Earlier  
Posted Nick Remark
#openstack-nova - 2023-01-24
16:38:05 zigo I tracked them using "git blame" and didn't try doing a backport of them to Train though ...
16:38:06 elodilles so this is fixed in Ussuri and newer
16:38:16 zigo Yeah, Ussuri and up are fine.
16:38:34 bauzas sec
16:38:34 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: api: extend evacuate instance to support target state https://review.opendev.org/c/openstack/nova/+/858384
16:38:35 elodilles so from upstream perspective Train is the only target
16:38:38 bauzas we have a series up
16:38:40 zigo But Train and before would need either such a backport, or something else to get the VMDK extended infos.
16:38:45 bauzas that's proposed to fix the CVE
16:39:01 bauzas oh, this is down to yoga
16:39:32 elodilles zigo: Nova's stable/stein and stable/rocky is End of Life already
16:39:57 bauzas I guess zigo wants at least Train
16:39:58 elodilles so that needs to be handled downstream as branches are deleted already
16:40:04 bauzas correct
16:40:05 zigo elodilles: Yeah, but Debian is doing LTS for Rocky, so I will need to do the patch backport. And so probably is Red Hat for its customers, etc.
16:40:08 bauzas those are tagged eol
16:40:26 zigo Ok, so out of scope for the team, and I'm on my own ... :P
16:40:40 dansmith zigo: you might need something more bespoke if backporting all the dependencies isn't possible
16:40:51 zigo Oh, also, when I'm at it ...
16:40:57 zigo This also need another patch in oslo.utils
16:41:10 dansmith but it is clearly out of scope for us, which doesn't necessarily mean we won't help you, but...
16:41:36 zigo Ok, thanks. :P
16:42:20 zigo FYI, that's the oslo.utils patch that I backported already: https://review.opendev.org/c/openstack/oslo.utils/+/706880
16:42:33 zigo That fixed one of the unit tests...
16:42:33 dansmith so with that,
16:42:42 zigo (for train and below)
16:42:50 bauzas dansmith: I guess there is no plan to backport https://review.opendev.org/c/openstack/nova/+/871624 downer than Yoga ?
16:42:51 dansmith even if you don't backport the privsep stuff, you should have the data you need I think
16:43:03 dansmith bauzas: I backported to xena,
16:43:13 dansmith I think because xena was still in scope at the time and I was asked
16:43:43 dansmith it was the only one with a conflict, trivial because of the config
16:43:46 bauzas I'm actually surprised than backporting requires pulling more deps
16:44:07 dansmith because of privsep conversions
16:44:18 dansmith this was run within nova before IIRC
16:44:18 bauzas dansmith: mmm, OK, can't see it proposed in the list of cherry-picks of https://review.opendev.org/c/openstack/nova/+/871624
16:44:27 dansmith and probably not with json output or something
16:44:35 dansmith bauzas: https://review.opendev.org/c/openstack/nova/+/871622
16:45:03 bauzas I'm fucking blind
16:45:08 bauzas it's on the list
16:45:17 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: api: extend evacuate instance to support target state https://review.opendev.org/c/openstack/nova/+/858384
16:45:20 sean-k-mooney that does not need any dep changes does it
16:45:45 bauzas after being deaf when dansmith speaks, I'm now blind
16:45:53 dansmith sean-k-mooney: not package deps, dependent patches
16:45:56 bauzas correct
16:46:06 bauzas but should be honestly minimal
16:46:13 bauzas the patch itself is well self-contained
16:46:25 dansmith but listen to what zigo is saying
16:46:30 sean-k-mooney but it does not have depend on so you mena we need to backprot each branch or changes in other repos
16:46:40 dansmith the information we need was not being exposed out of oslo utils before the patch he referenced
16:46:59 sean-k-mooney ok then thats kind of a problem
16:47:11 sean-k-mooney the olso backports would have to happen first
16:47:29 dansmith I don't think he's suggesting it upstream
16:47:31 sean-k-mooney and we would need to be able to work with older oslo
16:47:40 opendevreview Merged openstack/nova master: Make tenant network policy default to PROJECT_READER_OR_ADMIN https://review.opendev.org/c/openstack/nova/+/865071
16:47:43 dansmith he's talking about old and crusty packages debian is keeping on life support
16:48:00 bauzas oh
16:48:08 sean-k-mooney ok we can propably talk about this out of the meeting
16:48:15 bauzas that's gonna be fun then
16:48:24 dansmith yes, especially since it's out of our support scope, very clearly
16:48:41 sean-k-mooney https://review.opendev.org/c/openstack/oslo.utils/+/706880 is in ussuri and above
16:48:49 dansmith he's talking about rocky
16:48:56 sean-k-mooney so i think train is the only supported release without it
16:49:13 sean-k-mooney dansmith: right but we have one release that does not have the oslo patch
16:49:32 dansmith sean-k-mooney: who is we? not upstream openstack
16:49:41 zigo I don't suggest it upstream, just trying to share my findings at the moment (I don't have any blockers ... yet, if I do I'll let you know).
16:49:42 sean-k-mooney we still supprot train for nova
16:49:52 sean-k-mooney and https://review.opendev.org/c/openstack/oslo.utils/+/706880 is not in it
16:50:00 dansmith elodilles: ?
16:50:10 zigo Rocky, I haven't started working on it yet...
16:50:12 sean-k-mooney based on the gerrit included in output
16:50:57 zigo sean-k-mooney: Correct. (but not really a pb for me...)
16:51:43 sean-k-mooney anywya lets loop back to this after the meeting
16:52:06 sean-k-mooney if we need it for train then we can backport it to train in oslo
16:52:13 sean-k-mooney but there are plenty of branches to get through first
16:52:16 bauzas is it me or there was a typo in the oslo.utils patch ? https://review.opendev.org/c/openstack/oslo.utils/+/706880/4/oslo_utils/imageutils.py#88
16:52:50 sean-k-mooney not that i see
16:52:53 bauzas appened ?
16:53:28 sean-k-mooney its a list so i think that valid
16:53:44 bauzas I know I'm not a python expert, but I didn't know that a list object was having an 'appened' method
16:53:48 sean-k-mooney https://docs.python.org/3/tutorial/datastructures.html#more-on-lists
16:53:49 bauzas append, eyes
16:53:59 sean-k-mooney """Add an item to the end of the list. Equivalent to a[len(a):] = [x]."""
16:54:08 bauzas append, yes
16:54:14 bauzas appened, doesn't exist
16:54:22 sean-k-mooney oh
16:54:46 bauzas which tends me thinking this patch is nice but unsufficient
16:55:06 sean-k-mooney ya thats wrong i think but i shoudl not try and spot typos :)
16:55:19 sean-k-mooney that presumably was fixed
16:55:27 bauzas correct, probably in a fup
16:55:39 zigo Well, in this specific case, the code is executed in the format == 'json' path, so it *is* enough ... (but still wrong in that other case)
16:55:45 bauzas so it would require the fup to be dragged down too
16:56:15 sean-k-mooney aparenlty not https://github.com/openstack/oslo.utils/blob/stable/ussuri/oslo_utils/imageutils.py#L89
16:56:19 bauzas zigo: correct, the bug is only on the string definition
16:56:25 zigo Well, stable/zed has the typo ... :/
16:56:28 bauzas when you str()
16:56:34 bauzas or you print
16:56:48 bauzas so, technically, you don't need the fix
16:56:51 sean-k-mooney https://github.com/openstack/oslo.utils/commit/d49d5944824f15d00e04e1b9c7f8c3b03b440c95
16:57:01 sean-k-mooney it was fixed 2 months ago
16:57:02 bauzas anyway, the meeting is close to the end

Earlier   Later