Tuesday, 2026-07-28

opendevreviewSofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes  https://review.opendev.org/c/openstack/security-doc/+/99886100:15
opendevreviewHao Wang proposed openstack/governance master: Seed security liaison data from VMT wiki  https://review.opendev.org/c/openstack/governance/+/99656300:36
opendevreviewMerged openstack/election master: [Tool] update-governance: divide into tc/ptl/combined rounds  https://review.opendev.org/c/openstack/election/+/97808107:15
opendevreviewMerged openstack/election master: [Tool] update_releases_calendar: fix one-week mismatch  https://review.opendev.org/c/openstack/election/+/99477407:15
opendevreviewMatt Crees proposed openstack/governance master: Seed security liaison data from VMT wiki  https://review.opendev.org/c/openstack/governance/+/99656315:13
gouthamrtc-members: a gentle reminder that the weekly irc meeting will be hosted here in ~1 hour16:01
gouthamragenda is here: https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee16:01
gouthamr#startmeeting tc17:01
opendevmeetMeeting started Tue Jul 28 17:01:22 2026 UTC and is due to finish in 60 minutes.  The chair is gouthamr. Information about MeetBot at http://wiki.debian.org/MeetBot.17:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.17:01
opendevmeetThe meeting name has been set to 'tc'17:01
gouthamrWelcome to the weekly meeting of the OpenStack Technical Committee. A reminder17:01
gouthamrthat this meeting is held under the OpenInfra Code of Conduct available at17:01
gouthamrhttps://openinfra.dev/legal/code-of-conduct.17:01
gouthamrToday's meeting agenda can be found at17:01
gouthamrhttps://wiki.openstack.org/wiki/Meetings/TechnicalCommittee17:01
gouthamr#topic Roll Call17:01
frickler\o17:01
dansmitho/17:01
jlarribao/17:02
jwysoglao/17:02
bauzaso/17:02
mnasiadkao/17:02
mharley[m]\o/17:03
spotz[m]o/17:03
spotz[m]Sorry was working on OpenInfra NA.... Please submit talks:)17:03
gouthamrhaha, nice plug17:03
gouthamrcourtesy-ping: cardoe noonedeadpunk17:04
cardoesorry was in another channel17:04
cardoeo/17:04
gouthamrlet's get started17:05
gouthamrtoday's agenda is light, so we'll probably have plenty of time for open discussion, or maybe wrap up early17:05
* gouthamr here's hoping17:05
gouthamr#topic Last week's action items17:06
gouthamrwe need to follow up on the "Core Reviewers as Active Contributors" proposal17:06
gouthamrfrickler has posted an update to the change after the discussion here and comments on the charter change proposal17:06
gouthamr#link https://review.opendev.org/c/openstack/governance/+/995535 (Add reviewers as Active Contributors)17:07
spotz[m]I think frickler corrected the other part as part of his patch, I only glanced at it when it came in17:07
gouthamrthe changes look good to me, but, there's no definition of a "core reviewer" in the charter so far17:08
gouthamrthis is the first inclusion of it17:08
gouthamrmaybe there's a formalization somewhere else?17:08
fricklerI tried to make it implicit by stating the relevant votes17:08
dansmiththe "has +/-2 or +W" seems as good a definition as any17:08
dansmithyeah, that17:08
gouthamrfungi: would you know? is this meant to have come down from OIF bylaws? or has it always been informally understood17:08
spotz[m]+117:09
gouthamrack, i think the statement is correct.. but, it says "who are core reviewers and reviewed or approved one of the changes meeting the above criteria (with CR+2, CR-2 or W+1)"17:10
gouthamrit enhances what core reviewers should have done than explain what that role itself is.. 17:10
fungii left a similar -1 on the proposal just now17:10
dansmithwell, it means core reviewers not doing any core reviewing don't get it right?17:10
dansmithmaybe change it to "ACTIVE core reviewers, as defined by one of +2, -2, +W"17:11
spotz[m]Yes but I see Goutham's point, it doesn't talk about stewardship of the project under the PTL or DPL17:11
dansmiththen you are defining what an _active_ core reviewer is, so the actual definition of core reviewer doesn't matter17:11
fungi"core reviewer" isn't something that's ever been formally defined anywhere i know of, and i've had all sorts of attempted implemnentations in the past (e.g. back in the days of the "core reviewer parties") to enumerate every account that has permissions to approve changes17:11
bauzashah I miss those (parties)17:12
spotz[m]I became one after the parties stopped:(17:12
fungiwhen you take into consideration group inclusions in gerrit and groups that have permissions on different branches, it gets really hairy17:12
fungifor the bridging the gap data collection, we avoided using the term "core reviewer" entirely, opting for the less encumbered "active maintainer"17:13
fricklerso "s/core //" ? we don't really need the core if we specify which votes we care for?17:13
gouthamryes!17:13
fungiright, that was my suggestion in my review comment just now17:14
gouthamri like that direction, and would settle my issue... we don't need to define that role and formalize it.. .we haven't for ~16 years :) 17:14
bauzasso, only people having merge rights then ? (that's what I actually call 'maintainers' fwiw)17:14
spotz[m]+117:14
fungidrop the stipulation that they also be "core reviewers" (even "reviewers" is redundant since the definition talks specifically about review label votes)17:14
spotz[m]Yeah but we don't use the term maintainers17:14
frickleryeah, so "s/are core reviewers and //" is what I'd do now17:15
fungiagreed17:15
spotz[m]contributors who possess the ability to +2, -2, and +w a contribution17:15
spotz[m]maybe submission or patch to not have contribution twice17:15
spotz[m]or in gerrit17:16
fungior don't say "contributors" since it's defining a class of contributors already17:16
fungi"inmdividuals"17:16
fricklerwell we want the "active" part, so it is not the ability, but the actual vote that counts17:16
fungibut typed more accurately than i seem to be able to manage ;)17:16
spotz[m]individuals works17:16
gouthamrwhen you quote a typo, you need a coffee17:16
gouthamrperfect, let's review this change when posted.. i still don't see any change to the direction17:17
spotz[m]frickler you want to do that change?17:17
gouthamrif there's one to flag, please do now, or early.. we're hoping to still merge this and have it take effect for the election season that begins in a week17:18
gouthamr(voting begins Aug 26, 2026)17:18
opendevreviewDr. Jens Harbott proposed openstack/governance master: Add reviewers as Active Contributors  https://review.opendev.org/c/openstack/governance/+/99553517:18
fricklerthere you go17:19
gouthamrgreat, ty frickler 17:19
gouthamrlet's move on to the next one17:20
gouthamri guess noone dead punk is out today , so we'll table the barbican-ui check with him17:20
gouthamrfungi: cursive's transition was still on my tracker: https://github.com/openstack/cursive is 404 17:21
gouthamrwill that get automatically rectified, or should someone need to look into it?17:21
fungii'll check whether the job ran, i thought it normally went daily17:22
gouthamrthank you, no rush.. 17:22
gouthamrthe release team's still looking for any feedback on the 2027.1/Indri release schedule17:23
gouthamr#link https://review.opendev.org/c/openstack/releases/+/996808 (Indri release schedule)17:23
gouthamr#link https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_b3c/openstack/b3c99dee399c4fcc9f2707801576ad9d/docs/indri/schedule.html (render)17:23
bauzasoh shit I forgot17:23
bauzasI used to provide feedback but this year I went AWOL17:23
bauzasthanks for the reminder17:23
gouthamrthe thing that stood out was the gap between M-2 and M-3, it's 4 weeks17:23
bauzasyeah usually my comments are about the cadence17:24
gouthamrso, i think project folk need to pay attention to it17:24
bauzas4 weeks is a short timeframe but we're used to it usually every second cycled17:24
gouthamrbauzas: ack, see the discussion already on the patch.. there were issues moving things around this time17:24
bauzasack I will (if I don't forget - fucking brain) 17:25
gouthamrhey17:25
gouthamri'm sorry but, https://openinfra.dev/legal/code-of-conduct 17:25
bauzasah sorry, pardon my french (lollylol)17:26
gouthamrthe next thing on my action items was the TC visioning scatter-gather 17:26
gouthamrthis one is on all our plates, and mine to send over to the mailing list17:27
gouthamrbut, i was kinda unsure on how to gather the feedback.. 17:27
gouthamrany ideas?17:27
gouthamrshould it be like a survey link that the TC can view/access? or should it be freeform - send it however you'd like, even on the ML if you want to17:28
gouthamrany preferences? if survey, i could probably bother fungi/oif/opendev folks because we've done some surveys in the past.. this would be as "light" as the contributor/maintainer surveys17:30
fungii would recommend against having the foundation staff set up a survey for that, sounds like you could use something lightweight and free like limesurvey.org17:32
fungisince you only have, what, 9 people participating?17:33
gouthamri would personally like more17:33
gouthamri want people invested in the community to also have a voice in this.. not diluting the TC's voices, but, felt like even a few volunteers would express sentiments that the TC would appreciate having17:35
spotz[m]I will say the diversity survey was not heavily responded to last go round so I understand where fungi is coming from17:35
fungiah, okay you had said something about gathering feedback from tc members, i didn't realize you meant the whole community17:36
fungii misunderstood what you meant by "a survey link that the TC can view/access"17:36
gouthamrhoping we all see this as mandatory for TC members themselves :) 17:37
gouthamralright, looks like we spent some time on it.. let's move on to other things and table this for a post-meeting discussion if warranted17:39
gouthamrthat's all the action items i was tracking, was anyone here working on something to note this week?17:39
gouthamroh, all the DPL teams from last cycle voted to keep their DPL votes17:41
gouthamran important thing is we merged DPL changes to release management and freezer during the process17:41
gouthamri dropped oslo's proposal without stephenfin's vote on it - because i was aware he's away, and, he'd let us know if he'd not continue17:42
gouthamrand it's okay to spin up a patch to fix that17:42
gouthamri also dropped the release management change with ttx in it, and the release folks chatted about this.. there's redundancy in the liaisons on that team17:43
gouthamrso if ttx were to be dropped, the team can adjust that at any time17:43
gouthamrthat's all i had, got a couple of items for the open discussion if we have time17:43
gouthamranything else for $topic?17:44
gouthamr#topic A check on gate health17:44
gouthamranything to note wrt the gate this week?17:45
bauzaslooked apparently good17:46
bauzasbut we will have milestone-3 in a few weeks, so... :D17:47
gouthamrif not, i wanted to note a cool thing that the manila team's doing, motivated by virtiofs integration in concert with the nova team.. for a long time, the test jobs used heavy ubuntu based images to mount filesystems in scenario tests, we badly needed a CirrOS like image, and finally committed to bringing it to reality:17:48
gouthamr#link https://review.opendev.org/q/project:openstack/manila-test-image17:48
gouthamrjust for CI, but, it cut down CI run times from ~2 hours to ~40 minutes - allowed us to increase parallelism, and stop wasting ci cycles by "recheck"-ing failures because SSH or spawning failed17:48
gouthamrthe image is not for public consumption, but, ~16mb qcow2 replacing a 450mb qcow2 saves a lot of CI/opendev cycles/space for us.. 17:50
gouthamranything else regarding $topic?17:51
gouthamr#topic Open Discussion and Reviews17:52
fungithe earlier mention of the cursive repo not being created on github yet, i confirmed that the maintain-github-openstack-mirror job which should do that has been failing, and frickler reminded me that it was broken ever since the zuul key rotation back in january (the replacement seems to have been encoded incorrectly)17:54
gouthamrah!17:54
fungii'll see if i have access to an account with sufficient permissions to generate another one17:54
gouthamr++ thank you fungi frickler 17:54
gouthamri invited jlarriba here to chat about the telemetry team.. the VMT has started seeing vulnerability reports filed against some telemetry projects, but, project contacts seemed out of date, and we were confused what is being tracked where17:54
jlarribayeah, I was informed about this just yesterday and it is pretty concerning17:56
gouthamrjlarriba: there is no coresec team for "telemetry" on launchpad, and i'm not sure whether all projects are using launchpad, or some of them are on storyboard17:56
gouthamrwe tried https://launchpad.net/~ceilometer-coresec/+members#active17:56
gouthamrbut that's woefully out of date17:56
jlarribait is indeed17:56
jlarribaso, all telemetry projects should be using launchpad17:56
fungispot-checking our metadata for gerrit projects, at least ceilometer and aodh do correctly indicate they're using launchpad for defect tracking17:57
fungiso maybe some spring cleaning on the lp side is in order17:57
gouthamri see! good clarification, ty.. 17:57
fungithe easy way to check is to go to e.g. https://opendev.org/openstack/aodh and see where the "issues" link at the top takes you17:58
gouthamropenstack-admins owns that coresec group, so with my TC hat, we can ask fungi to add you jlarriba, and you can clean up the group and see who else to add17:58
gouthamri'm using https://github.com/openstack/governance/blob/7fb733a503d59ca976c3cc552866174ddb8582a7/reference/projects.yaml#L2494-L2522 as the list of official repos17:58
jlarribaindeed, if you add me i will add the correct members for the team17:58
jlarribabut maybe the team needs to be renamed to "telemetry-coresec" and be applied to all telemetry projects?17:59
gouthamrthat would be helpful17:59
fungidone17:59
fungias far as adding you, i mean17:59
fungi(i also made you an administrator)17:59
jlarribafungi thanks17:59
fungiany time!18:00
gouthamrawesome, glad to have your attention on it18:00
jlarribaso, I understand that all telemetry-related security embargoed issues should be visible to the members of this group18:00
fungiyes18:00
jlarribabut how do we get that list?18:00
gouthamryes, so keep the group small (i.e., a subset of your core reviewers) and keep it active (i.e., add/remove folks often as the team's dynamics change)18:01
jlarribaits just the ones in the "bugs" section?18:01
fungiadvanced search in the bugs view and select the "private security" bug type if you only want to see those18:01
fungiotherwise they'll just be mixed in with the project's normal bugs if you're logged into an account with permission to see them18:02
jlarribaack18:02
gouthamrperfect, we're over the meeting time18:02
gouthamris there anything to mention for the minutes today?18:02
mharley[m]Hey, gouthamr. 18:03
spotz[m]Submit talks to OpenInfra NA and volunteer to review!18:04
mharley[m]Time to talk about that subject?18:04
gouthamrmharley[m]: i suppose you wanted to chat about PQC, i didn't see a topic on the wiki.. please note, i try to freeze the agenda <24 hours before the meeting and let the community know on the openstack-discuss mailing list18:05
spotz[m]https://sessionize.com/OpenInfra2026/ and https://forms.gle/bwdPJVfZaB4s1JFb618:05
gouthamrany late topics can be added to Open Discussion, but, we don't get there sometimes, due to lack of time18:05
gouthamrmharley[m]: so, please do add your topics to the agenda now for next week18:05
gouthamrspotz[m]: ty for that call out!18:05
mharley[m]Absolutely.18:05
gouthamralright, let's wrap it up here.. thank you all for participating!18:05
gouthamr#endmeeting18:06
opendevmeetMeeting ended Tue Jul 28 18:06:01 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)18:06
opendevmeetMinutes:        https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.html18:06
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.txt18:06
opendevmeetLog:            https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.log.html18:06
gouthamrmharley[m]: i've updated https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee#Next_Meeting ; feel free to edit18:06
* bauzas leaves now as fried as a fish 18:06
mharley[m]Great. Will do. Thank you, gouthamr. 18:22
gouthamr++19:28
*** Unknown is now known as Mike--20:16
opendevreviewGoutham Pacha Ravi proposed openstack/governance master: Seed security liaison data from VMT wiki  https://review.opendev.org/c/openstack/governance/+/99656320:39
gouthamrtc-members: ^ the security liaisons change has been moving along.. lots of involvement over the month that it's been active.. i think we can merge what we have and start using this data formally20:41
gouthamrthere are 14 teams where i haven't had a response yet.. but, i can follow up with them on the ML now, or in direct pings rather than waiting20:44
spotz[m]+121:01

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!