| -opendevstatus- NOTICE: Recent POST_FAILURE job results with no logs were due to upload errors in one of our providers, which has been temporarily disabled now so rechecking those should be safe | 12:45 | |
| fungi | https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/ | 13:15 |
|---|---|---|
| opendevreview | Jay Faulkner proposed openstack/ossa master: [OSSA-2026-017] Errata 1: fix parsing edge cases https://review.opendev.org/c/openstack/ossa/+/993185 | 20:12 |
| JayF | fungi: gouthamr: ^ I played with the rendered version locally, I think that's as good as it's likely to look | 20:13 |
| fungi | thanks! i'll check it out as soon as zuul spits out a draft render | 20:15 |
| JayF | fungi: from my local rendering https://usercontent.irccloud-cdn.com/file/faucNmIM/image.png | 20:20 |
| JayF | go ahead and +A if you +2 please | 20:20 |
| fungi | zuul did the thing too, eventually: https://4a6cb73899a7f4b7d538-2873a01b0773a66592697113273431a2.ssl.cf5.rackcdn.com/openstack/c83482c1adf748d09c2e00663882925b/docs/ossa/OSSA-2026-017.html | 20:21 |
| fungi | lgtm | 20:21 |
| * gouthamr inserts late to party comment | 20:27 | |
| * gouthamr good that the releases identified haven't been tagged yet! | 20:27 | |
| gouthamr | but asking for the future, if we had, would we update the affects version string? | 20:27 |
| JayF | I would've likely done so, yes | 20:28 |
| JayF | Ironic is not rushing to push releases to update these because of the quantity of OSSAs/OSSNs issued by our team in a short time | 20:28 |
| gouthamr | ack, and probably treated it as a different bug | 20:28 |
| gouthamr | yeah | 20:28 |
| opendevreview | Merged openstack/ossa master: [OSSA-2026-017] Errata 1: fix parsing edge cases https://review.opendev.org/c/openstack/ossa/+/993185 | 20:31 |
| fungi | it's worth discussing, we can count the number of advisories in the history of openstack which have gotten errata patches on one hand, so those which spanned multiple releases are functionally close to zero | 20:31 |
| fungi | there's effectively no precedent, we can invent our own however makes the most sense | 20:32 |
| gouthamr | ack drawing a parallel: i've been in a situation where i've committed a bug fix and written a release note for it.. if a release has been tagged, and i needed to enhance the bug fix, I still reference the same LP, but I don't edit the release note.. I write a new one | 20:39 |
| gouthamr | sry, said that wrong.. i reference the LP for context, but it's a new LP too | 20:40 |
| gouthamr | just trying to keep things sane for someone that may have already consumed released software | 20:40 |
| fungi | my guiding rule is to do whatever is easiest and requires the least time/effort | 20:42 |
| fungi | because that's our worst bottleneck | 20:42 |
| gouthamr | seems easy to track the releases and look for this; but yes, an errata effort is definitely welcome :) | 20:47 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: [OSSA-2026-022]: IPA Binary Command Injection (CVE-2026-43003) https://review.opendev.org/c/openstack/ossa/+/986850 | 21:10 |
| JayF | I'm also reserving -023 | 21:13 |
| fungi | thanks | 21:13 |
| fungi | looking at 022 now, we usually don't do ossa on mondays, but since it's public workflow we're more flexible | 21:14 |
| JayF | If you look at my self-comment | 21:14 |
| JayF | it's more likely to be good to go on the morrow | 21:14 |
| fungi | okay, you'll obviously want to update the date field in that case | 21:15 |
| JayF | yep, I always check those on day-of-merge | 21:16 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421) https://review.opendev.org/c/openstack/ossa/+/993465 | 21:35 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: [OSSA-2026-022]: IPA Binary Command Injection (CVE-2026-43003) https://review.opendev.org/c/openstack/ossa/+/986850 | 21:39 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421) https://review.opendev.org/c/openstack/ossa/+/993465 | 21:39 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!