*** benfelin has quit IRC | 00:02 | |
*** spatel has quit IRC | 00:20 | |
*** penick has joined #openstack-cinder | 00:26 | |
*** penick has quit IRC | 00:30 | |
*** ChanServ changes topic to "The Block Storage Project | https://wiki.openstack.org/wiki/Cinder | https://tiny.cc/CinderPriorities" | 00:36 | |
-openstackstatus- NOTICE: The Gerrit service at review.opendev.org is back up and running; for outage details see analysis here: http://lists.opendev.org/pipermail/service-announce/2020-October/000011.html | 00:36 | |
*** whoami-rajat__ has joined #openstack-cinder | 00:44 | |
*** adrianc has quit IRC | 00:45 | |
*** adrianc has joined #openstack-cinder | 00:47 | |
*** senrique_ has quit IRC | 00:50 | |
*** andrebeltrami has quit IRC | 01:03 | |
*** sapd1 has joined #openstack-cinder | 01:23 | |
*** psachin has joined #openstack-cinder | 03:30 | |
*** psachin has quit IRC | 03:30 | |
*** dsariel has quit IRC | 03:31 | |
*** psachin has joined #openstack-cinder | 03:31 | |
*** dsariel has joined #openstack-cinder | 03:39 | |
*** hamalq has quit IRC | 03:46 | |
*** udesale has joined #openstack-cinder | 03:53 | |
*** manoj_kumar_kata has joined #openstack-cinder | 04:24 | |
*** abdysn has joined #openstack-cinder | 05:23 | |
*** m75abrams has joined #openstack-cinder | 05:25 | |
*** sharathkacham has joined #openstack-cinder | 06:05 | |
*** manoj_kumar_kata has quit IRC | 06:11 | |
*** manoj_kumar_kata has joined #openstack-cinder | 06:11 | |
*** manoj_kumar_kata has quit IRC | 06:17 | |
*** manoj_kumar_kata has joined #openstack-cinder | 06:17 | |
*** dsariel has quit IRC | 06:17 | |
*** dsariel has joined #openstack-cinder | 06:18 | |
*** manoj_kumar_kata has quit IRC | 06:18 | |
*** manoj_kumar_kata has joined #openstack-cinder | 06:19 | |
*** rpittau|afk is now known as rpittau | 06:42 | |
*** vishalmanchanda has joined #openstack-cinder | 06:47 | |
*** hoonetorg has joined #openstack-cinder | 06:51 | |
*** sapd1 has quit IRC | 06:56 | |
*** sapd1 has joined #openstack-cinder | 06:56 | |
*** mvorwerk has joined #openstack-cinder | 07:00 | |
*** manoj_kumar_kata has quit IRC | 07:02 | |
*** manoj_kumar_kata has joined #openstack-cinder | 07:04 | |
*** manoj_kumar_kata has quit IRC | 07:09 | |
*** manoj_kumar_kata has joined #openstack-cinder | 07:10 | |
*** pcaruana has quit IRC | 07:25 | |
*** manoj_kumar_kata has quit IRC | 07:31 | |
*** manoj_kumar_kata has joined #openstack-cinder | 07:33 | |
*** pcaruana has joined #openstack-cinder | 07:36 | |
*** openstackgerrit has quit IRC | 07:38 | |
*** rcernin has quit IRC | 07:39 | |
*** e0ne has joined #openstack-cinder | 07:41 | |
*** tosky has joined #openstack-cinder | 07:42 | |
*** priteau has joined #openstack-cinder | 07:54 | |
*** rcernin has joined #openstack-cinder | 08:08 | |
*** rcernin has quit IRC | 08:14 | |
*** rcernin has joined #openstack-cinder | 08:28 | |
*** martinkennelly has joined #openstack-cinder | 08:31 | |
*** ociuhandu has joined #openstack-cinder | 08:51 | |
*** rcernin has quit IRC | 08:56 | |
*** user_19173783170 has joined #openstack-cinder | 09:00 | |
user_19173783170 | I'm building a third-part-ci system, and using devstack to be the nodepool's provide,Should I use the latest openstack environment to build the devstack? Or just to keep the jenkins slave is the latest openstack environment? | 09:08 |
---|---|---|
user_19173783170 | I'm building a third-part-ci system, and using devstack to be the nodepool's provider. Should I use the latest openstack environment to build the devstack? Or just to keep the jenkins slave is the latest openstack environment? | 09:09 |
*** manoj_kumar_kata has quit IRC | 09:11 | |
*** manoj_kumar_kata has joined #openstack-cinder | 09:13 | |
*** manoj_kumar_kata has quit IRC | 09:20 | |
*** sharathkacham has quit IRC | 09:36 | |
*** abdysn has quit IRC | 09:45 | |
*** raghavendrat has joined #openstack-cinder | 10:06 | |
raghavendrat | hi geguileo: this is regarding https://review.opendev.org/#/c/756711 | 10:06 |
geguileo | raghavendrat: yes, sorry, I started working on the UTs, but got sidetracked with customer cases, the summit, etc | 10:07 |
raghavendrat | i know why UT are failing. Let me know if i can submit patchset to fix UT | 10:07 |
geguileo | raghavendrat: If you have the time, I would appreciate it :-) | 10:08 |
geguileo | raghavendrat: remember to add yourself in a footer with Co-Authored-By: | 10:09 |
raghavendrat | ok | 10:09 |
lseki | user_19173783170: it's required to deploy a brand new devstack environment for each patch you test | 10:14 |
lseki | you might want to join the forum session later, we'll talk about cinder 3rd part CI | 10:15 |
lseki | it will be happening 15:00-15:45 UTC | 10:19 |
*** abdysn has joined #openstack-cinder | 10:27 | |
*** laurent\ has quit IRC | 10:37 | |
*** priteau has quit IRC | 10:39 | |
*** manoj_kumar_kata has joined #openstack-cinder | 10:51 | |
*** abdysn has quit IRC | 11:02 | |
*** raghavendrat has quit IRC | 11:02 | |
*** pcaruana has quit IRC | 11:08 | |
*** priteau has joined #openstack-cinder | 11:15 | |
*** pcaruana has joined #openstack-cinder | 11:22 | |
*** sapd1 has quit IRC | 11:25 | |
*** priteau has quit IRC | 11:26 | |
*** manoj_kumar_kata has quit IRC | 11:31 | |
*** manoj_kumar_kata has joined #openstack-cinder | 11:31 | |
*** raghavendrat has joined #openstack-cinder | 11:42 | |
*** udesale_ has joined #openstack-cinder | 11:55 | |
*** udesale has quit IRC | 11:57 | |
*** udesale__ has joined #openstack-cinder | 11:59 | |
*** priteau has joined #openstack-cinder | 12:00 | |
*** udesale_ has quit IRC | 12:01 | |
*** raghavendrat has quit IRC | 12:05 | |
*** abdysn has joined #openstack-cinder | 12:17 | |
*** raghavendrat has joined #openstack-cinder | 12:18 | |
*** dsariel has quit IRC | 12:30 | |
*** raghavendrat has quit IRC | 12:37 | |
*** enriquetaso has joined #openstack-cinder | 12:53 | |
*** thgcorrea has joined #openstack-cinder | 13:08 | |
*** udesale_ has joined #openstack-cinder | 13:14 | |
*** KurtB has joined #openstack-cinder | 13:16 | |
*** udesale__ has quit IRC | 13:17 | |
*** psachin has quit IRC | 13:19 | |
*** GirishChilukuri has joined #openstack-cinder | 13:34 | |
*** openstackgerrit has joined #openstack-cinder | 13:37 | |
openstackgerrit | Mikhail Sharkov proposed openstack/cinder master: fix issues preventing cinder with s3 driver to operate https://review.opendev.org/759054 | 13:37 |
*** abdysn has quit IRC | 13:39 | |
GirishChilukuri | Hi Team, | 13:43 |
GirishChilukuri | getting this error "cinder.tests.unit.volume.drivers.ibm.test_storwize_svc:0:1: E902 FileNotFoundError" while running pep8 | 13:44 |
GirishChilukuri | any suggestions on this ? | 13:45 |
openstackgerrit | Rajat Dhasmana proposed openstack/cinder stable/ussuri: Fix: listing volumes with filters https://review.opendev.org/759056 | 13:46 |
*** sapd1 has joined #openstack-cinder | 13:51 | |
jungleboyj | rosmaita: I am thinking that we should probably do an audit of our recent merges like other projects are doing. | 13:53 |
rosmaita | jungleboyj: i am looking at that now | 13:53 |
jungleboyj | Ok. Let me know what I can do to help. | 13:54 |
rosmaita | i will!!! | 13:54 |
rosmaita | jungleboyj: let me know if I am reading this correctly: | 13:56 |
rosmaita | "We have no evidence that any account had its ssh keys compromised, thus we can rule out any unauthorized changes being uploaded via SSH. However we can not conclusively rule out that compromised HTTP API passwords were used to push a change through Gerrit. For example, a change could be uploaded that looks like it came from a user, or the API key of a core team member may have been used to approve a change without authorizatio | 13:56 |
rosmaita | n." | 13:56 |
rosmaita | my reading is | 13:56 |
jungleboyj | Ok. | 13:56 |
rosmaita | what we need to check is the approvals? | 13:57 |
rosmaita | for people who have API keys defined? | 13:57 |
*** enriquetaso has quit IRC | 13:57 | |
jungleboyj | rosmaita: That is how I read that. | 13:58 |
rosmaita | i guess there would be an approval with only that same person doing the review? | 13:58 |
jungleboyj | Which makes the audit a bit easier. | 13:58 |
jungleboyj | So we are looking for ninja merges? | 13:59 |
openstackgerrit | Mikhail Sharkov proposed openstack/cinder master: run without encryption and init check fix https://review.opendev.org/759054 | 13:59 |
rosmaita | jungleboyj: that's what i think | 13:59 |
rosmaita | let me check with fungi | 13:59 |
jungleboyj | Ok. | 13:59 |
rosmaita | because i don't think i have a http password defined for gerrit | 14:00 |
rosmaita | if no one else does either, then i don't think we'd have something to worry about | 14:00 |
fungi | they could have added an http password or an ssh key for your account | 14:00 |
fungi | if they did, those were cleaned up/cleared out prior to restart | 14:01 |
fungi | we didn't see any clear evidence of it happening, but can't be certain that the logs tell the complete story | 14:01 |
rosmaita | ok, so the fact that i have not HTTP password for gerrit right now tells me nothing about whether i had one earlier | 14:02 |
fungi | right, nobody has one now, because the attacker had access to see all of them, as well as set new ones | 14:02 |
rosmaita | ok | 14:02 |
fungi | we cleared them before starting it back up | 14:03 |
fungi | we also removed any ssh keys which were added during the time the attacker had administrative access to the system, in case they had added one of them | 14:03 |
rosmaita | so, at the risk of being stupid, what exactly do we need to look for? a ninja-merge, or could someone have compromised multiple cores, added the proper +2s and then done a +W ? | 14:03 |
fungi | so we recommend, so for thoroughness, at least skimming the changes which merged for the past few weeks to make sure you remember reviewing/approving | 14:03 |
jungleboyj | Don't suppose we have a list of those people? | 14:04 |
fungi | the list is everyone who has an account in gerrit | 14:04 |
rosmaita | :) | 14:04 |
fungi | because it could have been done via ssh or http | 14:04 |
rosmaita | ok, so there is no easy was to do this other than by looking | 14:05 |
fungi | yes, in theory, while we think it's quite unlikely, they could have proposed a change as one regular member of your project, +2's it as one of your core reviewer accounts, and approved it as another core reviewer account without raising suspicion | 14:05 |
rosmaita | will anyone be insulted if i say "motherfuckers" ? | 14:05 |
fungi | i'll join you ;) | 14:05 |
rosmaita | fungi: thanks for the clarifications | 14:06 |
fungi | we went through the gerrit and apache logs with a fine-toothed comb and are fairly certain we know the addresses that motherfucker was coming from, we can't rule out the possibility that they had even more internet connections or a vpn tunnel to another part of the world | 14:06 |
rosmaita | gotcha | 14:06 |
smcginnis | Glad it was caught! | 14:07 |
fungi | so we haven't *seen* evidence of them doing that degree of subterfuge, it can't be ruled out | 14:07 |
jungleboyj | Why the hell would someone do this? Are we really that board during lockdown? | 14:07 |
fungi | i think they just didn't want us getting any sleep | 14:07 |
jungleboyj | fungi: Thank you for all you guys have done. | 14:08 |
jungleboyj | Is there any action that can be taken against 'motherfucker' ? | 14:08 |
fungi | in the primary public communications we tried to avoid explaining the ways they could have better impersonated community members to insert backdoors in our software, so walking a fine line with more targeted responses about what to look out for | 14:09 |
rosmaita | ok, i have audited cinder-specs ... only 1 commit, we are ok there | 14:09 |
fungi | we don't want to basically write up "the next time you decide to hack an open source community, here are the ways you can better avoid going unnoticed..." | 14:09 |
smcginnis | ;) | 14:10 |
jungleboyj | :-) | 14:10 |
smcginnis | I'm not seeing anything suspect in openstack/cinder either. At least on master. | 14:10 |
fungi | i will say that it's apparent they had limited understanding of the interconneced systems we run, and of the workflows for our communities, which is how their activity ultimately stood out | 14:11 |
smcginnis | That's good. Then it wasn't a targeted attack. Just someone for the lolz. | 14:11 |
jungleboyj | Yeah, that is good. | 14:11 |
fungi | like the prowler who finds the back door unlocked but doesn't realize the kids have left toys scattered in the hallway before going off to bed | 14:11 |
*** enriquetaso has joined #openstack-cinder | 14:12 | |
jungleboyj | http://gph.is/W84TJU | 14:13 |
rosmaita | ok, cinder stable branches look fine | 14:14 |
rosmaita | although i think someone snuck a typo into my release notes :P | 14:14 |
jungleboyj | Bwah ha ha! | 14:14 |
*** venkatakrishnath has joined #openstack-cinder | 14:15 | |
openstackgerrit | Rajat Dhasmana proposed openstack/cinder stable/train: Fix: show volume transfer by name for non-admins https://review.opendev.org/759061 | 14:15 |
rosmaita | all i can say is thank goodness for having the library freeze early -- only 1 brick commit! | 14:15 |
rosmaita | python cinderclient are all doc changes | 14:16 |
rosmaita | somebody added a bunch of tests to cinder-tempest-plugin | 14:18 |
rosmaita | (just kidding) | 14:18 |
rosmaita | ok, i think we are good | 14:19 |
rosmaita | i will send something to the ML | 14:20 |
rosmaita | thanks smcginnis and jungleboyj | 14:20 |
jungleboyj | Hey, if they want to hack in tests, that is fine. ;-) | 14:21 |
smcginnis | Hah, that would be great if someone hacked in more tests. | 14:22 |
jungleboyj | rosmaita: Thank you for checking everything out. | 14:22 |
jungleboyj | smcginnis: Can we make that a honeypot? Trick people into helping us? | 14:22 |
smcginnis | You figure out a way to make that happen. ;) | 14:22 |
jungleboyj | :-) | 14:23 |
*** sharathkacham has joined #openstack-cinder | 14:32 | |
*** laurent\ has joined #openstack-cinder | 14:32 | |
venkatakrishnath | https://review.opendev.org/#/c/757082 got +1 from Zuul and got reviewed along with successful IBM storage CI run. | 14:34 |
venkatakrishnath | backend performance and applies to mirror replication types such as | 14:34 |
venkatakrishnath | Please review. | 14:34 |
rosmaita | everyone: http://lists.openstack.org/pipermail/openstack-discuss/2020-October/018192.html | 14:37 |
*** jawad_axd has joined #openstack-cinder | 14:42 | |
lseki | GirishChilukuri: is that the whole message you get? It doesn't tell which file it tried to find... | 14:43 |
lseki | are you getting this on upstream CI, or when running pep8 locally? | 14:44 |
GirishChilukuri | pep8 run-test: commands[0] | flake8 cinder.tests.unit.volume.drivers.ibm.test_storwize_svc .cinder.tests.unit.volume.drivers.ibm.test_storwize_svc:0:1: E902 FileNotFoundError: [Errno 2] No such file or directory: 'cinder.tests.unit.volume.drivers.ibm.test_storwize_svc'ERROR: InvocationError for command /opt/stack/cinder/.tox/pep8/bin/flake8 | 14:45 |
GirishChilukuri | cinder.tests.unit.volume.drivers.ibm.test_storwize_svc . (exited with code 1)_______________________________________________________________________________________ summary ________________________________________________________________________________________ py36: commands succeededERROR: pep8: commands failed | 14:45 |
GirishChilukuri | lseki this is the error i got , i got this when i run pep8 locally | 14:45 |
*** sharathkacham has quit IRC | 14:48 | |
lseki | rosmaita: I should check my activities in gerrit since Oct 1st, right? | 14:50 |
lseki | seems legit. | 14:50 |
rosmaita | lseki: yes, wouldn't hurt | 14:51 |
whoami-rajat__ | rosmaita: it's not possible that they created a random user having core privileges right? the code must be approved by existing cores? | 14:52 |
rosmaita | whoami-rajat__: correct, there were no new cores created during that time frame, so it would have to have been done by using existing core credentials | 14:53 |
lseki | GirishChilukuri: what's the commandline you're using? | 14:54 |
whoami-rajat__ | ok, then just the cores have to check their last reviewed patches for suspicion | 14:55 |
*** udesale_ has quit IRC | 14:55 | |
GirishChilukuri | lseki I ran this "tox -epy36,pep8 -- cinder.tests.unit.volume.drivers.ibm.test_storwize_svc" command | 14:56 |
smcginnis | GirishChilukuri: A couple ideas - you could recreate your virtual environment just in case something changed that is missing there. That is done with "tox -re pep8". | 14:56 |
smcginnis | Otherwise, to maybe get a little more details that could help pinpoint what file is missing, you can do "tox -e pep8 -- -v" | 14:57 |
lseki | not sure if pep8 accepts parameters in dot-separated format | 14:57 |
smcginnis | Oh, right. You can pass that argument to py36, but not pep8. | 14:58 |
smcginnis | lseki: Good call, I confirmed I get that FielNotFoundError if I try to pass the module path to pep8. | 14:59 |
smcginnis | GirishChilukuri: So you just need to drop that for the pep8 job when running locally. | 14:59 |
lseki | let's join Cinder 3rd party CI Forum! | 15:00 |
lseki | https://zoom.us/j/95495383034?pwd=b1FtQnNrY3h4eXo0RlhVKzdJQTVZQT09 | 15:00 |
smcginnis | GirishChilukuri: You can also check out tools/fast8.sh | 15:00 |
GirishChilukuri | @lseki I am running command in dot separated format from long it worked fine. | 15:01 |
GirishChilukuri | smcginnis I will checkout the tools/fast8.sh file | 15:02 |
smcginnis | rosmaita: Do that thing you do. :) | 15:02 |
GirishChilukuri | Thank you lseki and smcginnis | 15:05 |
*** GirishChilukuri has quit IRC | 15:06 | |
*** GirishChilukuri has joined #openstack-cinder | 15:07 | |
*** michael-mc-aleer has joined #openstack-cinder | 15:08 | |
*** abishop_ is now known as abishop | 15:33 | |
*** mvorwerk has quit IRC | 15:50 | |
*** m75abrams has quit IRC | 15:51 | |
*** noonedeadpunk has quit IRC | 15:51 | |
*** kaisers2 has quit IRC | 15:58 | |
*** lyarwood has quit IRC | 16:01 | |
openstackgerrit | Eric Harney proposed openstack/cinder master: mypy: annotate api.py https://review.opendev.org/733622 | 16:02 |
*** rosmaita has left #openstack-cinder | 16:03 | |
openstackgerrit | Eric Harney proposed openstack/cinder master: zuul: add mypy experimental job https://review.opendev.org/736857 | 16:03 |
*** rpittau is now known as rpittau|afk | 16:04 | |
*** rosmaita has joined #openstack-cinder | 16:08 | |
*** noonedeadpunk_ has joined #openstack-cinder | 16:13 | |
*** tosky has quit IRC | 16:16 | |
*** michael-mc-aleer has quit IRC | 16:18 | |
*** hamalq has joined #openstack-cinder | 16:27 | |
jungleboyj | smcginnis: I have the new version of the Cinder Logo you created in PNG if you want to add it to your blog. | 16:29 |
*** hamalq has quit IRC | 16:29 | |
*** hamalq has joined #openstack-cinder | 16:30 | |
*** noonedeadpunk_ has quit IRC | 16:33 | |
*** GirishChilukuri has quit IRC | 16:36 | |
*** ociuhandu_ has joined #openstack-cinder | 16:39 | |
*** noonedeadpunk has joined #openstack-cinder | 16:39 | |
*** ociuhandu has quit IRC | 16:42 | |
*** ociuhandu_ has quit IRC | 16:44 | |
smcginnis | Sweet! | 16:50 |
openstackgerrit | Merged openstack/cinder master: Refactor some unit tests https://review.opendev.org/757972 | 16:55 |
jungleboyj | smcginnis https://usercontent.irccloud-cdn.com/file/fW5ZkamR/NewCinder.png | 16:55 |
*** venkatakrishnath has quit IRC | 17:18 | |
*** sapd1 has quit IRC | 17:23 | |
*** e0ne has quit IRC | 17:33 | |
*** Luzi has joined #openstack-cinder | 17:35 | |
*** rosmaita has quit IRC | 17:39 | |
*** rosmaita has joined #openstack-cinder | 17:42 | |
jungleboyj | I feel like we have been more nostalgic during this summit, which has brought up some good memories and things we had forgotten about. | 17:46 |
openstackgerrit | Victoria Martinez de la Cruz proposed openstack/devstack-plugin-ceph master: Bump NFS Ganesha version https://review.opendev.org/756127 | 17:52 |
*** priteau has quit IRC | 18:01 | |
*** Luzi has quit IRC | 18:09 | |
*** manoj_kumar_kata has quit IRC | 18:26 | |
*** lyarwood has joined #openstack-cinder | 18:29 | |
*** jawad_axd has quit IRC | 18:49 | |
*** tosky has joined #openstack-cinder | 19:12 | |
openstackgerrit | Sofia Enriquez proposed openstack/cinder stable/ussuri: Fix service_get_log tests https://review.opendev.org/759126 | 19:29 |
*** vishalmanchanda has quit IRC | 19:57 | |
*** mvorwerk has joined #openstack-cinder | 19:59 | |
openstackgerrit | Mikhail Sharkov proposed openstack/cinder master: s3 init and no-sse mode fixes https://review.opendev.org/759054 | 20:01 |
*** priteau has joined #openstack-cinder | 20:02 | |
*** whoami-rajat__ has quit IRC | 20:06 | |
*** mvorwerk_ has joined #openstack-cinder | 20:21 | |
*** mvorwerk has quit IRC | 20:22 | |
*** e0ne has joined #openstack-cinder | 21:05 | |
*** e0ne has quit IRC | 21:11 | |
*** e0ne has joined #openstack-cinder | 21:12 | |
*** martinkennelly has quit IRC | 21:21 | |
*** tosky has quit IRC | 22:10 | |
*** tosky has joined #openstack-cinder | 22:11 | |
*** mvorwerk_ has quit IRC | 22:30 | |
*** e0ne has quit IRC | 22:33 | |
*** ociuhandu has joined #openstack-cinder | 22:34 | |
*** ociuhandu has quit IRC | 22:39 | |
*** enriquetaso has quit IRC | 22:42 | |
*** thgcorrea has quit IRC | 22:47 | |
*** rcernin has joined #openstack-cinder | 22:51 | |
*** tosky has quit IRC | 22:51 | |
*** hamalq has quit IRC | 22:57 | |
*** mvorwerk has joined #openstack-cinder | 23:01 | |
*** hamalq has joined #openstack-cinder | 23:01 | |
*** mvorwerk_ has joined #openstack-cinder | 23:27 | |
*** mvorwerk has quit IRC | 23:30 | |
*** spatel has joined #openstack-cinder | 23:44 | |
*** spatel has quit IRC | 23:50 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!