Earlier  
Posted Nick Remark
#openstack-nova - 2021-02-18
15:14:43 sean-k-mooney looks like mriedem was trying to remove the file injefction feature with https://review.opendev.org/c/openstack/nova/+/324720/
15:14:45 openstackgerrit Sylvain Bauza proposed openstack/nova master: Add a routed networks scheduler pre-filter https://review.opendev.org/c/openstack/nova/+/749068
15:20:02 gibi artom: lol
15:34:07 sean-k-mooney gibi: fyi just updated https://bugs.launchpad.net/nova/+bug/1798904 with my current understanding perhapes we shoudl review https://bugs.launchpad.net/nova/+bug/1552042 in the team call
15:34:09 openstack Launchpad bug 1798904 in os-vif "tenant isolation is bypassed if port admin-state-up=false" [Critical,Confirmed] - Assigned to sean mooney (sean-k-mooney)
15:34:10 openstack Launchpad bug 1552042 in OpenStack Compute (nova) "Host data corruption through nova inject_key feature" [Medium,In progress] - Assigned to Matt Riedemann (mriedem)
15:34:31 sean-k-mooney by which i mean nova meeting
15:36:49 sean-k-mooney stephenfin: have we removed file injection yet?
15:37:57 stephenfin I don't think so
15:38:04 stephenfin From nova, you mean?
15:38:09 sean-k-mooney ya
15:38:15 stephenfin I don't think we can without bumping out minimum API microversion
15:38:15 sean-k-mooney we deprecated it queens for removal
15:38:17 stephenfin *our
15:38:20 stephenfin Right?
15:38:34 sean-k-mooney well you just deleted half of the hyperviors api
15:38:43 sean-k-mooney and remove xen specifc ones last cycle
15:38:55 sean-k-mooney so we could
15:39:07 stephenfin That's different though
15:39:22 sean-k-mooney how
15:39:52 sean-k-mooney you flat out removed api with no fallback
15:40:24 stephenfin Right, but this would involve suggested removing certain microversions and keeping the rest of the API
15:40:33 sean-k-mooney we partly have doe this by the way in https://github.com/openstack/nova/blob/e6f5e814050a19d6f027037424556b2889514ec3/nova/api/openstack/compute/rest_api_version_history.rst#257
15:40:45 stephenfin Or at least having those microversions behave differently on one server than another
15:40:59 stephenfin which is arguably worse, depending on how much of a purist you are
15:41:14 sean-k-mooney yep thats what will happen with the xenapis or hyperviors
15:41:26 sean-k-mooney or any other api wehre we now return a 404 and removed the code
15:42:22 stephenfin not realllly
15:42:37 sean-k-mooney im really not seeing why it is not
15:42:53 stephenfin we've never (knowingly) changed behavior of an existing microversion
15:42:59 stephenfin except where it was returning a 5xx error
15:43:03 stephenfin right?
15:43:10 sean-k-mooney sure we have
15:43:22 sean-k-mooney you jsut did it with the hyperviors stats api
15:43:47 sean-k-mooney you cant use the old microverion and get that back right?
15:43:52 stephenfin No, you can
15:44:08 sean-k-mooney really i though you were killing the code
15:44:15 stephenfin 2.87 and boom, you're back to the bad old world full of lies and deceit
15:44:17 stephenfin nope
15:44:21 stephenfin cos we don't do that
15:44:28 stephenfin unless we have no choice
15:44:29 sean-k-mooney well you did kill the code for xen
15:44:42 stephenfin yes, we had no choice there. The APIs didn't work without it
15:44:51 sean-k-mooney and we have killed the code for nova networks and cells v1
15:45:17 stephenfin but we never had a release where 2.N still existed but gave different responses to previous releases
15:45:44 sean-k-mooney im not sure about that
15:46:12 stephenfin 2.N should yield consistent behaviour until we reach the point where we can no longer support it, in which case it'll return 404 or 410 for all microversions
15:46:17 sean-k-mooney do we still have the code for the xen specific console server action
15:46:45 stephenfin I think that's a HTTP 410 now
15:46:51 stephenfin Or 404, I don't recall
15:47:07 sean-k-mooney so there is a case where its go.
15:47:22 sean-k-mooney your conserned that we woudl be breaking server cretae for those that use file injection
15:47:29 sean-k-mooney usign the old microverion
15:47:34 stephenfin yeah, exactly
15:47:47 sean-k-mooney right im suggesting its been deprecated for remval since queens
15:47:51 sean-k-mooney and we shoudl actully remove it
15:48:05 stephenfin We don't think anyone was using the Xen stuff, and we know they couldn't use the nova-network stuff
15:48:19 stephenfin You'd only know that if you used a newer microversion though
15:48:26 stephenfin and if you're using OSC, you're probably using 2.1
15:48:33 stephenfin for now - we're working on it
15:48:38 sean-k-mooney yep probably
15:48:46 stephenfin this really feels like a PTG discussion
15:48:50 stephenfin or at least openstack-discuss
15:48:56 sean-k-mooney well its a long standing public security bug
15:49:05 stephenfin since you and I can't decide this unilaterally
15:49:06 sean-k-mooney we can fix it other ways too
15:49:28 stephenfin yup, aware there are attenuating circumstances here
15:49:32 sean-k-mooney i just dont want us to keep putting of fixing the secuity bug
15:50:55 sean-k-mooney deprecation happend via this spec by the way minimum supported microversion in the distant future.
15:50:58 sean-k-mooney ....
15:51:03 sean-k-mooney https://specs.openstack.org/openstack/nova-specs/specs/queens/implemented/deprecate-file-injection.html#rest-api-impact
15:51:23 stephenfin now bumping the API minimum is something I could get behind
15:51:30 stephenfin we're coming close to 3 digit microversions...
15:51:51 sean-k-mooney yep
15:51:51 stephenfin that's _definitely_ a PTG discussion though :-D
15:51:56 openstackgerrit Lucas Alvares Gomes proposed openstack/nova master: [OVN] Adapt the live-migration job scripts to work with OVN https://review.opendev.org/c/openstack/nova/+/776419
15:51:59 sean-k-mooney and we called that out in the spec by the way
15:52:02 sean-k-mooney " The point of this microversion is really to signal that users should not be using this legacy part of the compute API, and to set a timer on when it could be removed if nova ever starts requiring a higher minimum supported microversion in the distant future."
15:52:46 sean-k-mooney gibi: is there an etherpad for the xena ptg?
15:53:09 sean-k-mooney gibi: part of me really wants to declare xena a tech debt removal cycle
15:54:02 sean-k-mooney but i do think discussing raising the min microverion may be somethign we shoudl discuss or a differnt path to removing long deperecated apis
15:54:16 gibi sean-k-mooney: good point I should have start a xena ptg pad
15:54:40 sean-k-mooney gibi: ya that getting worringly close...
15:55:07 gibi sean-k-mooney: I've just read back, if you want to discuss the unembargoed security bug on the meeting then please bring it up :) either in the bug section or in the OpenDiscussion
15:56:02 sean-k-mooney an sure i thin the networking one im goign to fix via other work so ill just add it to the things i test
15:56:17 gibi ok
16:00:55 gibi sean-k-mooney: xena ptg etherpad https://etherpad.opendev.org/p/nova-xena-ptg
16:01:19 sean-k-mooney gibi: thanks im going to try and avoid adding too much to it if i can :)
16:01:43 gibi sean-k-mooney: do not limit yourself, we can always remove things later :)
16:01:52 sean-k-mooney oh you already have the do not translate message nice
16:02:41 gibi carried over from the wallaby pad :)
16:02:45 sean-k-mooney ya i guess i just havent done my onw retro on how things have gone over the last 6-12 monts and what did/didnt get done
16:03:03 gibi sean-k-mooney: btw team meeting is ongoing :)
16:03:08 gibi if you want to mention something
16:03:08 sean-k-mooney oh ya :)
16:58:07 sean-k-mooney actully looks liek we have a few others that were not on the list
16:58:31 sean-k-mooney like https://bugs.launchpad.net/nova/+bug/1861893
16:58:32 openstack Launchpad bug 1861893 in OpenStack Compute (nova) "os-assisted-volume-snapshots passes unsanitised file path to the libvirt driver" [Medium,Confirmed]
16:59:08 sean-k-mooney we could not actuly exploit ^ so its just a security hardening case
16:59:29 openstackgerrit Vishal Manchanda proposed openstack/nova master: Docs: Correct ``Password injection using the dashboard`` Explanation https://review.opendev.org/c/openstack/nova/+/775084

Earlier   Later