| opendevreview | cid proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression https://review.opendev.org/c/openstack/ossa/+/1000735 | 15:36 |
|---|---|---|
| fungi | https://bugs.launchpad.net/cinder/+bug/2163227 is now public | 15:41 |
| JayF | fungi: gouthamr: https://wiki.openstack.org/wiki/OSSN/OSSN-0074 exists in wiki; not in repo. It's not in sarhiri's change at all. fungi do you have context on this? | 22:03 |
| JayF | similarly https://wiki.openstack.org/wiki/OSSN/OSSN-0075 | 22:04 |
| JayF | repo goes from 70 -> 73 -> 77-79 for 007x | 22:05 |
| fungi | implicit context via occam's razor is that someone didn't propose a change to the git repo | 22:05 |
| JayF | https://wiki.openstack.org/wiki/OSSN/OSSN-0076 | 22:05 |
| JayF | the real actionable question is: add these to the OSSN migration or not | 22:06 |
| fungi | i van't give you more than that, the whole ossn process has been very much a "best effort" kind of thing in the past | 22:06 |
| fungi | i would add them, yes | 22:06 |
| JayF | if the only need for an OSSN existing is "the doc exists" b/c at that point in time we didn't announce | 22:06 |
| fungi | can't hurt | 22:06 |
| JayF | then we'll add them | 22:06 |
| gouthamr | ++ even if not in the same commit | 22:06 |
| gouthamr | basically do whatever is easier; ty for finding this | 22:07 |
| fungi | yeah, separate change is totally fine | 22:07 |
| gouthamr | i'm now curious also | 22:07 |
| gouthamr | OSSN-0074 was referenced recently too; and is a pretty popular guidance | 22:07 |
| fungi | i'm not even remotely curious. seeing it all unfold over the years, it's almost definitely that it just never got noticed and followed up on, but efforts like this are great for finding the gaps so thanks | 22:08 |
| gouthamr | we did mail it: https://www.openwall.com/lists/linux-distros/2016/12/12/3 | 22:08 |
| * fungi notes that was almost a decade ago now, just a few months shy | 22:08 | |
| JayF | if you look at that change, there's a significant amount of revision needed | 22:09 |
| JayF | I am -1 even if there was a follow up | 22:09 |
| JayF | I'm auditing the last 25 against the wiki now | 22:09 |
| JayF | I'm 99% sure we had two versions of many OSSNs; one in txt, one updated more recently in wiki | 22:09 |
| gouthamr | *facepalm* | 22:09 |
| JayF | so most of the things I'm finding are straight up repo/wiki inconsistencies, not something wrong in the process | 22:09 |
| JayF | s/process/migration/ | 22:09 |
| gouthamr | so which would you consider a source of truth? | 22:09 |
| JayF | wiki, easily | 22:09 |
| gouthamr | sigh, that complicates the approach? | 22:10 |
| JayF | wiki is the place we link to ML lists, and link inside the OSSN | 22:10 |
| JayF | not really | 22:10 |
| JayF | I'm doing a manual review of every OSSN, the rendered version in the change vs wiki. | 22:10 |
| JayF | I'm 90 minutes in and to OSSN-0080 so it's not been that miserable | 22:10 |
| JayF | there are detailed review comments | 22:10 |
| JayF | screw claude, this is a job for JAY-I | 22:10 |
| gouthamr | lol | 22:11 |
| fungi | yeah, the wiki is the source of truth, the git copies were in service of an incomplete migration that died half-done | 22:11 |
| fungi | and then got left in limbo for a decade | 22:11 |
| fungi | basically the folks in the ossg/osst who were responsible for the security guide and the ossn process initiated a move of ossn articles into the guide repo just before they all left for greener pastures | 22:13 |
| JayF | if anything, this project finally getting completed is proof that technical debt can be paid lol | 22:14 |
| fungi | the vmt mostly ignored the body of ossn articles and related process for many years after the osst dissolved and its remaining personal effects handed off to the security sig | 22:14 |
| fungi | hyakuhei and then gagehugo limped some of those efforts along under the auspices of the security sig until they eventually left too | 22:16 |
| fungi | i inherited chair of the security sig from gagehugo as essentially the "last man standing" | 22:16 |
| JayF | and I took on co-chair recently just to continue to reduce the list of "things only fungi is responsible for" lol | 22:17 |
| fungi | much appreciated! | 22:17 |
| JayF | as I've said before, I think the proper final state is Security SIG <merge> VMT | 22:17 |
| fungi | i was the security sig absentee slumlord basically | 22:17 |
| fungi | the title of chair had to hang on a neck and there was no other neck left | 22:18 |
| fungi | it's not like i really volunteered so much as i was the only one that didn't leave | 22:19 |
| gouthamr | am i on the sig? i don't even know :P but whatevs, call on me | 22:19 |
| fungi | yes, you're absolutely on the sig, i have decreed it | 22:19 |
| fungi | we never had any real way of identifying who was on the sig | 22:20 |
| fungi | it was "whoever showed up to things" | 22:20 |
| gouthamr | haha, that's true, besides the chairs, we don;t track SIG members anyway | 22:20 |
| fungi | i mean, in many ways that's the real selling feature of openstack's sig model over formal teams. show up and feel included | 22:21 |
| gouthamr | ++ | 22:23 |
| JayF | don't show up and make sig chair FeelsBadMan(tm) | 22:33 |
| * JayF has now read every OSSN ever filed against OpenStack | 22:34 | |
| fungi | that's lots more ossn articles than i've read, not kidding | 22:35 |
| JayF | I am not OK doing a migration like this in a lossy way | 22:35 |
| JayF | I should be, but it'd bother me too much if we missed something | 22:35 |
| * fungi is a notoriously slow reader | 22:35 | |
| JayF | again: that's not a positive attribute of me, it caused me to spend like 2 hours doing a thing that probably would've counted as Good Enough(tm) | 22:35 |
| fungi | i have definite ocd tendencies, so not going to throw any stones from my glass hovel | 22:36 |
| JayF | fungi: I'm the opposite; I read quickly. I just have a very weak memory so it's tough to recall. I've been known to read books multiple times when I need it to stick. I can probably get through a "normal size" novel in 3 or 4 hours if it's engaging | 22:36 |
| JayF | OSSNs are not engaging. lmao | 22:36 |
| fungi | great treatment for insomnia though | 22:37 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!