Monday, 2025-12-08

opendevreviewSeyeong Kim proposed openstack/nova master: libvirt: Support boot_index for multiple block devices  https://review.opendev.org/c/openstack/nova/+/96366500:45
*** mhen_ is now known as mhen02:15
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: create generic check for mem encryption support by host  https://review.opendev.org/c/openstack/nova/+/96796907:27
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: stop using _get_mem_encryption_config() for SEV checks  https://review.opendev.org/c/openstack/nova/+/96797007:27
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: remove explicit SEV dependency from nova.scheduler.utils  https://review.opendev.org/c/openstack/nova/+/96797107:27
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: make RP creation independent of specific encryption models  https://review.opendev.org/c/openstack/nova/+/96797207:27
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: fix code that assumes SEV in configuring guests  https://review.opendev.org/c/openstack/nova/+/96797307:27
opendevreviewTaketani Ryo proposed openstack/nova master: mem-enc: fix requirement checks for mem_encryption guests  https://review.opendev.org/c/openstack/nova/+/96797407:27
opendevreviewArtem Vasilyev proposed openstack/nova master: Fix functional tests on macOS  https://review.opendev.org/c/openstack/nova/+/93772708:38
opendevreviewArtem Vasilyev proposed openstack/nova master: Fix functional tests on macOS  https://review.opendev.org/c/openstack/nova/+/93772708:38
opendevreviewDmitriy Rabotyagov proposed openstack/nova-specs master: [spec] Add Cross-AZ scheduling blueprint  https://review.opendev.org/c/openstack/nova-specs/+/90029616:16
thillHello! Looking for additional feedback on this spec https://review.opendev.org/c/openstack/nova-specs/+/968065. Hoping to work through ideas/concerns to find a solution to our problem and it's proving to be a bit more difficult than anticipated.16:41
sean-k-mooneythill: ignoring the detail of the spec for a minute teh spec freeze for this cycle was last thursday meaing that by defult this will have to be repropsoed for 2026.218:35
sean-k-mooneyin general usign teh nvoa user to allwo access to a resuce that a user could not otherwise use si privldage eslcaltion so allwoign a user to boot form a image they canot normally download is generally a security problem18:37
sean-k-mooneythe user can exfiltrate any data form teh image by just booting form a rescue image and copyint the block device or chreating a snapshot and download that18:38
sean-k-mooneyso im not really seaing a compleing reason to supprot booting from an image you cant download18:38
jgwentworthsean-k-mooney: that's my thought on it as well ... if you can boot an instance from an image, you can effectively download the image. I appreciate that having to copy it is more difficult than being able to use the download API ... but the fact that the user can still effectively download it makes the idea of "can boot but cannot download" not so compelling to me either19:01
*** jgwentworth is now known as melwitt19:01
thillFair enough! I don't have any arguments against that logic at this point. I'll bubble this up and see what we want to do going forward. Thank you!19:38
opendevreviewMerged openstack/nova master: Use consistent program name for wsgi scripts and entry points  https://review.opendev.org/c/openstack/nova/+/94260522:18
*** melwitt is now known as jgwentworth22:31
*** jgwentworth is now known as melwitt22:32
JayFStable patch for Ironic 2024.2, already +2 from Elod, everything applied cleanly, if someone would help me land it'd be awesome: https://review.opendev.org/c/openstack/nova/+/96983323:02

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!