Thursday, 2026-07-09

opendevreviewMerged openstack/ironic master: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99646200:02
opendevreviewMerged openstack/ironic bugfix/37.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99646400:03
TheJuliawoot woot00:18
opendevreviewJulia Kreger proposed openstack/ironic unmaintained/2023.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99652900:21
opendevreviewMerged openstack/ironic stable/2026.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99646901:15
opendevreviewMerged openstack/ironic stable/2025.1: security: block vendor.send_raw (CVE-2026-54423)  https://review.opendev.org/c/openstack/ironic/+/99647701:36
opendevreviewMerged openstack/ironic bugfix/34.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99647101:36
opendevreviewMerged openstack/ironic bugfix/33.0: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99647404:16
opendevreviewMerged openstack/ironic stable/2025.2: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99647604:17
opendevreviewMerged openstack/ironic stable/2025.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99647804:43
opendevreviewMerged openstack/ironic bugfix/37.0: Fix BIOS firmware update not applied when TaskMonitor disappears  https://review.opendev.org/c/openstack/ironic/+/99628204:43
opendevreviewVerification of a change to openstack/tenks master failed: Add openstack.cloud collection to requirements  https://review.opendev.org/c/openstack/tenks/+/99306005:48
opendevreviewMerged openstack/networking-generic-switch master: Add NetconfOpenConfigSwitch driver  https://review.opendev.org/c/openstack/networking-generic-switch/+/99006106:37
opendevreviewMerged openstack/networking-generic-switch master: Add NETCONF OpenConfig driver documentation  https://review.opendev.org/c/openstack/networking-generic-switch/+/99006206:37
opendevreviewMerged openstack/ironic stable/2026.1: Only query Glance image members for shared images  https://review.opendev.org/c/openstack/ironic/+/99634406:54
opendevreviewMerged openstack/ironic stable/2026.1: Fix BIOS firmware update not applied when TaskMonitor disappears  https://review.opendev.org/c/openstack/ironic/+/99628307:37
*** elodilles_pto is now known as elodilles07:52
opendevreviewPierre Crégut proposed openstack/ironic master: Conditional check of remaining pending attributes  https://review.opendev.org/c/openstack/ironic/+/99377007:59
*** hroy_ is now known as hroy11:58
opendevreviewDmitry Tantsur proposed openstack/bifrost master: Enable TLS by default, deprecate enable_tls  https://review.opendev.org/c/openstack/bifrost/+/96836313:33
opendevreviewDmitry Tantsur proposed openstack/bifrost master: Fix TLS on CentOS 10  https://review.opendev.org/c/openstack/bifrost/+/99665313:33
dtantsurTheJulia: if you have a minute today, I'd like your thoughts on https://review.opendev.org/c/openstack/ironic-specs/+/995954 (standalone EVPN). It's not a full-blown spec yet, there is not much to read.14:17
TheJuliaReviewing is on my list today, so hopefully nothing distracts me too much today.14:18
dtantsurOpenShift is adding EVPN support to their user-defined networking, so we may get neutron-like virtual networking between bare-metal, VMs and containers if we get EVPN on our side.14:24
JayFdtantsur: It seems weird to me that we would add that before basic lag support14:59
dtantsurYou mean, to standalone networking?15:00
JayFYeah15:04
JayFJust seems like bonded interfaces are building block that almost anyone who used an evpn style setup would want15:04
JayFI know that any interest I would ever have in it would require lag to be supported 15:04
JayFDon't take this feedback is like a minus one or a minus two -- just a huh, this is interesting 15:05
dtantsurWe definitely have a lot of references to LAG in the standalone networking, don't we have it supported?15:09
JayFNo. That was a phase 2 item which I was told would be circled back around to. The basic metal3 integration was done15:10
JayF**once the basic metal3 integration was done15:10
dtantsurOkaaaaaay. Missed that entirely (which shows how little clue I have in reality, sigh).15:10
dtantsurHonestly, I hope that alegacy_ has plans for LAGs because I hardly understand them.15:10
JayFYeah, that's kind of why I mentioned it. Was hard for me to imagine a use case that needed evpn but not lag15:11
dtantsurPlease elaborate. I'm still clueless, you see :)15:11
JayFI'm also happy to be a resource for that work... and may be able to dedicate real engineering time to it depending on some ongoing decisions15:11
dtantsurIn the context of Metal3 providing BMs and OVN-kubernetes connecting VMs/containers to the same VNI, why do I need LAGs?15:11
JayFI'm just thinking about who would have a fancy enough Network to have vxlan but not care to have their conductors with highly available networking15:12
JayFIt's not some magical technical dependency, it's sort of one of those things that you would usually see together15:12
dtantsurI see, I see. Yeah, makes sense. I'll be happy if we all can collaborate on the final state of things.15:12
dtantsurDo you think https://review.opendev.org/c/openstack/ironic-specs/+/995954 needs more work to accommodate LAGs? Or is it more of backend work?15:13
JayFI don't know to that level of detail. I just knew the feature was missing because it was one of the things I would require before being able to use it15:15
opendevreviewMerged openstack/ironic unmaintained/2024.1: CVE-2026-44918: Prevent rehoming resources to nodes with different owner  https://review.opendev.org/c/openstack/ironic/+/99647915:37
opendevreviewDmitry Tantsur proposed openstack/bifrost master: Enable TLS by default, deprecate enable_tls  https://review.opendev.org/c/openstack/bifrost/+/96836316:29
opendevreviewDmitry Tantsur proposed openstack/bifrost master: Fix accessing OCI images with TLS  https://review.opendev.org/c/openstack/bifrost/+/99667216:29
dtantsursooo many TLS bugs..16:29
TheJuliaThey are easy to just kind of grow16:29
TheJuliasince its also a space which has been fairly solid for years and is now starting to evolve again as well16:29
dtantsurone of the reasons to enable TLS by default16:29
TheJuliayeah, technically I think OCI is expected to only be accessed via TLS, but... yeah. 16:30
TheJuliabut my brain there is fuzzy16:30
dtantsurit's possible that bifrost has relied on the HTTP fallback so far16:31
TheJuliayeah, and I think because it wasn't tls by default16:33
TheJuliaits all very very fuzzy16:33
* TheJulia goes back to trying to write another email.16:33
dtantsurWow, some old reviews of mine predate the sign-off requirement16:34
opendevreviewDmitry Tantsur proposed openstack/ironic-python-agent master: WIP add disk aliases to the inventory  https://review.opendev.org/c/openstack/ironic-python-agent/+/89657716:34
TheJuliaheh16:34
* dtantsur is trying to clean up his outgoing queue16:35
JayFcid and I are working on container console stuff16:35
JayFand we're seeing docker container build failures in the devstack spin up16:35
JayFI did some digging; AFAICT the only job that runs that build in CI runs against Nova16:35
JayFwhich means ... it could be a real, unseen failure(?)16:36
dtantsur:(16:40
JayFI'm hoping it's as simple as docker-buildx missing from bindep.txt16:41
dtantsurDoes anyone with integrated OpenStack actually care about https://review.opendev.org/c/openstack/ironic/+/910365 being finished? I can throw Claude on it.16:41
JayFbecause we're using the old builder16:41
dtantsurWhat's the failure? I definitely had to add buildx to Metal3 jobs.16:41
JayFStep 12/16 : ADD bin/* /usr/local/bin \n When using ADD with more than one source file, the destination must be a directory and end with a /16:41
JayFreproduced on cid's devstack ubuntu and my gentoo16:41
JayFwe are trying a docker-buildx install for a fix now16:42
dtantsurHmm, not the same issue. If you control the Dockerfile, you can also fix the complaint.16:42
JayFwe're trying to get it working in devstack16:42
JayFand as I said to cid: we'll have to figure out *why* it's broken now to avoid breaking older docker versions16:42
JayFbindep.txt is apparently correct for podman usage, but is missing pieces for using docker direct16:46
JayFwe can fix16:46
TheJuliasounds like it might be a podman-ism as well, fwiw16:48
JayFit works with docker-buildx, docker-buildx is the superior new way16:48
JayFI'm taking the obvious path16:48
opendevreviewJay Faulkner proposed openstack/ironic master: Ensure docker-buildx is installed on dpkg platforms  https://review.opendev.org/c/openstack/ironic/+/99668216:50
dtantsurJayF: ^^ is a bit odd. Where does docker installation come from? The file only refers to podman.16:52
JayFI assume ubuntu defaults to having it installed, I hadn't considered that16:53
JayFbut I also think docker-buildx does not dep on docker16:53
JayFwait, that's wrong16:53
dtantsurJayF: what I"m trying to say: our bindep looks like we intend to use podman16:54
JayFdtantsur: our lib/devstack/ironic executes `docker build ....`16:54
dtantsurif we end up using docker regardless, maybe we shouldn't install podman?16:54
dtantsuror do we depend on both?16:54
JayFI am coming at this from a "try to fix cid's devstack" and uncovered a build bug16:54
JayFI am not contexted up on this feature in any meaningful way16:54
JayFI suggested to cid directly (we are in 1:1 right now) that he sync up with stevebaker[m] to get some of that context 16:55
dtantsurJayF: I don't see any mentions of docker in ironic's devstack/lib/ironic16:55
JayFIt's 100% in his logs, :-O16:55
dtantsurOo16:55
dtantsurI see mentions of buildah, but not of podman or docker16:56
JayFthis is MUCH more interesting now :D 16:56
JayFhow dare I trust a log16:56
dtantsurI suggest figuring this out first, otherwise we risk that it's going to randomly break again16:56
JayF1000000000% agree16:56
JayFwe are looking actively16:56
dtantsur++16:57
JayFso I see buildah in the docker log; it's actually using docker on this ubuntu to implement it16:58
JayFcid: is about to paste in the logline16:58
cid++ /opt/stack/ironic/devstack/lib/ironic:install_ironic:1261 :   sudo docker build -f ./Containerfile.ubuntu -t localhost/ir16:58
JayFthat's the same line  of code that in devstack/lib/ironic is "buildah bug --from blah -f ....."16:59
JayFaha, we id'd it, it's a part of the change17:01
JayFnot an issue on master17:01
JayFI am going to abandon my change17:01
opendevreviewGhanshyam Maan proposed openstack/ironic master: Remove disabling the scope enforcement  https://review.opendev.org/c/openstack/ironic/+/99668717:39
gmaancardoe: are you ok with this now? 17:40
gmaancardoe: https://review.opendev.org/c/openstack/ironic/+/99655917:40
cardoegmaan: ah I hadn't followed up sorry.17:41
cardoeYes thank you for doing that17:42
gmaancardoe: thanks17:42
JayFFyi, I am unavailable this afternoon. If you need anything, I'll be checking back later this evening or tomorrow.17:54
TheJuliaack ack17:55
TheJuliaI'm likely going to have my last meeting in about an hour and then take the car into the shop to get a new tire17:56
TheJulia:(17:56
TheJuliaand do code review while waiting17:56
JayFWe've been dealing with a dryer that had a heating element go out. Luckily the repair guy is showing up this afternoon17:56
JayFSounds like you need to re-tire 😂17:57
TheJulialol17:59
TheJuliayeah, I must have hit something because I had a side wall bubble appear17:59
TheJuliaso... new tire time17:59
opendevreviewMerged openstack/ironic master: Conditional check of remaining pending attributes  https://review.opendev.org/c/openstack/ironic/+/99377018:03
opendevreviewMahnoor Asghar proposed openstack/ironic master: Soft power off before ejecting virtual media after inspection, regardless of CONF.inspector.power_off. Do not soft power off if PXE boot is enabled.  https://review.opendev.org/c/openstack/ironic/+/99669218:05
opendevreviewMerged openstack/ironic master: Remove setting of oslo_policy[enforce_scope] flag  https://review.opendev.org/c/openstack/ironic/+/99655918:07
TheJuliadtantsur: if you wouldn't mind, a quick review on https://review.opendev.org/c/openstack/ironic/+/996529 would be appreciated18:41
cardoeSo how expensive is a shared lock?18:56
cardoee.g. the power sync periodic queues up all devices even those that don't support power sync18:56
cardoeWould it be better before consuming those queue slots to ask the interface if we support power sync?18:57
TheJuliawell18:59
TheJuliathe more expensive thing is all the db selects for the hydration of the node to really be able to make that power sync call18:59
TheJuliathat being said, all drivers now do support it really18:59
TheJuliasooooo *shrug*18:59
cardoenoop doesn't ;)19:05
cardoeand fake has a hardcoded sleep(CONF.fake.sleep_time)19:07
cardoeWe also added 'disable_power_off' as a top-level node attribute when I wonder if that should have really been a driver_info field.19:08
TheJuliaokay, thats fair19:11
TheJuliadtantsur: we should talk about your evpn thingie19:11
opendevreviewMerged openstack/ironic master: Stop reimporting middleware modules  https://review.opendev.org/c/openstack/ironic/+/99352619:55
-Guest12850- NOTICE: The Gerrit service on review.opendev.org will be offline briefly one hour from now, at 21:00 UTC, while we rename a project.20:01
TheJuliahow many noop nodes to you have ?20:05
TheJuliafwiw, we did previously take a look at some of this and the big thing was the db read hits, but we've also been super gun-shy of building extra logic into constraint in the queries for specific cases, maybe we should, dunno20:05
-Guest12850- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily at 21:00 UTC while we rename a project, but will return within a few minutes.20:59
TheJuliaThank you guest-like bot!21:05
TheJulia:)21:05
cardoeTheJulia: sorry. got to be math tutor for a while21:27
cardoeI might have a bunch of noop nodes... <shifty eyes>21:27
cardoeSo basically we do nodes = list(iter_nodes(["uuid", "driver", "conductor", "id"]) which are the fields we lookup from the DB. 21:33
cardoeWe then split that list up by the number of workers and make futures and spawn off workers.21:34
cardoeThen those workers walk their list and call task_manager.acquire(node_uuid). Which loads the node from the DB and calls load_drivers_from_task(). Which ultimately uses those fields to call get_interface(node.driver, node.$interface)21:36
cardoeDo a whole bunch of metrics things21:37
cardoecache stuff21:38
cardoedo some counts21:38
cardoecheck some stuff if we want to skip checking the power state21:38
cardoeupgrade the shared lock to an exclusive lock21:38
TheJuliawe likely need to be able to exclude some nodes by drivers, I guess for some of that21:39
cardoeNow we call driver.interface.supports_power_sync()21:40
cardoeSo I patched it locally to nodes = [node for node in iter_nodes(["uuid", "driver", "conductor", "id", "power_interface") if get_interface(node.driver, node.power_interface).supports_power_sync()]21:41
TheJuliayeah, but there is a ton of overhead to even hydrate the node object to do all of that, I'm wondering if we can just short circuit even that need since power sync on fake-hardware seems... wrong21:45
cardoeBut I also misunderstood supports_power_sync()... because that function means that conductor should change the power state of the node if it doesn't match the database21:46
cardoeNot what I would have called it...21:46
cardoeIt ALWAYS calls get_power_state()21:47
cardoeAnd fake calls sleep(CONF.fake.power_delay) in that function21:47
cardoeWhich also returns None because of a slew of other code21:49
cardoeNone is not in the set of ALLOWED_POWER_STATES21:49
cardoeSo we send a notification and debug stuff.21:50
TheJuliayeah, so sort of going back, why invoke the loop on drivers which even *HAVE* that condition21:51
TheJuliahjensas: it might be a good idea to review jam ngs stuff at some point soon21:53
cardoeyeah I've been trying to go through them. But it's not light reading.22:46
TheJuliaYeah, I need to find spoons and I just think it would help to spread context and work through them with a couple people22:51

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!