*** sdake has joined #openstack-requirements | 00:46 | |
*** sdake has quit IRC | 01:03 | |
*** sdake has joined #openstack-requirements | 01:05 | |
*** sdake has quit IRC | 01:19 | |
*** hongbin has joined #openstack-requirements | 02:52 | |
*** sdake has joined #openstack-requirements | 03:03 | |
*** hongbin has quit IRC | 03:30 | |
*** sdake has quit IRC | 03:36 | |
*** sdake has joined #openstack-requirements | 03:40 | |
*** udesale has joined #openstack-requirements | 03:51 | |
*** sdake has quit IRC | 03:56 | |
*** udesale has quit IRC | 04:21 | |
*** sdake has joined #openstack-requirements | 04:22 | |
*** udesale has joined #openstack-requirements | 04:22 | |
*** spsurya has joined #openstack-requirements | 04:24 | |
*** sdake has quit IRC | 04:25 | |
*** sdake has joined #openstack-requirements | 04:29 | |
*** sdake has quit IRC | 04:30 | |
*** sdake has joined #openstack-requirements | 04:31 | |
*** sdake has quit IRC | 04:35 | |
*** sdake has joined #openstack-requirements | 04:37 | |
*** sdake has quit IRC | 04:40 | |
*** sdake has joined #openstack-requirements | 04:42 | |
*** sdake has quit IRC | 04:45 | |
*** sdake has joined #openstack-requirements | 04:46 | |
*** sdake has quit IRC | 04:48 | |
*** sdake has joined #openstack-requirements | 04:52 | |
*** sdake has quit IRC | 04:55 | |
*** sdake has joined #openstack-requirements | 04:57 | |
*** sdake has quit IRC | 05:00 | |
*** sdake has joined #openstack-requirements | 05:02 | |
*** sdake has quit IRC | 05:10 | |
*** sdake_ has joined #openstack-requirements | 05:11 | |
*** sdake_ has quit IRC | 05:15 | |
*** sdake has joined #openstack-requirements | 05:16 | |
*** sdake has quit IRC | 05:21 | |
*** sdake has joined #openstack-requirements | 05:21 | |
*** sdake has quit IRC | 05:26 | |
*** sdake has joined #openstack-requirements | 05:28 | |
*** sdake has quit IRC | 05:30 | |
*** sdake_ has joined #openstack-requirements | 05:33 | |
*** sdake_ has quit IRC | 05:35 | |
*** sdake has joined #openstack-requirements | 05:36 | |
*** sdake has quit IRC | 05:45 | |
*** sdake has joined #openstack-requirements | 05:49 | |
*** sdake has quit IRC | 05:51 | |
*** sdake has joined #openstack-requirements | 05:51 | |
*** sdake has quit IRC | 05:55 | |
*** sdake has joined #openstack-requirements | 05:57 | |
*** sdake has quit IRC | 06:00 | |
*** sdake has joined #openstack-requirements | 06:01 | |
*** sdake has quit IRC | 06:06 | |
*** sdake_ has joined #openstack-requirements | 06:08 | |
*** sdake_ has quit IRC | 06:10 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/requirements master: Updated from generate-constraints https://review.openstack.org/638928 | 06:21 |
---|---|---|
openstackgerrit | Matthew Thode proposed openstack/requirements master: Updated from generate-constraints https://review.openstack.org/638928 | 06:32 |
*** udesale has quit IRC | 07:27 | |
*** udesale has joined #openstack-requirements | 07:27 | |
*** dtantsur|afk is now known as dtantsur | 08:21 | |
*** zbr|ssbarnea has joined #openstack-requirements | 08:34 | |
*** hberaud|gone has quit IRC | 08:44 | |
*** ccamacho has joined #openstack-requirements | 08:45 | |
*** e0ne has joined #openstack-requirements | 08:51 | |
*** tosky has joined #openstack-requirements | 08:55 | |
*** hberaud has joined #openstack-requirements | 09:00 | |
*** jpich has joined #openstack-requirements | 09:03 | |
*** hberaud has quit IRC | 09:06 | |
*** hberaud has joined #openstack-requirements | 09:06 | |
*** zbr|ssbarnea is now known as zbr|out | 09:13 | |
*** ccamacho has quit IRC | 09:38 | |
*** smrcascao has joined #openstack-requirements | 09:54 | |
*** smrcascao has quit IRC | 09:58 | |
*** smrcascao has joined #openstack-requirements | 10:03 | |
*** ccamacho has joined #openstack-requirements | 10:13 | |
openstackgerrit | Merged openstack/requirements master: Updated from generate-constraints https://review.openstack.org/638928 | 10:16 |
*** smrcascao has quit IRC | 10:20 | |
*** smrcascao has joined #openstack-requirements | 10:23 | |
*** smrcascao has quit IRC | 10:23 | |
*** smrcascao has joined #openstack-requirements | 10:24 | |
*** smrcascao has quit IRC | 10:31 | |
*** smrcascao has joined #openstack-requirements | 10:33 | |
*** smrcascao has quit IRC | 10:33 | |
*** smrcascao has joined #openstack-requirements | 10:34 | |
*** smrcascao has quit IRC | 10:35 | |
*** ccamacho has quit IRC | 10:43 | |
*** ccamacho has joined #openstack-requirements | 10:43 | |
*** ccamacho has quit IRC | 10:45 | |
*** ccamacho has joined #openstack-requirements | 11:12 | |
*** ccamacho has quit IRC | 11:13 | |
*** ccamacho has joined #openstack-requirements | 11:14 | |
*** udesale has quit IRC | 11:18 | |
*** snapiri has quit IRC | 11:23 | |
*** ccamacho has quit IRC | 11:28 | |
*** finucannot is now known as stephenfin | 11:40 | |
*** sdake has joined #openstack-requirements | 11:46 | |
*** sdake has quit IRC | 11:50 | |
*** sdake has joined #openstack-requirements | 11:52 | |
*** sdake has quit IRC | 11:55 | |
*** sdake has joined #openstack-requirements | 11:56 | |
*** ccamacho has joined #openstack-requirements | 11:59 | |
*** sdake has quit IRC | 12:00 | |
*** hberaud is now known as hberaud|lunch | 12:01 | |
*** udesale has joined #openstack-requirements | 12:42 | |
*** e0ne has quit IRC | 12:47 | |
*** hberaud|lunch is now known as hberaud | 13:07 | |
openstackgerrit | Lucian Petrut proposed openstack/requirements master: Add platform check for xattr and pysendfile https://review.openstack.org/639084 | 13:13 |
*** e0ne has joined #openstack-requirements | 13:35 | |
*** snapiri has joined #openstack-requirements | 13:37 | |
*** udesale has quit IRC | 13:37 | |
*** udesale has joined #openstack-requirements | 13:38 | |
*** smrcascao has joined #openstack-requirements | 14:40 | |
*** smrcascao has quit IRC | 14:41 | |
*** abhi89 has joined #openstack-requirements | 14:42 | |
*** smrcascao has joined #openstack-requirements | 14:42 | |
abhi89 | prometheanfire: Hi Matthew.. reg https://storyboard.openstack.org/#!/story/2004979 | 14:43 |
abhi89 | prometheanfire: so if requirements team cannot update the upper constraints of packages in the event of a security issue, then will packagers/distros/deployment teams work on this to resolve it? like will they be ready to test the stable & supported openstack releases with requests package (having the fix) & if everything works fine then go & update the requirements.txt? | 14:43 |
*** smrcascao has quit IRC | 14:43 | |
abhi89 | prometheanfire: in short, how to take this forward! | 14:44 |
*** udesale has quit IRC | 15:02 | |
*** e0ne has quit IRC | 15:03 | |
*** e0ne has joined #openstack-requirements | 15:05 | |
*** abhi89 has quit IRC | 15:13 | |
dhellmann | abhi89: the constraints list is what we test with, and provides guidance but should not limit distributors from choosing other versions | 15:19 |
*** beekneemech is now known as bnemec | 15:21 | |
*** abhi89 has joined #openstack-requirements | 15:28 | |
prometheanfire | abhi89: distros also tend to backport the fixes to the packaged versions rather than update the version, less change | 15:55 |
abhi89 | prometheanfire: so there won't be any action from the openstack side for this vulenrability fix, right? distros or deployment teams need to take care of it | 16:19 |
prometheanfire | abhi89: correct | 16:22 |
*** e0ne has quit IRC | 16:26 | |
abhi89 | prometheanfire: ok, but if we ship this requests package as part of openstack installer to customers, then we can't rely on the distros alone. | 16:27 |
prometheanfire | abhi89: are you a packager or deployer? | 16:27 |
abhi89 | prometheanfire: packager.. we use openstack to create our own private cloud product.. as part of the installer we ship this requests pacakge also.. | 16:31 |
*** e0ne has joined #openstack-requirements | 16:31 | |
abhi89 | prometheanfire: and unlike the distros, we just cannot backport just the fix to older requests package.. | 16:31 |
prometheanfire | abhi89: then I'd ship a patched version of requests (or the new, fixed, update if tested) | 16:31 |
prometheanfire | if your a packager why can't you patch? | 16:32 |
prometheanfire | or use a version you want | 16:32 |
abhi89 | prometheanfire: yes, we will have to test our product with requests version > 2.20.0 & check if everything is intact | 16:32 |
abhi89 | prometheanfire: we are not packager of requests library.. we package openstack as a product, like all the dependent packages that is needed for opestack to get installed successfully.. requests is just one of them.. i don't think we can patch the older requests library with the fix.. | 16:34 |
prometheanfire | abhi89: ok, if you can't patch can you instead specify the updated version? | 16:35 |
abhi89 | prometheanfire: yes, we can ship the updated version.. as of now we are only shipping packages with version in accordance with openstack's requirements.txt.. this will be something out of the range.. so we will have to test thoroughly.. | 16:36 |
prometheanfire | abhi89: ya, you can submit a test patch to upper-constraints for the branches in question and it'll cross test with a few things, but it will not be merged | 16:38 |
prometheanfire | abhi89: osa has to do the same thing | 16:38 |
prometheanfire | odyssey4me: which file is OSA's UC override? | 16:39 |
abhi89 | prometheanfire: but osa will not be doing anything in this case right? this vulnerability doesn't qualify to be a openstack advisory | 17:05 |
prometheanfire | abhi89: imo they should do something, not sure if they will | 17:05 |
prometheanfire | asked in their channel | 17:06 |
abhi89 | can you please mention their channel name? | 17:06 |
prometheanfire | #openstack-ansible | 17:07 |
abhi89 | prometheanfire: thanks.. i will check there if they will be doing something about this vulnerability.. | 17:10 |
*** e0ne has quit IRC | 17:18 | |
*** jpich has quit IRC | 17:20 | |
*** dtantsur is now known as dtantsur|afk | 17:23 | |
*** sdake has joined #openstack-requirements | 17:25 | |
*** abhi89 has quit IRC | 17:48 | |
*** hberaud is now known as hberaud|gone | 17:49 | |
*** sdake_ has joined #openstack-requirements | 18:05 | |
*** sdake has quit IRC | 18:07 | |
*** sdake_ has quit IRC | 18:10 | |
*** sdake has joined #openstack-requirements | 18:10 | |
*** sdake_ has joined #openstack-requirements | 18:15 | |
*** sdake has quit IRC | 18:16 | |
*** sdake_ has quit IRC | 18:20 | |
*** sdake has joined #openstack-requirements | 18:22 | |
*** sdake has quit IRC | 18:26 | |
*** sdake_ has joined #openstack-requirements | 18:26 | |
*** sdake_ has quit IRC | 18:35 | |
*** sdake has joined #openstack-requirements | 18:36 | |
*** bnemec has quit IRC | 18:40 | |
*** sdake_ has joined #openstack-requirements | 18:40 | |
*** sdake has quit IRC | 18:41 | |
*** e0ne has joined #openstack-requirements | 18:44 | |
*** bnemec has joined #openstack-requirements | 18:45 | |
*** sdake_ has quit IRC | 18:45 | |
*** sdake has joined #openstack-requirements | 18:46 | |
*** sdake has quit IRC | 18:50 | |
*** sdake has joined #openstack-requirements | 18:52 | |
*** sdake has quit IRC | 18:55 | |
*** sdake has joined #openstack-requirements | 18:56 | |
*** sdake has quit IRC | 19:01 | |
*** sdake has joined #openstack-requirements | 19:01 | |
*** sdake has quit IRC | 19:05 | |
*** sdake has joined #openstack-requirements | 19:06 | |
*** sdake has quit IRC | 19:11 | |
*** sdake has joined #openstack-requirements | 19:13 | |
*** sdake has quit IRC | 19:15 | |
*** sdake_ has joined #openstack-requirements | 19:16 | |
*** sdake_ has quit IRC | 19:20 | |
*** ccamacho has quit IRC | 20:39 | |
*** e0ne has quit IRC | 21:21 | |
*** sdake has joined #openstack-requirements | 21:28 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/requirements master: update constraint for ldappool to new release 2.4.1 https://review.openstack.org/639199 | 21:46 |
*** sdake has quit IRC | 21:48 | |
*** e0ne has joined #openstack-requirements | 21:54 | |
*** e0ne has quit IRC | 21:55 | |
*** sdake has joined #openstack-requirements | 21:59 | |
*** sdake has quit IRC | 22:01 | |
*** sdake has joined #openstack-requirements | 22:03 | |
*** e0ne has joined #openstack-requirements | 22:05 | |
*** sdake has quit IRC | 22:05 | |
*** e0ne has quit IRC | 22:08 | |
*** sdake has joined #openstack-requirements | 22:08 | |
*** sdake has quit IRC | 22:10 | |
tonyb | prometheanfire: I think 'wget http://releases.openstack.org/constraints/upper/master' works as expected | 23:13 |
tonyb | prometheanfire: I'll do more testing later today but I'm confident it's working | 23:13 |
prometheanfire | nice | 23:24 |
prometheanfire | curl -L | 23:24 |
tonyb | Ahh cool, I used wget becuase it does that by default and has nice logging to show you it works ;P | 23:35 |
tonyb | prometheanfire: right now it's a static list but I'm workign on making it data-driven / dynamic | 23:35 |
prometheanfire | nice | 23:44 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/requirements master: update constraint for python-vitrageclient to new release 2.6.0 https://review.openstack.org/639222 | 23:56 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!