Earlier  
Posted Nick Remark
#openstack-nova - 2023-01-25
09:49:37 gibi bauzas: I can approve that but the job will kick it out from the gate
09:49:44 elodilles let me know if any patch needs review
09:49:50 gibi elodilles: it is more like a process thing
09:49:53 bauzas elodilles: we're on the CVE backports
09:50:03 elodilles (i'm not aware of any special handling of security bug fixes)
09:50:03 gibi elodilles: the stable policy allows parallel merge of secu stable fixes
09:50:06 bauzas elodilles: the zed one got kicked out due to some gate failure
09:50:09 gibi elodilles: but the backport job does not
09:50:43 elodilles ok, then [stable-only] is right
09:50:43 gibi elodilles: do you have a magic want to turn off the job or merge the patches against that job?
09:50:46 bauzas gibi: I'd say that if the stable policy agrees on that, we could refer to it if we respin the patch to add the [stable-only] tag
09:50:56 gibi OK then we have a consensus
09:51:04 elodilles if you want them to merge not in the known order
09:51:08 gibi bauzas: will you add the [stable-only] tags?
09:51:10 bauzas ideally, I'd rather prefer to have a specific tag but we're a bit on a rush
09:51:12 johnthetubaguy bauzas: we have a zoo of people on different things, I am not worried about them, thats all happening, I am more worried in general about it not landing in the stable branches.
09:51:32 gibi bauzas: then elodilles and me can approve qucikly
09:51:42 johnthetubaguy what about [stable-only][actually-a-cve] ?
09:52:05 gibi johnthetubaguy: adding a sentence why we add stable-only make sense, yes
09:52:11 elodilles :]
09:52:35 gibi and as a follow up we should extend the job to accept [cve] as a tag to silence the landing order check
09:52:45 johnthetubaguy gibi: +1
09:53:00 bauzas johnthetubaguy: as a reminder, train requires some oslo.utils bump due to https://review.opendev.org/c/openstack/oslo.utils/+/706880 missing
09:53:34 johnthetubaguy bauzas: appreciated, thanks, I saw zigo is working through that.
09:56:04 zigo Either oslo bump, or backport of https://review.opendev.org/c/openstack/oslo.utils/+/706880
09:56:07 zigo I did the later ...
09:56:32 zigo YEAH !!!
09:56:38 zigo Got something that worked ! \o/
09:56:45 bauzas gibi: if we start parallelizing the backports, then we'll break the sha1 information on the commit msgs
09:57:11 bauzas since there is no guarantee that the commit in the gerrit branch will have the same sha1 once merged
09:57:11 gibi bauzas: ignore the sha (it does not have it now either) as we disable the check anyhow
09:57:29 bauzas gibi: I'll then mention the gerrit links
09:57:50 gibi bauzas: the bug ref is there to make a connection, but yes if you want you can add gerrit change id
09:57:53 gibi or link
09:58:09 bauzas unfortunately, we can't also track all commits easily as they're on different branches
09:58:55 zigo So, I did:
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/cve-2022-47951-nova-stable-train.patch
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Move_qemu-img_info_calls_into_privsep.patch
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Make_JSON_the_default_output_format_of_calls_to_qemu-img_info.patch
09:58:56 zigo With these 3 patches, all unit tests are passing.
09:59:58 zigo Is this acceptable (from your Nova upstream point of view) to backport these 3 patches on the train branch?
10:01:39 bauzas zigo: propose the backports
10:01:54 bauzas Train is EM
10:02:08 zigo bauzas: The only issue is that I apply them in the wrong order, so patch 1 and 2 may have failures ...
10:02:22 zigo Can I just merge the 3 patches then?
10:02:37 johnthetubaguy zigo: +1 that looks like a nice solution to me. You can submit them as a patch chain in gerrit, that should work OK I think?
10:02:39 bauzas then I need to review those patches
10:02:50 bauzas and yeah, this would have to be a gerrit series
10:02:56 zigo Ok, doing this.
10:03:02 gibi zigo: https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Make_JSON_the_default_output_format_of_calls_to_qemu-img_info.patch#L416 format=output_format ?
10:04:04 zigo gibi: That's what is in there: https://review.opendev.org/c/openstack/nova/+/711679/6/nova/virt/images.py#57
10:04:13 opendevreview Sylvain Bauza proposed openstack/nova stable/yoga: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871624
10:04:32 zigo Ask Lee Yarwood I guess? :)
10:04:32 gibi zigo: then that is a latent bug, so keep it as is
10:04:55 opendevreview Sylvain Bauza proposed openstack/nova stable/xena: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871622
10:05:34 opendevreview Sylvain Bauza proposed openstack/nova stable/wallaby: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871557
10:05:40 gibi zigo: lyarwood is gone from openstack unfortunately
10:06:19 bauzas I'd be honest, I spotted a few bugs on this
10:06:27 bauzas (and ChatGPT as well)
10:06:37 bauzas but nothing prevents the cve to be fixed
10:07:01 bauzas gibi: did the [stable-only] hack
10:07:04 bauzas enjoy
10:07:11 bauzas johnthetubaguy: ditto
10:07:14 gibi bauzas: I agree, lets fix the cve, the latent bugs can be fixed later / separately
10:07:17 gibi bauzas: on it
10:07:34 zigo bauzas: Last time, I asked ChatGPT to write an alembic migration env.py for me, using oslo.db, and it did kind of well ... :)
10:07:34 gibi bauzas: you missed https://review.opendev.org/c/openstack/nova/+/871616
10:07:51 gibi zigo: you live dangerously :)
10:08:11 zigo gibi: I didn't use what ChatGPT produced ! :)
10:08:18 gibi ahh :)
10:08:18 bauzas gibi: no, this was on purpose, zed is on the check pipeline
10:08:32 bauzas and was on the gate before
10:08:34 gibi bauzas: zed will be kicked out of gate by the backport job as it has no commit hash
10:08:42 bauzas gibi: oh shit, you're right
10:08:46 bauzas doing then the hack
10:09:19 opendevreview Sylvain Bauza proposed openstack/nova stable/zed: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871616
10:09:23 bauzas there ^
10:09:28 zigo I really don't feel confident pushing the 3 patches I linked above to Gerrit. I'm sure I'll do some mistakes like commit ID and such ...
10:09:37 zigo Can someone else pick them up ?
10:10:17 johnthetubaguy gibi: does that job not run in the check queue?
10:10:28 gibi johnthetubaguy: it is non-voting in check
10:10:33 gibi afaik
10:10:56 johnthetubaguy oh, I see it now: nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/016594434b19461781e2dbb3688a61cd : FAILURE in 4m 51s (non-voting)
10:11:03 gibi yepp it failed ther nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/04bf544d0dc44ca48f45ba4d71bb8892 : FAILURE in 5m 45s (non-voting)
10:12:51 bauzas yup, missed that when I rechecked
10:12:56 bauzas I focused on the other failures :D
10:13:18 gibi the important ones :D
10:13:46 bauzas that's two weeks I devoted to upstream
10:14:03 bauzas and despite this, I nearly progressed on my feature by 5%.
10:14:05 bauzas lovely.
10:14:17 bauzas Zuul, I look at you
10:14:49 gibi bauzas: keeping Zuul happy is part of the deal unfortunately :)
10:15:05 gibi maybe you should ask ChatGPT to maintain it for us :D
10:15:33 bauzas that's... dangerous
10:16:30 gibi OK all the patches I know of has +2 +A https://review.opendev.org/q/topic:bug%252F1996188
10:16:34 kashyap gibi: Even ChatGPT will throw up in the hands and say "it's a Sisphean task"
10:16:51 gibi kashyap: we need better aligned AIs then
10:16:57 kashyap Heh
10:17:13 kashyap And this time-out seems unfortunate :-( https://review.opendev.org/c/openstack/nova/+/870794
10:18:11 zigo Looks like doing train -> stein is just a refresh of patches...

Earlier   Later