Wednesday, 2026-08-19

gouthamrhttps://bugs.launchpad.net/aodh/+bug/2161276 is now public14:06
gouthamrhttps://bugs.launchpad.net/watcher/+bug/2161771 is now public14:06
tkajinamthanks14:08
tkajinamthe fix and its backports are proposed in gerrit https://review.opendev.org/q/topic:%22bug/2161276%2214:08
mrungelooking14:09
gouthamrtkajinam, ty for pushing the patches.. will wait for dviroel to do the same and upload the ossa14:09
mrungeshould I +W the patches directly?14:12
tkajinamlet's wait until CI reports the result. I can vote +W from my end.14:13
fungihttps://bugs.launchpad.net/mistral/+bug/1785632 is now public14:13
tkajinamsounds like a busy day14:14
dviroelgouthamr: patches for watcher sent14:14
gouthamrty dviroel 14:15
gouthamrfungi: ty for responding to amorin on https://bugs.launchpad.net/mistral/+bug/1785632! i woke up to some messages :) 14:15
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/100152114:58
fungigouthamr: minor nit on that, could always be fixed later if you like too15:13
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/100152115:31
fungigouthamr: i can't tell if you're also waiting for feedback from aodh/watcher folks but i need to step away from the computer for maybe 30 minutes at this point, so feel free to self-approve 1001521 whenever you're ready if i'm not back before then15:33
fungii'll try to be quick15:33
gouthamrhey fungi; i was :) 15:35
gouthamrtkajinam: dviroel: can you please take a look and check for accuracy ^15:36
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/100152115:53
gouthamrsean-k-mooney suggested a fix ^ 15:53
opendevreviewMerged openstack/ossa master: Add OSSA-2026-036 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/100152116:04
fungiokay i'm back16:14
* gouthamr 's surreptitious reign just ended16:15
* gouthamr emails sent, updating MITRE16:19
fungiopenstack-announce copy accepted16:20
gouthamrTyty fungi16:30
fungiof course! sorry i had to disappear there for a bit16:31
gouthamri got wu_wenxiang to submit a nomination, but, d'oh he hasn't updated his foundation membership16:39
gouthamrargh16:39
gouthamrwrong channel? sigh16:39
tkajinamhmm it likely takes a few more hours until all the bug fixes land. I'll check these tomorrow morning and propose new releases if these are merged then16:49
* mrunge is here too, I'll also take a peek16:49
fungiobviously the sooner they merge, the better, but it's typical for that to take hours (or even occasionally days) until all backports are landed and point releases tagged16:53
fungiso definitely don't let it get in the way of sleep and other activities16:54
gouthamryeah, you're on top of things, and thanks for that tkajinam!16:55
gouthamri'd generally nudge teams to ship releases days/sometimes weeks after the patches all land :( 16:55
fungithe main caveat is don't make new releases *until* the fixes merge to the corresponding branches, otherwise we have to correct the affected version ranges in the advisory16:56
gouthamr++16:58
gouthamrPSA: we're aware of https://docs.ceph.com/en/latest/security/CVE-2025-30156/17:04
gouthamrand three other advisories published by Ceph today: 17:04
gouthamrhttps://github.com/ceph/ceph/security/advisories/GHSA-rmjq-ffrm-j6vj17:04
gouthamrhttps://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq217:04
gouthamrhttps://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h17:04
gouthamrWe're working on an OpenStack Security Note with more detail on how this affects OpenStack and what specific steps operators can take. 17:04
gouthamrin the meantime, the advisory details are captured here: https://docs.ceph.com/en/latest/security/cves/#past-vulnerabilities17:05
gouthamrand https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released/17:05
JayFRFR https://review.opendev.org/c/openstack/ossa/+/1000735 and feel free to +A if onboard, I'll announce it today17:53
JayFfungi: gouthamr: ^ you have a moment to help me land the errata?19:14
gouthamryes!19:14
gouthamrgtg19:15
fungiis the errata date there correct?19:15
gouthamroops19:16
JayFupdating real quick19:16
gouthamr++19:17
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073519:18
fungiJayF: oh, looking at the preview render you may also want to move the errata parentheticals for the changes19:18
fungithough maybe not as easy as it sounds19:18
fungicomparing the yaml to the rendered html19:18
fungiit's not incorrect, probably not worth the trouble of trying to orient it better19:19
JayFlet me look19:20
fungihttps://2589fbd4db650504153e-d3d57836e2611e65f8d99a9aeb37f4da.ssl.cf5.rackcdn.com/openstack/1f4ac5e176a54e31a659bc3c2a8dfb9c/docs/ossa/OSSA-2026-008.html19:20
JayFI had a previous errata that I got a good formatting for19:20
fungiyeah, if we have a particular way that renders better hopefully we can standardize (or maybe we need to tweak the sphinx plugin a little)19:21
JayFI think it was **errata 2** https://....19:21
JayFtrying that locally real quick19:22
gouthamrthat looks different from how we did: https://security.openstack.org/ossa/OSSA-2023-00319:23
gouthamrsry https://security.openstack.org/ossa/OSSA-2021-00219:23
gouthamryour current approach is matching that ^, no?19:24
fungiyeah, we've not been consustent, there's been 3 or 4 different ways we flagged them19:24
fungier, consisten19:24
fungit19:24
fungimy typing is almost gone for today19:24
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073519:25
JayFsource is uglier, rendering is better19:26
fungihttps://security.openstack.org/ossa/OSSA-2016-007.html is another way we've done them19:26
JayFfrom my local build https://usercontent.irccloud-cdn.com/file/9LjvIYPW/image.png19:26
JayFooh, marking the originals as well is a++19:26
JayFI kinda wanna merge the approaches; keep the bolded errata 2 from my change, and also add a bolded (original)19:26
fungiwfm19:26
JayFbetter, I think? https://usercontent.irccloud-cdn.com/file/QRcS3vTg/image.png19:27
gouthamrneat19:28
gouthamrenshrine this in the template please19:28
fungiwe could design a schema that covers project+branch+errata+other and then retrofit all the old advisories to it, but probably not worth the strife19:28
gouthamr+119:28
JayFthe better answer: stop needing erratas lol19:28
fungiexample lgtm19:28
JayFor more apt, stop needing PATCHES in erratas19:28
opendevreviewJay Faulkner proposed openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073519:28
gouthamreh? you bringe a sledgehammer to a scalpel fight19:29
JayFI *am* the sledgehammer19:29
fungijust want to hear you say "trust me, i know what i'm doing"19:30
JayFgouthamr: we have no ossa template19:30
JayFgouthamr: which you'd think I'd have known without just going now to go edit it lol19:30
* JayF +As 2026-00819:31
gouthamrthis one: https://security.openstack.org/vmt-process.html#openstack-security-advisories-ossa19:31
JayFOK; I think the answer will be to file an RFE to split that into a template.yaml or something and enhance it19:32
JayFI'm not doing it now19:32
gouthamrno all good.. we're the only users of such a template for now19:33
JayF"we" is a brave statement19:33
fungi"oui"19:33
JayFthe OSSA template is cp OSSA-last-one-done.yaml OSSA-next-number.yaml19:33
JayFlol19:33
JayFhttps://bugs.launchpad.net/ossa/+bug/216457819:35
JayFlow-hanging-fruit should someone have some desire to fix it19:36
gouthamrgood idea19:36
JayFgouthamr: real talk: if we care about whitespace in ossa yaml files, we need to encode that in lint19:36
JayFlike, I'm not saying your comment is wrong, no whitespace is better, but humans enforcing programatic style is basically turning us all into grammar school teachers lol19:37
fungiagreed, i saw it when reviewing but didn't flag it because it's cosmetic and would be yet another iteration19:37
JayF(I'm not qualified for such a glorious position)19:37
JayFOSSA-2026-008 announced, ty for the help19:39
fungiaccepted to openstack-announce just now19:40
gouthamri agree with all of that19:40
opendevreviewMerged openstack/ossa master: OSSA-2026-008: Errata 2 - socat console regression  https://review.opendev.org/c/openstack/ossa/+/100073519:41
*** mrunge_ is now known as mrunge23:29
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add pre-commit to enforce whitespace hygiene  https://review.opendev.org/c/openstack/ossa/+/100158423:33

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!