opendevreview | Clark Boylan proposed opendev/system-config master: Update our base container images https://review.opendev.org/c/opendev/system-config/+/897270 | 00:04 |
---|---|---|
opendevreview | Merged opendev/system-config master: Update our base container images https://review.opendev.org/c/opendev/system-config/+/897270 | 01:20 |
tonyb | What clarkb: Whay add the 'dist-upgrade' ?? in ^^ was something missing in the update? I don't have a problem with it just curious | 01:34 |
tonyb | Wow, english seems to be hard for me today | 01:35 |
opendevreview | OpenStack Proposal Bot proposed openstack/project-config master: Normalize projects.yaml https://review.opendev.org/c/openstack/project-config/+/897273 | 02:14 |
frickler | diablo_rojo: ack, so far it looks good, will try to move other sessions around that. just please move it to use meetpad instead of zoom | 04:38 |
NeilHanlon | x-post here for visibility -- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt | 12:03 |
fungi | yep, been keeping an eye on package updates. working on triggering new debian-based container images | 12:04 |
fungi | ubuntu packages for the servers shouldn't be far behind | 12:04 |
fungi | http://changelogs.ubuntu.com/changelogs/pool/main/g/glibc/glibc_2.35-0ubuntu3.4/changelog | 12:05 |
fungi | that's already in jammy-updates | 12:05 |
fungi | 2023-10-04 06:10:57 status installed libc-bin:amd64 2.35-0ubuntu3.4 | 12:06 |
fungi | from the dpkg.log on one of our servers i happened to be logged into already | 12:06 |
fungi | if only the exim/libspf2 vulnerabilities had been coordinated this well | 12:07 |
opendevreview | daniel.pawlik proposed zuul/zuul-jobs master: Add workaround for resolving DNS hostname in pod; add dns test https://review.opendev.org/c/zuul/zuul-jobs/+/896646 | 12:11 |
NeilHanlon | fungi: one can only hope the coordination continues to get better :) | 12:13 |
fungi | yup | 12:13 |
NeilHanlon | fwiw rocky has a mitigation for rocky 9 in our sig/security repository | 12:13 |
NeilHanlon | https://git.rockylinux.org/sig/security/src/glibc/-/blob/1bb322095e1c0589ded0aa93cf58afb54db2bcee/SOURCES/glibc-owl-alt-sanitize-env.patch | 12:14 |
fungi | noticing the "owl" in there. i saw the post solar made to oss-security about working with rocky, that's awesome | 12:14 |
NeilHanlon | yeah i'm pretty excited by it | 12:15 |
opendevreview | daniel.pawlik proposed zuul/zuul-jobs master: Add feature to set --vm-driver name for minikube https://review.opendev.org/c/zuul/zuul-jobs/+/894755 | 12:25 |
fungi | and i guess the next big preannounced vulnerability is for curl/libcurl, details coming one week from today | 12:32 |
opendevreview | Michal Nasiadka proposed openstack/project-config master: Add nested-virt-debian-bookworm https://review.opendev.org/c/openstack/project-config/+/897331 | 12:47 |
opendevreview | daniel.pawlik proposed zuul/zuul-jobs master: DNM Add workaround for unqualified-search in Minikube https://review.opendev.org/c/zuul/zuul-jobs/+/897337 | 14:18 |
clarkb | I'm going to stop nodepool-builder on nb04 again (the hourly job restarted it at some point) and then reboot the server. My file deletions compelted and we do have some successful builds now. I want to reboot for completeness | 15:17 |
clarkb | #status log Cleared /opt/dib_tmp on nb04 and rebooted the server to reset mounts. This should fix arm64 image builds | 15:22 |
opendevstatus | clarkb: finished logging | 15:22 |
opendevreview | Clark Boylan proposed opendev/system-config master: Fix python-builder container image system updates https://review.opendev.org/c/opendev/system-config/+/897342 | 15:34 |
fungi | yay, ubuntu got exim fixes pushed out for jammy and focal! i've gone ahead and forced an upgrade of those on the listservs, since they're the places we accept incoming smtp | 15:49 |
clarkb | the latest openssh release switches ssh-keygen to produce ed25519 keys by default | 16:06 |
clarkb | that seems like a good indication we should probably just cave into the new key type | 16:06 |
clarkb | infra-root if you have time for https://review.opendev.org/c/opendev/system-config/+/897342 it should be a quite review | 19:25 |
clarkb | I want to make sure that is in sync across the base images | 19:25 |
clarkb | the arm64 images seem to building successfully very slowly | 20:25 |
clarkb | I've gone ahead and approved https://review.opendev.org/c/opendev/system-config/+/897342 since it is a small cleanup | 21:24 |
clarkb | tomorrow morning I've got the gerrit community meeting and then a dentist appointment | 21:25 |
clarkb | Afterwards it might be a good time to land https://review.opendev.org/c/opendev/system-config/+/897244 and upgrade gitea if reviewers are happy with it | 21:25 |
clarkb | re etherpad upgrade the more I think about it the more I'm happy waiting for the PTG to finish first. It seems likely people will hit cache problems post upgrade and avoiding that during the PTG is worthwhile. If the new versions were more important I'd say oh well but the updates seem minimal | 21:38 |
opendevreview | Vladimir Kozhukalov proposed openstack/project-config master: Add Allow-Post-Review to openstack-helm-core group https://review.opendev.org/c/openstack/project-config/+/897366 | 21:51 |
opendevreview | Vladimir Kozhukalov proposed openstack/project-config master: Add Allow-Post-Review to openstack-helm-core group https://review.opendev.org/c/openstack/project-config/+/897366 | 21:53 |
clarkb | any idea if ^ use the standard jobs for uploading to docker hub? It might be a better use of time/effort to move to proven tools than go back and forth on something else if not | 21:53 |
fungi | clarkb: kozhukalov is in #openstack-infra if you want to re-ask there | 21:58 |
clarkb | ack | 21:59 |
opendevreview | Merged opendev/system-config master: Fix python-builder container image system updates https://review.opendev.org/c/opendev/system-config/+/897342 | 22:17 |
opendevreview | Vladimir Kozhukalov proposed openstack/project-config master: Add Allow-Post-Review to openstack-helm-core group https://review.opendev.org/c/openstack/project-config/+/897366 | 22:30 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!