Wednesday, 2026-07-29

opendevreviewMerged openstack/ironic-python-agent-builder master: Add minimal element ironic-python-agent-ramdisk-base  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99765900:02
opendevreviewMerged openstack/ironic stable/2026.1: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99801801:22
opendevreviewJacob Anders proposed openstack/bifrost master: Add uninstall playbook to reverse bifrost install  https://review.opendev.org/c/openstack/bifrost/+/99904101:40
opendevreviewJacob Anders proposed openstack/bifrost master: Add uninstall playbook to reverse bifrost install  https://review.opendev.org/c/openstack/bifrost/+/99904101:45
opendevreviewMerged openstack/ironic-python-agent-builder stable/2025.1: Fixed rescue ConditionPathExists flag  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99831804:09
opendevreviewVerification of a change to openstack/ironic-python-agent-builder master failed: Write container options as comma separated lists  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99838904:09
opendevreviewVerification of a change to openstack/ironic-python-agent-builder master failed: Do not require a container steps file to build  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99839004:09
opendevreviewMerged openstack/ironic-python-agent-builder stable/2025.2: Fixed rescue ConditionPathExists flag  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99902504:09
opendevreviewVerification of a change to openstack/ironic master failed: Remove disabling the scope enforcement  https://review.opendev.org/c/openstack/ironic/+/99668704:17
opendevreviewMerged openstack/ironic master: Remove disabling the scope enforcement  https://review.opendev.org/c/openstack/ironic/+/99668706:27
zigoHi team !08:45
zigoCan someone confirm that ironic-python-agent before Caracal is not affected by CVE-2026-54422 / OSSA-2026-028 ?08:45
zigoI tried backporting https://review.opendev.org/c/openstack/ironic-python-agent/+/998479 but it seems the affected code isn't present.08:45
zigostevebaker[m]: ^08:47
fricklerzigo: https://bugs.launchpad.net/ironic/+bug/2155826/comments/34 ?08:54
zigoThanks, perfect ! :)08:55
zigofrickler: Is the team now stopping backports at 2024.1 ?08:56
zigoA few weeks / months, it was up to 2023.1, which was nice (ie: Antelope, and I maintain up to Zed).08:57
fricklerwell the latest maintained branch is 2025.1 as far as openstack upstream (and thus also the ironic team) is concerned. older unmaintained branches are getting updates depending on who cares for them09:01
zigoI know, though the team has done more, which was super nice.09:01
zigoLooks like it's backporting without effort, so probably not needed for me.09:07
dtantsurHey folks, I've drafted an RFE based on our downstream requirements: https://bugs.launchpad.net/ironic/+bug/2162051. PTAL.09:55
rpittauTheJulia: I was out all morning, but I think I have a solution for that, I'll propose something during the afternoon10:54
dtantsurJayF: as in, you'll be willing to help with portgroups?10:55
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880612:44
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880612:51
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880613:03
cardoeTheJulia: that's a good change in my book13:10
TheJuliarpittau: ack, its just feeling weird since there are some differences13:34
TheJuliadtantsur: didn't I basically propose doing such during a PTG session a couple years ago?13:38
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880613:42
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880613:47
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880613:53
TheJuliafwiw, I've proposed https://review.opendev.org/c/openstack/project-config/+/999124 to clean up IRC messages14:02
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880614:02
dtantsurTheJulia: as far as my memory is concerned, if it was not a couple of weeks ago, it didn't happen :D14:02
opendevreviewPierre Riteau proposed openstack/tenks master: Configure sushy to listen on port 8100  https://review.opendev.org/c/openstack/tenks/+/99912714:02
TheJuliadtantsur: So... no "doublespace" update ? :)14:03
TheJuliaor... was it doubler.14:03
dtantsurwho? what? :)14:03
TheJuliaI don't remember anymore, it was so very very very very very long time ago14:03
TheJuliaOH! There was a product that you installed which compressed your filesystem contents for DOS14:04
TheJuliaI think there was a couple actually14:04
* dtantsur is so confused14:06
TheJuliahttps://en.wikipedia.org/wiki/DriveSpace14:07
dtantsurOh, Windows Me, fun times14:09
opendevreviewDoug Goldstein proposed openstack/ironic master: fix: TBN could not handle evaluations of items that were collections  https://review.opendev.org/c/openstack/ironic/+/99913814:18
opendevreviewRiccardo Pittau proposed openstack/ironic bugfix/37.0: Pin upper constraints to 2026.1 release branch  https://review.opendev.org/c/openstack/ironic/+/99851114:25
opendevreviewPierre Riteau proposed openstack/tenks master: Configure sushy to listen on port 8100  https://review.opendev.org/c/openstack/tenks/+/99912714:31
opendevreviewRowan Johns proposed openstack/tenks master: Add support for persistent networking  https://review.opendev.org/c/openstack/tenks/+/99880614:32
cardoeclif: https://review.opendev.org/c/openstack/ironic/+/999138 or am I crazy?14:33
TheJuliareading the code, I don't think so14:36
TheJuliatags was always a list, but that was likely more than anything, an oversight14:36
TheJuliaor expecting direct match which might have worked for single values14:36
cardoeokay. So I'm trying to use TBN should be the highlighted comment here.14:52
TheJuliaI think that was implied, fwiw14:53
JayFTheJulia: The original brand name of that before Microsoft bought it and put it into dos with stacker. I think stacker's a better name.14:53
TheJuliayeah "doublestacker"14:54
cardoeAfter the recent conversation about Waffle House, I object to using the phrase "doublestacker" so soon. It sounds like a terrifying menu option coming.14:58
TheJulia"scattered, smothered, covered, and peppered" is my only possible potato order.14:59
clifcardoe: you're not crazy15:11
cardoeSorry my claude attributed a note to you... I can delete that.15:11
clifI was about to leave a note on that15:13
clifSo glad clankers will blame me for things it wrote15:13
dtantsurCan I do that too? :-P15:14
clif:D15:14
clifblame me for things I actually did at least!15:15
TheJuliaOhhh! Ahhh! can we "sell" blame permission ?!?15:15
TheJuliaYeah, I'd fix the inline note and have updated my vote as such15:16
TheJuliaI didn't even parse that because I was focusing on the code path15:16
JayFTheJulia: selling blame is already a market cornered by anthropic/openai/friends15:17
TheJuliaWell, I mean among friends15:18
opendevreviewMerged openstack/ironic bugfix/33.0: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99802115:20
opendevreviewMerged openstack/ironic bugfix/34.0: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99802015:20
opendevreviewMerged openstack/ironic stable/2025.2: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99801915:20
opendevreviewMerged openstack/ironic master: Switch jobs to build centos10 IPA images  https://review.opendev.org/c/openstack/ironic/+/99257315:20
opendevreviewRiccardo Pittau proposed openstack/ironic bugfix/37.0: Set tox_constraints_file for bugfix branch Zuul jobs  https://review.opendev.org/c/openstack/ironic/+/99851115:25
dtantsurLooking for a 2nd +2 for a relatively easy bug fix: https://review.opendev.org/c/openstack/ironic/+/99862815:25
TheJuliaIf anyone is interested in moving more towards netconf + libssh for ngs, please take a look at https://review.opendev.org/c/openstack/ironic-specs/+/99765315:25
cardoeBeen trying out the clanker for more OpenStack writing... like it transformed my bug report... https://bugs.launchpad.net/neutron/+bug/216207215:26
dtantsurTheJulia: maybe merge https://review.opendev.org/c/openstack/ironic-specs/+/998363/ in? I'm normally all for smaller bits, but this one changes some of the decisions we do in the first one.15:26
opendevreviewDoug Goldstein proposed openstack/ironic master: fix: TBN could not handle evaluations of items that were collections  https://review.opendev.org/c/openstack/ironic/+/99913815:27
cardoeTheJulia: ^ if ya wanna reapply your review now that the note is clif-less.15:27
TheJuliadtantsur:  we likely need to improve the docstring of that method to detail return values, but that would "e nice"15:28
dtantsurI can follow-up15:28
TheJuliadtantsur: I'd kind of prefer to keep them separated, because we're functionally talking very different things. The libssh direct modeling for running a single command doesn't work in any case where we need to do more switch level config ui state engagement15:29
opendevreviewcid proposed openstack/ironic-tempest-plugin master: Add graphical console API tests  https://review.opendev.org/c/openstack/ironic-tempest-plugin/+/99914315:30
dtantsurTheJulia: it's just odd to discuss certain claims in the spec knowing that we want to change them completely..15:31
TheJuliasuch as rip/replace paramiko entirely?15:32
TheJuliaThis is a middle ground path to at *least* get us to a better place where non-paramiko paths exist15:32
TheJulia(responses will be delayed, on a call15:33
dtantsurOkay, I can live with that.15:33
opendevreviewcid proposed openstack/ironic master: A non-voting job for the container console provider  https://review.opendev.org/c/openstack/ironic/+/99893415:33
opendevreviewSerhii Ivanov proposed openstack/sushy-tools master: Add empty BootOptions collection stub and Boot navigation links  https://review.opendev.org/c/openstack/sushy-tools/+/99191015:38
TheJuliaYeah, the other reason is ncclient also has a dependency on paramiko, but the reason I've avoided making transport configurable, and even even preferred putting libssh as the transport in the name it lock down "what we know is good to be as clear as possible15:41
TheJuliatailing " needed there15:42
TheJuliaI guess the underlying tl;dr is there is a method to my madness15:44
opendevreviewMerged openstack/networking-generic-switch master: Remove Python 3.10 support  https://review.opendev.org/c/openstack/networking-generic-switch/+/99864215:51
opendevreviewSerhii Ivanov proposed openstack/sushy-tools master: Add empty FirmwareInventory collection stub under UpdateService  https://review.opendev.org/c/openstack/sushy-tools/+/99190515:55
opendevreviewSerhii Ivanov proposed openstack/sushy-tools master: Add EthernetInterface UefiDevicePath derived from PCI topology  https://review.opendev.org/c/openstack/sushy-tools/+/99190916:06
JayFTheJulia: https://review.opendev.org/c/openstack/ironic-specs/+/997653/3#message-4c038362bf0209aa11b7403f0befcb20f6d77f82 16:10
JayFTheJulia: tl;dr: I have reports, in the wild (from testing at Rackspace, on an OnMetal time frame) of NETCONF being so slow and unusable on some switches that we had to use SSH instead16:10
JayFTheJulia: so I am highly skeptical of the claims throughout that spec that SSH->NETCONF is a guaranteed performance boost in all cases; especially since I know at least one case in my not-that-extensive-history-of-networking where it wasn't the case.16:11
JayFThe -1 is because of the insistence throughout of a path to deprecation of netmiko/paramiko drivers. I do not believe we should commit to any of that in a spec until the drivers using a new method exist and have proven themselves to be performant. Adding a new, parallel driver framework for science? Yes. Committing to replacing existing stuff with code that doesn't exist yet? No way.16:12
TheJuliale sigh, I mean, the paramiko stuff is not super performant, either16:13
JayFNo, but it has known performance characteristics that folks have been dealing with for a while16:14
TheJuliafair, I guess.16:14
JayFI'd believe 100% that the stuff at Rackspace was some environental-based issue I didn't know enough about to remember now, but those kinda environmental things are exactly what I'm guarding against16:15
JayFI don't want all Ironic customers to have to have THE CONVERSATION(tm) with their NoC again.16:15
TheJuliaIf we dial back explicit early deprecation, then maybe just having the alternate path will be enough to make consumers happy16:16
JayFyeah I mean, to me NGS is the ultimate "bag full o'hacks"16:16
JayFand I don't wanna commit to throwing out all our dirty tricks until we know the proper paths are production ready :)16:17
JayFugly, gross, and working: NGS for a decade 16:17
JayFlol16:17
TheJuliaoh my16:23
TheJuliayeah, I was thinking deprecate just to signal "not the preferred path" once we had the new path16:24
JayFI think that's a good move once we have anyone at all running with the new driver :D16:24
cardoeJayF, TheJulia: NETCONF is a protocol over SSH16:32
TheJulia<teal'c>indeed.</teal'c>16:32
TheJuliaw/r/t running, I was thinking the bar upfront as "we've done basic evaluation and we're seeing it work", but that is different. I guess the concern is placing an expectation on working upon the known problematic feedback loop16:35
JayFTheJulia: you think https://docs.google.com/document/d/1UWPpvmzanmqHIsQOalEwM0yJWbxAx9x4Qz1ofnaiMJw/edit?tab=t.0 (a final draft of a blogpost you reviewed earlier) would be a good candidate for ironicbaremetal.org?16:37
JayFI can ungenericize it and make it about Ironic specifically if desired and we go that route16:37
TheJuliaI think so, but it might also be better for superuser16:39
JayFI just need it to have a home. There's a long enough backlog for GR blog that I need to find somewhere else. The other fallback option is a medium account we have at gr-oss ... but I think medium is gross (no hyphen) so I'm avoiding that16:40
JayFif for superuser, what's the route to make that happen?16:40
TheJuliaI'd normally ping allison price16:41
opendevreviewMerged openstack/ironic master: Power off before ejecting redfish virtual media on ramdisk cleanup  https://review.opendev.org/c/openstack/ironic/+/99864016:41
opendevreviewMerged openstack/ironic master: Another attempt to fix fast-track after inspection  https://review.opendev.org/c/openstack/ironic/+/99862816:41
JayFI'll assume I should act normally?16:42
TheJuliaGenerally yes. I mean, I guess you could emulate your spirit animal?16:47
TheJulia"oh, sun puddle! *flop"16:47
JayFmy spirit animal is another, angrier me16:47
TheJuliathen no spirit animal :)16:48
TheJuliaSo, the other reason I had regarding deprecation was to begin to flag and signal some drivers as items we're not spending time on16:55
TheJulialike.. c300, FastIron, and others16:55
TheJuliaif someone wants to put more effort into them that is fine, but we presently have no means to signal that besides some sort of deprecation.16:56
TheJuliaOR, we create a $new_bat_signal16:56
TheJuliaIt *appears* that renting an explicit bat signal is not an option at the moment16:57
TheJuliaJayF: would you instead agree that we likely need to state our expectations regarding some of the legacy drivers and that we can handle that in a separate spec to add a log warning?16:59
JayFI think just a PR marking those as unsupported is sufficient without mentioning it in the spec17:03
JayFfor that section of like "btw, these drivers are all crappy: " 17:03
JayFAs long as our definition of legacy is ^^^ and not "any *miko drivers"17:04
TheJuliawell, trying to set a tone more so that "we're not going to invest in these drivers"17:04
JayFThat's only a true statement if the netconf drivers have performance and feature partity17:05
JayFYour brain is visioned into the future that doesn't exist yet :) I'm happy to shelve the past once the future is the present 17:06
TheJuliaI mean, its not like these devices even support netconf either or any mode of configuration we can adapt so why not draw a line upfront?17:07
TheJuliaI guess I was hoping to make it clear upfront17:07
TheJuliaand your preferring the keep everything and not signal at all approach17:08
JayFI don't think it is clear though, regardless of what we say. We have likely hundreds of working NGS installs using existing drivers, across who-knows how many switch/firmware models in those families? 17:08
TheJuliawhich doesn't really work for me because then I risk inherent scope creep unless I explicitly limit for netconf supporting devices17:08
JayFHonestly, I see this as like ... ipmitool vs ipminative17:09
JayFipminative was cool and better 100% on paper17:09
JayFbut never panned out in the real world17:09
JayFI think this is much, much more likely to pan out -- but I don't wanna tell people to stop using the old, tested way until we *know* that17:09
TheJuliaI guess I'd still like to explicitly signal "hey, we're not investing in these drivers", but that can be another document17:10
TheJuliawhich is fine17:10
JayFI think *Redhat* is not investing in those drivers. I have a downstream running them, and so do many others, for a while still -- and so there are folks in the community invested in maintaining them and keeping them going.17:11
JayFthe only reason the status quo drivers aren't OK is because of the PQC push, and that's not something that every openstack user has as a priority ... or on their radar at all17:12
TheJuliaOkay, I just didn't think anyone would realistically be using any of those given the age of the gear at this point. Someone actually saying there is use changes things17:12
JayFso to be clear; two things here:17:12
JayF1) the big list of drivers in the spec -> JFDI deprecate/notice/whatever I am +1 to17:13
JayF2) any *miko driver -> JFDI deprecate/notice/whatever I am -1 to17:13
TheJuliaokay, I think I can work with that slicing17:13
JayFI think those are getting conflated17:13
TheJuliaAnd part of it is I want to frame this as advancing more modern mechanims as well17:14
JayFyeah, my main thing is "let's not mark the most well implemented, maintained drivers in NGS as anything-negative until they have better replacements" (even in a spec)17:14
TheJuliaand some of these others, its more full of nope because they are more "legacy" than somethihng more "modern"17:14
TheJuliafair enough17:15
TheJuliarpittau: I guess what I've been forgetting is the overall file to use is set as an environment variable, we just need to change the branch to use a local file and entirely disregard the environment variable17:43
cardoehjensas: https://review.opendev.org/c/openstack/neutron/+/999158 I needed that fwiw18:33
TheJuliahjensas is out for a few weeks18:57
TheJuliajfyi18:57
opendevreviewcid proposed openstack/ironic-python-agent-builder master: Write container options as comma separated lists  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99838919:09
opendevreviewcid proposed openstack/ironic-python-agent-builder master: Do not require a container steps file to build  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99839019:09
opendevreviewcid proposed openstack/ironic-python-agent-builder master: Verify registry TLS by default in the podman element  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99917819:09
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Security: Make mDNS discovery explicitly opt-in  https://review.opendev.org/c/openstack/ironic-python-agent/+/99763719:18
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Allow limiting what config can be set in mDNS  https://review.opendev.org/c/openstack/ironic-python-agent/+/99763819:18
opendevreviewJay Faulkner proposed openstack/ironic-python-agent master: Allow limiting what config can be set in mDNS  https://review.opendev.org/c/openstack/ironic-python-agent/+/99763819:18
JayFTheJulia: ^ had to add a Related-bug, if you get a chance and wanna restore your +219:18
opendevreviewSteve Baker proposed openstack/ironic-python-agent-builder master: Add podman package to ironic-python-agent-ramdisk  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/97033622:14
JayF^ We should absolutely not do that. We basically double the attack surface of our default IPA image by enabling bootc and containerhardwaremanager in default ramdisks. :( 22:36
* JayF has placed that comment on there22:36

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!