Friday, 2026-08-14

fungihttps://bugs.launchpad.net/horizon/+bug/2163119 is now public14:01
opendevreviewcid proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073517:50
JayFfungi: gouthamr: rosmaita: ^ curious what other VMT folks think about that errata? unsure how to handle the weirdness around 2024.2 not existing (and 2026.2 not existing) when the original OSSA hit17:54
JayFI think this is probably OK as it's written, but I'm tempted to suggest we add a line to both of those releases saying why they don't have (original fix) or (errata 2) patches 17:54
gouthamrisn't this a regular bugfix JayF? you have the release notes to explain this regression, and fix it up? or am i missing why this needs to be advisoried?17:57
gouthamris it about the reach of the advisory? 17:58
JayFthe advisory patch *introduced the bug*18:04
JayFwe secured the feature so well we broke it18:04
gouthamrwe've done this sorta thing, but rarely18:04
gouthamr> we secured the feature so well we broke it18:05
gouthamryes, i'm hoping distros/packagers that notice the bug are going to pick up the fixes18:05
JayFhm18:05
JayFI think I disagree strongly.18:05
JayFThat's based in an assumption that OSSA is only used at the point-in-time18:06
gouthamrthe precedent to publish errata patches: OSSA-2023-003, OSSA-2017-005, OSSA-2021-00218:06
JayFright now, we have a doc merged to our security repos saying "install this patch to secure this feature" but really those patches just break things18:06
JayFI don't care about the emails/notifications/etc18:06
JayFI just do not want that doc to say wrong things forever18:06
JayFthat's primarily where my head is at, and why I thought it was a slam dunk to errata it18:07
gouthamrhttps://security.openstack.org/ossa/OSSA-2023-00318:07
gouthamrhttps://security.openstack.org/ossa/OSSA-2017-00518:07
gouthamrhttps://security.openstack.org/ossa/OSSA-2021-00218:07
JayF2017-005 is a straight "we broke functionality with this security patch; errata patch fixes it"18:08
JayF2023-003 is two non-security bugfixes, just fixing regressions too18:08
JayFSo I think we have historical backing for errata'ing an OSSA when the original patch was breaky18:08
gouthamrno you're not wrong, my devils-advocate argument is also to learn 18:09
gouthamr> So I think we have historical backing for errata'ing an OSSA when the original patch was breaky18:09
gouthamryeah18:09
JayFtbf I didn't come with any reciepts18:09
gouthamrbut, who discovered the problem/18:09
JayFprobably the only human in the world still using this feature /s (but probably closer to the truth than not)18:10
JayFbut it was an operator who applied the patch and was like "this is totes broken"18:10
gouthamrJayF: ack, adding comments for some changes.. but am okay with it.. the timeline is ~4 months apart, which is longer than prior bugs had erratas.. but we have no time cutoff.. maybe fungi/rosmaita'll have a different opinion18:32
fungisorry, was on a conference call but catching back up now. yes the original reason for errata was when we needed to announce patches that fixed regressions introduced by the original fixes, though we've co-opted that same process for any other updates we make to advisories for the sake of transparency19:10
fungiand now it tends to mostly be the latter, but it's also still very much for the former19:12
fungithe only related exception is when a security fix introduces a new vulnerability or doesn't completely solve the original vulnerability, then we've preferred an entirely new advisory for those cases19:12
rosmaitaJayF: left a comment for you19:12
gouthamr> the only related exception is when a security fix introduces a new vulnerability or doesn't completely solve the original vulnerability, then we've preferred an entirely new advisory for those cases19:13
gouthamrah, good to know.. 19:13
gouthamr(since this hasn't happened this year so far)19:13
fungimainly because if you're an operator and you've applied security fix x and it broke your deployment you'll be looking for updates to the advisory for x, but if applying x silently left you still partly vulnerable or opened up a wholly new vulnerability you probably aren't looking for updates to x19:15
rosmaitafungi: what's our stance on what to call an individual item in an errata?  Red Hat pretty much uses 'errata' for this, but i believe the traditional term is 'erratum'19:20
fungii took (too) many years of latin in my youth and so also prefer erratum (errata is the plural form)19:21
fungisame for datum vs data19:21
fungiin my opinion if you're going to just steal words from another language, don't half-ass it19:22
fungilike indices instead of indexes, axes instead if axises, and so on19:23
rosmaitai had an argument with an editor at routledge about data vs datum in the context of a von neumann machine ... i said the content of a memory location could be an instruction or data, and she said it should be 'instruction or a datum'; my argument was that without interpreting it, you couldn't know whether it was a singular piece of data or several, so she let me get away with using "data"19:24
fungihttps://bugs.launchpad.net/horizon/+bug/2163088 is now public20:25
opendevreviewcid proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073520:27

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!