Monday, 2019-02-25

*** sdake has joined #openstack-requirements00:46
*** sdake has quit IRC01:03
*** sdake has joined #openstack-requirements01:05
*** sdake has quit IRC01:19
*** hongbin has joined #openstack-requirements02:52
*** sdake has joined #openstack-requirements03:03
*** hongbin has quit IRC03:30
*** sdake has quit IRC03:36
*** sdake has joined #openstack-requirements03:40
*** udesale has joined #openstack-requirements03:51
*** sdake has quit IRC03:56
*** udesale has quit IRC04:21
*** sdake has joined #openstack-requirements04:22
*** udesale has joined #openstack-requirements04:22
*** spsurya has joined #openstack-requirements04:24
*** sdake has quit IRC04:25
*** sdake has joined #openstack-requirements04:29
*** sdake has quit IRC04:30
*** sdake has joined #openstack-requirements04:31
*** sdake has quit IRC04:35
*** sdake has joined #openstack-requirements04:37
*** sdake has quit IRC04:40
*** sdake has joined #openstack-requirements04:42
*** sdake has quit IRC04:45
*** sdake has joined #openstack-requirements04:46
*** sdake has quit IRC04:48
*** sdake has joined #openstack-requirements04:52
*** sdake has quit IRC04:55
*** sdake has joined #openstack-requirements04:57
*** sdake has quit IRC05:00
*** sdake has joined #openstack-requirements05:02
*** sdake has quit IRC05:10
*** sdake_ has joined #openstack-requirements05:11
*** sdake_ has quit IRC05:15
*** sdake has joined #openstack-requirements05:16
*** sdake has quit IRC05:21
*** sdake has joined #openstack-requirements05:21
*** sdake has quit IRC05:26
*** sdake has joined #openstack-requirements05:28
*** sdake has quit IRC05:30
*** sdake_ has joined #openstack-requirements05:33
*** sdake_ has quit IRC05:35
*** sdake has joined #openstack-requirements05:36
*** sdake has quit IRC05:45
*** sdake has joined #openstack-requirements05:49
*** sdake has quit IRC05:51
*** sdake has joined #openstack-requirements05:51
*** sdake has quit IRC05:55
*** sdake has joined #openstack-requirements05:57
*** sdake has quit IRC06:00
*** sdake has joined #openstack-requirements06:01
*** sdake has quit IRC06:06
*** sdake_ has joined #openstack-requirements06:08
*** sdake_ has quit IRC06:10
openstackgerritOpenStack Proposal Bot proposed openstack/requirements master: Updated from generate-constraints  https://review.openstack.org/63892806:21
openstackgerritMatthew Thode proposed openstack/requirements master: Updated from generate-constraints  https://review.openstack.org/63892806:32
*** udesale has quit IRC07:27
*** udesale has joined #openstack-requirements07:27
*** dtantsur|afk is now known as dtantsur08:21
*** zbr|ssbarnea has joined #openstack-requirements08:34
*** hberaud|gone has quit IRC08:44
*** ccamacho has joined #openstack-requirements08:45
*** e0ne has joined #openstack-requirements08:51
*** tosky has joined #openstack-requirements08:55
*** hberaud has joined #openstack-requirements09:00
*** jpich has joined #openstack-requirements09:03
*** hberaud has quit IRC09:06
*** hberaud has joined #openstack-requirements09:06
*** zbr|ssbarnea is now known as zbr|out09:13
*** ccamacho has quit IRC09:38
*** smrcascao has joined #openstack-requirements09:54
*** smrcascao has quit IRC09:58
*** smrcascao has joined #openstack-requirements10:03
*** ccamacho has joined #openstack-requirements10:13
openstackgerritMerged openstack/requirements master: Updated from generate-constraints  https://review.openstack.org/63892810:16
*** smrcascao has quit IRC10:20
*** smrcascao has joined #openstack-requirements10:23
*** smrcascao has quit IRC10:23
*** smrcascao has joined #openstack-requirements10:24
*** smrcascao has quit IRC10:31
*** smrcascao has joined #openstack-requirements10:33
*** smrcascao has quit IRC10:33
*** smrcascao has joined #openstack-requirements10:34
*** smrcascao has quit IRC10:35
*** ccamacho has quit IRC10:43
*** ccamacho has joined #openstack-requirements10:43
*** ccamacho has quit IRC10:45
*** ccamacho has joined #openstack-requirements11:12
*** ccamacho has quit IRC11:13
*** ccamacho has joined #openstack-requirements11:14
*** udesale has quit IRC11:18
*** snapiri has quit IRC11:23
*** ccamacho has quit IRC11:28
*** finucannot is now known as stephenfin11:40
*** sdake has joined #openstack-requirements11:46
*** sdake has quit IRC11:50
*** sdake has joined #openstack-requirements11:52
*** sdake has quit IRC11:55
*** sdake has joined #openstack-requirements11:56
*** ccamacho has joined #openstack-requirements11:59
*** sdake has quit IRC12:00
*** hberaud is now known as hberaud|lunch12:01
*** udesale has joined #openstack-requirements12:42
*** e0ne has quit IRC12:47
*** hberaud|lunch is now known as hberaud13:07
openstackgerritLucian Petrut proposed openstack/requirements master: Add platform check for xattr and pysendfile  https://review.openstack.org/63908413:13
*** e0ne has joined #openstack-requirements13:35
*** snapiri has joined #openstack-requirements13:37
*** udesale has quit IRC13:37
*** udesale has joined #openstack-requirements13:38
*** smrcascao has joined #openstack-requirements14:40
*** smrcascao has quit IRC14:41
*** abhi89 has joined #openstack-requirements14:42
*** smrcascao has joined #openstack-requirements14:42
abhi89prometheanfire: Hi Matthew.. reg https://storyboard.openstack.org/#!/story/200497914:43
abhi89prometheanfire: so if requirements team cannot update the upper constraints of packages in the event of a security issue, then will packagers/distros/deployment teams work on this to resolve it? like will they be ready to test the stable & supported openstack releases with requests package (having the fix) & if everything works fine then go & update the requirements.txt?14:43
*** smrcascao has quit IRC14:43
abhi89prometheanfire: in short, how to take this forward!14:44
*** udesale has quit IRC15:02
*** e0ne has quit IRC15:03
*** e0ne has joined #openstack-requirements15:05
*** abhi89 has quit IRC15:13
dhellmannabhi89: the constraints list is what we test with, and provides guidance but should not limit distributors from choosing other versions15:19
*** beekneemech is now known as bnemec15:21
*** abhi89 has joined #openstack-requirements15:28
prometheanfireabhi89: distros also tend to backport the fixes to the packaged versions rather than update the version, less change15:55
abhi89prometheanfire: so there won't be any action from the openstack side for this vulenrability fix, right? distros or deployment teams need to take care of it16:19
prometheanfireabhi89: correct16:22
*** e0ne has quit IRC16:26
abhi89prometheanfire: ok, but if we ship this requests package as part of openstack installer to customers, then we can't rely on the distros alone.16:27
prometheanfireabhi89: are you a packager or deployer?16:27
abhi89prometheanfire: packager.. we use openstack to create our own private cloud product.. as part of the installer we ship this requests pacakge also..16:31
*** e0ne has joined #openstack-requirements16:31
abhi89prometheanfire: and unlike the distros, we just cannot backport just the fix to older requests package..16:31
prometheanfireabhi89: then I'd ship a patched version of requests (or the new, fixed, update if tested)16:31
prometheanfireif your a packager why can't you patch?16:32
prometheanfireor use a version you want16:32
abhi89prometheanfire: yes, we will have to test our product with requests version > 2.20.0 & check if everything is intact16:32
abhi89prometheanfire: we are not packager of requests library.. we package openstack as a product, like all the dependent packages that is needed for opestack to get installed successfully.. requests is just one of them.. i don't think we can patch the older requests library with the fix..16:34
prometheanfireabhi89: ok, if you can't patch can you instead specify the updated version?16:35
abhi89prometheanfire: yes, we can ship the updated version.. as of now we are only shipping packages with version in accordance with openstack's requirements.txt.. this will be something out of the range.. so we will have to test thoroughly..16:36
prometheanfireabhi89: ya, you can submit a test patch to upper-constraints for the branches in question and it'll cross test with a few things, but it will not be merged16:38
prometheanfireabhi89: osa has to do the same thing16:38
prometheanfireodyssey4me: which file is OSA's UC override?16:39
abhi89prometheanfire: but osa will not be doing anything in this case right? this vulnerability doesn't qualify to be a openstack advisory17:05
prometheanfireabhi89: imo they should do something, not sure if they will17:05
prometheanfireasked in their channel17:06
abhi89can you please mention their channel name?17:06
prometheanfire#openstack-ansible17:07
abhi89prometheanfire: thanks.. i will check there if they will be doing something about this vulnerability..17:10
*** e0ne has quit IRC17:18
*** jpich has quit IRC17:20
*** dtantsur is now known as dtantsur|afk17:23
*** sdake has joined #openstack-requirements17:25
*** abhi89 has quit IRC17:48
*** hberaud is now known as hberaud|gone17:49
*** sdake_ has joined #openstack-requirements18:05
*** sdake has quit IRC18:07
*** sdake_ has quit IRC18:10
*** sdake has joined #openstack-requirements18:10
*** sdake_ has joined #openstack-requirements18:15
*** sdake has quit IRC18:16
*** sdake_ has quit IRC18:20
*** sdake has joined #openstack-requirements18:22
*** sdake has quit IRC18:26
*** sdake_ has joined #openstack-requirements18:26
*** sdake_ has quit IRC18:35
*** sdake has joined #openstack-requirements18:36
*** bnemec has quit IRC18:40
*** sdake_ has joined #openstack-requirements18:40
*** sdake has quit IRC18:41
*** e0ne has joined #openstack-requirements18:44
*** bnemec has joined #openstack-requirements18:45
*** sdake_ has quit IRC18:45
*** sdake has joined #openstack-requirements18:46
*** sdake has quit IRC18:50
*** sdake has joined #openstack-requirements18:52
*** sdake has quit IRC18:55
*** sdake has joined #openstack-requirements18:56
*** sdake has quit IRC19:01
*** sdake has joined #openstack-requirements19:01
*** sdake has quit IRC19:05
*** sdake has joined #openstack-requirements19:06
*** sdake has quit IRC19:11
*** sdake has joined #openstack-requirements19:13
*** sdake has quit IRC19:15
*** sdake_ has joined #openstack-requirements19:16
*** sdake_ has quit IRC19:20
*** ccamacho has quit IRC20:39
*** e0ne has quit IRC21:21
*** sdake has joined #openstack-requirements21:28
openstackgerritOpenStack Proposal Bot proposed openstack/requirements master: update constraint for ldappool to new release 2.4.1  https://review.openstack.org/63919921:46
*** sdake has quit IRC21:48
*** e0ne has joined #openstack-requirements21:54
*** e0ne has quit IRC21:55
*** sdake has joined #openstack-requirements21:59
*** sdake has quit IRC22:01
*** sdake has joined #openstack-requirements22:03
*** e0ne has joined #openstack-requirements22:05
*** sdake has quit IRC22:05
*** e0ne has quit IRC22:08
*** sdake has joined #openstack-requirements22:08
*** sdake has quit IRC22:10
tonybprometheanfire: I think 'wget http://releases.openstack.org/constraints/upper/master' works as expected23:13
tonybprometheanfire: I'll do more testing later today but I'm confident it's working23:13
prometheanfirenice23:24
prometheanfirecurl -L23:24
tonybAhh cool, I used wget becuase it does that by default and has nice logging to show you it works ;P23:35
tonybprometheanfire: right now it's a static list but I'm workign on making it data-driven / dynamic23:35
prometheanfirenice23:44
openstackgerritOpenStack Proposal Bot proposed openstack/requirements master: update constraint for python-vitrageclient to new release 2.6.0  https://review.openstack.org/63922223:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!