 | sean-k-mooney | Ciphers +aes128-cbc | |
| 18:10:12 | sean-k-mooney | for some reason witch i relly dont need | |
| 18:10:46 | clarkb | bauzas: correct. The problem is that some servers don't know how to negotiate that with you like old dropbear and old gerrit | |
| 18:10:49 | sean-k-mooney | thats what i treid when PubkeyAcceptedKeyTypes +ssh-rsa stopped working for gerrit | |
| 18:11:17 | bauzas | clarkb: so the per-host config is still required, gotcha | |
| 18:11:19 | clarkb | the gerrit we have deployed at review.opendev.org should work fine though. ianw and I worked with gerrit and mina sshd upstream and got that all fixed and eventually got it backported to gerrit 3.5 (it was always on 3.6) | |
| 18:11:42 | clarkb | bauzas: if the servers don't know how to negotiate rsa + sha2 | |
| 18:11:48 | clarkb | review.opendev.org should not need this anymore | |
| 18:11:49 | bauzas | yeah got it | |
| 18:12:02 | bauzas | clarkb: how to enable rsa+sha2 globally in the config ? | |
| 18:12:24 | clarkb | bauzas: if your openssh client is new (like on fedora or jammy etc) then thats the only version they will use by default | |
| 18:12:25 | bauzas | because I assume my current OS doesn't have its defaults changed | |
| 18:12:35 | bauzas | oh | |
| 18:12:52 | clarkb | thats why it failed to talk to cirros. jammy will only use rsa + sha2 by default, but cirros dropbear will only do rsa + sha1 | |
| 18:13:02 | clarkb | this mismatch leads to a failure to negotiate between them and no ssh connection | |
| 18:13:04 | sean-k-mooney | i think you would add PubkeyAcceptedKeyTypes rsa-sha2-256 | |
| 18:13:16 | sean-k-mooney | under "HOST *" | |
| 18:13:18 | clarkb | sean-k-mooney: that shouldn't be necessary its automatic | |
| 18:13:27 | clarkb | since all the new lcients only do sha2 | |
| 18:13:28 | bauzas | hmmm | |
| 18:13:43 | sean-k-mooney | ya it should not but if you wanted to force it that would be how | |
| 18:14:08 | bauzas | yeah got it | |
| 18:14:23 | bauzas | this chat is definitely a helper | |
| 18:14:26 | bauzas | clarkb: thanks a lot ! | |
| 18:15:37 | sean-k-mooney | i really would like to just upload a pulic key to keystone and use that to authenticate with osc | |
| 18:23:28 | sean-k-mooney | bauzas: for what its woth its in te seciryt enhancmetns secation fo the 22.04 release notes https://discourse.ubuntu.com/t/jammy-jellyfish-release-notes/24668 | |
| 18:25:45 | sean-k-mooney | it was disabled by defult in openssh https://www.openssh.com/txt/release-8.8 | |
| 18:26:35 | sean-k-mooney | after being deprecated in 8.3 https://lwn.net/Articles/821544/ | |
| 18:42:07 | clarkb | right but they didn't change the fallback key | |
| 18:42:33 | clarkb | so there are layers of problems here. The first is that you can no longer negotiate ssh-rsa with servers that need it. Second is that when that negotiate fails both sides expect ssh-rsa | |
| 18:42:40 | clarkb | which of course fails making the fallback useless | |
| 18:43:23 | clarkb | they should've changed the fallback to rsa-sha-256 so that clients would attempt that after a failed negotiation. This wold still fail on cirros but would've worked with gerrit | |
| 18:52:24 | opendevreview | Merged openstack/nova stable/victoria: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866086 | |
| 22:39:08 | opendevreview | Dan Smith proposed openstack/nova master: Add grenade-skip-level-always to nova https://review.opendev.org/c/openstack/nova/+/875773 | |
| 23:59:05 | opendevreview | melanie witt proposed openstack/nova master: testing: Reset affinity support global variables https://review.opendev.org/c/openstack/nova/+/875991 | |
| #openstack-nova - 2023-03-02 | |||
| 08:47:41 | opendevreview | Jorge San Emeterio proposed openstack/nova master: Have host look for CPU controller of cgroupsv2 location. https://review.opendev.org/c/openstack/nova/+/873127 | |
| 09:12:01 | opendevreview | Sylvain Bauza proposed openstack/nova master: Add service version for Antelope https://review.opendev.org/c/openstack/nova/+/874932 | |
| 09:12:02 | opendevreview | Sylvain Bauza proposed openstack/nova master: DNM (yet) Update min support for Bobcat https://review.opendev.org/c/openstack/nova/+/875621 | |
| 09:14:06 | bauzas | gibi: I'd appreciate your review on both https://review.opendev.org/c/openstack/nova/+/874932/5 and https://review.opendev.org/c/openstack/nova/+/875380 | |
| 09:33:37 | kgube | Hi! So, I ran out of time with the implementation of my specs that got accepted for antelope and I want to resubmit them for bobcat. | |
| 09:33:40 | kgube | Should I create a new change for this, or is it possible to reuse the old change, even though it was already merged, to keep previous discussions? | |
| 09:35:46 | gibi | bauzas: on it | |
| 09:37:00 | Uggla | Hi gibi, I need help regarding this comment https://review.opendev.org/c/openstack/nova/+/851029/19/doc/notification_samples/common_payloads/InstancePayload.json#42. As InstancePayload is the "root" of all notifications, I can not change it adding a share as it will impact all notifications tests. Is there a way to do that without copying this file and calling it only on specific cases ? | |
| 09:51:48 | gibi | bauzas: Im OK with the prelude, I left comments in the service version patch | |
| 09:52:08 | gibi | Uggla: looking | |
| 09:52:50 | gibi | Uggla: duplicate the file and use it for the share related notification samples | |
| 09:53:31 | gibi | Uggla: alternativel you could manipulate the sample in the test code but that would be missleading | |
| 09:54:09 | gibi | you are right we probably don't want to add shares for each notification test | |
| 09:54:31 | gibi | still we want to have samples with shares as that is basically our API definition | |
| 09:56:16 | Uggla | @gibi, ok if I duplicate, then it will be documented automatically or should I do something special ? | |
| 10:05:29 | gibi | Uggla: the doc generation happens via the @base.notification_sample decorators | |
| 10:06:21 | gibi | doc generation code is here https://github.com/openstack/nova/blob/master/doc/ext/versioned_notifications.py | |
| 10:07:33 | gibi | so if you create a sample that has shares | |
| 10:07:51 | gibi | then you need to add that to the related class via the @base.notification_sample | |
| 10:07:55 | gibi | decorator | |
| 10:08:31 | gibi | kgube: do you mean resubmitting the spec? | |
| 10:09:13 | gibi | kgube: if so then you need a new change, but you can copy the already approved spec there. And please note that this is a re-propose in the commit message so that people can look at the old discussion | |
| 10:14:53 | bauzas | sorry folks, was in meeting | |
| 10:15:00 | bauzas | gibi: ack, will be looking | |
| 10:15:23 | bauzas | kgube: the bobcat specs directory is now present, you can indeed resubmit | |
| 10:15:38 | bauzas | like gibi said, just copy the rst file and mention it was previously-approved | |
| 10:16:13 | bauzas | so you would benefit from a straight fast-approval if no modification is made in the spec file besides the mention of the previous approval | |
| 10:16:30 | bauzas | see other specs in Antelope, that pattern is often used :) | |
| 10:18:07 | Uggla | gibi ok, I ll check | |
| 10:20:46 | kgube | bauzas, gibi: alright, thanks! | |
| 10:47:05 | opendevreview | Merged openstack/nova stable/train: Refactor volume connection cleanup out of _post_live_migration https://review.opendev.org/c/openstack/nova/+/864670 | |
| 10:47:14 | opendevreview | Merged openstack/nova stable/train: Adds a repoducer for post live migration fail https://review.opendev.org/c/openstack/nova/+/863806 | |
| 11:18:57 | opendevreview | Sylvain Bauza proposed openstack/nova master: DNM (yet) Update min support for Bobcat https://review.opendev.org/c/openstack/nova/+/875621 | |
| 11:18:57 | opendevreview | Sylvain Bauza proposed openstack/nova master: Add service version for Antelope https://review.opendev.org/c/openstack/nova/+/874932 | |
| 11:34:53 | opendevreview | Danylo Vodopianov proposed openstack/os-traits master: Add 'COMPUTE_NET_VIRTIO_PACKED' https://review.opendev.org/c/openstack/os-traits/+/876069 | |
| 11:47:59 | opendevreview | Danylo Vodopianov proposed openstack/nova master: Packed virtqueue support was added. https://review.opendev.org/c/openstack/nova/+/876075 | |
| 11:55:07 | opendevreview | Jorge San Emeterio proposed openstack/nova master: WIP: Have schema for 'lock' action be applied to all microversions. https://review.opendev.org/c/openstack/nova/+/875653 | |