Thursday, 2026-03-19

zigoHi there!09:18
zigoI'm trying to validate OpenStack gazpacho, Glance seems to be kind of working, though when I try to spawn a VM, I get a stack trace in nova-compute.log, with an error in Glance. On the Glance side, I get this stack trace:09:18
zigohttps://paste.opendev.org/show/bw5r2oAFU0fagJmadVzO/09:18
zigoDoes this ring a bell to someone?09:18
zigorosmaita: dansmith: ^09:29
zigoI think it's because I'm getting:11:32
zigonova.exception.ImageUnacceptable: Image 1f9640fd-75ff-4bee-87b0-e8f0c5c57ec2 is unacceptable: Image is not raw format11:32
zigoWeird, whatever the image I upload, I always get the same os_hash_value ...12:46
dansmithzigo: I dunno about that glance error, but "not in raw format" means (likely) you  uploaded something like a qcow2 to glance and told it it was a raw13:23
croelandt#startmeeting glance14:00
opendevmeetMeeting started Thu Mar 19 14:00:55 2026 UTC and is due to finish in 60 minutes.  The chair is croelandt. Information about MeetBot at http://wiki.debian.org/MeetBot.14:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
opendevmeetThe meeting name has been set to 'glance'14:00
croelandt#topic roll call14:00
croelandto/14:00
sakumbhao/14:01
croelandt#link https://etherpad.openstack.org/p/glance-team-meeting-agenda14:01
dansmitho/14:01
croelandtdansmith: welcome back!14:02
croelandtabhishekk: around?14:03
croelandtrosmaita: ^14:03
abhishekko/14:03
rosmaitao/14:03
croelandtshould be a quick one14:04
croelandt#topic Release/periodic job updates14:04
croelandt#link https://zuul.opendev.org/t/openstack/builds?project=openstack%2Fglance&project=openstack%2Fglance_store&project=openstack%2Fpython-glanceclient&pipeline=periodic14:04
croelandtall good14:04
croelandt#topic PTG14:05
croelandt#link https://etherpad.opendev.org/p/2026.2-ptg-glance-planning14:05
croelandtreminder that this is up if you have any topics to add14:06
croelandt#topic Open Discussion14:06
croelandtAnybody got anything else?14:06
dansmithjust wanted to say I replied to mhen's last comment on the encryption spec14:06
dansmithso I hope we're off to the races now14:07
croelandtThe coffee machine broke today so I really could not figure out a good agenda14:07
* croelandt is addicted14:07
rosmaitai have not had time to look closely, but what's with all the failures on https://review.opendev.org/c/openstack/python-glanceclient/+/979189 ?14:09
rosmaitai guess maybe it's because of https://review.opendev.org/c/openstack/python-glanceclient/+/979678 ?14:09
croelandthm14:10
croelandtwhat's the link between these two?14:11
croelandtoh "certificate failure received"14:11
croelandtok we're gonna need to debug this14:12
croelandtoh we should recheck it I guess it's older than the fix by tkajinam 14:12
croelandtthanks for bringing this up!14:13
croelandtanything else?14:13
abhishekknothing from me14:17
croelandtwell14:17
croelandtthanks for joining!14:17
croelandt#endmeeting14:17
opendevmeetMeeting ended Thu Mar 19 14:17:08 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:17
opendevmeetMinutes:        https://meetings.opendev.org/meetings/glance/2026/glance.2026-03-19-14.00.html14:17
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/glance/2026/glance.2026-03-19-14.00.txt14:17
opendevmeetLog:            https://meetings.opendev.org/meetings/glance/2026/glance.2026-03-19-14.00.log.html14:17
zigoFYI, the issue I'm having is because of glance-store.14:30
zigoDowngrading to Glance from Flamingo lead to same issue, until I also downgraded glance-store.14:30
opendevreviewAbhishek Kekane proposed openstack/glance master: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129514:37
opendevreviewAbhishek Kekane proposed openstack/glance stable/2026.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129614:37
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129714:37
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129814:37
opendevreviewAbhishek Kekane proposed openstack/glance stable/2024.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129914:38
abhishekko/15:07
abhishekkso 2024.* needs some additional changes to pin setuptools15:08
abhishekkI am working on fixing releasenotes for master 15:11
opendevreviewAbhishek Kekane proposed openstack/glance master: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129515:12
opendevreviewAbhishek Kekane proposed openstack/glance master: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129515:18
opendevreviewAbhishek Kekane proposed openstack/glance stable/2026.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129615:24
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129715:28
dansmithzigo: are you using swift backed glance by chance?15:33
rosmaitaabhishekk: croelandt: dansmith: i got the OSSA published and the advisory emails sent out, lmk if there's anything you need me to help with15:45
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129815:46
abhishekkrosmaita: thank you, I am working on pinning setuptools for stable branches15:46
dansmithcool15:46
opendevreviewMerged openstack/python-glanceclient stable/2026.1: Fix unit tests with urllib3 2.x  https://review.opendev.org/c/openstack/python-glanceclient/+/97967816:01
opendevreviewAbhishek Kekane proposed openstack/glance stable/2024.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129916:03
samiWill it be backported to caracal or it's based on if someone needs it?16:03
abhishekksami caracl is stable?16:04
abhishekkif it is unmaintained then that depends on someone who needs it should work on it16:05
samiIt's marked as unmaintained 2024.1 https://opendev.org/openstack/glance/src/branch/unmaintained/2024.1/16:05
dansmithsami: unmaintained branches are ... unmaintained :)16:07
dansmiththere's a separate group of people that work on that stuff16:07
clarkbthough its not exclusive. I think if you are interested in a backport you can propose one and then work with that group to land it16:09
clarkbthe idea is that the project teams (like glance) don't need to add extra work to their plate while allowing other people to help out if they need it16:09
rosmaitasami: this will give you some background: https://governance.openstack.org/tc/resolutions/20230724-unmaintained-branches.html16:11
samiokk thank you for the information16:11
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129816:12
zigodansmith: Yeah, swift backend.16:16
zigoAbout OSSA-2026-004, am I right that only Zed and up are affected, because Yoga and down do not have web-download capacity ?16:17
zigoI can see that glance_download.py doesn't exist in Yoga and down.16:17
zigoabhishekk: dansmith: ^16:17
abhishekkzigo, let me confirm, I think web-download was present post ussuri and ovf is before that as well16:19
zigoHow far are you going to backport? I've been able to do zed -> gazpacho so far, Yoga seems to be harder.16:20
abhishekkyes web-download is in yoga as well, https://github.com/openstack/glance/tree/unmaintained/yoga/glance/async_/flows/_internal_plugins16:20
zigoOh...16:21
abhishekkas an contributor I can backport to only stable branches16:21
zigoThough I don't see a urllib.request.urlopen call, so it must be done otherwise.16:21
opendevreviewAbhishek Kekane proposed openstack/glance stable/2024.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129916:22
abhishekkzigo, from glance.common.scripts import utils as script_utils in here you will find which is used in web_download.py (get_image_data_iter method call)16:27
dansmithzigo: anything with import and ovf is affected right?16:28
zigoWell, that's what I'd like to understand, I'm fearing to miss some stuff to patch.16:29
zigoHere's the result when trying to apply on Yoga: https://paste.opendev.org/show/bpQjL8T7o3bE4tPPL8Mb/16:29
dansmithabhishekk: ^ correct about OVF right?16:30
abhishekkyes16:30
zigoI'm not worried about tests, I'll be able to add them. Just, glance/async_/flows/_internal_plugins/glance_download.py is not in Yoga, so where is it?!?16:31
abhishekkzigo you will not be able to apply the patch as it is from master cleanly16:31
dansmithI'm sure no glance-download in Yoga16:31
abhishekkno16:31
zigoabhishekk: Of course, I'm used to doing backports... just here, I'm not sure were to look.16:32
abhishekkit was added in zed16:32
abhishekkhttps://github.com/openstack/glance/tree/unmaintained/zed/glance/async_/flows/_internal_plugins16:32
zigoGot to go, will see this tomorrow...16:33
zigo:)16:33
abhishekkgood day16:34
abhishekkdansmith: rosmaita: croelandt: gmaan: https://review.opendev.org/c/openstack/tempest/+/981329 this needs for all glance SSRF patches17:10
gmaanabhishekk: ack17:12
dansmithabhishekk: makes sense17:14
opendevreviewAbhishek Kekane proposed openstack/glance master: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129517:15
opendevreviewAbhishek Kekane proposed openstack/glance stable/2026.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129617:15
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129717:16
opendevreviewAbhishek Kekane proposed openstack/glance stable/2025.1: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129817:16
opendevreviewAbhishek Kekane proposed openstack/glance stable/2024.2: Fix SSRF vulnerabilities in image import API  https://review.opendev.org/c/openstack/glance/+/98129917:16
opendevreviewMerged openstack/python-glanceclient stable/2026.1: Update .gitreview for stable/2026.1  https://review.opendev.org/c/openstack/python-glanceclient/+/97918817:42
opendevreviewMerged openstack/python-glanceclient stable/2026.1: Update TOX_CONSTRAINTS_FILE for stable/2026.1  https://review.opendev.org/c/openstack/python-glanceclient/+/97918917:42
*** vhari_ is now known as vhari17:50
* abhishekk signing out for the day, need to add recheck on stable/2025.1 for grenade failure, rest looks good I think19:25
abhishekksome1 need to put +w on patches again19:47
rosmaitai will hit those once the tempest patch merges ... it is going to need a recheck, tempest-full-py3 is going to fail, but it's because an instance went bad during a test (there's a console dump in the log)20:29
abhishekkack, if things goes south, i will look at them in morning20:37
opendevreviewMerged openstack/python-glanceclient master: Update master for stable/2026.1  https://review.opendev.org/c/openstack/python-glanceclient/+/97919023:29

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!