Friday, 2026-06-12

fungihttps://bugs.launchpad.net/keystone/+bug/2152715 is now public17:03
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Errata 1: Bugfixes in parsing  https://review.opendev.org/c/openstack/security-doc/+/99318220:46
JayFfungi: gouthamr: ^ I am unfamiliar with how we do errata on OSSN-0099 (this may be the first OSSN errata?) ... I took a swing at a format, pleas review20:47
JayFwait, no, this is just wrong20:48
JayFthis belongs in a different OSSA, I have no idea why my notes said to revise this one20:48
JayFfungi: please do not rapid merge those, I had reviews out for Ironic'ers too20:49
JayFfungi: also that one was so incredibly invalid I have now abandoned it20:49
fungithanks, i incorrectly assumed you were in a hurry to send out errata notices20:49
fungibut yes, i was trying to unapprove before i saw you had abandoned it20:49
JayFI wouldn't do it on a Friday at 2pm20:49
JayFwe have a config option escape hatch just for this case, so like, doing the right thing is more important than the urgent thing ... 20:50
fungifor errata we've generally published as soon as possible, e.g. because the original fix was breaking people's systems already20:50
JayFwe parsed too tightly and were rejecting URL encoded characters in kernel CLI20:50
fungimakes sense20:50
JayFwe knew this had a larger-than-usual chance of breaking, so we put a knob in that someone could flip to keep the most-security-sensitive checks but not get the whole parsing deal20:51
fungismart20:51
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-017] Errata 1: fix parsing edge cases  https://review.opendev.org/c/openstack/ossa/+/99318520:58
JayFfungi: ^ that should be, you know, the correct bug 🤦‍♂️ -- if you wanna +2 if it LGT-you, I can land and announce it Monday morning20:59
fungilooking again, and yeah will hold approval since it sounds non-urgent then21:03
JayFthe customer of ours impacted by this primarily was metal3, they already knew and wrote the fix before we even were working the next day. Just took a while to get it backported around and advisoried. 21:19
fungioh fun21:20
fungianyway, lgtm but i'll wait for ironicfolk to weigh in as well21:24
fungii left you a couple of very minor notes, nothing that demands revision though21:24
JayFI noted something to myself. I'll leave it until it gets other feedback and revise before announcing.,21:26
fungiJayF: see ossa-2023-003 for the last time we seem to have done that21:29
fungithat advisory had 3 errata, the first added a second patch for most affected projects, the second added a patch for a previously uninvolved project (tempest, to fix testing)21:31
fungithough that one seems to be a bit of an anomaly, prior examples are ossa-2021-002, ossa-2017-005, ossa-2016-007, and ossa-2014-03921:35
fungiwe haven't really been consistent about how we flag errata-related change urls in the data since errata are infrequent and sort of bolted on as an afterthought21:37

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!