Thursday, 2024-03-07

fungii pinged them both in irc to hopefully get eyes on that fairly quickly00:07
JayFthanks00:08
* JayF &00:08
*** gthiemon1e is now known as gthiemonge13:36
*** hberaud_ is now known as hberaud13:52
opendevreviewElod Illes proposed openstack/openstack-manuals master: [www] Set Xena, Wallaby and Victoria state as Unmaintained  https://review.opendev.org/c/openstack/openstack-manuals/+/91186114:56
dansmithfungi: yeah makes sense to get them to weigh in as well. are those projects under the VMT?15:06
fungidansmith: heat is, but it looks like maybe the fix needs to happen in a dependency which isn't, discussion continuing in the bug15:08
dansmithack, catching up15:09
fungialso we still haven't heard back from one of the potentially impacted projects (either in the bug or to my irc /msg to the ptl)15:17
dansmithokay, we can proceed with the murano warning though yeah?15:17
fricklerfungi: can you share which project? maybe someone has some other contact15:19
fungifrickler: i guess it can't hurt at this point... mistral15:20
dansmithyeah JayF already exfil'd heat earlier I guess :)15:21
fricklerfungi: hmm, good luck with that, I've still to get feedback from avanzaghi regarding some release patches, too ;-/15:21
fungidansmith: i think what we proceed with depends on whether we need to keep the bug private long enough to give the other projects a chance to fix it if the impact in them is severe (if they decide it's not severe then we can stick to the previously discussed schedule)15:22
dansmithfungi: okay and/or if we need to add mistral to the early warning15:22
fungialso if the fix happens in the dependency it may solve it for all affected projects15:22
dansmithyeah we probably need someone to decide if that applies to others or not though15:23
dansmithjust because it's used in one place of the project doesn't mean every such usage is covered I imagine15:23
JayFfungi: being able to say that requires someone who is expert enough in murano to say so strongly15:23
dansmithand every arrangement or scenario15:23
dansmithJayF: you mean mistral right?15:23
fungiJayF: agreed. basically, i'm hesitant to set a disclosure date of next thursday if there are other projects also impacted (badly enough that we want to not reveal the underlying cause yet) who are actually going to work on a fix15:24
JayFI mean "if the fix happens in the dependency it may solve for all affected projects" <--- as long as we have a person who knows enough about that project to feel confident about that15:24
dansmithI think JayF said or eluded to it before, but what we're seeing here is an excellent example of why we shouldn't let abandoned projects hang around past their expiration date15:25
fungiso i do think the guidance to disable/remove murano from deployments is still a good idea, it's more a question of when do we want to plan to make the details of why public, and i think we don't have enough information just yet to decide15:28
dansmithfungi: we could make that warning without a hard date of when the disclosure is going to happen right?15:28
dansmithsooner rather than later for the murano people can only benefit the situation IMHO15:28
fungiyes, we could say "at a later date" or something15:29
JayF++15:30
fungiJayF: dansmith: rosmaita: revised draft removing the specific disclosure date: https://wiki.openstack.org/wiki/OSSN/OSSN-009315:48
fungii'll be afk for the next two hours, but can make whatever additional edits you want and/or send it once i'm back at the keyboard15:49
JayF+115:49
rosmaitafungi: ack15:49
dansmithyeah seems okay to me15:50
rosmaitafungi: sorry, was in a meeting, LGTM16:17
-opendevstatus- NOTICE: Jobs that fail due to being unable to resolve mirror.dfw.rackspace.opendev.org can be rechecked. This error was an unexpected side effect of some nodepool configuration changes which have been reverted.16:55
fungilast call for comments on https://wiki.openstack.org/wiki/OSSN/OSSN-0093 before i add it to the ossn index and send copies to openstack-announce, openstack-discuss, and oss-security@lists.openwall.com (our usual notification destinations) at 20:00 utc today (about an hour from now)18:57
dansmithfungi: did I miss it?21:38
fungidansmith: no, haven't sent it yet but will shortly21:46
fungidid you have any last-minute edits?21:46
dansmithnope21:46
fungiokay, cool21:46
fungisent to openstack-announce, openstack-discuss, and oss-security@lists.openwall.com22:45
fungialso the ossn index in the wiki has been updated to link to it22:45
fungiif anyone wants to link to it elsewhere: https://lists.openstack.org/archives/list/openstack-announce@lists.openstack.org/thread/4FYM6GSIM5WZSJQIG4TT5Q3UBKQIHLWX/22:47
spotz[m]Thanks fungi 22:52

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!