| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2023-01-25 | |||
| 10:41:51 | sean-k-mooney | it does but i didnt tink it warrented it | |
| 10:41:58 | sean-k-mooney | but if other are happy then ok | |
| 10:42:09 | sean-k-mooney | i just wont try and babysit the patches today | |
| 10:42:15 | gibi | at least bauzas, johnthetubaguy, elodilles and myself was OK with it | |
| 10:43:00 | johnthetubaguy | sean-k-mooney: I am curious, why do you think its not urgent enough? | |
| 10:44:03 | sean-k-mooney | form my perspective there is nothign preventing a downstream form merging them once its proposed. and for anyone that ues a release i.e. form pypi its not going to get it to them faster. those that use source builds can use the gerrit version | |
| 10:44:25 | opendevreview | John Garbutt proposed openstack/nova stable/victoria: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871699 | |
| 10:44:35 | sean-k-mooney | i was still expecting them to all merge today or tommorrow without needing to do it in parallel | |
| 10:44:39 | gibi | sean-k-mooney: I assume we will propose a stable release as soon as a stable patch lands | |
| 10:45:29 | sean-k-mooney | i think anyone who is going to deploy that by the end of the week would jsut take the patch and do it them selevs | |
| 10:45:32 | gibi | sean-k-mooney: given the gate speed parallel is lot faster than sequential when we need to do 7 backports | |
| 10:46:05 | sean-k-mooney | the gate is fast if this is the only thing we are merging | |
| 10:46:40 | gibi | gate is unstable regardles of the number of patches on it, also we have no power over how other projects using the gate resources | |
| 10:46:50 | sean-k-mooney | if we are merging things in parallel less so but as i said im fine with it i just dont think we needed it. i was still expecting all these to be merged by tomrrow either ay | |
| 10:47:18 | sean-k-mooney | gibi: i didnt mean other project i ment lets not merge anything that would put these in merge conflict | |
| 10:47:49 | sean-k-mooney | anyway ill leave this to ye since ye have a plan | |
| 10:48:04 | bauzas | sean-k-mooney: I don't disagree with you, and I expressed the fact that we need anyway need to release so those fixes could be eventually helpful | |
| 10:48:11 | gibi | I think the merge conflict is just a small percent of why serial merge would be slower here. It is more like rechecks and waiting for the patch on the newer branch that slow sequential down | |
| 10:48:25 | opendevreview | John Garbutt proposed openstack/nova stable/ussuri: [stable-only][cve] Check VMDK create-type against an allowed list https://review.opendev.org/c/openstack/nova/+/871702 | |
| 10:48:28 | bauzas | but it occurred from johnthetubaguy that we could rush the things a little bit up | |
| 10:48:52 | bauzas | and eventually I joined the 'rush' team when I saw our stable policy was accepting it | |
| 10:49:05 | sean-k-mooney | we have a second CVE fix with backprots that need review upstream | |
| 10:49:07 | bauzas | sean-k-mooney: just explaining my thoughts journey | |
| 10:49:23 | sean-k-mooney | if we are going to do a release we proably shoudl also merge that with the same speed | |
| 10:49:42 | bauzas | sean-k-mooney: that's understandable, despite that one was pretty nasty | |
| 10:49:53 | bauzas | sean-k-mooney: patches ? | |
| 10:50:07 | sean-k-mooney | looking for them now | |
| 10:50:11 | bauzas | I only remember the former-embargoed one which is now public | |
| 10:50:17 | gibi | https://review.opendev.org/q/topic:bug%252F1981813 | |
| 10:50:22 | gibi | I think sean-k-mooney refers to ^^ | |
| 10:50:28 | gibi | it is a lot less sever though | |
| 10:50:32 | sean-k-mooney | yes | |
| 10:50:50 | sean-k-mooney | we have a downstream deadlien ot have that merged internally by next week | |
| 10:51:04 | gibi | and we have downstream proactive backport too ;) | |
| 10:51:05 | sean-k-mooney | but i would prefer to also have it merged upstream | |
| 10:51:51 | johnthetubaguy | I didn't see that one, yes, that should get some love too. | |
| 10:51:55 | sean-k-mooney | if we are doing a release we should ideally include both or do a second release once both are there | |
| 10:51:57 | bauzas | mmm, OK, I only tho see 'in progress' on ossa | |
| 10:52:09 | bauzas | so I guess that one isn't on mitre | |
| 10:52:37 | bauzas | nevermind me, it is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37394 | |
| 10:52:52 | bauzas | but yeah, it's a dos | |
| 10:53:00 | bauzas | not a compute exposure | |
| 10:53:11 | sean-k-mooney | preventign the compute agent form stating | |
| 10:53:26 | bauzas | yup, hence the security level | |
| 10:53:39 | sean-k-mooney | from a public cloud perspecivive both are costly in different ways | |
| 10:53:55 | bauzas | we can try to land them at the same pace, but I don't want to wait more than one day if we can't due to them | |
| 10:54:29 | bauzas | sean-k-mooney: I tend to set a different priority on it | |
| 10:54:52 | gibi | I agree to not wait more than a day with a release if the latest cve fix lands | |
| 10:54:56 | bauzas | we're not talking of direct access to the host which could compromize all the dataplane | |
| 10:55:21 | sean-k-mooney | well that not quite what the other cve does | |
| 10:55:44 | sean-k-mooney | it can give you direct access to the file system but not the network | |
| 10:56:39 | sean-k-mooney | anyway fine lets continue but before i saw the new cve patches yesterday i had planned to ask use to prioites this older one in the team meeting yesterday | |
| 10:56:39 | bauzas | if you have access to the file system, you can access the network later | |
| 10:56:53 | opendevreview | ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (db) https://review.opendev.org/c/openstack/nova/+/831193 | |
| 10:56:53 | opendevreview | ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (objects) https://review.opendev.org/c/openstack/nova/+/839401 | |
| 10:56:54 | opendevreview | ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (manila abstraction) https://review.opendev.org/c/openstack/nova/+/831194 | |
| 10:56:54 | opendevreview | ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (drivers and compute manager part) https://review.opendev.org/c/openstack/nova/+/833090 | |
| 10:56:55 | opendevreview | ribaudr proposed openstack/nova master: Attach Manila shares via virtiofs (api) https://review.opendev.org/c/openstack/nova/+/836830 | |
| 10:56:55 | opendevreview | ribaudr proposed openstack/nova master: Check shares support https://review.opendev.org/c/openstack/nova/+/850499 | |
| 10:56:56 | opendevreview | ribaudr proposed openstack/nova master: Add metadata for shares https://review.opendev.org/c/openstack/nova/+/850500 | |
| 10:56:57 | opendevreview | ribaudr proposed openstack/nova master: Add instance.share_attach notification https://review.opendev.org/c/openstack/nova/+/850501 | |
| 10:56:57 | opendevreview | ribaudr proposed openstack/nova master: Add instance.share_detach notification https://review.opendev.org/c/openstack/nova/+/851028 | |
| 10:56:59 | opendevreview | ribaudr proposed openstack/nova master: Add shares to InstancePayload https://review.opendev.org/c/openstack/nova/+/851029 | |
| 10:56:59 | opendevreview | ribaudr proposed openstack/nova master: Add helper methods to attach/detach shares https://review.opendev.org/c/openstack/nova/+/852085 | |
| 10:57:01 | opendevreview | ribaudr proposed openstack/nova master: Add libvirt test to ensure metadata are working. https://review.opendev.org/c/openstack/nova/+/852086 | |
| 10:57:01 | opendevreview | ribaudr proposed openstack/nova master: Add virt/libvirt error test cases https://review.opendev.org/c/openstack/nova/+/852087 | |
| 10:57:03 | opendevreview | ribaudr proposed openstack/nova master: Add share_info parameter to reboot method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/854823 | |
| 10:57:03 | opendevreview | ribaudr proposed openstack/nova master: Support rebooting an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/854824 | |
| 10:57:05 | opendevreview | ribaudr proposed openstack/nova master: Add instance.share_attach_error notification https://review.opendev.org/c/openstack/nova/+/860282 | |
| 10:57:05 | opendevreview | ribaudr proposed openstack/nova master: Add instance.share_detach_error notification https://review.opendev.org/c/openstack/nova/+/860283 | |
| 10:57:07 | opendevreview | ribaudr proposed openstack/nova master: Add share_info parameter to resume method for each driver (driver part) https://review.opendev.org/c/openstack/nova/+/860284 | |
| 10:57:07 | opendevreview | ribaudr proposed openstack/nova master: Support resuming an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860285 | |
| 10:57:09 | opendevreview | ribaudr proposed openstack/nova master: Add helper methods to rescue/unrescue shares https://review.opendev.org/c/openstack/nova/+/860286 | |
| 10:57:09 | opendevreview | ribaudr proposed openstack/nova master: Support rescuing an instance with shares (driver part) https://review.opendev.org/c/openstack/nova/+/860287 | |
| 10:57:11 | opendevreview | ribaudr proposed openstack/nova master: Support rescuing an instance with shares (compute and API part) https://review.opendev.org/c/openstack/nova/+/860288 | |
| 10:57:11 | opendevreview | ribaudr proposed openstack/nova master: Change microversion to 2.XX https://review.opendev.org/c/openstack/nova/+/852088 | |
| 10:57:13 | opendevreview | ribaudr proposed openstack/nova master: Documentation https://review.opendev.org/c/openstack/nova/+/871642 | |
| 10:57:54 | sean-k-mooney | bauzas: have they confirmed that raw devices special files are actully usable im not sure file access imples network access | |
| 10:58:05 | sean-k-mooney | it would come down to the speicics of the vmdk impl | |
| 10:58:14 | sean-k-mooney | anyway we dont need to speculate | |
| 10:58:16 | bauzas | sean-k-mooney: I tested it by myself | |
| 10:58:29 | bauzas | and when I say it's nasty, trust me it is | |
| 10:58:51 | sean-k-mooney | ok well since this has been discusled upstream we now also need ot have it downstream by next week at the latest | |
| 11:01:42 | johnthetubaguy | bauzas: escation to something nasty should be assume with these things, for sure. Even if we can't see it yet. | |
| 11:02:49 | sean-k-mooney | johnthetubaguy: i was just thinking that if it was anythin like virtio-fs special files cant be accesed but i trust dan and bauzas when they say it was nasty | |
| 11:03:10 | bauzas | johnthetubaguy: sean-k-mooney: read the bug report | |
| 11:03:18 | bauzas | and the first comments, there is a reproducer | |
| 11:03:22 | sean-k-mooney | i have not reviewed the bug/cve in any detail rather just enduing the patches were moving last night | |
| 11:06:25 | sean-k-mooney | ok so on that reading it does not allow direct network access form the main descrption anyway lets not look for other ways to abuse this | |
| 11:06:59 | sean-k-mooney | if i try hard enough im sure i can come up with ways to make it worse and i really dont want to do that on a public channel | |
| 11:09:56 | bauzas | +1 | |
| 11:18:32 | zigo | bauzas: I'll push my patches in a bit... | |
| 11:18:39 | zigo | FYI, I got Stein fixed too... :) | |
| 11:18:54 | zigo | Stein -> Rocky backport seems another tricky one... | |
| 12:13:24 | priteau | Anyone know why grenade keeps failing on stable/wallaby with the vmdk patch? | |
| 12:38:07 | opendevreview | Merged openstack/nova stable/yoga: Reproduce bug 1981813 in func env https://review.opendev.org/c/openstack/nova/+/859312 | |
| 12:53:29 | zigo | I also got Rocky in shape! :P | |
| 13:15:18 | opendevreview | Merged openstack/nova stable/yoga: Gracefully ERROR in _init_instance if vnic_type changed https://review.opendev.org/c/openstack/nova/+/859313 | |
| 13:22:25 | bauzas | sent the xena patches for ^ to the gate | |
| 13:22:43 | bauzas | passports* even | |