Thursday, 2018-08-02

gagehugo#startmeeting security15:02
openstackMeeting started Thu Aug  2 15:02:18 2018 UTC and is due to finish in 60 minutes.  The chair is gagehugo. Information about MeetBot at
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:02
*** openstack changes topic to " (Meeting topic: security)"15:02
openstackThe meeting name has been set to 'security'15:02
gagehugoping eeiden fungi gagehugo lhinds nickthetait browne redrobot15:02
fungiaround but also in tc office hour as usual15:03
fungi(back from vacation at least!)15:03
gagehugofungi o/ hope the vacation was good15:03
gagehugoI will be covering for lhinds chairing for the next 3 weeks, I believe he is out on PTO15:05
gagehugonickthetait o/15:05
*** alexpilotti has quit IRC15:06
*** davidsha_ has joined #openstack-meeting15:06
gagehugo#topic bandit migration15:07
*** openstack changes topic to "bandit migration (Meeting topic: security)"15:07
gagehugoI believe lhinds had this on his agenda, no updates from me15:07
gagehugo#topic OSSN/OSSA15:07
*** openstack changes topic to "OSSN/OSSA (Meeting topic: security)"15:07
gagehugofungi nickthetait any updates?15:08
fungithere's this:15:09
fungi#link Remove Security project team15:09
fungibasically cleanup and reassigning its deliverable repos to the security sig15:09
gagehugooh yeah15:09
fungieasier than bothernig to have someone volunteer to be ptl of a defunct team for another cycle15:10
fungier, bothering15:10
fungialso there's been some followup discussion on ossa-2018-002 that it may be an incomplete fix15:11
openstackLaunchpad bug 1779205 in OpenStack Identity (keystone) rocky "[OSSA-2018-002] GET /v3/OS-FEDERATION/projects leaks project information (CVE-2018-14432)" [Critical,Fix released] - Assigned to Lance Bragstad (lbragstad)15:11
fungianyone who wants to pitch in on that is welcome. it's all public15:12
*** _alastor_ has joined #openstack-meeting15:14
gagehugo#topic documentation15:14
*** openstack changes topic to "documentation (Meeting topic: security)"15:14
gagehugonothing from me here15:15
gagehugo#topic threat analysis15:15
*** openstack changes topic to "threat analysis (Meeting topic: security)"15:15
gagehugothere's some projects under the keystone umbrella that have drafts15:16
gagehugoI think the pycadf one should be close15:16
gagehugoit's a pretty simple library15:17
gagehugonot sure about the other two, I need to double check15:17
gagehugobut that's all I got for this15:18
gagehugo#topic PTG15:19
*** openstack changes topic to "PTG (Meeting topic: security)"15:19
gagehugolittle over a month away now15:19
gagehugowe're sharing a room with Barbican I believe Mon/Tue15:20
* nickthetait gets excited15:20
gagehugokeystone is being weird this time and having Mon/Thur/Fri sessions, so Mon I will likely be more involved in there, but I should be around15:21
*** psachin has quit IRC15:21
gagehugoI believe it's for a cross-project day15:21
fungiyeah, mon/tue are focused on cross-project activities15:22
fungifor the ptg in general i mean15:22
gagehugoI can reach out to Ade and we can figure out an agenda for us sharing15:22
gagehugoIf anyone has anything they want to discuss there, please add it to the agenda15:23
gagehugo#topic open discussion15:24
*** openstack changes topic to "open discussion (Meeting topic: security)"15:24
gagehugofloor is open15:24
lbragstadqq on #link
openstackLaunchpad bug 1779205 in OpenStack Identity (keystone) rocky "[OSSA-2018-002] GET /v3/OS-FEDERATION/projects leaks project information (CVE-2018-14432)" [Critical,Fix released] - Assigned to Lance Bragstad (lbragstad)15:24
gagehugolbragstad o/15:24
lbragstadthe patches we merged were to all supported releases15:24
*** bobh has joined #openstack-meeting15:25
lbragstadand it makes the implementation consistent regardless of the branch - but i think people were a little confused about the vulnerability description15:25
lbragstadis there anyway to change that after disclosing the report?15:25
lbragstador has that ship sailed?15:25
gagehugothe bit about enabling via policy.json?15:25
gagehugofungi: ^15:26
lbragstadand some of that gyee had input on is valueable15:26
lbragstador do we just keep evolving the context in the bug report?15:26
fungiwe issue errata in that case15:27
nickthetaitSome relevant personal news... On Aug 20 I start as a Security Engineer for Red Hat focusing on OpenStack 😊15:27
fungibasically we update the ossa, add a history section to it noting the modification, and send another round of public announcements about the errata15:28
fungiit happens infrequently enough we might be lacking documentation about that process15:28
lbragstadfungi: ack - so is that some i can initiate?15:28
gagehugonickthetait grats!15:28
fungilbragstad: definitely! the openstack/ossa repo is in public code review for precisely that reason. we love having the community involved15:29
nickthetaitthanks. I am pretty excited15:29
lbragstadfungi: yeah - i was going to say, i've never had to step through this after a disclosure goes public15:29
gagehugofungi: ah ok15:29
fungilbragstad: if you skim/git grep older ossas you should be able to find an errata example15:29
fungiif you can't, lmk and i'll dig one up15:29
lbragstadcool - i can try and get something worked up today and propose it for review15:29
fungithanks! i'll be around15:30
lbragstadsee if i can get gyee and kmalloc to weigh in on it15:30
fungihappy to review when you have it up15:30
lbragstadthanks for the help15:30
gagehugothanks everyone!15:32
*** openstack changes topic to "OpenStack Meetings ||"15:32
openstackMeeting ended Thu Aug  2 15:32:22 2018 UTC.  Information about MeetBot at . (v 0.1.4)15:32
openstackMinutes (text):
nickthetaitLater everyone15:32
melwitt#startmeeting nova21:00
openstackMeeting started Thu Aug  2 21:00:30 2018 UTC and is due to finish in 60 minutes.  The chair is melwitt. Information about MeetBot at
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.21:00
openstackThe meeting name has been set to 'nova'21:00
melwittI think this will be a short meeting21:00
melwittlet's start21:01
melwitt#topic Release News21:01
melwitt#link Rocky release schedule:
melwitt(the bot didn't appear to change the topic)21:01
*** cfriesen has joined #openstack-meeting21:01
melwittrc1 is next week Aug 921:01
melwittwe're tracking rc1 bug candidates here ^21:02
melwittthe currently tagged bugs have had their patches merge already21:02
melwittif you have bugs that you think are important for rc1, add them to the etherpad21:03
mriedemis anyone working on the release note stuff?21:03
mriedemi talked with dan about bumping any rpc api versions and didn't seem justification for doing so21:03
melwittthe reno prelude?21:03
mriedemthe reno prelude has been pretty copy/paste the last few releases,21:04
mriedemformat wise, and then tweak for highlights,21:04
mriedemsimilar but with more detail to the things that are in the release hightlights in the releases repo21:04
melwittokay. I don't know of anyone working on it yet. is anyone interested in doing that?21:05
melwittif no one is interested, I will do it21:05
mriedeme.g. ^21:05
melwittokay, that's helpful21:05
mriedemprobably want to talk to dansmith about "Ideally add the RPC version alias just before opening the next release"21:06
melwitt#action melwitt to check with dansmith about RPC version alias for RC121:07
melwitt#action melwitt to propose draft or reno prelude next monday21:07
melwittokay, anything else for release news?21:08
melwitt#topic Bugs (stuck/critical)21:08
melwittno critical bugs in the link21:09
melwitt#link 56 new untriaged bugs (up 7 since the last meeting):
melwittuntriaged bug count is climbing21:09
melwittI triaged a couple of things yesterday, will continue to do more21:09
*** sean-k-mooney has joined #openstack-meeting21:09
melwittwe really want to make sure there's nothing new in there that we need to target for RC121:10
melwitt#link 8 untagged untriaged bugs (up 3 since the last meeting):*&field.status%3Alist=NEW21:10
melwitt#link bug triage how-to:
melwitt#help need help with bug triage21:10
melwittGate status21:10
melwitt#link check queue gate status
melwittlots of timeouts and other fails21:10
melwittanecdotally I've noticed21:10
mriedemi can't tell if it's better than last week,21:10
mriedemor i just haven't watched or cared as much21:11
melwittI think it's better but still not happy town21:11
melwitt3rd party CI21:11
melwitt#link 3rd party CI status
melwittI've seen some failures in third party CIs but haven't followed up with any yet21:11
melwittanything else for bugs or gate status or third party CI?21:12
melwitt#topic Reminders21:12
melwitt#link Rocky Subteam Patches n Bugs:
melwitt#link Stein PTG planning:
melwittstein ptg planning, add your topics and comments. please add your nick to your topics and comments so we know who to talk to21:13
melwittI added a link to an empty rocky retro etherpad on there ^21:13
melwittwhich is21:13
melwitt#link Rocky retrospective for the PTG:
melwittI'll send an email to the dev ML about it21:13
melwittbut it's there, we'll start adding things to it21:13
melwittanyone else have any reminders?21:14
melwitt#topic Stable branch status21:14
melwitt#link stable/queens:,n,z21:14
melwitt#link stable/pike:,n,z21:14
melwitt#link stable/ocata:,n,z21:14
melwittlots of backports have merged, thanks to all the stable reviewers who've been working on that21:14
melwittwe had planned to propose releases for stable branches this week. is that ready to do at this point? anything else we want to wait for before releases?21:15
melwittelse = specific bug fixes21:15
*** rfolco|ruck is now known as rfolco|off21:15
mriedemthe stats thing probably21:16
melwittah, yup. I'll keep an eye on that21:16
mriedemnot critical to wait,21:16
mriedemsince it's been regressed since ocata...21:16
efriedBe nice to get it out there sooner rather than later so we can make sure the fix doesn't regress worse...21:17
efriedsince it wasn't exactly trivial21:17
melwittpike backport failed functional, both py27 and py35 so that's concerning21:18
melwittocata passed though, you'd think if it failed pike it would fail both. hm. anyway, that's the only snag I'm seeing there21:19
melwittif those failures are legit21:19
melwittanything else for stable branch status?21:19
melwitt#topic Subteam Highlights21:20
melwittcells v2, we skipped holding a meeting this week21:20
melwittwe have two bugs to highlight21:20
openstackLaunchpad bug 1784074 in OpenStack Compute (nova) "Instances end up with no cell assigned in instance_mappings" [Medium,In progress] - Assigned to Matt Riedemann (mriedem)21:20
openstackLaunchpad bug 1784093 in OpenStack Compute (nova) "Build requests can be orphaned without instance mappings" [Medium,In progress] - Assigned to Mohammed Naser (mnaser)21:20
melwittthose fixes are in the WIP stage21:21
melwittanything else to call out mriedem that I'm forgetting for cells this week?21:21
melwittokay, we'll move on21:21
melwittscheduler, efried?21:22
efried#link Scheduler subteam minutes
efriedThe main discussion point was around having21:22
efried#link yanked the partial support for sharing DISK_GB in libvirt
efrieddue to the associated21:22
efried#link bug about what needs to be fixed before we can reinstate sharing DISK_GB
openstackLaunchpad bug 1784020 in OpenStack Compute (nova) "Shared storage providers are not supported and will break things if used" [High,Triaged]21:22
efriedThis came as a shock to some, and there was some brainstorming about whether/how it could be fixed in Rocky. Answer: the non-migration parts probably could be fixed via reshaper, if that were able to get in, which it probably won't, but we'll get it reviewed and ready anyway. That series has since been completed and is undergoing review.21:22
efried#link reshaper series bottom
efriedWe discussed the migration aspects some; and overall agreed it probably makes sense to write an uber-spec that addresses sharing providers as a whole, from which component-level specs could be branched which talk about the actual work items involved. As yet, no volunteers to write that.21:22
efriedagh, I tried to split it in two to avoid getting spambotted, but got spambotted anyway. What's the last thing you saw?21:22
melwittI got the END message21:22
efriedokay, cool.21:23
melwittthanks for the summary21:23
melwittgibi left a note on the agenda for notifications subteam21:23
melwitt"We had a really short meeting this week but there was nothing to report."21:23
melwittand gmann for API subteam says "no office hour this week, nothing special to report from API side."21:23
melwittthat's it for subteams21:23
melwitt#topic Stuck Reviews21:23
*** abishop has quit IRC21:24
melwittno items on the agenda. anyone in the room have anything for stuck reviews?21:24
melwitt#topic Open discussion21:24
melwittanyone have anything they'd like to discuss?21:24
melwittokay, I guess that's all folks21:25
openstackMeeting ended Thu Aug  2 21:25:27 2018 UTC.  Information about MeetBot at . (v 0.1.4)21:25
openstackMinutes (text):
