*** yamamoto has joined #openstack-meeting | 00:00 | |
*** hongbin has quit IRC | 00:04 | |
*** yamamoto has quit IRC | 00:05 | |
*** hongbin has joined #openstack-meeting | 00:05 | |
*** gyee has quit IRC | 00:21 | |
*** mlavalle has quit IRC | 00:30 | |
*** hongbin has quit IRC | 00:41 | |
*** hongbin has joined #openstack-meeting | 01:06 | |
*** rcernin has quit IRC | 01:11 | |
*** rcernin has joined #openstack-meeting | 01:11 | |
*** Liang__ has joined #openstack-meeting | 01:23 | |
*** yamamoto has joined #openstack-meeting | 01:52 | |
*** hyunsikyang__ has quit IRC | 02:27 | |
*** hyunsikyang has joined #openstack-meeting | 02:27 | |
*** lbragstad has quit IRC | 02:32 | |
*** ykatabam has quit IRC | 02:59 | |
*** Liang__ has quit IRC | 03:01 | |
*** ykatabam has joined #openstack-meeting | 03:02 | |
*** rcernin has quit IRC | 03:06 | |
*** armax has quit IRC | 03:08 | |
*** Liang__ has joined #openstack-meeting | 03:14 | |
*** psachin has joined #openstack-meeting | 03:31 | |
*** ayoung has quit IRC | 03:48 | |
*** ayoung has joined #openstack-meeting | 03:48 | |
*** rcernin has joined #openstack-meeting | 03:52 | |
*** psahoo has joined #openstack-meeting | 03:52 | |
*** ayoung has quit IRC | 03:53 | |
*** ayoung has joined #openstack-meeting | 03:56 | |
*** Liang__ has quit IRC | 04:02 | |
*** ricolin has joined #openstack-meeting | 04:04 | |
*** eharney has quit IRC | 04:05 | |
*** Liang__ has joined #openstack-meeting | 04:05 | |
*** manpreet has joined #openstack-meeting | 04:16 | |
*** eharney has joined #openstack-meeting | 04:24 | |
*** hongbin has quit IRC | 04:26 | |
*** vishalmanchanda has joined #openstack-meeting | 04:32 | |
*** evrardjp has joined #openstack-meeting | 04:33 | |
*** Liang__ has quit IRC | 04:34 | |
*** yamamoto has quit IRC | 04:36 | |
*** yamamoto has joined #openstack-meeting | 04:39 | |
*** masahito has joined #openstack-meeting | 05:06 | |
*** sridharg has joined #openstack-meeting | 05:10 | |
*** masahito has quit IRC | 05:24 | |
*** masahito has joined #openstack-meeting | 05:38 | |
*** apetrich has joined #openstack-meeting | 05:42 | |
*** e0ne has joined #openstack-meeting | 06:19 | |
*** e0ne has quit IRC | 06:20 | |
*** markvoelker has joined #openstack-meeting | 06:45 | |
*** slaweq has joined #openstack-meeting | 06:46 | |
*** Liang__ has joined #openstack-meeting | 06:46 | |
*** psahoo has quit IRC | 06:48 | |
*** markvoelker has quit IRC | 06:49 | |
*** maciejjozefczyk has joined #openstack-meeting | 06:57 | |
*** moguimar has joined #openstack-meeting | 06:59 | |
*** bbowen has quit IRC | 06:59 | |
*** Liang__ has quit IRC | 07:23 | |
*** Liang__ has joined #openstack-meeting | 07:24 | |
*** psahoo has joined #openstack-meeting | 07:26 | |
*** e0ne has joined #openstack-meeting | 07:35 | |
*** markvoelker has joined #openstack-meeting | 07:35 | |
*** markvoelker has quit IRC | 07:39 | |
*** tosky has joined #openstack-meeting | 07:42 | |
*** markvoelker has joined #openstack-meeting | 07:50 | |
*** markvoelker has quit IRC | 07:51 | |
*** TusharTgite has joined #openstack-meeting | 07:52 | |
*** Lucas_Gray has joined #openstack-meeting | 08:01 | |
*** ykatabam has quit IRC | 08:11 | |
*** Wryhder has joined #openstack-meeting | 08:14 | |
*** maciejjozefczyk_ has joined #openstack-meeting | 08:14 | |
*** maciejjozefczyk has quit IRC | 08:15 | |
*** maciejjozefczyk has joined #openstack-meeting | 08:15 | |
*** Lucas_Gray has quit IRC | 08:15 | |
*** Wryhder is now known as Lucas_Gray | 08:15 | |
*** masahito has quit IRC | 08:19 | |
*** maciejjozefczyk_ has quit IRC | 08:19 | |
*** belmoreira has joined #openstack-meeting | 08:30 | |
*** rcernin has quit IRC | 09:05 | |
*** Lucas_Gray has quit IRC | 09:22 | |
*** Liang__ has quit IRC | 09:24 | |
*** Lucas_Gray has joined #openstack-meeting | 09:30 | |
*** Lucas_Gray has quit IRC | 09:48 | |
*** Wryhder has joined #openstack-meeting | 09:48 | |
*** Wryhder is now known as Lucas_Gray | 09:49 | |
*** moguimar has quit IRC | 09:54 | |
*** moguimar has joined #openstack-meeting | 09:54 | |
*** moguimar has joined #openstack-meeting | 09:56 | |
*** moguimar has joined #openstack-meeting | 09:56 | |
*** rcernin has joined #openstack-meeting | 09:58 | |
*** bbowen has joined #openstack-meeting | 10:07 | |
*** e0ne has quit IRC | 10:14 | |
*** e0ne has joined #openstack-meeting | 10:15 | |
*** jmasud has quit IRC | 10:31 | |
*** jmasud has joined #openstack-meeting | 10:33 | |
*** rcernin has quit IRC | 10:40 | |
*** rcernin has joined #openstack-meeting | 10:47 | |
*** rcernin has quit IRC | 11:00 | |
*** yamamoto has quit IRC | 11:01 | |
*** carloss has joined #openstack-meeting | 11:08 | |
*** apetrich has quit IRC | 11:11 | |
*** apetrich has joined #openstack-meeting | 11:23 | |
*** yamamoto has joined #openstack-meeting | 11:23 | |
*** TusharTgite has quit IRC | 11:26 | |
*** yamamoto has quit IRC | 11:29 | |
*** raildo has joined #openstack-meeting | 11:49 | |
*** rh-jelabarre has joined #openstack-meeting | 11:55 | |
*** rh-jelabarre has quit IRC | 11:55 | |
*** rh-jelabarre has joined #openstack-meeting | 11:56 | |
*** yamamoto has joined #openstack-meeting | 12:03 | |
*** rfolco has joined #openstack-meeting | 12:05 | |
*** yamamoto has quit IRC | 12:11 | |
*** ayoung has quit IRC | 12:33 | |
*** ayoung has joined #openstack-meeting | 12:45 | |
*** TrevorV has joined #openstack-meeting | 12:57 | |
*** dklyle has quit IRC | 13:07 | |
*** ociuhandu has quit IRC | 13:09 | |
*** lbragstad has joined #openstack-meeting | 13:13 | |
*** ociuhandu has joined #openstack-meeting | 13:24 | |
*** ociuhandu has quit IRC | 13:29 | |
*** rosmaita has joined #openstack-meeting | 13:57 | |
*** Steap has joined #openstack-meeting | 14:01 | |
abhishekk | #startmeeting glance | 14:01 |
---|---|---|
openstack | Meeting started Thu Aug 13 14:01:45 2020 UTC and is due to finish in 60 minutes. The chair is abhishekk. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: glance)" | 14:01 | |
openstack | The meeting name has been set to 'glance' | 14:01 |
abhishekk | #topic roll call | 14:01 |
*** openstack changes topic to "roll call (Meeting topic: glance)" | 14:01 | |
dansmith | o/ | 14:01 |
abhishekk | #link https://etherpad.openstack.org/p/glance-team-meeting-agenda | 14:01 |
abhishekk | o/ | 14:02 |
*** ociuhandu has joined #openstack-meeting | 14:02 | |
Steap | o/ | 14:02 |
jokke | o/ | 14:02 |
abhishekk | lets wait couple of minutes for others | 14:02 |
abhishekk | lets start, others will join soon | 14:03 |
abhishekk | #topic Updates | 14:03 |
*** openstack changes topic to "Updates (Meeting topic: glance)" | 14:03 | |
*** alistarle has joined #openstack-meeting | 14:03 | |
abhishekk | Date for next PTG are out | 14:04 |
abhishekk | it will be held after one week of W summit | 14:04 |
abhishekk | between October 26th to October 30th, 2020 | 14:04 |
abhishekk | registrations are open for PTG and summit and as it is virtual it is free | 14:05 |
abhishekk | Summit registration - https://openinfrasummit2020.eventbrite.com | 14:05 |
abhishekk | PTG registration - https://october2020ptg.eventbrite.com | 14:05 |
abhishekk | moving ahead | 14:05 |
abhishekk | #topic release/periodic job updtes | 14:05 |
*** openstack changes topic to "release/periodic job updtes (Meeting topic: glance)" | 14:05 | |
abhishekk | this is a release week for us | 14:05 |
rosmaita | o/ | 14:06 |
abhishekk | we have released python-glanceclient for master and stable/ussuri | 14:06 |
abhishekk | we have also released stable/train and stable/ussuri for glance with some important bug fixes | 14:06 |
abhishekk | glance_store 2.2.0 release patch is in review | 14:06 |
abhishekk | #link https://review.opendev.org/745796 | 14:07 |
patchbot | patch 745796 - releases - Release glance_store 2.2.0 - 1 patch set | 14:07 |
abhishekk | smcginnis, ^^ | 14:07 |
*** alistarle has quit IRC | 14:07 | |
abhishekk | We are approaching towards V3 milestones, which is just 4 weeks away | 14:07 |
abhishekk | and for non-client release we have 3 weeks | 14:08 |
jokke | Also note, there was some issue in the announce-release job but the release of 3.2.1 itself went through just mail of it wasn't sent out | 14:08 |
abhishekk | jokke, ++, thank you | 14:08 |
jokke | that's for python-glanceclint | 14:08 |
abhishekk | glance sparse image upload, cinder multiple stores support we are expecting this to be completed on time | 14:09 |
*** alistarle has joined #openstack-meeting | 14:09 | |
abhishekk | For glanceclient we don't have any major addition this time, so we are good on that front | 14:09 |
abhishekk | Also for glance apart from cinder multiple stores support related changes and few bug fixes we are going to shift most of the work to next cycle | 14:10 |
jokke | And I think the final client release is later anyways if we need to get something released from the work that is still to be done | 14:10 |
abhishekk | Periodic job, mostly yellow due to requirement constrainsts issue, couple of failures due to timeout and flaky test copy_image_revert_lifecycle | 14:10 |
abhishekk | jokke, agree | 14:10 |
abhishekk | dansmith, has found out the cause of timeout issue we were hitting and submitted one patch to reduce its possibility | 14:11 |
dansmith | well, that patch should prevent it always, | 14:12 |
abhishekk | cool | 14:12 |
dansmith | but it just fixes a bug that causes us to deadlock, not the actual problem | 14:12 |
dansmith | debugging of the real issue here: https://bugs.launchpad.net/glance/+bug/1891190 | 14:12 |
openstack | Launchpad bug 1891190 in Glance "test_reload() functional test causes hang and jobs TIMED_OUT" [Undecided,New] | 14:12 |
dansmith | but not to the bottom of it yet | 14:12 |
jokke | So I'm not exactly sure how that is the case (I assume we're talking about the bug 1891352) | 14:13 |
openstack | bug 1891352 in Glance "Failed import of one store will remain in progress forever if all_stores_must_succeed=True" [Undecided,In progress] https://launchpad.net/bugs/1891352 | 14:13 |
abhishekk | ok, thank you for debugging it | 14:13 |
dansmith | jokke: that's why I wrote the functional reproducer, so it's clear | 14:13 |
dansmith | (for 1891352) | 14:13 |
jokke | dansmith: oh sorry ... actually looking at the code I do see why that is happening ... I read that condition wrong way around | 14:15 |
abhishekk | the scenario here is when all_stores_must_succeed is True and import failed to one of the store then that store was never added to failed list, and the test which I have written for it sometimes proceed before removing the location of previously imported stores | 14:15 |
jokke | for some reason my brain flipped that boolean around when reading the bug | 14:16 |
abhishekk | :D, it happened with me as well | 14:16 |
abhishekk | Ok, moving ahead | 14:17 |
abhishekk | #topic Work moved to next cycle | 14:17 |
jokke | I was wondering "What in earth fails the task when we're catching all exceptions" ;) | 14:17 |
*** openstack changes topic to "Work moved to next cycle (Meeting topic: glance)" | 14:17 | |
abhishekk | We are moving most of the work to next cycle due to time crunch and ferry of bug fixes occurred this cycle | 14:18 |
abhishekk | Below is the list, which we will shift to next cycle | 14:18 |
abhishekk | Image encryption - Will wait one more week to here from Luzi | 14:18 |
abhishekk | Optimize Ceph store network usage - https://review.opendev.org/#/c/740980/ | 14:18 |
abhishekk | Update proposal for duplication image download - https://review.opendev.org/734683 | 14:18 |
abhishekk | Cache API - https://review.opendev.org/#/c/665258 | 14:18 |
abhishekk | Cluster awareness - | 14:18 |
patchbot | patch 740980 - glance-specs - Optimize Ceph store network usage - 2 patch sets | 14:18 |
abhishekk | Remove single store configuration | 14:18 |
patchbot | patch 734683 - glance-specs - Update proposal for duplication image download - 3 patch sets | 14:18 |
patchbot | patch 665258 - glance-specs - Spec for Glance cache API - 4 patch sets | 14:18 |
abhishekk | Any suggestion/objection? | 14:19 |
*** ociuhandu_ has joined #openstack-meeting | 14:19 | |
abhishekk | alistarle, would you like to share the progress of sparse image upload? | 14:20 |
alistarle | Sure | 14:20 |
jokke | abhishekk: taken the sparse image upload is available, I'll see what I can do about some of the rbd things next week. Don't pull trigger on that just yet | 14:21 |
abhishekk | jokke, ack | 14:21 |
alistarle | We decided to split the two optimization in two commit, first the write optim, which is quite easy, and then the second one, more difficult because it touch some old glance code | 14:21 |
*** ociuhandu has quit IRC | 14:22 | |
abhishekk | alistarle, sounds good, but we should expect it in this cycle, right? | 14:22 |
alistarle | I will submit the first commit this week, it is fully functionnal and tested in production | 14:22 |
alistarle | sure | 14:22 |
jokke | alistarle: that sounds like a good approach at this point of the cycle | 14:22 |
abhishekk | ++ | 14:23 |
abhishekk | and please let us know if you need any help in understanding glance code | 14:23 |
abhishekk | thank you alistarle for updates | 14:24 |
abhishekk | moving to next topic | 14:24 |
*** andrebeltrami has joined #openstack-meeting | 14:24 | |
abhishekk | #topic doc updates in python-glanceclient | 14:25 |
*** openstack changes topic to "doc updates in python-glanceclient (Meeting topic: glance)" | 14:25 | |
abhishekk | python-glanceclient still shows create-image-via-import as experimental | 14:25 |
abhishekk | https://docs.openstack.org/python-glanceclient/latest/cli/details.html#glance-image-create-via-import | 14:25 |
abhishekk | So this section shows glance-image-create-via-import as experimental and also states that it might be removed in future | 14:25 |
abhishekk | IMO there is a need to correct it and also backport it to some stable branches | 14:26 |
jokke | yeah ... so the original plan was to change image-crete using the Import workflow and get rid of the mai long image-create-via-import once the code was stable enough to do so | 14:26 |
rosmaita | that's my recollection too | 14:27 |
abhishekk | but we are not moving it, right? | 14:27 |
jokke | Personally I'm not sure if we want to keep that via-import around but instead merge that with image-create with perhaps some flag indicating which way to go | 14:27 |
jokke | it would be cleaner to use, but I'm open for suggestions | 14:28 |
abhishekk | hmm | 14:28 |
jokke | I'd kind of prefer just one image-create command | 14:28 |
abhishekk | One command sounds good to me as well | 14:29 |
rosmaita | right, and since we're talking about CLI here and not changing the rest of the client code, shouldn't impact any services | 14:29 |
dansmith | well, | 14:29 |
jokke | I could do it to utilize --method ... so if import method is provided that flow will be used | 14:29 |
dansmith | people write scripts based on the CLI so I wouldn't say it won't break anyone | 14:29 |
dansmith | not any services, true, but.. | 14:29 |
rosmaita | party pooper | 14:30 |
jokke | dansmith: yeah, there is reason why it's flagged experimental with warning it may go away :P | 14:30 |
dansmith | is it flagged that way in the CLI output? | 14:30 |
abhishekk | it is not flagged in CLI output but in the documentation IMO | 14:31 |
jokke | yes | 14:31 |
dansmith | yeah, then nobody noticed :) | 14:31 |
jokke | If you take the help text of the command (which you would need to know what parameters to use) there is like 10 line EXPERIMENTAL: warning on it | 14:31 |
dansmith | so there is in the CLI? | 14:32 |
abhishekk | Also I think, its lot to do in this cycle, so we should do it in next cycle | 14:32 |
jokke | yup | 14:32 |
dansmith | ack, though abhishekk said not | 14:32 |
jokke | `glance help image-create-via-import` | 14:32 |
rosmaita | "EXPERIMENTAL: Create a new image via image import." | 14:33 |
rosmaita | even in all caps | 14:33 |
*** dklyle has joined #openstack-meeting | 14:33 | |
dansmith | so this was just a shortcut for doing create..stage..import all in one go? | 14:34 |
abhishekk | cool, I never looked at help message as I known all the parameters | 14:34 |
jokke | dansmith: correct | 14:34 |
rosmaita | yes, the idea was that it would be a drop-in replacement for glance image-create | 14:34 |
dansmith | well, just MHO, but I'm sure lots of people interested in import used that instead of the three separate calls... | 14:35 |
rosmaita | (for some definition of "drop-in") | 14:35 |
abhishekk | I am glad that I didn't removed experimental directly and decided to bring it here | 14:35 |
dansmith | I'd not have been in favor of a temporary command in the CLI in the first place, so I'm a little biased, but... | 14:35 |
jokke | dansmith: yeah, that's why I prefer to kind of squash it with image-create so people could keep doing that with very minimal change | 14:36 |
abhishekk | I also think it will be tricky for copy-image support | 14:36 |
dansmith | it's little stuff like this that people hate about upgrading in openstack.. even if the get all the hard ducks in a row, there's still stuff like this to make it painful.. but, you warned them, so I guess you're safe :) | 14:36 |
jokke | as image-create is already doing different stages depending of the parameters it's given | 14:36 |
dansmith | what's the cost of keeping it for compatibility? just weight on our conscience? | 14:37 |
jokke | dansmith: since the initial explosion around v1->v2 we have been pretty darn good flagging stuff we expect might change once the feedback comes in as experimental | 14:38 |
jokke | dansmith: and clutter in the client commands ... the list os already long | 14:38 |
jokke | s/os/is/ | 14:38 |
dansmith | it is, and confusingly overlapping | 14:39 |
jokke | yup | 14:39 |
*** armax has joined #openstack-meeting | 14:40 | |
jokke | So I'd like to see i I can get the feature set in image-create before I start my holidays, so we can mark that experimental,deprecated and we could clean it out next cycle. I don't want to not give any transition period for those who are cripting on it | 14:40 |
abhishekk | So to be on safe side, we will keep this command as deprectaed this cycle as well and remove it next cycle | 14:41 |
dansmith | can we reno that it _will_ be remove next cycle? | 14:41 |
abhishekk | just for confirmation image-stage and image-import will stay as it is | 14:42 |
jokke | abhishekk: experimental at least, if I get the squash of the features done this cycle, then deprecated. Otherwise I get it done next cycle and we can deprecate it then and remove following | 14:42 |
jokke | abhishekk: correct | 14:42 |
jokke | just like image-upload | 14:42 |
abhishekk | dansmith, the patch jokke will push will have releasenote saying it is deprecated and will be removed in next cycle | 14:42 |
*** alistarle has quit IRC | 14:42 | |
abhishekk | jokke, ACK | 14:43 |
jokke | dansmith: for sure, I've been quite decent with renos too ;) | 14:43 |
jokke | even no-one reads them, no docs | 14:43 |
abhishekk | ok, moving into open discussion | 14:43 |
*** psahoo has quit IRC | 14:44 | |
abhishekk | #topic Open discussion | 14:44 |
*** openstack changes topic to "Open discussion (Meeting topic: glance)" | 14:44 | |
abhishekk | we need reviews on copy-image race condition patches | 14:44 |
jokke | oh, the favorite | 14:44 |
abhishekk | its almost in last phase and will be good enough if we have it merged before vacation period starts | 14:45 |
abhishekk | jokke, rosmaita kindly have a look at those patches | 14:45 |
rosmaita | abhishekk: ack ... can you give me a list? | 14:45 |
dansmith | I think the new functional test is pretty easy to read also | 14:45 |
*** alistarle has joined #openstack-meeting | 14:45 | |
dansmith | so it should be find to start from there to get the idea | 14:45 |
dansmith | *fine | 14:45 |
abhishekk | rosmaita, https://review.opendev.org/743597 | 14:45 |
patchbot | patch 743597 - glance - Implement time-limited import locking - 16 patch sets | 14:45 |
jokke | I think there is still that one revert that will more likely break than not before it hits the code that is supposed to not break it | 14:46 |
dansmith | I didn't parse that | 14:46 |
jokke | The _CompleteTask ... I flagged in one of the previous PSs | 14:47 |
rosmaita | dansmith: nice commit message on 743597 | 14:47 |
abhishekk | we also need to backport it to stable/ussuri | 14:47 |
dansmith | jokke: I replied to a comment of yours in _CompleteTask but never saw a reply, from PS8 | 14:48 |
dansmith | not sure if that's what you're referring to or not | 14:48 |
dansmith | but if you think something is broken, kindly highlight it again and I'll try to cover that concern with tests | 14:49 |
jokke | dansmith: likely yes. How about I reply to it in the PS8 so no need to hop back and forth trying to follow the convo. IIRC nothing in that part changed between | 14:50 |
dansmith | ack | 14:50 |
jokke | kk will do it after the meeting | 14:50 |
abhishekk | dansmith, how tough it will be to backport to stable/ussuri (considering we need to backport your ImportAction work as well)? | 14:50 |
dansmith | note that we're actively hitting this race in the nova jobs | 14:51 |
dansmith | so it would definitely be good to get this in | 14:51 |
dansmith | abhishekk: I dunno, seems like a big backport | 14:51 |
jokke | yeah we've been bikeshedding around this for what almost two months now | 14:51 |
abhishekk | yeah, I suspect that | 14:51 |
dansmith | the biggest problem is with copy-image.. when did that become a thing? first in ussuri? | 14:51 |
abhishekk | yes, in ussuri | 14:52 |
dansmith | yeah, so that's as far back as I'd want to take it, but still.. eesh, it'd be a big backport | 14:52 |
*** sridharg has quit IRC | 14:52 | |
abhishekk | right | 14:52 |
jokke | mhm ... also the whole race got introduced with that copy-image, it did not exist before | 14:52 |
abhishekk | :D | 14:53 |
jokke | well not on the obvious scale | 14:53 |
abhishekk | Just for FYI tomorrow I will not be around | 14:54 |
dansmith | same | 14:54 |
jokke | same for all of us | 14:54 |
abhishekk | (I guess most of us will not be) | 14:54 |
jokke | pretty much | 14:54 |
abhishekk | That's it from me for today | 14:54 |
abhishekk | we have 5 minutes left before closing | 14:55 |
jokke | I don't think I had anything else either | 14:55 |
jokke | thanks abhishekk for reminding about the -via-import I had kind of forgotten that whole thing already | 14:55 |
abhishekk | I found one small bug in it | 14:56 |
abhishekk | and that's when I noticed it | 14:56 |
abhishekk | there is '-' missing in 'create-image-via import' | 14:56 |
*** ayoung has quit IRC | 14:56 | |
abhishekk | actually its not me but my teammate rajat found it :P | 14:57 |
abhishekk | Lets wrap up for today | 14:57 |
abhishekk | have a nice long weekend guys | 14:58 |
jokke | Thanks all | 14:58 |
jokke | indeed! | 14:58 |
abhishekk | thank you all | 14:58 |
abhishekk | #endmeeting | 14:58 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:58 | |
openstack | Meeting ended Thu Aug 13 14:58:31 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:58 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-08-13-14.01.html | 14:58 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-08-13-14.01.txt | 14:58 |
openstack | Log: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-08-13-14.01.log.html | 14:58 |
*** alistarle has quit IRC | 15:00 | |
gagehugo | #startmeeting security | 15:01 |
openstack | Meeting started Thu Aug 13 15:01:59 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:02 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:02 |
*** openstack changes topic to " (Meeting topic: security)" | 15:02 | |
openstack | The meeting name has been set to 'security' | 15:02 |
fungi | ahoy, y'all | 15:02 |
*** Steap has left #openstack-meeting | 15:02 | |
gagehugo | #link https://etherpad.opendev.org/p/security-agenda agenda | 15:03 |
gagehugo | o/ | 15:03 |
*** rosmaita has left #openstack-meeting | 15:04 | |
*** alistarle has joined #openstack-meeting | 15:04 | |
*** alistarle has quit IRC | 15:06 | |
gagehugo | #topic https://bugs.launchpad.net/nova/+bug/1888722 | 15:07 |
*** openstack changes topic to "https://bugs.launchpad.net/nova/+bug/1888722 (Meeting topic: security)" | 15:07 | |
openstack | Launchpad bug 1888722 in OpenStack Compute (nova) "The Nova api permits any possible hostname, including for example "../.." or "; --" or "hostname.openstack.org"" [Undecided,New] | 15:07 |
fungi | this was one the vmt and nova devs basically considered not a bug | 15:07 |
fungi | but some users find it surprising, so i felt it was worth calling out | 15:08 |
gagehugo | So OSSN? | 15:08 |
fungi | well, basically there's no obvious vulnerability here, though if people try to use instance names in places where those characters are dangerous, then that could be a risk | 15:09 |
gagehugo | or just a warning I guess? | 15:09 |
*** moguimar has quit IRC | 15:10 | |
fungi | though one of the examples given was that of "." in instance names, the reporter seemed legitimately concerned about instances with names which looked like fqdns | 15:10 |
*** mlavalle has joined #openstack-meeting | 15:10 | |
fungi | i and others actually like to use fqdns as instance names, so this really seemed like a matter of personal taste | 15:10 |
fungi | anyway, i figured i'd point this one out in case anyone has concerns similar to those of the reporter | 15:12 |
fungi | the suggestion to disallow "." in instance names, for example, was dismissed fairly quickly | 15:12 |
fungi | but also the idea of making a configurable filter for allowed characters was (rightly in my opinion) seen as hindering interoperability | 15:13 |
gagehugo | hmm ok | 15:14 |
gagehugo | #topic security issue - some command injection vulnerability found and fixed | 15:15 |
*** openstack changes topic to "security issue - some command injection vulnerability found and fixed (Meeting topic: security)" | 15:15 | |
gagehugo | #link https://bugs.launchpad.net/cinder/+bug/1889055 | 15:15 |
openstack | Launchpad bug 1889055 in OpenStack Security Advisory "security issue - some command injection vulnerability found and fixed" [Undecided,Invalid] | 15:15 |
gagehugo | I see also invalid | 15:16 |
fungi | yeah, this one was a good example of a researcher running code analysis on a repository and assuming a vulnerability without knowing how that part of the software was used | 15:19 |
fungi | bugs like that serve as reminders that reports of suspected vulnerabilities without any idea of what the exploit scenario would be are not terribly useful, and we would much prefer folks research the bugs they think they've found before reporting them as suspected vulnerabilities | 15:21 |
gagehugo | ah ok | 15:28 |
gagehugo | #topic CVE-2020-11984 mod_proxy_uwsgi buffer overflow | 15:28 |
*** openstack changes topic to "CVE-2020-11984 mod_proxy_uwsgi buffer overflow (Meeting topic: security)" | 15:28 | |
gagehugo | #link https://httpd.apache.org/security/vulnerabilities_24.html | 15:30 |
*** vishalmanchanda has quit IRC | 15:32 | |
fungi | this was more a heads up, i know lots of openstack deployments utilize apache mod_proxy_uwsgi and this is a pretty significant remote exploit | 15:32 |
fungi | this might be something someone who's interested in writing an ossn might be interested in tackling | 15:33 |
fungi | #info CVE-2020-11984 may be a good opportunity for an OSSN to alert OpenStack deployers to potential risks in unpatched Apache mod_proxy_uwsgi | 15:33 |
gagehugo | Do we cover non-openstack services? Or is that specific to OSSAs? | 15:34 |
gagehugo | It makes sense imo | 15:34 |
fungi | in the past we've used ossn to alert users to critical vulnerabilities in our dependencies | 15:37 |
fungi | not often, but there are some examples in the record | 15:38 |
gagehugo | ok cool | 15:38 |
fungi | i think the most recent one was on spectre/meltdown | 15:38 |
fungi | anyway, i just figured i'd bring it to the attention of meeting attendees or anyone reading the logs/minutes/summary, in case there's maybe a lurker who wants to get involved, since this could be a fairly easy one | 15:39 |
fungi | feel free to hit us up in the #openstack-security channel on freenode or the openstack-discuss ml if there are questions about the ossn process | 15:40 |
gagehugo | sounds good! | 15:41 |
gagehugo | I need to run, thanks as always fungi! | 15:41 |
gagehugo | #endmeeting | 15:41 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:41 | |
openstack | Meeting ended Thu Aug 13 15:41:27 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:41 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-08-13-15.01.html | 15:41 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2020/security.2020-08-13-15.01.txt | 15:41 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-08-13-15.01.log.html | 15:41 |
*** belmoreira has quit IRC | 15:42 | |
fungi | thanks! | 15:42 |
fungi | gagehugo: also maybe worth bringing up next time, ptg dates have been announced and reg is open: http://lists.openstack.org/pipermail/openstack-discuss/2020-August/016424.html | 15:42 |
fungi | week after summit, save the date! | 15:42 |
gagehugo | good idea | 15:43 |
*** e0ne_ has joined #openstack-meeting | 15:45 | |
*** priteau has joined #openstack-meeting | 15:47 | |
*** e0ne has quit IRC | 15:47 | |
*** armstrong has joined #openstack-meeting | 15:54 | |
*** manuvakery has joined #openstack-meeting | 16:11 | |
*** psachin has quit IRC | 16:25 | |
*** TrevorV has quit IRC | 16:26 | |
*** Lucas_Gray has quit IRC | 16:36 | |
*** gyee has joined #openstack-meeting | 16:40 | |
*** ociuhandu_ has quit IRC | 16:43 | |
*** tosky has quit IRC | 16:43 | |
*** ociuhandu has joined #openstack-meeting | 16:44 | |
*** ociuhandu has quit IRC | 16:50 | |
*** ociuhandu has joined #openstack-meeting | 16:57 | |
*** ociuhandu has quit IRC | 17:04 | |
*** priteau has quit IRC | 17:36 | |
*** manpreet has quit IRC | 17:36 | |
*** priteau has joined #openstack-meeting | 17:45 | |
*** e0ne_ has quit IRC | 17:50 | |
*** priteau has quit IRC | 17:53 | |
*** andrebeltrami has quit IRC | 18:03 | |
*** manuvakery has quit IRC | 18:21 | |
*** armstrong has quit IRC | 18:24 | |
*** maciejjozefczyk has quit IRC | 18:47 | |
*** armstrong has joined #openstack-meeting | 18:51 | |
*** e0ne has joined #openstack-meeting | 19:01 | |
*** e0ne has quit IRC | 19:15 | |
*** andrebeltrami has joined #openstack-meeting | 19:40 | |
*** e0ne has joined #openstack-meeting | 19:59 | |
*** e0ne has quit IRC | 20:02 | |
*** hyunsikyang has quit IRC | 20:07 | |
*** e0ne has joined #openstack-meeting | 20:07 | |
*** e0ne has quit IRC | 20:07 | |
*** tosky has joined #openstack-meeting | 20:10 | |
*** yamamoto has joined #openstack-meeting | 20:13 | |
*** yamamoto has quit IRC | 20:18 | |
*** slaweq has quit IRC | 20:37 | |
*** slaweq has joined #openstack-meeting | 20:43 | |
*** slaweq has quit IRC | 20:48 | |
*** rfolco has quit IRC | 20:51 | |
*** armstrong has quit IRC | 20:54 | |
*** raildo has quit IRC | 20:59 | |
*** yamamoto has joined #openstack-meeting | 21:55 | |
*** rcernin has joined #openstack-meeting | 22:00 | |
*** patchbot has quit IRC | 22:02 | |
*** armax has quit IRC | 22:07 | |
*** rfolco has joined #openstack-meeting | 22:12 | |
*** andrebeltrami has quit IRC | 22:23 | |
*** yamamoto has quit IRC | 22:31 | |
*** armax has joined #openstack-meeting | 22:49 | |
*** ociuhandu has joined #openstack-meeting | 23:00 | |
*** ayoung has joined #openstack-meeting | 23:02 | |
*** ociuhandu has quit IRC | 23:05 | |
*** mlavalle has quit IRC | 23:08 | |
*** tosky has quit IRC | 23:09 | |
*** ircuser-1 has quit IRC | 23:29 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!