Earlier  
Posted Nick Remark
#openstack-nova - 2023-01-25
10:39:09 sean-k-mooney i have not read back but why do we have stable only variants
10:39:32 sean-k-mooney dan had proposed cherry picks already
10:40:22 gibi sean-k-mooney: we want to land them in parallel
10:40:31 gibi sean-k-mooney: and the only way to allow it is to add [stable-only]
10:40:41 sean-k-mooney hum ok
10:40:44 gibi otherwise the backport job will prevent the merge
10:40:55 gibi elodilles: was OK with this from stable :D
10:40:55 sean-k-mooney i was going to try and land them in sequence
10:41:06 sean-k-mooney and just hold other patches until they were merged
10:41:26 gibi sean-k-mooney: johnthetubaguy expressed time sensitiveness and the stable/policy actually allows it for secu patches
10:41:51 sean-k-mooney it does but i didnt tink it warrented it
10:41:58 sean-k-mooney but if other are happy then ok
10:42:09 sean-k-mooney i just wont try and babysit the patches today
10:42:15 gibi at least bauzas, johnthetubaguy, elodilles and myself was OK with it
10:43:00 johnthetubaguy sean-k-mooney: I am curious, why do you think its not urgent enough?
10:44:03 sean-k-mooney form my perspective there is nothign preventing a downstream form merging them once its proposed. and for anyone that ues a release i.e. form pypi its not going to get it to them faster. those that use source builds can use the gerrit version
10:44:25 opendevreview John Garbutt proposed openstack/nova stable/victoria: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871699
10:44:35 sean-k-mooney i was still expecting them to all merge today or tommorrow without needing to do it in parallel
10:44:39 gibi sean-k-mooney: I assume we will propose a stable release as soon as a stable patch lands
10:45:29 sean-k-mooney i think anyone who is going to deploy that by the end of the week would jsut take the patch and do it them selevs
10:45:32 gibi sean-k-mooney: given the gate speed parallel is lot faster than sequential when we need to do 7 backports
10:46:05 sean-k-mooney the gate is fast if this is the only thing we are merging
10:46:40 gibi gate is unstable regardles of the number of patches on it, also we have no power over how other projects using the gate resources
10:46:50 sean-k-mooney if we are merging things in parallel less so but as i said im fine with it i just dont think we needed it. i was still expecting all these to be merged by tomrrow either ay
10:47:18 sean-k-mooney gibi: i didnt mean other project i ment lets not merge anything that would put these in merge conflict
10:47:49 sean-k-mooney anyway ill leave this to ye since ye have a plan
10:48:04 bauzas sean-k-mooney: I don't disagree with you, and I expressed the fact that we need anyway need to release so those fixes could be eventually helpful
10:48:11 gibi I think the merge conflict is just a small percent of why serial merge would be slower here. It is more like rechecks and waiting for the patch on the newer branch that slow sequential down
10:48:25 opendevreview John Garbutt proposed openstack/nova stable/ussuri: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871702
10:48:28 bauzas but it occurred from johnthetubaguy that we could rush the things a little bit up
10:48:52 bauzas and eventually I joined the 'rush' team when I saw our stable policy was accepting it
10:49:05 sean-k-mooney we have a second CVE fix with backprots that need review upstream
10:49:07 bauzas sean-k-mooney: just explaining my thoughts journey
10:49:23 sean-k-mooney if we are going to do a release we proably shoudl also merge that with the same speed
10:49:42 bauzas sean-k-mooney: that's understandable, despite that one was pretty nasty
10:49:53 bauzas sean-k-mooney: patches ?
10:50:07 sean-k-mooney looking for them now
10:50:11 bauzas I only remember the former-embargoed one which is now public
10:50:17 gibi https://review.opendev.org/q/topic:bug%252F1981813
10:50:22 gibi I think sean-k-mooney refers to ^^
10:50:28 gibi it is a lot less sever though
10:50:32 sean-k-mooney yes
10:50:50 sean-k-mooney we have a downstream deadlien ot have that merged internally by next week
10:51:04 gibi and we have downstream proactive backport too ;)
10:51:05 sean-k-mooney but i would prefer to also have it merged upstream
10:51:51 johnthetubaguy I didn't see that one, yes, that should get some love too.
10:51:55 sean-k-mooney if we are doing a release we should ideally include both or do a second release once both are there
10:51:57 bauzas mmm, OK, I only tho see 'in progress' on ossa
10:52:09 bauzas so I guess that one isn't on mitre
10:52:37 bauzas nevermind me, it is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37394
10:52:52 bauzas but yeah, it's a dos
10:53:00 bauzas not a compute exposure
10:53:11 sean-k-mooney preventign the compute agent form stating
10:53:26 bauzas yup, hence the security level
10:53:39 sean-k-mooney from a public cloud perspecivive both are costly in different ways
10:53:55 bauzas we can try to land them at the same pace, but I don't want to wait more than one day if we can't due to them
10:54:29 bauzas sean-k-mooney: I tend to set a different priority on it
10:54:52 gibi I agree to not wait more than a day with a release if the latest cve fix lands
10:54:56 bauzas we're not talking of direct access to the host which could compromize all the dataplane
10:55:21 sean-k-mooney well that not quite what the other cve does
10:55:44 sean-k-mooney it can give you direct access to the file system but not the network
10:56:39 sean-k-mooney anyway fine lets continue but before i saw the new cve patches yesterday i had planned to ask use to prioites this older one in the team meeting yesterday
10:56:39 bauzas if you have access to the file system, you can access the network later
10:56:53 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (db) https://review.opendev.org/c/openstack/nova/+/831193
10:56:53 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (objects) https://review.opendev.org/c/openstack/nova/+/839401
10:56:54 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (manila abstraction) https://review.opendev.org/c/openstack/nova/+/831194
10:56:54 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (drivers and compute manager part) https://review.opendev.org/c/openstack/nova/+/833090
10:56:55 opendevreview ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (api) https://review.opendev.org/c/openstack/nova/+/836830
10:56:55 opendevreview ribaudr proposed openstack/nova master: Check shares support https://review.opendev.org/c/openstack/nova/+/850499
10:56:56 opendevreview ribaudr proposed openstack/nova master: Add metadata for shares https://review.opendev.org/c/openstack/nova/+/850500
10:56:57 opendevreview ribaudr proposed openstack/nova master: Add instance.share_attach notification https://review.opendev.org/c/openstack/nova/+/850501
10:56:57 opendevreview ribaudr proposed openstack/nova master: Add instance.share_detach notification https://review.opendev.org/c/openstack/nova/+/851028
10:56:59 opendevreview ribaudr proposed openstack/nova master: Add shares to InstancePayload https://review.opendev.org/c/openstack/nova/+/851029
10:56:59 opendevreview ribaudr proposed openstack/nova master: Add helper methods to attach/detach shares https://review.opendev.org/c/openstack/nova/+/852085
10:57:01 opendevreview ribaudr proposed openstack/nova master: Add libvirt test to ensure metadata are working. https://review.opendev.org/c/openstack/nova/+/852086
10:57:01 opendevreview ribaudr proposed openstack/nova master: Add virt/libvirt error test cases https://review.opendev.org/c/openstack/nova/+/852087
10:57:03 opendevreview ribaudr proposed openstack/nova master: Add share_info parameter to reboot method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/854823
10:57:03 opendevreview ribaudr proposed openstack/nova master: Support rebooting an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/854824
10:57:05 opendevreview ribaudr proposed openstack/nova master: Add instance.share_attach_error notification https://review.opendev.org/c/openstack/nova/+/860282
10:57:05 opendevreview ribaudr proposed openstack/nova master: Add instance.share_detach_error notification https://review.opendev.org/c/openstack/nova/+/860283
10:57:07 opendevreview ribaudr proposed openstack/nova master: Add share_info parameter to resume method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/860284
10:57:07 opendevreview ribaudr proposed openstack/nova master: Support resuming an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860285
10:57:09 opendevreview ribaudr proposed openstack/nova master: Add helper methods to rescue/unrescue shares https://review.opendev.org/c/openstack/nova/+/860286
10:57:09 opendevreview ribaudr proposed openstack/nova master: Support rescuing an instance with shares (driver part) https://review.opendev.org/c/openstack/nova/+/860287
10:57:11 opendevreview ribaudr proposed openstack/nova master: Support rescuing an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860288
10:57:11 opendevreview ribaudr proposed openstack/nova master: Change microversion to 2.XX https://review.opendev.org/c/openstack/nova/+/852088
10:57:13 opendevreview ribaudr proposed openstack/nova master: Documentation https://review.opendev.org/c/openstack/nova/+/871642
10:57:54 sean-k-mooney bauzas: have they confirmed that raw devices special files are actully usable im not sure file access imples network access
10:58:05 sean-k-mooney it would come down to the speicics of the vmdk impl
10:58:14 sean-k-mooney anyway we dont need to speculate
10:58:16 bauzas sean-k-mooney: I tested it by myself
10:58:29 bauzas and when I say it's nasty, trust me it is
10:58:51 sean-k-mooney ok well since this has been discusled upstream we now also need ot have it downstream by next week at the latest
11:01:42 johnthetubaguy bauzas: escation to something nasty should be assume with these things, for sure. Even if we can't see it yet.
11:02:49 sean-k-mooney johnthetubaguy: i was just thinking that if it was anythin like virtio-fs special files cant be accesed but i trust dan and bauzas when they say it was nasty
11:03:10 bauzas johnthetubaguy: sean-k-mooney: read the bug report
11:03:18 bauzas and the first comments, there is a reproducer
11:03:22 sean-k-mooney i have not reviewed the bug/cve in any detail rather just enduing the patches were moving last night
11:06:25 sean-k-mooney ok so on that reading it does not allow direct network access form the main descrption anyway lets not look for other ways to abuse this
11:06:59 sean-k-mooney if i try hard enough im sure i can come up with ways to make it worse and i really dont want to do that on a public channel

Earlier   Later