Earlier  
Posted Nick Remark
#openstack-nova - 2023-01-25
09:56:07 zigo I did the later ...
09:56:32 zigo YEAH !!!
09:56:38 zigo Got something that worked ! \o/
09:56:45 bauzas gibi: if we start parallelizing the backports, then we'll break the sha1 information on the commit msgs
09:57:11 bauzas since there is no guarantee that the commit in the gerrit branch will have the same sha1 once merged
09:57:11 gibi bauzas: ignore the sha (it does not have it now either) as we disable the check anyhow
09:57:29 bauzas gibi: I'll then mention the gerrit links
09:57:50 gibi bauzas: the bug ref is there to make a connection, but yes if you want you can add gerrit change id
09:57:53 gibi or link
09:58:09 bauzas unfortunately, we can't also track all commits easily as they're on different branches
09:58:55 zigo So, I did:
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/cve-2022-47951-nova-stable-train.patch
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Move_qemu-img_info_calls_into_privsep.patch
09:58:55 zigo https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Make_JSON_the_default_output_format_of_calls_to_qemu-img_info.patch
09:58:56 zigo With these 3 patches, all unit tests are passing.
09:59:58 zigo Is this acceptable (from your Nova upstream point of view) to backport these 3 patches on the train branch?
10:01:39 bauzas zigo: propose the backports
10:01:54 bauzas Train is EM
10:02:08 zigo bauzas: The only issue is that I apply them in the wrong order, so patch 1 and 2 may have failures ...
10:02:22 zigo Can I just merge the 3 patches then?
10:02:37 johnthetubaguy zigo: +1 that looks like a nice solution to me. You can submit them as a patch chain in gerrit, that should work OK I think?
10:02:39 bauzas then I need to review those patches
10:02:50 bauzas and yeah, this would have to be a gerrit series
10:02:56 zigo Ok, doing this.
10:03:02 gibi zigo: https://salsa.debian.org/openstack-team/services/nova/-/blob/debian/train/debian/patches/images_Make_JSON_the_default_output_format_of_calls_to_qemu-img_info.patch#L416 format=output_format ?
10:04:04 zigo gibi: That's what is in there: https://review.opendev.org/c/openstack/nova/+/711679/6/nova/virt/images.py#57
10:04:13 opendevreview Sylvain Bauza proposed openstack/nova stable/yoga: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871624
10:04:32 zigo Ask Lee Yarwood I guess? :)
10:04:32 gibi zigo: then that is a latent bug, so keep it as is
10:04:55 opendevreview Sylvain Bauza proposed openstack/nova stable/xena: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871622
10:05:34 opendevreview Sylvain Bauza proposed openstack/nova stable/wallaby: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871557
10:05:40 gibi zigo: lyarwood is gone from openstack unfortunately
10:06:19 bauzas I'd be honest, I spotted a few bugs on this
10:06:27 bauzas (and ChatGPT as well)
10:06:37 bauzas but nothing prevents the cve to be fixed
10:07:01 bauzas gibi: did the [stable-only] hack
10:07:04 bauzas enjoy
10:07:11 bauzas johnthetubaguy: ditto
10:07:14 gibi bauzas: I agree, lets fix the cve, the latent bugs can be fixed later / separately
10:07:17 gibi bauzas: on it
10:07:34 zigo bauzas: Last time, I asked ChatGPT to write an alembic migration env.py for me, using oslo.db, and it did kind of well ... :)
10:07:34 gibi bauzas: you missed https://review.opendev.org/c/openstack/nova/+/871616
10:07:51 gibi zigo: you live dangerously :)
10:08:11 zigo gibi: I didn't use what ChatGPT produced ! :)
10:08:18 gibi ahh :)
10:08:18 bauzas gibi: no, this was on purpose, zed is on the check pipeline
10:08:32 bauzas and was on the gate before
10:08:34 gibi bauzas: zed will be kicked out of gate by the backport job as it has no commit hash
10:08:42 bauzas gibi: oh shit, you're right
10:08:46 bauzas doing then the hack
10:09:19 opendevreview Sylvain Bauza proposed openstack/nova stable/zed: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871616
10:09:23 bauzas there ^
10:09:28 zigo I really don't feel confident pushing the 3 patches I linked above to Gerrit. I'm sure I'll do some mistakes like commit ID and such ...
10:09:37 zigo Can someone else pick them up ?
10:10:17 johnthetubaguy gibi: does that job not run in the check queue?
10:10:28 gibi johnthetubaguy: it is non-voting in check
10:10:33 gibi afaik
10:10:56 johnthetubaguy oh, I see it now: nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/016594434b19461781e2dbb3688a61cd : FAILURE in 4m 51s (non-voting)
10:11:03 gibi yepp it failed ther nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/04bf544d0dc44ca48f45ba4d71bb8892 : FAILURE in 5m 45s (non-voting)
10:12:51 bauzas yup, missed that when I rechecked
10:12:56 bauzas I focused on the other failures :D
10:13:18 gibi the important ones :D
10:13:46 bauzas that's two weeks I devoted to upstream
10:14:03 bauzas and despite this, I nearly progressed on my feature by 5%.
10:14:05 bauzas lovely.
10:14:17 bauzas Zuul, I look at you
10:14:49 gibi bauzas: keeping Zuul happy is part of the deal unfortunately :)
10:15:05 gibi maybe you should ask ChatGPT to maintain it for us :D
10:15:33 bauzas that's... dangerous
10:16:30 gibi OK all the patches I know of has +2 +A https://review.opendev.org/q/topic:bug%252F1996188
10:16:34 kashyap gibi: Even ChatGPT will throw up in the hands and say "it's a Sisphean task"
10:16:51 gibi kashyap: we need better aligned AIs then
10:16:57 kashyap Heh
10:17:13 kashyap And this time-out seems unfortunate :-( https://review.opendev.org/c/openstack/nova/+/870794
10:18:11 zigo Looks like doing train -> stein is just a refresh of patches...
10:22:38 bauzas zigo: I've quickly read your patches on your server
10:22:47 bauzas why aren't you proposing them upstream ?
10:23:19 bauzas the problem is that I don't know which objects or methods you've touched
10:24:05 bauzas I mean, if you need help on how to propose a series on a stable branch, I can surely offer my help
10:30:24 opendevreview John Garbutt proposed openstack/nova stable/victoria: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871699
10:31:26 opendevreview John Garbutt proposed openstack/nova stable/ussuri: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871702
10:33:25 johnthetubaguy ah, thanks gibi, your cut and paste of the topic was faster
10:35:12 gibi johnthetubaguy: I think there is a merge conflict resolution issue in https://review.opendev.org/c/openstack/nova/+/871699
10:35:27 johnthetubaguy oops, yes
10:35:46 johnthetubaguy I only got as far as pep8 locally
10:36:02 johnthetubaguy fixing that now
10:36:23 gibi affects the stable/ussuri one too
10:36:32 johnthetubaguy yeah, I cherry-picked that down
10:39:09 sean-k-mooney i have not read back but why do we have stable only variants
10:39:32 sean-k-mooney dan had proposed cherry picks already
10:40:22 gibi sean-k-mooney: we want to land them in parallel
10:40:31 gibi sean-k-mooney: and the only way to allow it is to add [stable-only]
10:40:41 sean-k-mooney hum ok
10:40:44 gibi otherwise the backport job will prevent the merge
10:40:55 gibi elodilles: was OK with this from stable :D
10:40:55 sean-k-mooney i was going to try and land them in sequence
10:41:06 sean-k-mooney and just hold other patches until they were merged
10:41:26 gibi sean-k-mooney: johnthetubaguy expressed time sensitiveness and the stable/policy actually allows it for secu patches
10:41:51 sean-k-mooney it does but i didnt tink it warrented it
10:41:58 sean-k-mooney but if other are happy then ok

Earlier   Later