Thursday, 2026-08-06

opendevreviewJacob Anders proposed openstack/ironic master: Unify non-BMC firmware updates under batched state machine  https://review.opendev.org/c/openstack/ironic/+/99972005:23
opendevreviewJacob Anders proposed openstack/ironic master: Document batched firmware updates and add release note  https://review.opendev.org/c/openstack/ironic/+/99972105:23
opendevreviewJacob Anders proposed openstack/ironic master: Refactor firmware update SimpleUpdate submission and error dispatch  https://review.opendev.org/c/openstack/ironic/+/99923006:27
opendevreviewJacob Anders proposed openstack/ironic master: Unify non-BMC firmware updates under batched state machine  https://review.opendev.org/c/openstack/ironic/+/99972006:27
opendevreviewJacob Anders proposed openstack/ironic master: Document batched firmware updates and add release note  https://review.opendev.org/c/openstack/ironic/+/99972106:27
opendevreviewMerged openstack/ironic bugfix/38.0: Fix fast-track deployment failure with autodetect deploy interface  https://review.opendev.org/c/openstack/ironic/+/99987007:28
zigoJayF: Hi there! Are versions <= Flamingo unaffected by CVE-2026-71201, or is it that you consider it not grave, and so will not backport ?09:33
iurygregorygood morning ironic o/11:06
cardoevmedia busted?12:37
dtantsurhttps://zuul.opendev.org/t/openstack/builds?job_name=ironic-tempest-uefi-redfish-vmedia&project=openstack/ironic?12:39
dtantsurlooks inconclusive12:39
cardoeJust everything I pushed yesterday failed on it and then rechecks did as well. Even the patch that was just docs and code comments and I renamed a few variables to make things more clear.12:42
opendevreviewYorick proposed openstack/sushy master: system: guard HttpBootUri writes against iDRAC 10 removal  https://review.opendev.org/c/openstack/sushy/+/99974313:20
TheJuliagood orning13:24
TheJuliamorning13:24
JayFzigo: if you're talking the one from yesterday, the ossa describes the affected versions correctly. The CVE might be incorrect depending on how quickly they update it13:33
zigoJayF: My understanding is that for OSSA-2026-033 aka CVE-2026-71201 only Gazpacho is affected indeed. Though I'm talking about OSSN-0104 where I can read:13:35
zigo"The following patches are backwards incompatible and were not merged into stable branches"13:35
zigoand there, I'm unsure what to do.13:35
zigoOh, yeah, when I wrote that earlier, I wasn't sure about OSSA-2026-033 indeed, but I think I understood since ! :)13:36
* TheJulia attempts to wake up more13:41
cardoejanders: you work on MultipartHttpPush?13:52
TheJuliaRegarding CI failures, it is sure looking like somewhere deep in pip installation when installing tempest that things go completely sideways :\13:53
cardoeYeah. It’s the fetch of the constraints13:53
cardoeWe need to update packages and things that devstack and tempest do. I’ve been trying to do so but I’ve gotten stuck.13:54
TheJuliathe error for those interested https://www.irccloud.com/pastebin/kH17eXit/13:55
TheJuliastuck how so?13:55
cardoestephenfin pointed out its related to how we reach into tox’s paths instead of using our own virtualenv.13:56
dtantsurI saw this pip error in Metal3 as well. Seems transient.13:56
TheJuliacardoe: when you say we, you mean devstack?13:57
cardoeYes sorry.13:58
cardoeIt’s not ironic specific.13:58
cardoeNeed more spoons and multi-yak shaver to get it done.13:58
TheJuliaso, Interesitngly enough, the tempest install also forces a downgrade of tox 8(14:01
JayFzigo: The ossn basically lays it out. It's a security fix that cannot be done in a stable non-breaking way for a back port, so we didn't backport it.14:09
JayFI would suggest with a package maintainer hat on that you not back port as well14:09
mnaserappreciate eyes on https://review.opendev.org/c/openstack/ironic/+/998711 and https://review.opendev.org/c/openstack/sushy/+/999741 please14:13
dtantsuralso backport please https://review.opendev.org/q/Iec722dd65a27a7f0043f8ed5e0126929960f8f8a14:14
TheJuliaare we not using ironic-week-prio ?14:15
dtantsurhmm, indeed, forgot on these ones14:17
TheJuliaI just ask because I've been struggling to get folks to review prio items for a while and there were 36 items on ther eearlier14:19
TheJulias/ther/there/14:19
dtantsurthey accummulate rapidly..14:24
TheJuliaEh, sometimes yes14:24
TheJuliabut I landed a number last week and its climbed back up too14:25
opendevreviewMerged openstack/ironic bugfix/37.0: security: Fix poisoning of the allowed origin list  https://review.opendev.org/c/openstack/ironic/+/99801714:35
TheJuliaQuestion: has anyone submitted anything to OpenInfra Days NA ?15:03
TheJuliaugh, looks like ci is just in super bad state upon my lance at the dashboard15:06
JayFthis is the first I'm finding it has a date set15:06
JayFHow is both the call for papers still open *and* they have presentations listed?15:08
JayFhttps://us06web.zoom.us/j/81440356009?pwd=x7wiYOdHP2NzLv3714yyzFhUeNlNC6.1 cid and I will be doing some group reviewing until the top of the hour (about 1700 UTC)16:16
JayFfolks are welcome to join16:16
JayFrpittau: https://review.opendev.org/c/openstack/ironic/+/997366/10#message-a4783c18ee3acb8dd19a1e0694d7b7969302f880 I'm fairly sure I'm missing something here; but the release note seems to describe different behavior than what was happening in the "before" diff? /me suspects there's a nuance he's missing16:32
opendevreviewDoug Goldstein proposed openstack/ironic master: Deprecate list-style args for inspection rule operations  https://review.opendev.org/c/openstack/ironic/+/100000716:49
opendevreviewDoug Goldstein proposed openstack/ironic master: Document inspection rule operation arguments explicitly  https://review.opendev.org/c/openstack/ironic/+/100000816:49
cardoeJayF: I'm jumping between calls and cannot join you guys today... but would you mind asking cid to look at the above? I believe he wrote the inspection rules bit originally.16:50
JayFhe can see that too, you pinged him :D 16:50
cardoeI realized that we actually released that feature in 2025.1 so I'm going with deprecation instead.16:50
JayFalthoguh I'll admit we both worked on the inspection rules with nearly-zero context16:50
JayFTheJulia: please re-evaluate your -1 on https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/998389 16:51
cardoeWell I've got 10 minutes before my next call so I could join ya for 10 minutes. But I suspect you don't wanna talk inspection rules.16:51
JayFwe're close to wrapping tbh16:51
JayFand just did a big context dump on policy16:51
cardoeoooo policy16:51
TheJuliaJayF: will do when I'm off my current call16:52
cardoeThat's something I've got on my real soon now backlog.16:52
JayFTheJulia: same here https://review.opendev.org/c/openstack/ironic/+/99838516:52
opendevreviewMerged openstack/ironic master: Utilize KernelCommmandLine.parse() instead of ironic.common.utils.parse_kernel_params  https://review.opendev.org/c/openstack/ironic/+/99230917:05
TheJuliaJayF: I pinged spotz and she asked if you could provide anymore context or a link, its apparently her first time driving an event with sessionize17:14
TheJuliaso a different view may be what is needed17:14
JayFTheJulia: *blink*17:14
JayFTheJulia: I am missing context on that comment?17:14
TheJuliaJayF: w/r/t oid NA showing talks already while the cfp is open17:15
TheJuliaShe is going to try and jump in here momentarily17:15
JayFah okay17:15
JayFIt's not a big deal, I just didn't even know that had gotten a date yet17:15
JayFand it's soon17:15
JayFbut it's also in the same state as my BFF so I got two reasons to go lol17:15
TheJuliaI was thinking of submitting FWIW17:16
JayFTheJulia: I went to check to the dates with Vanessa to ensure I could travel and discovered I was on the 2024 days page17:17
JayFlol17:17
JayFWHOOPS17:17
JayFhttps://linuxfoundation.regfox.com/openinfra-day-north-america okay that's better lol17:18
TheJuliaokay, that explains a LOT17:19
JayFyeah basically everything lol17:19
* TheJulia wonders how many NA contributors we could collect17:20
JayFI kinda feel like a "wow, security huh?" talk would go over well17:21
TheJulia++17:21
JayFjust VMT lookback over the last 12-18 months + some basics about the process, good, bad, etc17:21
TheJulia+100017:21
opendevreviewJulia Kreger proposed openstack/ironic-python-agent master: Enforce checksum algorithm validation for Nvidia NIC firmware  https://review.opendev.org/c/openstack/ironic-python-agent/+/100001817:39
opendevreviewJulia Kreger proposed openstack/ironic-python-agent master: Change md5_enabled default to False  https://review.opendev.org/c/openstack/ironic-python-agent/+/100001917:39
opendevreviewMerged openstack/ironic master: CI: collect libvirt/qemu logs in the Metal3 BMO job  https://review.opendev.org/c/openstack/ironic/+/99880717:47
opendevreviewMerged openstack/ironic stable/2026.1: Fix Redfish inspection without Storage API  https://review.opendev.org/c/openstack/ironic/+/99980917:55
opendevreviewMerged openstack/ironic bugfix/37.0: Fix Redfish inspection without Storage API  https://review.opendev.org/c/openstack/ironic/+/99981117:55
TheJuliaJayF: Regarding https://review.opendev.org/c/openstack/ironic/+/992542 node.py, I guess we're doing the additional layer of policy validation later on because it is after the version checks, we can move up and merge in, I guess. I think its all mental modeling related17:55
opendevreviewMerged openstack/ironic bugfix/38.0: Fix Redfish inspection without Storage API  https://review.opendev.org/c/openstack/ironic/+/99981017:55
JayFmy comment was basically driven by "I don't think the ordering matters, but if it does I don't fully understand"17:56
JayFand given it was duping an if, worth the ask :)17:56
TheJuliaI could see moving it up I guess17:57
JayFI'm less concerned about it needing change and more making sure my mental model of the method was right17:58
JayFmy vote is already upgraded to a +2 fwiw :D 17:58
opendevreviewMerged openstack/ironic-python-agent-builder master: Write container options as comma separated lists  https://review.opendev.org/c/openstack/ironic-python-agent-builder/+/99838917:58
TheJuliawell, I'll revise it real quick then17:58
opendevreviewJulia Kreger proposed openstack/ironic master: Extend the RBAC policy matrix to steps  https://review.opendev.org/c/openstack/ironic/+/99254218:05
opendevreviewVerification of a change to openstack/ironic master failed: doc: Fix the container-based steps guide  https://review.opendev.org/c/openstack/ironic/+/99838718:07
opendevreviewMerged openstack/ironic master: Fix the types of the agent_containers options  https://review.opendev.org/c/openstack/ironic/+/99838518:15
opendevreviewJulia Kreger proposed openstack/ironic master: Document ansible deploy interface SSH host key checking  https://review.opendev.org/c/openstack/ironic/+/100002318:27
opendevreviewMerged openstack/ironic-python-agent stable/2025.2: security: fix NTP command handling  https://review.opendev.org/c/openstack/ironic-python-agent/+/99848918:34
TheJuliaJayF: w/r/t the ramdisk endpoints stuff, happy to do the ossn if you want18:58
opendevreviewMerged openstack/ironic bugfix/34.0: Portgroup shard filter bypasses scope to project  https://review.opendev.org/c/openstack/ironic/+/99976519:16
opendevreviewMerged openstack/ironic master: Drop the unused container_conf_file option  https://review.opendev.org/c/openstack/ironic/+/99838619:25
JayFTheJulia: I can or you can, no rush though because at this point we're likely waiting until Tuesday to advisory it anyway (VMT policy -> no advisories on Fri-Mon)20:14
TheJuliaOh yeah, I'd sort of love to see the patch get traction as well in the mean time. I'll likely try to whip something up tomorrow, although I'm starting to feel a little udner the weather and hopefully that is not a sign I'm getting a cold or something20:15
JayFThe outcome of this conversation was gonna decide if I take today-afternoon or tomorrow-afternoon off20:18
JayFthis means today-afternoon wins 20:19
JayFlol20:19
JayFo/ 20:19
TheJuliahave a great afternoon!20:19
opendevreviewMerged openstack/ironic-python-agent master: security: Fix the container allowlist not being enforced  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837521:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Prevent container steps from shadowing existing steps  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837621:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Only honor container step priorities while cleaning  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837721:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Accept whitespace separated container options  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837821:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Check that the configured container runtime is present  https://review.opendev.org/c/openstack/ironic-python-agent/+/99837921:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Report errors reading the container steps file  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838021:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Ignore the transport prefix when matching allowed containers  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838121:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Drop the unused container_conf_file option  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838221:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Rename container_clean_step to generic_container_step  https://review.opendev.org/c/openstack/ironic-python-agent/+/99838321:57
opendevreviewVerification of a change to openstack/ironic-python-agent master failed: Verify registry TLS by default  https://review.opendev.org/c/openstack/ironic-python-agent/+/99972521:57
opendevreviewDoug Goldstein proposed openstack/ironic master: fix runbook create notifications  https://review.opendev.org/c/openstack/ironic/+/100005022:10
opendevreviewDoug Goldstein proposed openstack/ironic master: Allow disable_ramdisk to be updated via runbook PATCH  https://review.opendev.org/c/openstack/ironic/+/100005923:15
opendevreviewJay Jahns proposed openstack/ironic master: Redfish: retry transient 409 conflict on power-on  https://review.opendev.org/c/openstack/ironic/+/100006023:25

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!