Earlier  
Posted Nick Remark
#openstack-nova - 2023-03-01
18:07:29 dansmith yeah because I definitely didn't
18:07:30 bauzas well
18:07:47 bauzas we are trying to untangle the oddness of ssh negociation
18:07:48 dansmith and I have a bunch of hacks in my own ssh_config that probably need revisiting now that more of my systems are upgraded
18:07:56 bauzas me too
18:08:10 bauzas this discussion is half-workwise, halp-personalwise
18:08:14 sean-k-mooney ok i got burned by this years ago and have helped other fix it in the past so i mostly just accpet it at this point
18:08:36 bauzas I just shamelessly tuned the signature negociation on the fly with my ssh_config
18:09:04 bauzas as I didn't wanted to generate a new pair of ECDSA or something else keys
18:09:15 sean-k-mooney ya i still have PubkeyAcceptedKeyTypes +ssh-rsa for one site in my config
18:09:20 sean-k-mooney but i think thats offline
18:09:41 bauzas but now if I understand correctly, I could rather continue to use my RSA keys but ask for a different signature
18:09:58 sean-k-mooney i also still have
18:10:01 sean-k-mooney host review.opendev.org
18:10:01 bauzas using rsa-sha2
18:10:03 sean-k-mooney HostKeyAlgorithms ssh-rsa
18:10:05 sean-k-mooney KexAlgorithms +diffie-hellman-group1-sha1
18:10:07 sean-k-mooney Ciphers +aes128-cbc
18:10:12 sean-k-mooney for some reason witch i relly dont need
18:10:46 clarkb bauzas: correct. The problem is that some servers don't know how to negotiate that with you like old dropbear and old gerrit
18:10:49 sean-k-mooney thats what i treid when PubkeyAcceptedKeyTypes +ssh-rsa stopped working for gerrit
18:11:17 bauzas clarkb: so the per-host config is still required, gotcha
18:11:19 clarkb the gerrit we have deployed at review.opendev.org should work fine though. ianw and I worked with gerrit and mina sshd upstream and got that all fixed and eventually got it backported to gerrit 3.5 (it was always on 3.6)
18:11:42 clarkb bauzas: if the servers don't know how to negotiate rsa + sha2
18:11:48 clarkb review.opendev.org should not need this anymore
18:11:49 bauzas yeah got it
18:12:02 bauzas clarkb: how to enable rsa+sha2 globally in the config ?
18:12:24 clarkb bauzas: if your openssh client is new (like on fedora or jammy etc) then thats the only version they will use by default
18:12:25 bauzas because I assume my current OS doesn't have its defaults changed
18:12:35 bauzas oh
18:12:52 clarkb thats why it failed to talk to cirros. jammy will only use rsa + sha2 by default, but cirros dropbear will only do rsa + sha1
18:13:02 clarkb this mismatch leads to a failure to negotiate between them and no ssh connection
18:13:04 sean-k-mooney i think you would add PubkeyAcceptedKeyTypes rsa-sha2-256
18:13:16 sean-k-mooney under "HOST *"
18:13:18 clarkb sean-k-mooney: that shouldn't be necessary its automatic
18:13:27 clarkb since all the new lcients only do sha2
18:13:28 bauzas hmmm
18:13:43 sean-k-mooney ya it should not but if you wanted to force it that would be how
18:14:08 bauzas yeah got it
18:14:23 bauzas this chat is definitely a helper
18:14:26 bauzas clarkb: thanks a lot !
18:15:37 sean-k-mooney i really would like to just upload a pulic key to keystone and use that to authenticate with osc
18:23:28 sean-k-mooney bauzas: for what its woth its in te seciryt enhancmetns secation fo the 22.04 release notes https://discourse.ubuntu.com/t/jammy-jellyfish-release-notes/24668
18:25:45 sean-k-mooney it was disabled by defult in openssh https://www.openssh.com/txt/release-8.8
18:26:35 sean-k-mooney after being deprecated in 8.3 https://lwn.net/Articles/821544/
18:42:07 clarkb right but they didn't change the fallback key
18:42:33 clarkb so there are layers of problems here. The first is that you can no longer negotiate ssh-rsa with servers that need it. Second is that when that negotiate fails both sides expect ssh-rsa
18:42:40 clarkb which of course fails making the fallback useless
18:43:23 clarkb they should've changed the fallback to rsa-sha-256 so that clients would attempt that after a failed negotiation. This wold still fail on cirros but would've worked with gerrit
18:52:24 opendevreview Merged openstack/nova stable/victoria: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866086
22:39:08 opendevreview Dan Smith proposed openstack/nova master: Add grenade-skip-level-always to nova https://review.opendev.org/c/openstack/nova/+/875773
23:59:05 opendevreview melanie witt proposed openstack/nova master: testing: Reset affinity support global variables https://review.opendev.org/c/openstack/nova/+/875991
#openstack-nova - 2023-03-02
08:47:41 opendevreview Jorge San Emeterio proposed openstack/nova master: Have host look for CPU controller of cgroupsv2 location. https://review.opendev.org/c/openstack/nova/+/873127
09:12:01 opendevreview Sylvain Bauza proposed openstack/nova master: Add service version for Antelope https://review.opendev.org/c/openstack/nova/+/874932
09:12:02 opendevreview Sylvain Bauza proposed openstack/nova master: DNM (yet) Update min support for Bobcat https://review.opendev.org/c/openstack/nova/+/875621
09:14:06 bauzas gibi: I'd appreciate your review on both https://review.opendev.org/c/openstack/nova/+/874932/5 and https://review.opendev.org/c/openstack/nova/+/875380
09:33:37 kgube Hi! So, I ran out of time with the implementation of my specs that got accepted for antelope and I want to resubmit them for bobcat.
09:33:40 kgube Should I create a new change for this, or is it possible to reuse the old change, even though it was already merged, to keep previous discussions?
09:35:46 gibi bauzas: on it
09:37:00 Uggla Hi gibi, I need help regarding this comment https://review.opendev.org/c/openstack/nova/+/851029/19/doc/notification_samples/common_payloads/InstancePayload.json#42. As InstancePayload is the "root" of all notifications, I can not change it adding a share as it will impact all notifications tests. Is there a way to do that without copying this file and calling it only on specific cases ?
09:51:48 gibi bauzas: Im OK with the prelude, I left comments in the service version patch
09:52:08 gibi Uggla: looking
09:52:50 gibi Uggla: duplicate the file and use it for the share related notification samples
09:53:31 gibi Uggla: alternativel you could manipulate the sample in the test code but that would be missleading
09:54:09 gibi you are right we probably don't want to add shares for each notification test
09:54:31 gibi still we want to have samples with shares as that is basically our API definition
09:56:16 Uggla @gibi, ok if I duplicate, then it will be documented automatically or should I do something special ?
10:05:29 gibi Uggla: the doc generation happens via the @base.notification_sample decorators
10:06:21 gibi doc generation code is here https://github.com/openstack/nova/blob/master/doc/ext/versioned_notifications.py
10:07:33 gibi so if you create a sample that has shares
10:07:51 gibi then you need to add that to the related class via the @base.notification_sample
10:07:55 gibi decorator
10:08:31 gibi kgube: do you mean resubmitting the spec?
10:09:13 gibi kgube: if so then you need a new change, but you can copy the already approved spec there. And please note that this is a re-propose in the commit message so that people can look at the old discussion
10:14:53 bauzas sorry folks, was in meeting
10:15:00 bauzas gibi: ack, will be looking
10:15:23 bauzas kgube: the bobcat specs directory is now present, you can indeed resubmit
10:15:38 bauzas like gibi said, just copy the rst file and mention it was previously-approved
10:16:13 bauzas so you would benefit from a straight fast-approval if no modification is made in the spec file besides the mention of the previous approval
10:16:30 bauzas see other specs in Antelope, that pattern is often used :)
10:18:07 Uggla gibi ok, I ll check
10:20:46 kgube bauzas, gibi: alright, thanks!
10:47:05 opendevreview Merged openstack/nova stable/train: Refactor volume connection cleanup out of _post_live_migration https://review.opendev.org/c/openstack/nova/+/864670
10:47:14 opendevreview Merged openstack/nova stable/train: Adds a repoducer for post live migration fail https://review.opendev.org/c/openstack/nova/+/863806
11:18:57 opendevreview Sylvain Bauza proposed openstack/nova master: Add service version for Antelope https://review.opendev.org/c/openstack/nova/+/874932
11:18:57 opendevreview Sylvain Bauza proposed openstack/nova master: DNM (yet) Update min support for Bobcat https://review.opendev.org/c/openstack/nova/+/875621
11:34:53 opendevreview Danylo Vodopianov proposed openstack/os-traits master: Add 'COMPUTE_NET_VIRTIO_PACKED' https://review.opendev.org/c/openstack/os-traits/+/876069
11:47:59 opendevreview Danylo Vodopianov proposed openstack/nova master: Packed virtqueue support was added. https://review.opendev.org/c/openstack/nova/+/876075
11:55:07 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Have schema for 'lock' action be applied to all microversions. https://review.opendev.org/c/openstack/nova/+/875653
13:37:53 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Have schema for 'lock' action be applied to all microversions. https://review.opendev.org/c/openstack/nova/+/875653
13:47:32 bauzas man, the gate is sloooooow https://zuul.openstack.org/status#873584
13:47:52 elodilles bauzas: it's rc1 day :D
13:48:07 bauzas elodilles: we may need to defer RC1 branching tomorrow given that
13:48:16 elodilles :S
13:48:42 bauzas I'm fighting against treadmills, y'know
13:49:01 elodilles actually, talked a bit about this with gibi at today's lunch :)
13:49:14 elodilles until -1 is on the patch, release team will wait
13:49:19 opendevreview Jorge San Emeterio proposed openstack/nova master: WIP: Have schema for 'lock' action be applied to all microversions. https://review.opendev.org/c/openstack/nova/+/875653
13:49:40 bauzas elodilles: gibi: damn I should take my car and visit you
13:50:01 elodilles bauzas: sure, anytime, we are here :)

Earlier   Later