| gouthamr | https://bugs.launchpad.net/aodh/+bug/2161276 is now public | 14:06 |
|---|---|---|
| gouthamr | https://bugs.launchpad.net/watcher/+bug/2161771 is now public | 14:06 |
| tkajinam | thanks | 14:08 |
| tkajinam | the fix and its backports are proposed in gerrit https://review.opendev.org/q/topic:%22bug/2161276%22 | 14:08 |
| mrunge | looking | 14:09 |
| gouthamr | tkajinam, ty for pushing the patches.. will wait for dviroel to do the same and upload the ossa | 14:09 |
| mrunge | should I +W the patches directly? | 14:12 |
| tkajinam | let's wait until CI reports the result. I can vote +W from my end. | 14:13 |
| fungi | https://bugs.launchpad.net/mistral/+bug/1785632 is now public | 14:13 |
| tkajinam | sounds like a busy day | 14:14 |
| dviroel | gouthamr: patches for watcher sent | 14:14 |
| gouthamr | ty dviroel | 14:15 |
| gouthamr | fungi: ty for responding to amorin on https://bugs.launchpad.net/mistral/+bug/1785632! i woke up to some messages :) | 14:15 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/1001521 | 14:58 |
| fungi | gouthamr: minor nit on that, could always be fixed later if you like too | 15:13 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/1001521 | 15:31 |
| fungi | gouthamr: i can't tell if you're also waiting for feedback from aodh/watcher folks but i need to step away from the computer for maybe 30 minutes at this point, so feel free to self-approve 1001521 whenever you're ready if i'm not back before then | 15:33 |
| fungi | i'll try to be quick | 15:33 |
| gouthamr | hey fungi; i was :) | 15:35 |
| gouthamr | tkajinam: dviroel: can you please take a look and check for accuracy ^ | 15:36 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/1001521 | 15:53 |
| gouthamr | sean-k-mooney suggested a fix ^ | 15:53 |
| opendevreview | Merged openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/1001521 | 16:04 |
| fungi | okay i'm back | 16:14 |
| * gouthamr 's surreptitious reign just ended | 16:15 | |
| * gouthamr emails sent, updating MITRE | 16:19 | |
| fungi | openstack-announce copy accepted | 16:20 |
| gouthamr | Tyty fungi | 16:30 |
| fungi | of course! sorry i had to disappear there for a bit | 16:31 |
| gouthamr | i got wu_wenxiang to submit a nomination, but, d'oh he hasn't updated his foundation membership | 16:39 |
| gouthamr | argh | 16:39 |
| gouthamr | wrong channel? sigh | 16:39 |
| tkajinam | hmm it likely takes a few more hours until all the bug fixes land. I'll check these tomorrow morning and propose new releases if these are merged then | 16:49 |
| * mrunge is here too, I'll also take a peek | 16:49 | |
| fungi | obviously the sooner they merge, the better, but it's typical for that to take hours (or even occasionally days) until all backports are landed and point releases tagged | 16:53 |
| fungi | so definitely don't let it get in the way of sleep and other activities | 16:54 |
| gouthamr | yeah, you're on top of things, and thanks for that tkajinam! | 16:55 |
| gouthamr | i'd generally nudge teams to ship releases days/sometimes weeks after the patches all land :( | 16:55 |
| fungi | the main caveat is don't make new releases *until* the fixes merge to the corresponding branches, otherwise we have to correct the affected version ranges in the advisory | 16:56 |
| gouthamr | ++ | 16:58 |
| gouthamr | PSA: we're aware of https://docs.ceph.com/en/latest/security/CVE-2025-30156/ | 17:04 |
| gouthamr | and three other advisories published by Ceph today: | 17:04 |
| gouthamr | https://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj | 17:04 |
| gouthamr | https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2 | 17:04 |
| gouthamr | https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h | 17:04 |
| gouthamr | We're working on an OpenStack Security Note with more detail on how this affects OpenStack and what specific steps operators can take. | 17:04 |
| gouthamr | in the meantime, the advisory details are captured here: https://docs.ceph.com/en/latest/security/cves/#past-vulnerabilities | 17:05 |
| gouthamr | and https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released/ | 17:05 |
| JayF | RFR https://review.opendev.org/c/openstack/ossa/+/1000735 and feel free to +A if onboard, I'll announce it today | 17:53 |
| JayF | fungi: gouthamr: ^ you have a moment to help me land the errata? | 19:14 |
| gouthamr | yes! | 19:14 |
| gouthamr | gtg | 19:15 |
| fungi | is the errata date there correct? | 19:15 |
| gouthamr | oops | 19:16 |
| JayF | updating real quick | 19:16 |
| gouthamr | ++ | 19:17 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression https://review.opendev.org/c/openstack/ossa/+/1000735 | 19:18 |
| fungi | JayF: oh, looking at the preview render you may also want to move the errata parentheticals for the changes | 19:18 |
| fungi | though maybe not as easy as it sounds | 19:18 |
| fungi | comparing the yaml to the rendered html | 19:18 |
| fungi | it's not incorrect, probably not worth the trouble of trying to orient it better | 19:19 |
| JayF | let me look | 19:20 |
| fungi | https://2589fbd4db650504153e-d3d57836e2611e65f8d99a9aeb37f4da.ssl.cf5.rackcdn.com/openstack/1f4ac5e176a54e31a659bc3c2a8dfb9c/docs/ossa/OSSA-2026-008.html | 19:20 |
| JayF | I had a previous errata that I got a good formatting for | 19:20 |
| fungi | yeah, if we have a particular way that renders better hopefully we can standardize (or maybe we need to tweak the sphinx plugin a little) | 19:21 |
| JayF | I think it was **errata 2** https://.... | 19:21 |
| JayF | trying that locally real quick | 19:22 |
| gouthamr | that looks different from how we did: https://security.openstack.org/ossa/OSSA-2023-003 | 19:23 |
| gouthamr | sry https://security.openstack.org/ossa/OSSA-2021-002 | 19:23 |
| gouthamr | your current approach is matching that ^, no? | 19:24 |
| fungi | yeah, we've not been consustent, there's been 3 or 4 different ways we flagged them | 19:24 |
| fungi | er, consisten | 19:24 |
| fungi | t | 19:24 |
| fungi | my typing is almost gone for today | 19:24 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression https://review.opendev.org/c/openstack/ossa/+/1000735 | 19:25 |
| JayF | source is uglier, rendering is better | 19:26 |
| fungi | https://security.openstack.org/ossa/OSSA-2016-007.html is another way we've done them | 19:26 |
| JayF | from my local build https://usercontent.irccloud-cdn.com/file/9LjvIYPW/image.png | 19:26 |
| JayF | ooh, marking the originals as well is a++ | 19:26 |
| JayF | I kinda wanna merge the approaches; keep the bolded errata 2 from my change, and also add a bolded (original) | 19:26 |
| fungi | wfm | 19:26 |
| JayF | better, I think? https://usercontent.irccloud-cdn.com/file/QRcS3vTg/image.png | 19:27 |
| gouthamr | neat | 19:28 |
| gouthamr | enshrine this in the template please | 19:28 |
| fungi | we could design a schema that covers project+branch+errata+other and then retrofit all the old advisories to it, but probably not worth the strife | 19:28 |
| gouthamr | +1 | 19:28 |
| JayF | the better answer: stop needing erratas lol | 19:28 |
| fungi | example lgtm | 19:28 |
| JayF | or more apt, stop needing PATCHES in erratas | 19:28 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression https://review.opendev.org/c/openstack/ossa/+/1000735 | 19:28 |
| gouthamr | eh? you bringe a sledgehammer to a scalpel fight | 19:29 |
| JayF | I *am* the sledgehammer | 19:29 |
| fungi | just want to hear you say "trust me, i know what i'm doing" | 19:30 |
| JayF | gouthamr: we have no ossa template | 19:30 |
| JayF | gouthamr: which you'd think I'd have known without just going now to go edit it lol | 19:30 |
| * JayF +As 2026-008 | 19:31 | |
| gouthamr | this one: https://security.openstack.org/vmt-process.html#openstack-security-advisories-ossa | 19:31 |
| JayF | OK; I think the answer will be to file an RFE to split that into a template.yaml or something and enhance it | 19:32 |
| JayF | I'm not doing it now | 19:32 |
| gouthamr | no all good.. we're the only users of such a template for now | 19:33 |
| JayF | "we" is a brave statement | 19:33 |
| fungi | "oui" | 19:33 |
| JayF | the OSSA template is cp OSSA-last-one-done.yaml OSSA-next-number.yaml | 19:33 |
| JayF | lol | 19:33 |
| JayF | https://bugs.launchpad.net/ossa/+bug/2164578 | 19:35 |
| JayF | low-hanging-fruit should someone have some desire to fix it | 19:36 |
| gouthamr | good idea | 19:36 |
| JayF | gouthamr: real talk: if we care about whitespace in ossa yaml files, we need to encode that in lint | 19:36 |
| JayF | like, I'm not saying your comment is wrong, no whitespace is better, but humans enforcing programatic style is basically turning us all into grammar school teachers lol | 19:37 |
| fungi | agreed, i saw it when reviewing but didn't flag it because it's cosmetic and would be yet another iteration | 19:37 |
| JayF | (I'm not qualified for such a glorious position) | 19:37 |
| JayF | OSSA-2026-008 announced, ty for the help | 19:39 |
| fungi | accepted to openstack-announce just now | 19:40 |
| gouthamr | i agree with all of that | 19:40 |
| opendevreview | Merged openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression https://review.opendev.org/c/openstack/ossa/+/1000735 | 19:41 |
| *** mrunge_ is now known as mrunge | 23:29 | |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add pre-commit to enforce whitespace hygiene https://review.opendev.org/c/openstack/ossa/+/1001584 | 23:33 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!