Earlier  
Posted Nick Remark
#openstack-nova - 2023-05-23
16:31:30 bauzas #info As a reminder, cores eager to review changes can +1 to indicate their interest, +2 for committing to the review
16:32:06 bauzas #topic Stable Branches
16:32:10 bauzas elodilles: your turn !
16:32:14 elodilles o/
16:32:16 elodilles #info stable nova release patches merged on Wednesday: 2023.1 Antelope (27.1.0), Zed (26.2.0), Yoga (25.2.0)
16:32:22 bauzas huzzah
16:32:26 elodilles so these have been released ^^^ \o/
16:32:38 elodilles #info stable/wallaby is unblocked as gmann's nova-ceph-multistore job fix has merged (thanks!) -- https://review.opendev.org/871920
16:32:54 bauzas those include the CVE 2023-2088 fixes, I'm happy to have them now :)
16:33:07 elodilles bauzas: yepp
16:33:12 bauzas huzzah again
16:33:19 elodilles :]
16:33:19 bauzas about the ceph-multistore problem
16:33:32 elodilles yepp-yepp
16:33:36 elodilles #info stable/train is blocked by failing openstacksdk-functional-devstack job
16:33:42 bauzas doh
16:33:54 elodilles this is probably because of heat's stable/train eol
16:34:18 elodilles i'm looking at multiple ways of possibilities to unblock the gate
16:34:33 elodilles will see which is the best / working :P
16:34:47 elodilles and the general info:
16:34:53 elodilles #info stable branch status / gate failures tracking etherpad: https://etherpad.opendev.org/p/nova-stable-branch-ci
16:35:01 elodilles EOM
16:35:41 bauzas about Train, given some parts of the universe started to EOL it
16:35:51 bauzas then, my question is, should we copy them ?
16:36:05 elodilles heat EOL'd their ussuri as well
16:36:08 bauzas I know that my paycheck comes partly from Train, but that's still a question to me
16:36:33 elodilles bauzas: i still say that until we can merge patches (hehh) we can keep it open o:)
16:37:42 bauzas stable/train also doesn't include the previous CVE fix you know ;)
16:38:08 elodilles hmmm, i forgot that
16:38:23 elodilles though there are some who still wanted rocky to accept patches ;)
16:38:48 bauzas I'm not only talking of the brick CVE
16:38:57 bauzas I'm also taking of the VMDK CVE
16:39:24 bauzas if people want to risk their lifes, I'm OK
16:39:37 elodilles good point
16:39:44 bauzas but that is still two serious security flaws that haven't been fixed
16:39:45 elodilles i cannot ague with that
16:39:57 sean-k-mooney i would may keep it alive for a few more months and ask operators at the summit
16:40:15 sean-k-mooney but i could see use retiring it after bobcat in either case
16:40:30 dansmith I'm fine (and prefer) to keep branches available, but if we're maintaining part of it but not backporting critical CVEs it really sends a mixed message
16:40:45 bauzas dansmith: that's my whole point
16:40:46 dansmith mixed and confusing I would say
16:40:57 elodilles dansmith: true
16:41:57 sean-k-mooney the vmdk cve however makes me more inclided to say we should be keeping train
16:41:59 bauzas dansmith: we can't reasonably say we're open to keep a branch open and accept backports if the most critical ones aren't done
16:42:35 sean-k-mooney we fixed it downstream in our train based product but it causes a lot fo pain because it had a bug that would have been caught if we fixed it upstream instead
16:42:40 dansmith bauzas: I just like the branches to be open over tags personally, but if people see "last commit X days ago" they're likely to assume that some of those commits are critical fixes
16:42:42 bauzas sean-k-mooney: train doesn't include the vmdk fix
16:42:48 sean-k-mooney i know
16:42:55 bauzas ah, missed your poiint
16:43:18 bauzas sean-k-mooney: truly, we missed something downstream because we lacked some upstream backport
16:43:23 sean-k-mooney if we had fixed the cve via the upstream backport process it would have caught the missing patch we had downstream
16:43:57 bauzas but the upstream branch isn't really arguably in a good shape if the two most major CVEs that I know since a decade aren't fixed
16:44:11 sean-k-mooney well they could be fixed
16:44:26 sean-k-mooney we just dont have peopel volentering to fix it
16:44:32 bauzas sean-k-mooney: true, and this hadn't been done because of the way we manage our dependencies upstream is tough
16:44:50 dansmith right the point is that we're not meant to be maintaining these.. so we either need to do it, or stop *signaling* that we're doing it
16:45:05 bauzas +1
16:45:06 sean-k-mooney yep
16:45:30 bauzas the brick CVE isn't AFAIK proposed against train now
16:45:31 dansmith so I guess I'll say I'm +1 for EOLing train
16:46:08 bauzas so, honestly, if we want to keep train, let's do the efforts to backport both CVE fixes to train
16:46:13 dansmith are we even sync/importing from train downstream anymore?
16:46:21 bauzas don't look at me, I'm not rushing to do it
16:46:35 sean-k-mooney we are
16:46:51 sean-k-mooney but our last release that will do that is planed for q3
16:47:00 sean-k-mooney so after bobcat is release we wont be
16:47:09 bauzas don't speak redhat greek in this channel please :)
16:47:49 sean-k-mooney well the point being that we will stop consuming form the stable branch anyway in the next few months
16:47:56 dansmith right
16:47:56 sean-k-mooney for our downstream uses
16:48:24 bauzas yeah, but we still don't provide the CVE fixes to it ? :)
16:48:53 sean-k-mooney you know i orgianly wanted use to fix both of those on upstream train right
16:49:08 dansmith sean-k-mooney: so then why didn't you?
16:49:33 sean-k-mooney i asked the peopel that did the backprot to do it
16:49:35 bauzas we all have priorities and I don't blame anyone
16:50:03 bauzas particularly me, since I was owning the backports for the VMDK one and I intentionally skipped the train one
16:50:35 bauzas because it would have required some oslo.utils release number belly dance
16:51:16 bauzas and as a reminder, Extended Maintenance is clear on its intents
16:51:26 dansmith bauzas: exactly
16:51:31 bauzas https://docs.openstack.org/project-team-guide/stable-branches.html#extended-maintenance
16:52:40 bauzas anyway, seems we won't reach a consensus, but I can propose to send an email to openstack-discuss
16:52:52 bauzas we'll see if people argue
16:53:57 bauzas #action bauzas to send an email to -discuss to gauge the freakiness of EOLing stable/train now
16:54:33 bauzas I guess we're done with this hot topic
16:54:54 bauzas #topic Open Discussion
16:54:58 bauzas nothing on the agenda
16:55:16 bauzas is anyone having a thought to share with the team ?
16:56:47 bauzas looks not
16:56:55 bauzas sorry this week I won't save too much of your time
16:56:59 bauzas thanks all
16:57:03 bauzas #endmeeting
16:57:03 opendevmeet Meeting ended Tue May 23 16:57:03 2023 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)
16:57:03 opendevmeet Minutes: https://meetings.opendev.org/meetings/nova/2023/nova.2023-05-23-16.01.html
16:57:03 opendevmeet Minutes (text): https://meetings.opendev.org/meetings/nova/2023/nova.2023-05-23-16.01.txt
16:57:03 opendevmeet Log: https://meetings.opendev.org/meetings/nova/2023/nova.2023-05-23-16.01.log.html
16:58:04 gibi thanks
16:58:20 elodilles thanks o/
16:59:35 Uggla_ thx
#openstack-nova - 2023-05-24
14:59:01 opendevreview Merged openstack/nova stable/yoga: Ironic: retry when node not available https://review.opendev.org/c/openstack/nova/+/868010
17:56:02 melwitt dansmith: fyi this is a fix for our subclass signature checker test that detects when volume drivers are not matching the base class https://review.opendev.org/c/openstack/nova/+/883217 I found it wasn't working when I was working on the cve stuff. it would have caught the issue with the wallaby patch

Earlier   Later