Tuesday, 2026-09-01

opendevreviewJacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching  https://review.opendev.org/c/openstack/ironic/+/100319401:20
opendevreviewJacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching  https://review.opendev.org/c/openstack/ironic/+/100319501:26
opendevreviewJacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching  https://review.opendev.org/c/openstack/ironic/+/100319401:28
opendevreviewAdam McArthur proposed openstack/ironic master: api: Add schema for ports API  https://review.opendev.org/c/openstack/ironic/+/100320203:21
opendevreviewAdam McArthur proposed openstack/ironic master: api: Add schema for nodes API  https://review.opendev.org/c/openstack/ironic/+/100320303:21
opendevreviewAdam McArthur proposed openstack/ironic master: api: Add schema for ramdisk API  https://review.opendev.org/c/openstack/ironic/+/100320403:21
opendevreviewAdam McArthur proposed openstack/ironic-python-agent master: Add pyright type checking  https://review.opendev.org/c/openstack/ironic-python-agent/+/95833303:43
opendevreviewJacob Anders proposed openstack/ironic master: redfish: prefer FirmwareInventory for NIC firmware version caching  https://review.opendev.org/c/openstack/ironic/+/100319404:12
opendevreviewOpenStack Proposal Bot proposed openstack/ironic-ui master: Imported Translations from Zanata  https://review.opendev.org/c/openstack/ironic-ui/+/100321305:01
kubajjgood morning Ironic! o/08:04
iurygregorygood morning ironic o/13:11
kubajjmorning iurygregory 13:34
iurygregorymorning kubajj o/13:40
TheJuliagood morning13:43
iurygregorymorning TheJulia o/13:46
clifgm o/14:02
JayFgm o/ I'll be out again today, still not doing well. Around for a little this morning for a meeting so if you need my +2 or brain speak up soon14:07
TheJuliaugh, feel better Jay :(14:12
cardoehttps://review.opendev.org/c/openstack/releases/+/1003288 is something I proposed. It would help with anyone using dependency validations against the OSSNs that are published.14:18
iurygregorycardoe, tks!14:19
iurygregorylooking now14:19
iurygregoryJayF, take care! hope you will feel better soon!14:19
cardoeJayF: feel better :/14:20
iurygregorycardoe, in case you have others feel free to ping me!14:20
JayFjust my chronic stuff. I think it's winding down, I was expecting to be back in business today14:20
iurygregory=( 14:20
cardoeiurygregory: I'll have to review all the OSSNs. I'm slowly doing it after JayF had asked me to.14:20
iurygregorynp! just ping me when you have something o/14:21
cardoeI just saw one that said >=35.0.2,<36 and we didn't have 35.0.214:21
iurygregory<insert this is fine gif>14:22
JayFcardoe: Generally those are supposed to end with <MAJOR.Minor.CURRENT+114:23
JayFcardoe: so seeing a release that doesn't exist is expected, as the assumption is "a release with this fix will come after this advisory"14:24
cardoeGitHub now automatically scans requirements.txt and pyproject.toml and screams security problems when you don't match.14:25
iurygregoryffs github =X14:26
cardoeTheir own advistory DB, which they use and others use show that ironic is bad due to not having a release.14:26
JayFcardoe: in this context I'm talking about OSSA/OSSN14:26
cardoeSure.14:26
cardoeI'm just wanting to not have us show up badly in the audit tools out there.14:27
cardoeI found out about this in a round about way.14:28
cardoeLike Kevin Bacon stuff.14:28
cardoeMy kid's Boy Scout troop has a kid whose dad works for GitHub and maybe works on this feature.14:28
cardoeThe last camp out we were talking about software stuff and he knew I had OpenStack involvement.14:29
cardoeAnd he's sent me a text message about some OpenStack stuff with their security scanning product.14:29
cardoeI had a convo with him about it and I don't disagree with what he's saying and how security scanners will work.14:32
cardoee.g. https://docs.openstack.org/security-notes/OSSN-0099.html14:32
cardoeThat says to me there's 0 "OpenStack stable" versions of Ironic that can qualify for being secure.14:32
cardoeSorry 2025.1 is secure14:33
cardoeCause 32.0.0 was 2025.2 and 35.0.0 was 2026.1. There's no version that's good. GitHub's DB takes community input to provide a broader version range.14:33
* cardoe shrugs.14:34
TheJuliacardoe: perhaps the idea needs to be surfaced amongst the TC that we should likely aggressively release new changes on stable branches to cover security backports, where right now it might be 1-2 times a cycle based upon the current capacity/capability/memory14:44
cardoeI can do that.14:44
TheJuliaImpression are important, and in the github world they control the modeling of interaction *through* that reporting, so for us to be good citizens and keep up our image, we need to play along with a bot if at all possible.14:45
cardoeThat’s exactly where my head was at.14:45
TheJuliaI'm sure everyone has mentally modeled on "my downstream will pick it up", but thats frankly kind of foolish to focus on when we should be focusing on the public perception (besides, then we control version numbering of that revision number, and not distros incrementing it whenever they feel like)14:47
cardoeneutron seems to make a point release after a security item.14:47
iurygregorypoint release?14:48
TheJuliazed release14:49
cardoelike 35.0.214:49
TheJuliax.y.z14:49
TheJulia.z ;)14:49
cardoeyes14:49
iurygregoryyeah ok!14:49
TheJuliaQuickly, get us the Zed-PMs14:49
* TheJulia should download stargate to the tablet for the upcoming trip14:49
iurygregoryto me it was patch release =), point release makes sense also14:51
iurygregoryI do think we should release after we fix a security item, just worried about the amount we would end up doing, or if we should wait some period of time (so we can include other fixes etc)14:52
TheJuliaIdeally yeah, but we should just bot it at this point14:53
TheJulialand a thing, if there hasn't been a release in a week, cut it.14:53
iurygregory++14:53
iurygregoryyeah, this makes sense to me14:53
cardoeYeah I’m thinking a bit here makes sense.15:26
cardoeBot15:26
cardoeWhat I don't want is more manual work for humans. Especially the security humans.15:29
TheJuliaJFYI, I added an item to the etherpad "Lets discuss architectures we're seeing Ironic" so we can frame topics in the models of use. Feel free to add15:57
* TheJulia suspects cardoe's will be epic ;)15:57
TheJuliacardoe: yeah, please no more security work15:58
TheJulia;)15:58
opendevreviewcid proposed openstack/sushy master: Read reset types from ResetActionInfo when not listed inline  https://review.opendev.org/c/openstack/sushy/+/100330216:17
opendevreviewJulia Kreger proposed openstack/ironic master: json-rpc: Clarify upgrade impact for ksa 5.17.0  https://review.opendev.org/c/openstack/ironic/+/100285416:20
JayFTheJulia: cardoe: I think what makes it a bit difficult is that we've had such an influx that usually we wait for there to be a beat before we cut the release, but we just haven't had that rest period (from reported security issues) this cycle16:21
JayFI'm going to echo what I've said in a lot of VMT discussions: We should not modify the status quo in response to a temporary spike in reports unless we get some proof that spike is going to continue16:22
TheJuliaJayF: yeah, really just more reason to automate that though16:22
JayFYou would have to automate the impacted versions stuff too in order to keep that from making work for security coordinators16:22
TheJuliaWell, cardoe is talking about external perception management16:22
JayFAnd I'm making the point that the circumstances that led to that may be temporary, so I would err on the side of caution16:23
opendevreviewcid proposed openstack/sushy master: Read reset types from ResetActionInfo when not listed inline  https://review.opendev.org/c/openstack/sushy/+/100330216:24
cardoeJayF: TheJulia: https://github.com/advisories/GHSA-jrh2-f5jc-xpgr here's the one that I'm looking at16:25
TheJuliaI think the need to manage our perceptions is disjointed, but I can see your point, yet I don't think our own perception of it maybe being temporary is a basis to not strive to improve because human managing new revision releases after the fact is still putting work on humans16:25
cardoeSo since June 3rd, there's no officially supported version of Ironic that is not affected.16:26
TheJuliaYeah, because we're mentally modeling people just go from git, not pip16:26
TheJuliawhere as github is reporting on pip16:26
cardoeYep16:26
TheJuliaand if you go from git, of course you get that version because pbr16:27
cardoeI'm not saying we're doing anything wrong.16:27
TheJuliabut it hasn't been "released"16:27
JayFWho is our release liaison?16:27
cardoeI'm also saying "I understand the perception of GitHub"16:27
TheJuliaTo be clear, I'm saying we can't keep putting putting releases on a "human do a thing" when it should be like a train of sorts, it should get on the tracks to depart automatically.16:29
cardoeYep16:29
cardoeI absolutely agree there.16:29
cardoeSo my personal pypi packages, if I have a PR (cause I use GitHub) and I add the label "release:patch" well it'll automatically MAJOR.MINOR.PATCH+1 push to PyPi.16:30
cardoeIn fact I have that setup for all programming languages cause I'm lazy.16:31
cardoeWhat I'm saying is that I think we need something similar.16:31
TheJuliaAnd to be clear, It is Iury and Riccardo who presently have to be the ones driving that getting it on a track standpoitn.16:32
TheJuliaor, anyone can, but they have to bless it in addition to the release team16:33
opendevreviewAntony Messerli proposed openstack/ironic-prometheus-exporter master: Ignore non-metrics notifications in PrometheusFileDriver  https://review.opendev.org/c/openstack/ironic-prometheus-exporter/+/100330816:36
* TheJulia blinks16:36
iurygregoryI think the list on our side is only me and Riccardo17:01
iurygregoryso we need to +1 the release patches17:01
TheJuliayes, it is, I checked it.17:01
cardoeTheJulia: you blinkin at Ant?17:02
cardoeCause that was my reaction too17:02
iurygregorywondering if we can have some automation for the case of the OSSNs...17:02
TheJuliawell, the issue more to the point is stuff needs to ship more like on a train schedule once stuff is batched there. Humans with full plates have to context switch which is mentally costly.17:03
TheJuliacardoe: more that any change to the exporter17:03
cardoeI mean it's a good change +2 from me. It actually cleans up something I had asked for previously when that code got added.17:05
TheJuliacardoe: I'll try to review it later today17:05
cardoeTheJulia: I'm wondering if we can introduce a header like "Auto-Release: patch"17:05
cardoeAnd when that change merges it automatically proposes that change for a release17:06
TheJuliaIt might be a technical middle ground, but I think the challenge to work through is the expectation that we can just always rely upon human engagement when I don't think that is really the right answer17:08
cardoeI do think whatever we come up with is probably valid for more than just ironic.17:14
cardoeI can agree that if we publish something like https://security.openstack.org/ossa/OSSA-2026-017.html17:15
cardoeIronic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.217:15
cardoePublic perception wise people aren't gonna say "oh lemme run pbr against your source trees to check the version numbers when auditing"17:15
JayFcardoe: that's an eratta so it's a weird one fwiw17:23
cardoeHe sent me a number of other ones. This one was against Ironic so I figured I'd start the convo here.17:24
TheJuliaSomeone on a call just recalled "standing room only" from our last openinfra EU on an entirely unrelated call. ;)18:52
opendevreviewJulia Kreger proposed openstack/networking-generic-switch master: Add opt-in MTU management for switch ports  https://review.opendev.org/c/openstack/networking-generic-switch/+/98483218:56
zigoWhat's this fake advertizing in neutron-generic-switch, that pretends it doesn't import things from Neutron, removes it from requirements.txt, but "from neutron... import blah" is all over the place ?!?!19:17
TheJuliamultiple modes of use, integrated with and also not integrated19:18
opendevreviewJulia Kreger proposed openstack/networking-generic-switch master: Add opt-in MTU management for switch ports  https://review.opendev.org/c/openstack/networking-generic-switch/+/98483219:29
JayFSimilar to the ironic driver-requirements.txt19:53
opendevreviewcid proposed openstack/ironic master: Don't fail publishing an already published image  https://review.opendev.org/c/openstack/ironic/+/100337119:57
opendevreviewJulia Kreger proposed openstack/networking-generic-switch master: Add opt-in port carrier bounce on bind  https://review.opendev.org/c/openstack/networking-generic-switch/+/98483319:58
opendevreviewJulia Kreger proposed openstack/networking-generic-switch master: Add opt-in STP edge port and BPDU guard support  https://review.opendev.org/c/openstack/networking-generic-switch/+/98484719:58
TheJuliaiurygregory: I tagged you on https://review.opendev.org/c/openstack/ironic-prometheus-exporter/+/1003308, if you coudl just take a glance. I'm not sure we're expecting internal conductor metrics to get surfaced through there 20:09
TheJulia(I just don't remember)20:10
iurygregoryhey TheJulia o/ looking20:57
iurygregorywe did add support for the conductor metrics and they can be stored like  node metrics, but its on a different file ofc20:59
iurygregoryin general the logic makes sense to me20:59
iurygregorya bit worried about "Hardware types without a dedicated sensor parser must still export the header timestamp metric rather than being dropped."21:02
iurygregorythoughts?21:02
iurygregoryto me we shouldn't even export...21:03
iurygregorybut if people like the idea I'm ok21:03
TheJuliaiurygregory: fair to ask questions and for clarity, they are obviously trying to use it21:05
iurygregorydone21:08
cardoeSo my only gripe with ironic-prometheus-exporter is that I want to get the notifications still via my regular notifications channel.21:17
cardoeSo it needs to almost be a middleware21:17
iurygregoryit's the rfe we created right? after the ptg21:18
cardoeoh did we? okay22:03
cardoerm_work has me thinking about switching to kafka too22:03
TheJuliaoh my22:08
rm_workDo it22:08
rm_workFuck rabbit22:09
TheJuliaAhem... language.22:09
rm_workrm -rf rabbitmq22:09
TheJuliaAnyway! I'm trying to remember if it was kafka or activemq that I had sad times with long ago22:09
TheJuliaI think the other major issue is people using quorum queues hwne they likely should ahve bever been used in the first place.22:11
rm_work[m]here's the end of the three-patch chain that replaces rabbit entirely (assuming you swap out notifications to Kafka): https://review.opendev.org/c/openstack/oslo.messaging/+/99747222:11
TheJulianice!22:13

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!