Tuesday, 2026-08-18

opendevreviewcid proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073515:36
fungihttps://bugs.launchpad.net/cinder/+bug/2163227 is now public15:41
JayFfungi: gouthamr: https://wiki.openstack.org/wiki/OSSN/OSSN-0074 exists in wiki; not in repo. It's not in sarhiri's change at all. fungi do you have context on this?22:03
JayFsimilarly https://wiki.openstack.org/wiki/OSSN/OSSN-007522:04
JayFrepo goes from 70 -> 73 -> 77-79 for 007x22:05
fungiimplicit context via occam's razor is that someone didn't propose a change to the git repo22:05
JayFhttps://wiki.openstack.org/wiki/OSSN/OSSN-007622:05
JayFthe real actionable question is: add these to the OSSN migration or not22:06
fungii van't give you more than that, the whole ossn process has been very much a "best effort" kind of thing in the past22:06
fungii would add them, yes22:06
JayFif the only need for an OSSN existing is "the doc exists" b/c at that point in time we didn't announce22:06
fungican't hurt22:06
JayFthen we'll add them22:06
gouthamr++ even if not in the same commit22:06
gouthamrbasically do whatever is easier; ty for finding this22:07
fungiyeah, separate change is totally fine22:07
gouthamri'm now curious also22:07
gouthamrOSSN-0074 was referenced recently too; and is a pretty popular guidance22:07
fungii'm not even remotely curious. seeing it all unfold over the years, it's almost definitely that it just never got noticed and followed up on, but efforts like this are great for finding the gaps so thanks22:08
gouthamrwe did mail it: https://www.openwall.com/lists/linux-distros/2016/12/12/322:08
* fungi notes that was almost a decade ago now, just a few months shy22:08
JayFif you look at that change, there's a significant amount of revision needed22:09
JayFI am -1 even if there was a follow up22:09
JayFI'm auditing the last 25 against the wiki now22:09
JayFI'm 99% sure we had two versions of many OSSNs; one in txt, one updated more recently in wiki22:09
gouthamr*facepalm*22:09
JayFso most of the things I'm finding are straight up repo/wiki inconsistencies, not something wrong in the process22:09
JayFs/process/migration/22:09
gouthamrso which would you consider a source of truth?22:09
JayFwiki, easily22:09
gouthamrsigh, that complicates the approach?22:10
JayFwiki is the place we link to ML lists, and link inside the OSSN22:10
JayFnot really22:10
JayFI'm doing a manual review of every OSSN, the rendered version in the change vs wiki.22:10
JayFI'm 90 minutes in and to OSSN-0080 so it's not been that miserable22:10
JayFthere are detailed review comments22:10
JayFscrew claude, this is a job for JAY-I22:10
gouthamrlol22:11
fungiyeah, the wiki is the source of truth, the git copies were in service of an incomplete migration that died half-done22:11
fungiand then got left in limbo for a decade22:11
fungibasically the folks in the ossg/osst who were responsible for the security guide and the ossn process initiated a move of ossn articles into the guide repo just before they all left for greener pastures22:13
JayFif anything, this project finally getting completed is proof that technical debt can be paid lol22:14
fungithe vmt mostly ignored the body of ossn articles and related process for many years after the osst dissolved and its remaining personal effects handed off to the security sig22:14
fungihyakuhei and then gagehugo limped some of those efforts along under the auspices of the security sig until they eventually left too22:16
fungii inherited chair of the security sig from gagehugo as essentially the "last man standing"22:16
JayFand I took on co-chair recently just to continue to reduce the list of "things only fungi is responsible for" lol22:17
fungimuch appreciated!22:17
JayFas I've said before, I think the proper final state is Security SIG <merge> VMT22:17
fungii was the security sig absentee slumlord basically22:17
fungithe title of chair had to hang on a neck and there was no other neck left22:18
fungiit's not like i really volunteered so much as i was the only one that didn't leave22:19
gouthamram i on the sig? i don't even know :P but whatevs, call on me22:19
fungiyes, you're absolutely on the sig, i have decreed it22:19
fungiwe never had any real way of identifying who was on the sig22:20
fungiit was "whoever showed up to things"22:20
gouthamrhaha, that's true, besides the chairs, we don;t track SIG members anyway22:20
fungii mean, in many ways that's the real selling feature of openstack's sig model over formal teams. show up and feel included22:21
gouthamr++22:23
JayFdon't show up and make sig chair FeelsBadMan(tm)22:33
* JayF has now read every OSSN ever filed against OpenStack22:34
fungithat's lots more ossn articles than i've read, not kidding22:35
JayFI am not OK doing a migration like this in a lossy way22:35
JayFI should be, but it'd bother me too much if we missed something22:35
* fungi is a notoriously slow reader22:35
JayFagain: that's not a positive attribute of me, it caused me to spend like 2 hours doing a thing that probably would've counted as Good Enough(tm)22:35
fungii have definite ocd tendencies, so not going to throw any stones from my glass hovel22:36
JayFfungi: I'm the opposite; I read quickly. I just have a very weak memory so it's tough to recall. I've been known to read books multiple times when I need it to stick. I can probably get through a "normal size" novel in 3 or 4 hours if it's engaging22:36
JayFOSSNs are not engaging. lmao22:36
fungigreat treatment for insomnia though22:37

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!