| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2018-10-03 | |||
| 20:33:23 | mriedem | the spec is proposing that you can swap the root volume while the instance is offloaded or stopped | |
| 20:34:16 | sean-k-mooney | right but you could do that by createing a new volume. stoping the instance. detach the root volmu and attach the volume created in step 1 then start | |
| 20:34:43 | sean-k-mooney | do you need an explcit api to do the swap as an atopmic operation | |
| 20:34:55 | mriedem | no, and that is what the spec is proposing | |
| 20:35:01 | mriedem | "createing a new volume. stoping the instance. detach the root volmu and attach the volume created in step 1 then start" | |
| 20:35:22 | mriedem | my point is, i don't know that all virt drivers could handle that today for the root volume | |
| 20:35:26 | mriedem | while the instance is stopped | |
| 20:35:45 | sean-k-mooney | ha ok am perhaps | |
| 20:36:23 | sean-k-mooney | i cant think why they could not if they support rebuild | |
| 20:36:49 | sean-k-mooney | its basicaly the same thing except we are not chaning host | |
| 20:37:45 | mriedem | rebuild does a driver.destroy and then a driver.spawn | |
| 20:37:51 | mriedem | it assumes destruction | |
| 20:38:01 | mriedem | i can't say that stop/start assume that same thing | |
| 20:38:27 | mriedem | same with shelve/unshelve | |
| 20:38:37 | mriedem | shelve does a driver.destroy and unshelve does a driver.spawn | |
| 20:39:08 | mriedem | sean-k-mooney: haven't you been working for like 20 straight hours at this point or something? | |
| 20:39:17 | mriedem | at what point do you become drunk by exhaustion? | |
| 20:39:46 | sean-k-mooney | mriedem: all of this is true. i would be surprised if this could not be supported on multiple hyperviors but its good to check. | |
| 20:40:14 | sean-k-mooney | haha not quite but if i get tired enough i do find it harder to concentrate. | |
| 20:41:00 | sean-k-mooney | i have been working sine 10:30 + i took an hour for lunch but ya im just finishing up for the day | |
| 20:41:27 | mriedem | pretty sure you said you were finishing for the day about 4 hours ago | |
| 20:41:56 | sean-k-mooney | i did finish rather late last night. ya got distracted with a few things | |
| 20:44:24 | sean-k-mooney | i really need to file my ptg expensice tomrrow... i started twice today but then got pull into email threads + code. | |
| 20:44:56 | sean-k-mooney | thats what i was trying to figure out for the last 30 mins but it can wait | |
| 20:45:11 | sean-k-mooney | talk to you tommorw | |
| 20:46:46 | melwitt | mriedem, tssurya: I told dansmith we're skipping the meeting based on the earlier convo | |
| 20:47:07 | tssurya | melwitt: ack, thanks for the info :) | |
| 20:47:09 | melwitt | he's not going to be back in time anyway | |
| 20:47:42 | mriedem | he said he would be back in time | |
| 20:47:45 | tssurya | wfm, Its too late here anyways, you guys have a good day | |
| 20:47:59 | mriedem | <3 broken | |
| 20:48:06 | melwitt | heh | |
| 20:48:19 | tssurya | :) | |
| 20:49:38 | mriedem | https://bugs.launchpad.net/nova/+bug/1795966 | |
| 20:49:38 | openstack | Launchpad bug 1795966 in OpenStack Compute (nova) "<class 'oslo_db.exception.DBNonExistentTable'> (HTTP 500)" [Undecided,Invalid] | |
| 20:50:15 | melwitt | meanwhile, gd consoleauth. we have an API where you can 'show' your console auth token. and that is making the deprecation nightmare worse. have to figure out if/how to adjust this for the database backend | |
| 20:50:51 | melwitt | mriedem: that must be the shortest bug report ever | |
| 20:50:56 | mriedem | https://developer.openstack.org/api-ref/compute/#create-remote-console ? | |
| 20:51:11 | melwitt | https://developer.openstack.org/api-ref/compute/#show-console-connection-information | |
| 20:51:31 | mriedem | ah heh | |
| 20:51:36 | melwitt | FML | |
| 20:51:56 | mriedem | well, | |
| 20:52:18 | mriedem | oh heh you can't know which cell to route it to right | |
| 20:52:23 | mriedem | b/c the token isn't mapped in the api | |
| 20:52:36 | mriedem | you'll have to iterate the cell dbs looking for that token id | |
| 20:53:05 | melwitt | no... which I'm trying to remember, what did I find last time I looked at this. arrrrgghh | |
| 20:55:03 | mriedem | hmm, we only store the hashed token in the db right | |
| 20:55:14 | mriedem | and that's not what the API would have in it? | |
| 20:55:47 | melwitt | yeah only the hashed token. and I think the API takes the unhashed token from the user | |
| 20:56:22 | mriedem | ha, cool | |
| 20:56:58 | mriedem | for cell in all_cells(): for console_auth_token in all_console_auth_tokens_in_this_cell(): if console_auth_token == req_id: do that thing() | |
| 20:58:27 | mriedem | i bet we log that unhashed token in the nova-api logs too... | |
| 20:58:31 | mriedem | since it's on the path | |
| 20:59:09 | mriedem | https://github.com/openstack/nova/blob/master/nova/api/openstack/requestlog.py#L41 | |
| 20:59:30 | melwitt | indeed, I can see it in the func test output | |
| 20:59:43 | mriedem | ha, cool | |
| 20:59:52 | melwitt | 2018-10-03 20:37:40,870 INFO [nova.api.openstack.requestlog] 127.0.0.1 "GET /v2.1/os-console-auth-tokens/714a26ff-d7e6-4698-bc30-9934ebf38807" | |
| 21:00:17 | mriedem | well luckily logging credentials isn't a CVE | |
| 21:01:44 | melwitt | ... | |
| 21:02:27 | melwitt | I guess people aren't paying too much attention to this API, myself included | |
| 21:02:34 | mriedem | it's admin-only by default | |
| 21:02:49 | melwitt | I see, ok | |
| 21:03:11 | melwitt | Note "This is only used in Xenserver VNC Proxy." | |
| 21:03:21 | melwitt | really? I wonder how | |
| 21:03:35 | mriedem | that's for the other 4 | |
| 21:03:37 | mriedem | i saw that as well | |
| 21:03:52 | mriedem | os-console-auth-tokens was added specifically for rdp consoles for hyperv | |
| 21:04:42 | melwitt | O.o | |
| 21:09:15 | melwitt | yeah, so we could scatter-gather a ConsoleAuthToken.validate(context, token) call and only one will return token object, the others will raise exceptions. that method takes an unhashed token and will hash it before looking for it in the db | |
| 21:10:53 | mriedem | sure | |
| 21:11:05 | mriedem | shitty performance but whatareyougonnado | |
| 21:11:13 | mriedem | plus it's admin-only and no one knew it existed | |
| 21:11:13 | melwitt | yeah, exactly | |
| 21:11:21 | melwitt | haha, right. we have that going for us | |
| 21:11:45 | mriedem | is there a bug for this? | |
| 21:11:46 | melwitt | I'll add it to the pile o poopatches | |
| 21:11:51 | melwitt | no | |
| 21:11:57 | melwitt | I'll open one | |
| 21:12:22 | mriedem | cool. not sure if we should report the token logging thing or just pretend i never said it. | |
| 21:12:28 | melwitt | I was just making the changes to only access consoleauth if [workarounds] and ran into this in the func tests | |
| 21:12:46 | melwitt | so I'm doing really good here | |
| 21:14:09 | melwitt | yeah, I'm not sure either. I expect it wouldn't cause a CVE because it's been this way for years | |
| 21:19:41 | mriedem | heh, well, we've had things "this way for years" that are CVEs, | |
| 21:19:52 | mriedem | but logging credentials and tokens and such isn't considered one of them | |
| 21:20:13 | mriedem | it's a "hardening opportunity" | |
| 21:20:18 | melwitt | haha, ok | |
| 21:20:22 | openstackgerrit | Jay Pipes proposed openstack/nova stable/ocata: Re-use existing ComputeNode on ironic rebalance https://review.openstack.org/607626 | |
| 21:21:12 | melwitt | https://bugs.launchpad.net/nova/+bug/1795982 | |
| 21:21:12 | openstack | Launchpad bug 1795982 in OpenStack Compute (nova) "/os-console-auth-tokens/{console_token} API doesn't handle the database backend" [High,Triaged] - Assigned to melanie witt (melwitt) | |
| 21:30:17 | melwitt | so, these other console create/delete/get APIs are connected to cell database models, with nothing at the API level to target cells for the consoles | |
| 21:31:38 | melwitt | "nova-console, which is a XenAPI-specific service that most recent VNC proxy architectures do not use." | |
| 21:32:34 | melwitt | it sounds like that should be deprecated. we didn't do anything to handle it in a cells v2 world | |
| 21:35:17 | melwitt | maybe I should send something to the ML to ask about it | |
| 21:45:37 | mriedem | i thought the xvp stuff was xen-only | |
| 21:46:21 | melwitt | yeah, the nova-console service is xen-only. but if someone ran multi-cell with xen, the nova-console part wouldn't work right | |
| 21:46:25 | mriedem | but yeah this is clearly busted in a cells v2 world | |
| 21:47:17 | melwitt | so the question will be, do we cells-v2-ify it or do we deprecate it. tbc, this is for the other APIs, not the consoleauth one I'm fixing | |
| 21:47:35 | melwitt | *the other 4 | |
| 21:48:50 | mriedem | yeah i know | |
| 21:50:10 | mriedem | idk, i've asked about killing xvp in the past | |