Earlier  
Posted Nick Remark
#openstack-nova - 2023-05-09
19:49:13 bauzas dansmith: now that we merged a lot of volume-related ssh stuff, I guess I only need to recheck https://review.opendev.org/c/openstack/nova/+/882052 ? or shall I rebase it from master ?
19:49:46 bauzas after a week, we're still unable to land this critical bugfix
19:49:57 dansmith did that fail on volume things?
19:50:09 bauzas yes, https://878773ae5f0379c9d548-8605f807f0b1cdc197533279c15edd0d.ssl.cf1.rackcdn.com/882052/1/check/tempest-integrated-compute-enforce-scope-new-defaults/2d80ba4/testr_results.html
19:50:46 bauzas (at least one test, not the second one which is a panicking guest)
19:50:51 dansmith bauzas: that failed with a kernel panic
19:51:08 dansmith unrelated to the things I've been working on fixing, but related to the thing I asked kashyap to try to chase down
19:51:27 dansmith but cirros 0.5.2's kernel being unsupported now, we don't really have any recourse
19:51:49 bauzas dansmith: but the first test failed on teardown after a timeout
19:52:05 dansmith because the guest was totally hung
19:53:36 bauzas oh, shit
19:53:43 dansmith bauzas: only one test failed, the first row is the teardown for the test that failed
19:53:54 bauzas missed that the first test failing is actually a teardownclass
19:53:59 bauzas yeah that
19:54:17 dansmith yeah
19:54:57 bauzas roger and do we have the cirros bug report ?
19:56:06 bauzas nvm, found it https://bugs.launchpad.net/nova/+bug/1939108
19:58:26 dansmith actually I have a newer one
19:58:48 dansmith although my kernel crash looks different than the one you have here
19:59:12 dansmith yours looks like that one in the above bug indeed
19:59:25 bauzas yup
19:59:26 dansmith mine is quite different, but we see it a fair bit too
19:59:45 dansmith https://bugs.launchpad.net/nova/+bug/2018612\
19:59:47 dansmith https://bugs.launchpad.net/nova/+bug/2018612
20:00:19 bauzas I see
20:00:23 bauzas different problem indeed
20:00:30 bauzas kernel taintaing
20:00:35 bauzas tainting*
20:00:38 dansmith yours looks like crash on startup, mine is on attach, I think
20:00:42 bauzas yes
20:00:47 bauzas the acpi boot fails
20:01:12 bauzas we also have a problem with udhcpd leases, related to cirros too
20:01:30 dansmith yeaj
20:41:58 opendevreview sean mooney proposed openstack/os-vif master: remove focal based jobs https://review.opendev.org/c/openstack/os-vif/+/882755
23:54:06 opendevreview Merged openstack/nova master: Revert "Debug Nova APIs call failures" https://review.opendev.org/c/openstack/nova/+/882052
23:54:22 dansmith last time's a charm ^
23:56:03 melwitt lol finally
#openstack-nova - 2023-05-10
05:54:27 opendevreview Amit Uniyal proposed openstack/nova master: Allow swap resize from non-zero to zero https://review.opendev.org/c/openstack/nova/+/857339
07:38:50 opendevreview Amit Uniyal proposed openstack/nova master: WIP: Reproducer for dangling volumes https://review.opendev.org/c/openstack/nova/+/881457
07:38:50 opendevreview Amit Uniyal proposed openstack/nova master: WIP: Delete dangling bdms https://review.opendev.org/c/openstack/nova/+/882284
08:54:39 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: [wip]network: convert usage of neutronclient to openstacksdk https://review.opendev.org/c/openstack/nova/+/882714
11:10:58 opendevreview Sahid Orentino Ferdjaoui proposed openstack/nova master: [wip]network: convert usage of neutronclient to openstacksdk https://review.opendev.org/c/openstack/nova/+/882714
13:20:19 sean-k-mooney sahid: when you have time can you take a look at https://review.opendev.org/c/openstack/os-vif/+/881751 and https://review.opendev.org/c/openstack/os-vif/+/882755
14:19:05 sahid sean-k-mooney: sure, sorry I just have noticed your message
14:23:21 sean-k-mooney sahid: no rush
14:40:26 opendevreview Dan Smith proposed openstack/nova master: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882847
14:53:25 opendevreview melanie witt proposed openstack/nova master: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882852
14:57:43 opendevreview melanie witt proposed openstack/nova stable/2023.1: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882858
14:57:44 opendevreview melanie witt proposed openstack/nova stable/2023.1: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882859
14:59:46 opendevreview melanie witt proposed openstack/nova stable/zed: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882860
14:59:47 opendevreview melanie witt proposed openstack/nova stable/zed: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882861
15:00:51 opendevreview melanie witt proposed openstack/nova stable/yoga: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882863
15:00:52 opendevreview melanie witt proposed openstack/nova stable/yoga: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882864
15:03:26 opendevreview melanie witt proposed openstack/nova stable/xena: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882867
15:03:27 opendevreview melanie witt proposed openstack/nova stable/xena: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882868
15:05:58 opendevreview melanie witt proposed openstack/nova stable/wallaby: Use force=True for os-brick disconnect during delete https://review.opendev.org/c/openstack/nova/+/882869
15:05:59 opendevreview melanie witt proposed openstack/nova stable/wallaby: Enable use of service user token with admin context https://review.opendev.org/c/openstack/nova/+/882870
17:01:57 dansmith need another quick +W on this to avoid a regression introduced in the CVE fix: https://review.opendev.org/c/openstack/nova/+/882852/1
17:01:59 dansmith sean-k-mooney: ^
17:02:07 dansmith gmann: ^
17:05:18 gmann dansmith: sure, checking
17:23:21 gmann dansmith: so this is not that CVE fix regression but before also this exist right? I mean admin token was not made as service token ?
17:23:34 gmann or cinder had put the check about service token instead of just admin
17:24:10 dansmith gmann: we didn't need service token for these admins contexts before.. there was literally no reason,
17:24:16 dansmith so it's not a regression without the CVE fix (from cinder)
17:24:34 dansmith however now we *do* need service users for things other than long-running user activities
17:24:35 gmann I see, so now cinder API check service token or not.
17:24:38 dansmith right
17:24:43 gmann got it
17:26:14 gmann +W
17:26:46 dansmith gmann: thanks :)
17:29:34 sean-k-mooney dansmith: sorry distracted but i was starting to review those now too
17:29:52 dansmith ack, I think we're good now
17:30:20 dansmith sailed through zuul first time.. probably because some awesome guy did a bunch of volume test hardening the last few weeks :P
17:30:32 dansmith or luck. yeah, it's probably luck :)
17:30:44 sean-k-mooney :)
17:31:04 sean-k-mooney there is a serprising amouth of doc updates in the previos patch
17:31:05 gmann I am sure its a special treatment given for volume test fixes :)
17:31:29 dansmith sean-k-mooney: yeah it's a pretty big change required for deployers
17:31:40 sean-k-mooney not that im complaing really but i was expecing ti to be more targeted
17:31:51 sean-k-mooney ack i have not read it all yet but that was just my intial reaction
17:31:57 dansmith no real option to be targeted unfortunately
17:32:12 dansmith a bunch of smart people spent the last 90 days trying to figure out a better way to do it
17:33:33 sean-k-mooney ok so the service user is now required
17:33:54 sean-k-mooney ok
17:34:45 dansmith the ossa went to the ML with more summary which might be good reading
17:35:01 sean-k-mooney ill read that after
17:35:12 sean-k-mooney we debated making the service user required in the past
17:35:26 sean-k-mooney not that it is we can use that for other usecases going forward
17:35:32 dansmith yup
17:35:42 sean-k-mooney like the manila stuff
17:35:57 dansmith yup, it was hard not to mention this during that discussion :)
17:36:11 dansmith seems like we could extend that to neutron and avoid nova having to be admin too
17:36:12 sean-k-mooney or any other interaction with other service where we need service to service interaction
17:36:18 dansmith yup
17:36:25 sean-k-mooney yep
17:36:43 sean-k-mooney we could simply nova config ot just need service user and no other sections for other services
17:36:50 sean-k-mooney at least by defualt
17:36:53 dansmith it's unfortunate to have to force that on a bunch of old deployments without a grace period, but.. not much choice
17:37:23 sean-k-mooney for what its worth i think many installer tools started using the service user a few years ago by default

Earlier   Later