| opendevreview | Jacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching https://review.opendev.org/c/openstack/ironic/+/1003194 | 01:20 |
|---|---|---|
| opendevreview | Jacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching https://review.opendev.org/c/openstack/ironic/+/1003195 | 01:26 |
| opendevreview | Jacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching https://review.opendev.org/c/openstack/ironic/+/1003194 | 01:28 |
| opendevreview | Adam McArthur proposed openstack/ironic master: api: Add schema for ports API https://review.opendev.org/c/openstack/ironic/+/1003202 | 03:21 |
| opendevreview | Adam McArthur proposed openstack/ironic master: api: Add schema for nodes API https://review.opendev.org/c/openstack/ironic/+/1003203 | 03:21 |
| opendevreview | Adam McArthur proposed openstack/ironic master: api: Add schema for ramdisk API https://review.opendev.org/c/openstack/ironic/+/1003204 | 03:21 |
| opendevreview | Adam McArthur proposed openstack/ironic-python-agent master: Add pyright type checking https://review.opendev.org/c/openstack/ironic-python-agent/+/958333 | 03:43 |
| opendevreview | Jacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching https://review.opendev.org/c/openstack/ironic/+/1003194 | 04:12 |
| opendevreview | OpenStack Proposal Bot proposed openstack/ironic-ui master: Imported Translations from Zanata https://review.opendev.org/c/openstack/ironic-ui/+/1003213 | 05:01 |
| kubajj | good morning Ironic! o/ | 08:04 |
| iurygregory | good morning ironic o/ | 13:11 |
| kubajj | morning iurygregory | 13:34 |
| iurygregory | morning kubajj o/ | 13:40 |
| TheJulia | good morning | 13:43 |
| iurygregory | morning TheJulia o/ | 13:46 |
| clif | gm o/ | 14:02 |
| JayF | gm o/ I'll be out again today, still not doing well. Around for a little this morning for a meeting so if you need my +2 or brain speak up soon | 14:07 |
| TheJulia | ugh, feel better Jay :( | 14:12 |
| cardoe | https://review.opendev.org/c/openstack/releases/+/1003288 is something I proposed. It would help with anyone using dependency validations against the OSSNs that are published. | 14:18 |
| iurygregory | cardoe, tks! | 14:19 |
| iurygregory | looking now | 14:19 |
| iurygregory | JayF, take care! hope you will feel better soon! | 14:19 |
| cardoe | JayF: feel better :/ | 14:20 |
| iurygregory | cardoe, in case you have others feel free to ping me! | 14:20 |
| JayF | just my chronic stuff. I think it's winding down, I was expecting to be back in business today | 14:20 |
| iurygregory | =( | 14:20 |
| cardoe | iurygregory: I'll have to review all the OSSNs. I'm slowly doing it after JayF had asked me to. | 14:20 |
| iurygregory | np! just ping me when you have something o/ | 14:21 |
| cardoe | I just saw one that said >=35.0.2,<36 and we didn't have 35.0.2 | 14:21 |
| iurygregory | <insert this is fine gif> | 14:22 |
| JayF | cardoe: Generally those are supposed to end with <MAJOR.Minor.CURRENT+1 | 14:23 |
| JayF | cardoe: so seeing a release that doesn't exist is expected, as the assumption is "a release with this fix will come after this advisory" | 14:24 |
| cardoe | GitHub now automatically scans requirements.txt and pyproject.toml and screams security problems when you don't match. | 14:25 |
| iurygregory | ffs github =X | 14:26 |
| cardoe | Their own advistory DB, which they use and others use show that ironic is bad due to not having a release. | 14:26 |
| JayF | cardoe: in this context I'm talking about OSSA/OSSN | 14:26 |
| cardoe | Sure. | 14:26 |
| cardoe | I'm just wanting to not have us show up badly in the audit tools out there. | 14:27 |
| cardoe | I found out about this in a round about way. | 14:28 |
| cardoe | Like Kevin Bacon stuff. | 14:28 |
| cardoe | My kid's Boy Scout troop has a kid whose dad works for GitHub and maybe works on this feature. | 14:28 |
| cardoe | The last camp out we were talking about software stuff and he knew I had OpenStack involvement. | 14:29 |
| cardoe | And he's sent me a text message about some OpenStack stuff with their security scanning product. | 14:29 |
| cardoe | I had a convo with him about it and I don't disagree with what he's saying and how security scanners will work. | 14:32 |
| cardoe | e.g. https://docs.openstack.org/security-notes/OSSN-0099.html | 14:32 |
| cardoe | That says to me there's 0 "OpenStack stable" versions of Ironic that can qualify for being secure. | 14:32 |
| cardoe | Sorry 2025.1 is secure | 14:33 |
| cardoe | Cause 32.0.0 was 2025.2 and 35.0.0 was 2026.1. There's no version that's good. GitHub's DB takes community input to provide a broader version range. | 14:33 |
| * cardoe shrugs. | 14:34 | |
| TheJulia | cardoe: perhaps the idea needs to be surfaced amongst the TC that we should likely aggressively release new changes on stable branches to cover security backports, where right now it might be 1-2 times a cycle based upon the current capacity/capability/memory | 14:44 |
| cardoe | I can do that. | 14:44 |
| TheJulia | Impression are important, and in the github world they control the modeling of interaction *through* that reporting, so for us to be good citizens and keep up our image, we need to play along with a bot if at all possible. | 14:45 |
| cardoe | That’s exactly where my head was at. | 14:45 |
| TheJulia | I'm sure everyone has mentally modeled on "my downstream will pick it up", but thats frankly kind of foolish to focus on when we should be focusing on the public perception (besides, then we control version numbering of that revision number, and not distros incrementing it whenever they feel like) | 14:47 |
| cardoe | neutron seems to make a point release after a security item. | 14:47 |
| iurygregory | point release? | 14:48 |
| TheJulia | zed release | 14:49 |
| cardoe | like 35.0.2 | 14:49 |
| TheJulia | x.y.z | 14:49 |
| TheJulia | .z ;) | 14:49 |
| cardoe | yes | 14:49 |
| iurygregory | yeah ok! | 14:49 |
| TheJulia | Quickly, get us the Zed-PMs | 14:49 |
| * TheJulia should download stargate to the tablet for the upcoming trip | 14:49 | |
| iurygregory | to me it was patch release =), point release makes sense also | 14:51 |
| iurygregory | I do think we should release after we fix a security item, just worried about the amount we would end up doing, or if we should wait some period of time (so we can include other fixes etc) | 14:52 |
| TheJulia | Ideally yeah, but we should just bot it at this point | 14:53 |
| TheJulia | land a thing, if there hasn't been a release in a week, cut it. | 14:53 |
| iurygregory | ++ | 14:53 |
| iurygregory | yeah, this makes sense to me | 14:53 |
| cardoe | Yeah I’m thinking a bit here makes sense. | 15:26 |
| cardoe | Bot | 15:26 |
| cardoe | What I don't want is more manual work for humans. Especially the security humans. | 15:29 |
| TheJulia | JFYI, I added an item to the etherpad "Lets discuss architectures we're seeing Ironic" so we can frame topics in the models of use. Feel free to add | 15:57 |
| * TheJulia suspects cardoe's will be epic ;) | 15:57 | |
| TheJulia | cardoe: yeah, please no more security work | 15:58 |
| TheJulia | ;) | 15:58 |
| opendevreview | cid proposed openstack/sushy master: Read reset types from ResetActionInfo when not listed inline https://review.opendev.org/c/openstack/sushy/+/1003302 | 16:17 |
| opendevreview | Julia Kreger proposed openstack/ironic master: json-rpc: Clarify upgrade impact for ksa 5.17.0 https://review.opendev.org/c/openstack/ironic/+/1002854 | 16:20 |
| JayF | TheJulia: cardoe: I think what makes it a bit difficult is that we've had such an influx that usually we wait for there to be a beat before we cut the release, but we just haven't had that rest period (from reported security issues) this cycle | 16:21 |
| JayF | I'm going to echo what I've said in a lot of VMT discussions: We should not modify the status quo in response to a temporary spike in reports unless we get some proof that spike is going to continue | 16:22 |
| TheJulia | JayF: yeah, really just more reason to automate that though | 16:22 |
| JayF | You would have to automate the impacted versions stuff too in order to keep that from making work for security coordinators | 16:22 |
| TheJulia | Well, cardoe is talking about external perception management | 16:22 |
| JayF | And I'm making the point that the circumstances that led to that may be temporary, so I would err on the side of caution | 16:23 |
| opendevreview | cid proposed openstack/sushy master: Read reset types from ResetActionInfo when not listed inline https://review.opendev.org/c/openstack/sushy/+/1003302 | 16:24 |
| cardoe | JayF: TheJulia: https://github.com/advisories/GHSA-jrh2-f5jc-xpgr here's the one that I'm looking at | 16:25 |
| TheJulia | I think the need to manage our perceptions is disjointed, but I can see your point, yet I don't think our own perception of it maybe being temporary is a basis to not strive to improve because human managing new revision releases after the fact is still putting work on humans | 16:25 |
| cardoe | So since June 3rd, there's no officially supported version of Ironic that is not affected. | 16:26 |
| TheJulia | Yeah, because we're mentally modeling people just go from git, not pip | 16:26 |
| TheJulia | where as github is reporting on pip | 16:26 |
| cardoe | Yep | 16:26 |
| TheJulia | and if you go from git, of course you get that version because pbr | 16:27 |
| cardoe | I'm not saying we're doing anything wrong. | 16:27 |
| TheJulia | but it hasn't been "released" | 16:27 |
| JayF | Who is our release liaison? | 16:27 |
| cardoe | I'm also saying "I understand the perception of GitHub" | 16:27 |
| TheJulia | To be clear, I'm saying we can't keep putting putting releases on a "human do a thing" when it should be like a train of sorts, it should get on the tracks to depart automatically. | 16:29 |
| cardoe | Yep | 16:29 |
| cardoe | I absolutely agree there. | 16:29 |
| cardoe | So my personal pypi packages, if I have a PR (cause I use GitHub) and I add the label "release:patch" well it'll automatically MAJOR.MINOR.PATCH+1 push to PyPi. | 16:30 |
| cardoe | In fact I have that setup for all programming languages cause I'm lazy. | 16:31 |
| cardoe | What I'm saying is that I think we need something similar. | 16:31 |
| TheJulia | And to be clear, It is Iury and Riccardo who presently have to be the ones driving that getting it on a track standpoitn. | 16:32 |
| TheJulia | or, anyone can, but they have to bless it in addition to the release team | 16:33 |
| opendevreview | Antony Messerli proposed openstack/ironic-prometheus-exporter master: Ignore non-metrics notifications in PrometheusFileDriver https://review.opendev.org/c/openstack/ironic-prometheus-exporter/+/1003308 | 16:36 |
| * TheJulia blinks | 16:36 | |
| iurygregory | I think the list on our side is only me and Riccardo | 17:01 |
| iurygregory | so we need to +1 the release patches | 17:01 |
| TheJulia | yes, it is, I checked it. | 17:01 |
| cardoe | TheJulia: you blinkin at Ant? | 17:02 |
| cardoe | Cause that was my reaction too | 17:02 |
| iurygregory | wondering if we can have some automation for the case of the OSSNs... | 17:02 |
| TheJulia | well, the issue more to the point is stuff needs to ship more like on a train schedule once stuff is batched there. Humans with full plates have to context switch which is mentally costly. | 17:03 |
| TheJulia | cardoe: more that any change to the exporter | 17:03 |
| cardoe | I mean it's a good change +2 from me. It actually cleans up something I had asked for previously when that code got added. | 17:05 |
| TheJulia | cardoe: I'll try to review it later today | 17:05 |
| cardoe | TheJulia: I'm wondering if we can introduce a header like "Auto-Release: patch" | 17:05 |
| cardoe | And when that change merges it automatically proposes that change for a release | 17:06 |
| TheJulia | It might be a technical middle ground, but I think the challenge to work through is the expectation that we can just always rely upon human engagement when I don't think that is really the right answer | 17:08 |
| cardoe | I do think whatever we come up with is probably valid for more than just ironic. | 17:14 |
| cardoe | I can agree that if we publish something like https://security.openstack.org/ossa/OSSA-2026-017.html | 17:15 |
| cardoe | Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2 | 17:15 |
| cardoe | Public perception wise people aren't gonna say "oh lemme run pbr against your source trees to check the version numbers when auditing" | 17:15 |
| JayF | cardoe: that's an eratta so it's a weird one fwiw | 17:23 |
| cardoe | He sent me a number of other ones. This one was against Ironic so I figured I'd start the convo here. | 17:24 |
| TheJulia | Someone on a call just recalled "standing room only" from our last openinfra EU on an entirely unrelated call. ;) | 18:52 |
| opendevreview | Julia Kreger proposed openstack/networking-generic-switch master: Add opt-in MTU management for switch ports https://review.opendev.org/c/openstack/networking-generic-switch/+/984832 | 18:56 |
| zigo | What's this fake advertizing in neutron-generic-switch, that pretends it doesn't import things from Neutron, removes it from requirements.txt, but "from neutron... import blah" is all over the place ?!?! | 19:17 |
| TheJulia | multiple modes of use, integrated with and also not integrated | 19:18 |
| opendevreview | Julia Kreger proposed openstack/networking-generic-switch master: Add opt-in MTU management for switch ports https://review.opendev.org/c/openstack/networking-generic-switch/+/984832 | 19:29 |
| JayF | Similar to the ironic driver-requirements.txt | 19:53 |
| opendevreview | cid proposed openstack/ironic master: Don't fail publishing an already published image https://review.opendev.org/c/openstack/ironic/+/1003371 | 19:57 |
| opendevreview | Julia Kreger proposed openstack/networking-generic-switch master: Add opt-in port carrier bounce on bind https://review.opendev.org/c/openstack/networking-generic-switch/+/984833 | 19:58 |
| opendevreview | Julia Kreger proposed openstack/networking-generic-switch master: Add opt-in STP edge port and BPDU guard support https://review.opendev.org/c/openstack/networking-generic-switch/+/984847 | 19:58 |
| TheJulia | iurygregory: I tagged you on https://review.opendev.org/c/openstack/ironic-prometheus-exporter/+/1003308, if you coudl just take a glance. I'm not sure we're expecting internal conductor metrics to get surfaced through there | 20:09 |
| TheJulia | (I just don't remember) | 20:10 |
| iurygregory | hey TheJulia o/ looking | 20:57 |
| iurygregory | we did add support for the conductor metrics and they can be stored like node metrics, but its on a different file ofc | 20:59 |
| iurygregory | in general the logic makes sense to me | 20:59 |
| iurygregory | a bit worried about "Hardware types without a dedicated sensor parser must still export the header timestamp metric rather than being dropped." | 21:02 |
| iurygregory | thoughts? | 21:02 |
| iurygregory | to me we shouldn't even export... | 21:03 |
| iurygregory | but if people like the idea I'm ok | 21:03 |
| TheJulia | iurygregory: fair to ask questions and for clarity, they are obviously trying to use it | 21:05 |
| iurygregory | done | 21:08 |
| cardoe | So my only gripe with ironic-prometheus-exporter is that I want to get the notifications still via my regular notifications channel. | 21:17 |
| cardoe | So it needs to almost be a middleware | 21:17 |
| iurygregory | it's the rfe we created right? after the ptg | 21:18 |
| cardoe | oh did we? okay | 22:03 |
| cardoe | rm_work has me thinking about switching to kafka too | 22:03 |
| TheJulia | oh my | 22:08 |
| rm_work | Do it | 22:08 |
| rm_work | Fuck rabbit | 22:09 |
| TheJulia | Ahem... language. | 22:09 |
| rm_work | rm -rf rabbitmq | 22:09 |
| TheJulia | Anyway! I'm trying to remember if it was kafka or activemq that I had sad times with long ago | 22:09 |
| TheJulia | I think the other major issue is people using quorum queues hwne they likely should ahve bever been used in the first place. | 22:11 |
| rm_work[m] | here's the end of the three-patch chain that replaces rabbit entirely (assuming you swap out notifications to Kafka): https://review.opendev.org/c/openstack/oslo.messaging/+/997472 | 22:11 |
| TheJulia | nice! | 22:13 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!