Tuesday, 2022-10-04

*** mhen_ is now known as mhen02:04
dmendiza[m]#startmeeting barbican13:00
opendevmeetMeeting started Tue Oct  4 13:00:56 2022 UTC and is due to finish in 60 minutes.  The chair is dmendiza[m]. Information about MeetBot at http://wiki.debian.org/MeetBot.13:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.13:00
opendevmeetThe meeting name has been set to 'barbican'13:00
dmendiza[m]#topic Roll Call13:01
dmendiza[m]Courtesy ping for ade_lee dave-mccowan d34dh0r53 hrybacki jamespage Luzi lxkong mhen rm_work tosky xek nearyo oleksandry13:01
xeko/13:01
Luzio/13:01
toskyo/13:01
dmendiza[m]Hi y'all!13:01
dmendiza[m]OK, let's get started13:02
dmendiza[m]#topic Review Past Meeting Action Items13:02
dmendiza[m]#link https://meetings.opendev.org/meetings/barbican/2022/barbican.2022-09-27-13.00.html13:02
dmendiza[m]Looks like we didn't have any13:05
dmendiza[m]moving on 13:05
dmendiza[m]#topic Liaison Updates13:05
dmendiza[m]tosky: around?  Any updates from QA/QE?13:06
dmendiza[m]Moving on to release liaison (we'll come back to tosky if he stops by)13:08
dmendiza[m]actually, let's talk VMT first13:08
dmendiza[m]...13:09
dmendiza[m]I'm waiting for coffee to kick in and need to organize my thoughts ...13:09
dmendiza[m]...13:09
dmendiza[m]OK, so for release liaison, I've submitted a patch to volunteer myself as Release Liaison:13:10
tosky(sorry, no updates from me)13:10
dmendiza[m]#link https://review.opendev.org/c/openstack/releases/+/86015213:10
ade_leeo/13:10
dmendiza[m]thanks tosky !13:10
d34dh0r53o/13:10
dmendiza[m]Dave McCowan was still the release liaison on the releases repo, so that's why he was still being added to all release reviews13:10
dmendiza[m]Not sure xek is around, but I'll ask him to +1 that patch so we can get that update in13:11
dmendiza[m]after it merges both xek and I will be able to approve release requests13:11
ade_leedmendiza[m], can we add more than one ?  looks like cyborg has two ..13:11
dmendiza[m]ade_lee I suppose so ... are you volunteering as tribute?13:12
ade_leedmendiza[m], what does the release liaison do?13:12
dmendiza[m]* Pay attention to release deadlines13:13
dmendiza[m]* Approve release patches that are created by the release team automation13:13
dmendiza[m]* Request releases for libraries when the team feels there's a need13:13
ade_leedmendiza[m], interesting that we haven't had any issues for awhile -- given that dave has been away for awhile now13:14
dmendiza[m]ade_lee: if that's something you're interested in, just submit a patch like mine and ask xek to +1 (or ask me if my patch has already merged.)13:14
dmendiza[m]ade_lee: well, PTL is the default liaison so I've been handling all that stuff13:14
ade_leedmendiza[m], gotcha -- so liaison is backup in case ptl is not around?13:15
ade_leeor it goes to both>13:15
ade_lee?13:15
dmendiza[m]ade_lee: yeah, or helping had if PTL is too busy13:15
dmendiza[m]yeah, so when my patch merges, the release automation will add both myself and xek.  Previously it used to add me and Dave.  Now it's adding Dave and xek13:15
dmendiza[m]The release team waits for either one to +1 before merging13:16
ade_leedmendiza[m], ok - I'll put my own patch up -- or you can add me to your13:16
ade_leeeither way13:16
dmendiza[m]ade_lee: I don't want to update mine because it will drop the +2 that's already there13:16
ade_leedmendiza[m], ack - I'll add my own13:16
dmendiza[m]ade_lee++ thanks!13:17
dmendiza[m]#info antelope cycle will have two release liaisons ade_lee and dmendiza[m]13:17
ade_leeand xek by default13:17
dmendiza[m]right13:17
dmendiza[m]On the topic of releases, I did request a Zed RC3 this week:13:18
dmendiza[m]https://review.opendev.org/c/openstack/releases/+/85989413:18
dmendiza[m]*last week13:18
dmendiza[m]that was to pull in a CVE fix that' I'll talk about in a bit13:18
dmendiza[m]RC3 should be the final spin and will likely be the Zed final release13:19
dmendiza[m]OK, moving on 13:19
dmendiza[m]#topic CVE-2022-310013:20
dmendiza[m]#link https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-310013:21
dmendiza[m]it was reported via Red Hat CVE tracking:13:22
dmendiza[m]#link https://access.redhat.com/security/cve/CVE-2022-310013:22
dmendiza[m]We also have an errata page with more info:13:22
dmendiza[m]#link https://access.redhat.com/errata/RHSA-2022:675013:22
dmendiza[m]Storyboard was private, but I just toggled the flag to make it public:13:24
dmendiza[m]#link https://storyboard.openstack.org/#!/story/201025813:24
dmendiza[m]Long story short, there is a vulnerability that will allow malicious users to access secret payloads when they have no roles assigned on the project that owns the secret13:24
dmendiza[m]We've patched Wallaby, Xena, Yoga, Zed and Master branches: 13:26
dmendiza[m]#link https://review.opendev.org/q/topic:cve-2022-310013:26
dmendiza[m]I'm currently working on the Victoria patch, but the Victoria gates are a mess13:26
dmendiza[m]so it's taking a bit longer than it should.13:26
dmendiza[m]Once that's sorted I'll be backporting the fix all the way back to Train13:27
dmendiza[m]Stein and older branches are EOL and folks should upgrade to a newer release to get the fix.13:27
dmendiza[m]d34dh0r53: anything else you want to add for this topic?13:28
dmendiza[m]I want to say that d34dh0r53 is working on an OSSA for this13:31
dmendiza[m]OK, moving on 13:33
dmendiza[m]#topic PTG Planning13:33
dmendiza[m]It's that time again13:33
dmendiza[m]#link https://openinfra.dev/ptg/13:33
dmendiza[m]We've got two weeks to come up with an agenda13:34
dmendiza[m]I'll probably spend some time with xek and ade_lee reviewing the last PTG notes to get things started13:34
dmendiza[m]Etherpad for topic ideas is here:13:35
dmendiza[m]#link https://etherpad.opendev.org/p/antelope-ptg-barbican13:35
dmendiza[m]#action xek and dmeniza[m] to reserve time slots for Barbican sessions during PTG13:35
dmendiza[m]I think we'll stick to 2x 2hr blocks on different days again13:36
dmendiza[m]Any questions/commets about the upcoming PTG?13:38
dmendiza[m]OK, moving on13:40
dmendiza[m]#topic New meeting time proposal13:40
dmendiza[m]Now that xek is the brand new shiny PTL we'll need to move this meeting13:41
dmendiza[m]because xek has a conflict at this time13:41
dmendiza[m]I should say he has a conflicting meeting.13:41
xekI have a conflict, so I propose to move it 1 hour later13:41
dmendiza[m]oh hi Grzegorz Grasza !13:41
dmendiza[m]1 hr later would work for me13:41
dmendiza[m]how about you, Luzi ?13:41
dmendiza[m]...  maybe Luzi had to run ... 13:46
xekI'll send out an email before I change the meeting time13:46
dmendiza[m]sounds good13:46
dmendiza[m]#info This meeting time is proposed to move to an hour later13:47
dmendiza[m]OK, moving on13:47
dmendiza[m]#topic Secret Consumers13:47
dmendiza[m]Not a whole lot of progress on the client side13:47
dmendiza[m]I've been busy with CVE things and haven't gotten a chance to update the first python-barbicanclient patch13:48
xekdmendiza: you can +w the spec change, since the implementation already merged: https://review.opendev.org/c/openstack/barbican-specs/+/85675913:48
dmendiza[m]Grzegorz Grasza: we should probably update the Core team 13:49
dmendiza[m]Grzegorz Grasza: I'll add you and you can +W yourself 😄13:49
ade_leedmendiza[m], xek one hour later puts this meeting 10 minutes from now , right?13:49
dmendiza[m]ade_lee: correct ... overlaps with both PGM and FIPS for you13:49
ade_leeyup13:50
dmendiza[m]I'd be down with an hour earlier also13:50
dmendiza[m]but that might be too early for d34dh0r53 13:50
d34dh0r53I can make that work13:51
d34dh0r53dmendiza[m]: ^13:51
dmendiza[m]Grzegorz Grasza: what does 1 hr earlier look like for you? (1200 UTC)?13:52
xekdmendiza: looks good13:52
dmendiza[m]OK, let's plan for that, hopefully that'll also work for Luzi 13:53
dmendiza[m]back to Secret Consumers13:56
dmendiza[m]I'll continue to work on that as soon as we get all these CVE patches backported13:56
dmendiza[m]afaranha_ and Mauricio are also helping out with the Castellan bits13:56
dmendiza[m]...13:56
dmendiza[m]and we're just about out of time13:56
dmendiza[m]#topic Open Discussion13:56
dmendiza[m]Anything else y'all want to talk about during the last couple of minutes?13:57
dmendiza[m]Thanks for joining, y'all!14:01
dmendiza[m]#endmeeting14:01
opendevmeetMeeting ended Tue Oct  4 14:01:48 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:01
opendevmeetMinutes:        https://meetings.opendev.org/meetings/barbican/2022/barbican.2022-10-04-13.00.html14:01
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/barbican/2022/barbican.2022-10-04-13.00.txt14:01
opendevmeetLog:            https://meetings.opendev.org/meetings/barbican/2022/barbican.2022-10-04-13.00.log.html14:01

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!