| opendevreview | Merged openstack/ironic master: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996462 | 00:02 |
|---|---|---|
| opendevreview | Merged openstack/ironic bugfix/37.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996464 | 00:03 |
| TheJulia | woot woot | 00:18 |
| opendevreview | Julia Kreger proposed openstack/ironic unmaintained/2023.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996529 | 00:21 |
| opendevreview | Merged openstack/ironic stable/2026.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996469 | 01:15 |
| opendevreview | Merged openstack/ironic stable/2025.1: security: block vendor.send_raw (CVE-2026-54423) https://review.opendev.org/c/openstack/ironic/+/996477 | 01:36 |
| opendevreview | Merged openstack/ironic bugfix/34.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996471 | 01:36 |
| opendevreview | Merged openstack/ironic bugfix/33.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996474 | 04:16 |
| opendevreview | Merged openstack/ironic stable/2025.2: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996476 | 04:17 |
| opendevreview | Merged openstack/ironic stable/2025.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996478 | 04:43 |
| opendevreview | Merged openstack/ironic bugfix/37.0: Fix BIOS firmware update not applied when TaskMonitor disappears https://review.opendev.org/c/openstack/ironic/+/996282 | 04:43 |
| opendevreview | Verification of a change to openstack/tenks master failed: Add openstack.cloud collection to requirements https://review.opendev.org/c/openstack/tenks/+/993060 | 05:48 |
| opendevreview | Merged openstack/networking-generic-switch master: Add NetconfOpenConfigSwitch driver https://review.opendev.org/c/openstack/networking-generic-switch/+/990061 | 06:37 |
| opendevreview | Merged openstack/networking-generic-switch master: Add NETCONF OpenConfig driver documentation https://review.opendev.org/c/openstack/networking-generic-switch/+/990062 | 06:37 |
| opendevreview | Merged openstack/ironic stable/2026.1: Only query Glance image members for shared images https://review.opendev.org/c/openstack/ironic/+/996344 | 06:54 |
| opendevreview | Merged openstack/ironic stable/2026.1: Fix BIOS firmware update not applied when TaskMonitor disappears https://review.opendev.org/c/openstack/ironic/+/996283 | 07:37 |
| *** elodilles_pto is now known as elodilles | 07:52 | |
| opendevreview | Pierre Crégut proposed openstack/ironic master: Conditional check of remaining pending attributes https://review.opendev.org/c/openstack/ironic/+/993770 | 07:59 |
| *** hroy_ is now known as hroy | 11:58 | |
| opendevreview | Dmitry Tantsur proposed openstack/bifrost master: Enable TLS by default, deprecate enable_tls https://review.opendev.org/c/openstack/bifrost/+/968363 | 13:33 |
| opendevreview | Dmitry Tantsur proposed openstack/bifrost master: Fix TLS on CentOS 10 https://review.opendev.org/c/openstack/bifrost/+/996653 | 13:33 |
| dtantsur | TheJulia: if you have a minute today, I'd like your thoughts on https://review.opendev.org/c/openstack/ironic-specs/+/995954 (standalone EVPN). It's not a full-blown spec yet, there is not much to read. | 14:17 |
| TheJulia | Reviewing is on my list today, so hopefully nothing distracts me too much today. | 14:18 |
| dtantsur | OpenShift is adding EVPN support to their user-defined networking, so we may get neutron-like virtual networking between bare-metal, VMs and containers if we get EVPN on our side. | 14:24 |
| JayF | dtantsur: It seems weird to me that we would add that before basic lag support | 14:59 |
| dtantsur | You mean, to standalone networking? | 15:00 |
| JayF | Yeah | 15:04 |
| JayF | Just seems like bonded interfaces are building block that almost anyone who used an evpn style setup would want | 15:04 |
| JayF | I know that any interest I would ever have in it would require lag to be supported | 15:04 |
| JayF | Don't take this feedback is like a minus one or a minus two -- just a huh, this is interesting | 15:05 |
| dtantsur | We definitely have a lot of references to LAG in the standalone networking, don't we have it supported? | 15:09 |
| JayF | No. That was a phase 2 item which I was told would be circled back around to. The basic metal3 integration was done | 15:10 |
| JayF | **once the basic metal3 integration was done | 15:10 |
| dtantsur | Okaaaaaay. Missed that entirely (which shows how little clue I have in reality, sigh). | 15:10 |
| dtantsur | Honestly, I hope that alegacy_ has plans for LAGs because I hardly understand them. | 15:10 |
| JayF | Yeah, that's kind of why I mentioned it. Was hard for me to imagine a use case that needed evpn but not lag | 15:11 |
| dtantsur | Please elaborate. I'm still clueless, you see :) | 15:11 |
| JayF | I'm also happy to be a resource for that work... and may be able to dedicate real engineering time to it depending on some ongoing decisions | 15:11 |
| dtantsur | In the context of Metal3 providing BMs and OVN-kubernetes connecting VMs/containers to the same VNI, why do I need LAGs? | 15:11 |
| JayF | I'm just thinking about who would have a fancy enough Network to have vxlan but not care to have their conductors with highly available networking | 15:12 |
| JayF | It's not some magical technical dependency, it's sort of one of those things that you would usually see together | 15:12 |
| dtantsur | I see, I see. Yeah, makes sense. I'll be happy if we all can collaborate on the final state of things. | 15:12 |
| dtantsur | Do you think https://review.opendev.org/c/openstack/ironic-specs/+/995954 needs more work to accommodate LAGs? Or is it more of backend work? | 15:13 |
| JayF | I don't know to that level of detail. I just knew the feature was missing because it was one of the things I would require before being able to use it | 15:15 |
| opendevreview | Merged openstack/ironic unmaintained/2024.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner https://review.opendev.org/c/openstack/ironic/+/996479 | 15:37 |
| opendevreview | Dmitry Tantsur proposed openstack/bifrost master: Enable TLS by default, deprecate enable_tls https://review.opendev.org/c/openstack/bifrost/+/968363 | 16:29 |
| opendevreview | Dmitry Tantsur proposed openstack/bifrost master: Fix accessing OCI images with TLS https://review.opendev.org/c/openstack/bifrost/+/996672 | 16:29 |
| dtantsur | sooo many TLS bugs.. | 16:29 |
| TheJulia | They are easy to just kind of grow | 16:29 |
| TheJulia | since its also a space which has been fairly solid for years and is now starting to evolve again as well | 16:29 |
| dtantsur | one of the reasons to enable TLS by default | 16:29 |
| TheJulia | yeah, technically I think OCI is expected to only be accessed via TLS, but... yeah. | 16:30 |
| TheJulia | but my brain there is fuzzy | 16:30 |
| dtantsur | it's possible that bifrost has relied on the HTTP fallback so far | 16:31 |
| TheJulia | yeah, and I think because it wasn't tls by default | 16:33 |
| TheJulia | its all very very fuzzy | 16:33 |
| * TheJulia goes back to trying to write another email. | 16:33 | |
| dtantsur | Wow, some old reviews of mine predate the sign-off requirement | 16:34 |
| opendevreview | Dmitry Tantsur proposed openstack/ironic-python-agent master: WIP add disk aliases to the inventory https://review.opendev.org/c/openstack/ironic-python-agent/+/896577 | 16:34 |
| TheJulia | heh | 16:34 |
| * dtantsur is trying to clean up his outgoing queue | 16:35 | |
| JayF | cid and I are working on container console stuff | 16:35 |
| JayF | and we're seeing docker container build failures in the devstack spin up | 16:35 |
| JayF | I did some digging; AFAICT the only job that runs that build in CI runs against Nova | 16:35 |
| JayF | which means ... it could be a real, unseen failure(?) | 16:36 |
| dtantsur | :( | 16:40 |
| JayF | I'm hoping it's as simple as docker-buildx missing from bindep.txt | 16:41 |
| dtantsur | Does anyone with integrated OpenStack actually care about https://review.opendev.org/c/openstack/ironic/+/910365 being finished? I can throw Claude on it. | 16:41 |
| JayF | because we're using the old builder | 16:41 |
| dtantsur | What's the failure? I definitely had to add buildx to Metal3 jobs. | 16:41 |
| JayF | Step 12/16 : ADD bin/* /usr/local/bin \n When using ADD with more than one source file, the destination must be a directory and end with a / | 16:41 |
| JayF | reproduced on cid's devstack ubuntu and my gentoo | 16:41 |
| JayF | we are trying a docker-buildx install for a fix now | 16:42 |
| dtantsur | Hmm, not the same issue. If you control the Dockerfile, you can also fix the complaint. | 16:42 |
| JayF | we're trying to get it working in devstack | 16:42 |
| JayF | and as I said to cid: we'll have to figure out *why* it's broken now to avoid breaking older docker versions | 16:42 |
| JayF | bindep.txt is apparently correct for podman usage, but is missing pieces for using docker direct | 16:46 |
| JayF | we can fix | 16:46 |
| TheJulia | sounds like it might be a podman-ism as well, fwiw | 16:48 |
| JayF | it works with docker-buildx, docker-buildx is the superior new way | 16:48 |
| JayF | I'm taking the obvious path | 16:48 |
| opendevreview | Jay Faulkner proposed openstack/ironic master: Ensure docker-buildx is installed on dpkg platforms https://review.opendev.org/c/openstack/ironic/+/996682 | 16:50 |
| dtantsur | JayF: ^^ is a bit odd. Where does docker installation come from? The file only refers to podman. | 16:52 |
| JayF | I assume ubuntu defaults to having it installed, I hadn't considered that | 16:53 |
| JayF | but I also think docker-buildx does not dep on docker | 16:53 |
| JayF | wait, that's wrong | 16:53 |
| dtantsur | JayF: what I"m trying to say: our bindep looks like we intend to use podman | 16:54 |
| JayF | dtantsur: our lib/devstack/ironic executes `docker build ....` | 16:54 |
| dtantsur | if we end up using docker regardless, maybe we shouldn't install podman? | 16:54 |
| dtantsur | or do we depend on both? | 16:54 |
| JayF | I am coming at this from a "try to fix cid's devstack" and uncovered a build bug | 16:54 |
| JayF | I am not contexted up on this feature in any meaningful way | 16:54 |
| JayF | I suggested to cid directly (we are in 1:1 right now) that he sync up with stevebaker[m] to get some of that context | 16:55 |
| dtantsur | JayF: I don't see any mentions of docker in ironic's devstack/lib/ironic | 16:55 |
| JayF | It's 100% in his logs, :-O | 16:55 |
| dtantsur | Oo | 16:55 |
| dtantsur | I see mentions of buildah, but not of podman or docker | 16:56 |
| JayF | this is MUCH more interesting now :D | 16:56 |
| JayF | how dare I trust a log | 16:56 |
| dtantsur | I suggest figuring this out first, otherwise we risk that it's going to randomly break again | 16:56 |
| JayF | 1000000000% agree | 16:56 |
| JayF | we are looking actively | 16:56 |
| dtantsur | ++ | 16:57 |
| JayF | so I see buildah in the docker log; it's actually using docker on this ubuntu to implement it | 16:58 |
| JayF | cid: is about to paste in the logline | 16:58 |
| cid | ++ /opt/stack/ironic/devstack/lib/ironic:install_ironic:1261 : sudo docker build -f ./Containerfile.ubuntu -t localhost/ir | 16:58 |
| JayF | that's the same line of code that in devstack/lib/ironic is "buildah bug --from blah -f ....." | 16:59 |
| JayF | aha, we id'd it, it's a part of the change | 17:01 |
| JayF | not an issue on master | 17:01 |
| JayF | I am going to abandon my change | 17:01 |
| opendevreview | Ghanshyam Maan proposed openstack/ironic master: Remove disabling the scope enforcement https://review.opendev.org/c/openstack/ironic/+/996687 | 17:39 |
| gmaan | cardoe: are you ok with this now? | 17:40 |
| gmaan | cardoe: https://review.opendev.org/c/openstack/ironic/+/996559 | 17:40 |
| cardoe | gmaan: ah I hadn't followed up sorry. | 17:41 |
| cardoe | Yes thank you for doing that | 17:42 |
| gmaan | cardoe: thanks | 17:42 |
| JayF | Fyi, I am unavailable this afternoon. If you need anything, I'll be checking back later this evening or tomorrow. | 17:54 |
| TheJulia | ack ack | 17:55 |
| TheJulia | I'm likely going to have my last meeting in about an hour and then take the car into the shop to get a new tire | 17:56 |
| TheJulia | :( | 17:56 |
| TheJulia | and do code review while waiting | 17:56 |
| JayF | We've been dealing with a dryer that had a heating element go out. Luckily the repair guy is showing up this afternoon | 17:56 |
| JayF | Sounds like you need to re-tire 😂 | 17:57 |
| TheJulia | lol | 17:59 |
| TheJulia | yeah, I must have hit something because I had a side wall bubble appear | 17:59 |
| TheJulia | so... new tire time | 17:59 |
| opendevreview | Merged openstack/ironic master: Conditional check of remaining pending attributes https://review.opendev.org/c/openstack/ironic/+/993770 | 18:03 |
| opendevreview | Mahnoor Asghar proposed openstack/ironic master: Soft power off before ejecting virtual media after inspection, regardless of CONF.inspector.power_off. Do not soft power off if PXE boot is enabled. https://review.opendev.org/c/openstack/ironic/+/996692 | 18:05 |
| opendevreview | Merged openstack/ironic master: Remove setting of oslo_policy[enforce_scope] flag https://review.opendev.org/c/openstack/ironic/+/996559 | 18:07 |
| TheJulia | dtantsur: if you wouldn't mind, a quick review on https://review.opendev.org/c/openstack/ironic/+/996529 would be appreciated | 18:41 |
| cardoe | So how expensive is a shared lock? | 18:56 |
| cardoe | e.g. the power sync periodic queues up all devices even those that don't support power sync | 18:56 |
| cardoe | Would it be better before consuming those queue slots to ask the interface if we support power sync? | 18:57 |
| TheJulia | well | 18:59 |
| TheJulia | the more expensive thing is all the db selects for the hydration of the node to really be able to make that power sync call | 18:59 |
| TheJulia | that being said, all drivers now do support it really | 18:59 |
| TheJulia | sooooo *shrug* | 18:59 |
| cardoe | noop doesn't ;) | 19:05 |
| cardoe | and fake has a hardcoded sleep(CONF.fake.sleep_time) | 19:07 |
| cardoe | We also added 'disable_power_off' as a top-level node attribute when I wonder if that should have really been a driver_info field. | 19:08 |
| TheJulia | okay, thats fair | 19:11 |
| TheJulia | dtantsur: we should talk about your evpn thingie | 19:11 |
| opendevreview | Merged openstack/ironic master: Stop reimporting middleware modules https://review.opendev.org/c/openstack/ironic/+/993526 | 19:55 |
| -Guest12850- NOTICE: The Gerrit service on review.opendev.org will be offline briefly one hour from now, at 21:00 UTC, while we rename a project. | 20:01 | |
| TheJulia | how many noop nodes to you have ? | 20:05 |
| TheJulia | fwiw, we did previously take a look at some of this and the big thing was the db read hits, but we've also been super gun-shy of building extra logic into constraint in the queries for specific cases, maybe we should, dunno | 20:05 |
| -Guest12850- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily at 21:00 UTC while we rename a project, but will return within a few minutes. | 20:59 | |
| TheJulia | Thank you guest-like bot! | 21:05 |
| TheJulia | :) | 21:05 |
| cardoe | TheJulia: sorry. got to be math tutor for a while | 21:27 |
| cardoe | I might have a bunch of noop nodes... <shifty eyes> | 21:27 |
| cardoe | So basically we do nodes = list(iter_nodes(["uuid", "driver", "conductor", "id"]) which are the fields we lookup from the DB. | 21:33 |
| cardoe | We then split that list up by the number of workers and make futures and spawn off workers. | 21:34 |
| cardoe | Then those workers walk their list and call task_manager.acquire(node_uuid). Which loads the node from the DB and calls load_drivers_from_task(). Which ultimately uses those fields to call get_interface(node.driver, node.$interface) | 21:36 |
| cardoe | Do a whole bunch of metrics things | 21:37 |
| cardoe | cache stuff | 21:38 |
| cardoe | do some counts | 21:38 |
| cardoe | check some stuff if we want to skip checking the power state | 21:38 |
| cardoe | upgrade the shared lock to an exclusive lock | 21:38 |
| TheJulia | we likely need to be able to exclude some nodes by drivers, I guess for some of that | 21:39 |
| cardoe | Now we call driver.interface.supports_power_sync() | 21:40 |
| cardoe | So I patched it locally to nodes = [node for node in iter_nodes(["uuid", "driver", "conductor", "id", "power_interface") if get_interface(node.driver, node.power_interface).supports_power_sync()] | 21:41 |
| TheJulia | yeah, but there is a ton of overhead to even hydrate the node object to do all of that, I'm wondering if we can just short circuit even that need since power sync on fake-hardware seems... wrong | 21:45 |
| cardoe | But I also misunderstood supports_power_sync()... because that function means that conductor should change the power state of the node if it doesn't match the database | 21:46 |
| cardoe | Not what I would have called it... | 21:46 |
| cardoe | It ALWAYS calls get_power_state() | 21:47 |
| cardoe | And fake calls sleep(CONF.fake.power_delay) in that function | 21:47 |
| cardoe | Which also returns None because of a slew of other code | 21:49 |
| cardoe | None is not in the set of ALLOWED_POWER_STATES | 21:49 |
| cardoe | So we send a notification and debug stuff. | 21:50 |
| TheJulia | yeah, so sort of going back, why invoke the loop on drivers which even *HAVE* that condition | 21:51 |
| TheJulia | hjensas: it might be a good idea to review jam ngs stuff at some point soon | 21:53 |
| cardoe | yeah I've been trying to go through them. But it's not light reading. | 22:46 |
| TheJulia | Yeah, I need to find spoons and I just think it would help to spread context and work through them with a couple people | 22:51 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!