Wednesday, 2026-07-08

opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-025: Ironic send_raw (CVE-2026-54423)  https://review.opendev.org/c/openstack/ossa/+/99648114:04
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-026: Ironic rehoming (CVE-2026-44918)  https://review.opendev.org/c/openstack/ossa/+/99648214:09
JayFgouthamr: fungi: ^ Not super urgent as we'll have to wait for the gate to settle14:10
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-025: Ironic send_raw (CVE-2026-54423)  https://review.opendev.org/c/openstack/ossa/+/99648114:10
JayFgouthamr: fungi: I will self-merge -025 after double-checking the patch URLs in the rendered version14:21
JayFplease say something if you are reviewing 14:21
fungii can review, i just needed to get ovh gra1 disabled now that my internet has come back14:22
fungiotherwise there was a good chance it wouldn't merge14:22
fungilooking at 996481 now14:22
JayFlooks like I malformed the bug urls14:23
fungiah yes14:23
JayFoh, I should open the bugs too, huh14:24
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-025: Ironic send_raw (CVE-2026-54423)  https://review.opendev.org/c/openstack/ossa/+/99648114:24
JayF-025 passes my review now, and that bug is open14:26
JayFgoing to review -026 and then touch that bug14:26
fungianother nice-to-have coding task for an intern would be adding a per-deliverable cross-cycle view to releases.openstack.org14:29
fungiwould make it a lot easier to check the affected versions14:29
JayF-026 LGTM too, and those bugs are open14:29
JayFfungi: please merge them or lmk if I need to revise. I do not think it's worth it to churn the patch for whitespace (sorry Julia!)14:29
fungiwill do, just about done checking the version numbers14:30
JayFI didn't re-review those; I just checked to make sure we didn't do a release.14:30
JayFDoing that slog once per patch is enough 14:30
fungiapproved OSSA-2026-02514:31
fungilooking at the other one now14:31
fungiJayF: i'm still double-checking the urls but see my comment about the description rendering14:34
fungiit can also be fixed later in a non-errata followup if you think it's warranted14:35
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-026: Ironic rehoming (CVE-2026-44918)  https://review.opendev.org/c/openstack/ossa/+/99648214:36
JayFfixed14:36
fungiJayF: does OSSA-2026-026 really not affect some recent releases of ironic? the patches linked for those branches haven't merged yet14:39
JayFfungi: today is the embargo lift? Those patches didn't get uploaded until ~1 hour ago?14:40
JayFOH14:40
fungitalking about the affected versions list14:40
JayFfungi: I think that draft OSSA might have sat around past a release, I just need to bump the patch release versions across?14:40
fungiyes seems like it14:40
fungifor example is says 32.0.1 is unaffected14:41
JayFyeah I know what happened, I'll take a pass there14:41
JayFfungi:     version: '>=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0'14:43
JayFfungi: quick review on that without churning CI?14:43
* JayF adds a <37.0.1 to the end14:44
opendevreviewMerged openstack/ossa master: OSSA-2026-025: Ironic send_raw (CVE-2026-54423)  https://review.opendev.org/c/openstack/ossa/+/99648114:45
fungiJayF: lgtm, matches the other ironic ossa i just proofed14:45
JayFwell copying that would've been smart of me, eh14:45
JayFlol14:45
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-026: Ironic rehoming (CVE-2026-44918)  https://review.opendev.org/c/openstack/ossa/+/99648214:46
fungii'm surprised i'm even thinking this straight, came home from the mountains to find the air conditioning was out, and the hvac contractor can't seem to figure out the problem yet, so after an all-day drive i've spent two nights straight trying to sleep in humid 85f temperatures so far14:47
JayFOSSA-2026-025 is announced14:48
JayFfungi: portable AC units are not a horrible thing to have as a backup. Also car A/C can help. We lost ours for two days during a historic 100F+ hot pair of days some years back14:49
fungiyeah, there's a heat wave here so every portable/window ac is sold out for miles in all directions. i'd get a hotel room but it's the height of tourist season so no vacancies14:50
fungiat least we were able to just leave the cats boarded for a couple more days while we sort things out14:50
JayFfungi: I'm somewhat serious: I can call my folks and see if they have one in the garage. They are like an hour from you iirc14:51
fungitempting, but thankfully today's not as hot as yesterday. also i'll be outside a good chunk of the afternoon catching up on lingering yardwork14:52
fungii approved the other ossa14:53
JayFI just self-approved my announce for -02514:53
JayFI'll announce -026 once it lands14:53
fungioh, thanks i meant to be watching the announce moderation queue14:53
JayFany way we can get https://zuul.opendev.org/t/openstack/status?change=996482 to the top of the queue15:02
JayFidk if you did it or not, but it's running15:05
fungiit already is at the top of the queue15:05
fungiopenstack/ossa doesn't share a dependent change queue in the gate pipeline with any other projects15:05
fungiitems in the gate pipeline also get priority on their node requests over items in the check pipeline15:06
fungireordering changes in a queue is only beneficial if you want some change to merge before other changes in the same queue anyway, in this case it's a queue of one15:06
opendevreviewMerged openstack/ossa master: OSSA-2026-026: Ironic rehoming (CVE-2026-44918)  https://review.opendev.org/c/openstack/ossa/+/99648215:07
fungithere are also other factors that weight the prioritization though, like how many jobs have been run for the same project recently15:07
fungiso that projects running a lot of jobs for a lot of changes won't starve out projects that run comparatively few jobs for few changes15:08
fungipart of what zuul terms its "fair queuing algorithm"15:08
JayFOSSA-2026-026 announced15:09
JayFcrap, I missed the (CVE-xxxx) on the end15:09
JayFgoing to reject my announce but I can't fix the oss-security one15:09
fungiyeah, i see it in the announce pipeline15:10
fungidon't sweat the ones that already went out, the message bodies mention the cve multiple times anyway15:10
fungihaving it in the subject is merely convenience15:10
fungiaccepted the new version in the moderation queue15:12
JayFI can't find how to mark a CVE as public/released in the new mitre form?15:17
fungii haven't done it yet myself... gouthamr ^ ?15:18
gouthamryes, update the CAN15:18
gouthamrset the field: "Should the vulnerability be published on the CVE List now?" to yes15:19
JayFso what you're saying is15:19
JayFI should've saved the CAN- number15:19
gouthamrand add a comment under "New Communication to CNA-LR" 15:19
gouthamrhaha, yes :D 15:19
gouthamrbut, you'll find it under "Portal"15:19
JayFthis new system is awful15:19
JayFyeah those don't have CVE- or OSSA- on them15:19
JayFnot enough metadata to map to tickets15:19
gouthamrYES, i hate that part15:20
JayFI mean, hate that part or not hate that part, I do not have the info to do this15:20
JayFwhat a flawed system :( 15:20
gouthamri literally Ctrl-F the CAN-ID i commented on the LP to track it15:20
JayFYeah, same, except for that part where I didn't put the CAN-ID for this one on there15:20
JayFit's a chance I got this CVE through the old form, tbh15:20
fungiif i were cynical i'd suspect it's a passive-aggressive way of encouraging people to request cve assignments elsewhere or apply to become a cna themselves15:20
JayFI am cynical, and I suggest that.15:21
JayFlol15:21
JayFI am using their "report a public-but-reserved CVE" form, with something in the comment section describing my inability to map CAN- to CVE- for that bug15:24
gouthamrack, hope that works.. do you have too many CANs?15:25
JayFI will wait to submit until -026 appears on the web15:25
JayFI have like 7 CANs in here right now15:25
JayFand am NOT going to play process of elimination so I can intellegently guess which one15:25
JayFwhich might be wrong15:25
JayFthis is not a place for guessing. if it's extra work for them to use that form, then maybe their website shouldn't look like the finest in enterprise software from 199615:26
gouthamr:P wasn't luring you to divulge the number.. but, i have had to open each of mine to verify stuff in the past few weeks.. sucks, /me shakes fist at MITRE15:26
* JayF kicks the AFS server15:27
JayFI don't have any access, I'm only kicking it in my heart :D 15:27
JayFlol15:27
JayFhttps://security.openstack.org/ossa/OSSA-2026-026.html still 404'ing a good hour after merge?15:27
JayFfungi: ^15:27
* gouthamr imitates south park, don't kick the AFS15:27
fungilookin15:27
fungilooks like someone uploaded something large to the tarballs volume shortly before 15:00 utc so that's been syncing to the remote read-only volumes for a while15:29
fungii'll manually force a release of the security site volume in the meantime15:29
fungioh, wait, it just woke up on its own15:30
fungiit's updated now15:31
JayFI think I told MITRE to release both CVEs now, too15:33
fungiJayF: following the comments on OSSA-2026-026 are we likely to have errata patches added for that?17:47
fungijust making sure i keep an eye out so i can expedite reviewing if so17:48
JayFI'm pretty sure it's just a patch-is-not-right-in-all-cases issue17:50
fungiokay17:50
JayFwe never merged a broken patch17:50
JayFso URLs will still work and things will get merged once Julia finds the fix17:51
fungimakes sense, hard to tell from the discussion in the bug alone17:51

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!