| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Add OSSN build pipeline for security-notes https://review.opendev.org/c/openstack/security-doc/+/998861 | 00:15 |
|---|---|---|
| opendevreview | Hao Wang proposed openstack/governance master: Seed security liaison data from VMT wiki https://review.opendev.org/c/openstack/governance/+/996563 | 00:36 |
| opendevreview | Merged openstack/election master: [Tool] update-governance: divide into tc/ptl/combined rounds https://review.opendev.org/c/openstack/election/+/978081 | 07:15 |
| opendevreview | Merged openstack/election master: [Tool] update_releases_calendar: fix one-week mismatch https://review.opendev.org/c/openstack/election/+/994774 | 07:15 |
| opendevreview | Matt Crees proposed openstack/governance master: Seed security liaison data from VMT wiki https://review.opendev.org/c/openstack/governance/+/996563 | 15:13 |
| gouthamr | tc-members: a gentle reminder that the weekly irc meeting will be hosted here in ~1 hour | 16:01 |
| gouthamr | agenda is here: https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee | 16:01 |
| gouthamr | #startmeeting tc | 17:01 |
| opendevmeet | Meeting started Tue Jul 28 17:01:22 2026 UTC and is due to finish in 60 minutes. The chair is gouthamr. Information about MeetBot at http://wiki.debian.org/MeetBot. | 17:01 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 17:01 |
| opendevmeet | The meeting name has been set to 'tc' | 17:01 |
| gouthamr | Welcome to the weekly meeting of the OpenStack Technical Committee. A reminder | 17:01 |
| gouthamr | that this meeting is held under the OpenInfra Code of Conduct available at | 17:01 |
| gouthamr | https://openinfra.dev/legal/code-of-conduct. | 17:01 |
| gouthamr | Today's meeting agenda can be found at | 17:01 |
| gouthamr | https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee | 17:01 |
| gouthamr | #topic Roll Call | 17:01 |
| frickler | \o | 17:01 |
| dansmith | o/ | 17:01 |
| jlarriba | o/ | 17:02 |
| jwysogla | o/ | 17:02 |
| bauzas | o/ | 17:02 |
| mnasiadka | o/ | 17:02 |
| mharley[m] | \o/ | 17:03 |
| spotz[m] | o/ | 17:03 |
| spotz[m] | Sorry was working on OpenInfra NA.... Please submit talks:) | 17:03 |
| gouthamr | haha, nice plug | 17:03 |
| gouthamr | courtesy-ping: cardoe noonedeadpunk | 17:04 |
| cardoe | sorry was in another channel | 17:04 |
| cardoe | o/ | 17:04 |
| gouthamr | let's get started | 17:05 |
| gouthamr | today's agenda is light, so we'll probably have plenty of time for open discussion, or maybe wrap up early | 17:05 |
| * gouthamr here's hoping | 17:05 | |
| gouthamr | #topic Last week's action items | 17:06 |
| gouthamr | we need to follow up on the "Core Reviewers as Active Contributors" proposal | 17:06 |
| gouthamr | frickler has posted an update to the change after the discussion here and comments on the charter change proposal | 17:06 |
| gouthamr | #link https://review.opendev.org/c/openstack/governance/+/995535 (Add reviewers as Active Contributors) | 17:07 |
| spotz[m] | I think frickler corrected the other part as part of his patch, I only glanced at it when it came in | 17:07 |
| gouthamr | the changes look good to me, but, there's no definition of a "core reviewer" in the charter so far | 17:08 |
| gouthamr | this is the first inclusion of it | 17:08 |
| gouthamr | maybe there's a formalization somewhere else? | 17:08 |
| frickler | I tried to make it implicit by stating the relevant votes | 17:08 |
| dansmith | the "has +/-2 or +W" seems as good a definition as any | 17:08 |
| dansmith | yeah, that | 17:08 |
| gouthamr | fungi: would you know? is this meant to have come down from OIF bylaws? or has it always been informally understood | 17:08 |
| spotz[m] | +1 | 17:09 |
| gouthamr | ack, i think the statement is correct.. but, it says "who are core reviewers and reviewed or approved one of the changes meeting the above criteria (with CR+2, CR-2 or W+1)" | 17:10 |
| gouthamr | it enhances what core reviewers should have done than explain what that role itself is.. | 17:10 |
| fungi | i left a similar -1 on the proposal just now | 17:10 |
| dansmith | well, it means core reviewers not doing any core reviewing don't get it right? | 17:10 |
| dansmith | maybe change it to "ACTIVE core reviewers, as defined by one of +2, -2, +W" | 17:11 |
| spotz[m] | Yes but I see Goutham's point, it doesn't talk about stewardship of the project under the PTL or DPL | 17:11 |
| dansmith | then you are defining what an _active_ core reviewer is, so the actual definition of core reviewer doesn't matter | 17:11 |
| fungi | "core reviewer" isn't something that's ever been formally defined anywhere i know of, and i've had all sorts of attempted implemnentations in the past (e.g. back in the days of the "core reviewer parties") to enumerate every account that has permissions to approve changes | 17:11 |
| bauzas | hah I miss those (parties) | 17:12 |
| spotz[m] | I became one after the parties stopped:( | 17:12 |
| fungi | when you take into consideration group inclusions in gerrit and groups that have permissions on different branches, it gets really hairy | 17:12 |
| fungi | for the bridging the gap data collection, we avoided using the term "core reviewer" entirely, opting for the less encumbered "active maintainer" | 17:13 |
| frickler | so "s/core //" ? we don't really need the core if we specify which votes we care for? | 17:13 |
| gouthamr | yes! | 17:13 |
| fungi | right, that was my suggestion in my review comment just now | 17:14 |
| gouthamr | i like that direction, and would settle my issue... we don't need to define that role and formalize it.. .we haven't for ~16 years :) | 17:14 |
| bauzas | so, only people having merge rights then ? (that's what I actually call 'maintainers' fwiw) | 17:14 |
| spotz[m] | +1 | 17:14 |
| fungi | drop the stipulation that they also be "core reviewers" (even "reviewers" is redundant since the definition talks specifically about review label votes) | 17:14 |
| spotz[m] | Yeah but we don't use the term maintainers | 17:14 |
| frickler | yeah, so "s/are core reviewers and //" is what I'd do now | 17:15 |
| fungi | agreed | 17:15 |
| spotz[m] | contributors who possess the ability to +2, -2, and +w a contribution | 17:15 |
| spotz[m] | maybe submission or patch to not have contribution twice | 17:15 |
| spotz[m] | or in gerrit | 17:16 |
| fungi | or don't say "contributors" since it's defining a class of contributors already | 17:16 |
| fungi | "inmdividuals" | 17:16 |
| frickler | well we want the "active" part, so it is not the ability, but the actual vote that counts | 17:16 |
| fungi | but typed more accurately than i seem to be able to manage ;) | 17:16 |
| spotz[m] | individuals works | 17:16 |
| gouthamr | when you quote a typo, you need a coffee | 17:16 |
| gouthamr | perfect, let's review this change when posted.. i still don't see any change to the direction | 17:17 |
| spotz[m] | frickler you want to do that change? | 17:17 |
| gouthamr | if there's one to flag, please do now, or early.. we're hoping to still merge this and have it take effect for the election season that begins in a week | 17:18 |
| gouthamr | (voting begins Aug 26, 2026) | 17:18 |
| opendevreview | Dr. Jens Harbott proposed openstack/governance master: Add reviewers as Active Contributors https://review.opendev.org/c/openstack/governance/+/995535 | 17:18 |
| frickler | there you go | 17:19 |
| gouthamr | great, ty frickler | 17:19 |
| gouthamr | let's move on to the next one | 17:20 |
| gouthamr | i guess noone dead punk is out today , so we'll table the barbican-ui check with him | 17:20 |
| gouthamr | fungi: cursive's transition was still on my tracker: https://github.com/openstack/cursive is 404 | 17:21 |
| gouthamr | will that get automatically rectified, or should someone need to look into it? | 17:21 |
| fungi | i'll check whether the job ran, i thought it normally went daily | 17:22 |
| gouthamr | thank you, no rush.. | 17:22 |
| gouthamr | the release team's still looking for any feedback on the 2027.1/Indri release schedule | 17:23 |
| gouthamr | #link https://review.opendev.org/c/openstack/releases/+/996808 (Indri release schedule) | 17:23 |
| gouthamr | #link https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_b3c/openstack/b3c99dee399c4fcc9f2707801576ad9d/docs/indri/schedule.html (render) | 17:23 |
| bauzas | oh shit I forgot | 17:23 |
| bauzas | I used to provide feedback but this year I went AWOL | 17:23 |
| bauzas | thanks for the reminder | 17:23 |
| gouthamr | the thing that stood out was the gap between M-2 and M-3, it's 4 weeks | 17:23 |
| bauzas | yeah usually my comments are about the cadence | 17:24 |
| gouthamr | so, i think project folk need to pay attention to it | 17:24 |
| bauzas | 4 weeks is a short timeframe but we're used to it usually every second cycled | 17:24 |
| gouthamr | bauzas: ack, see the discussion already on the patch.. there were issues moving things around this time | 17:24 |
| bauzas | ack I will (if I don't forget - fucking brain) | 17:25 |
| gouthamr | hey | 17:25 |
| gouthamr | i'm sorry but, https://openinfra.dev/legal/code-of-conduct | 17:25 |
| bauzas | ah sorry, pardon my french (lollylol) | 17:26 |
| gouthamr | the next thing on my action items was the TC visioning scatter-gather | 17:26 |
| gouthamr | this one is on all our plates, and mine to send over to the mailing list | 17:27 |
| gouthamr | but, i was kinda unsure on how to gather the feedback.. | 17:27 |
| gouthamr | any ideas? | 17:27 |
| gouthamr | should it be like a survey link that the TC can view/access? or should it be freeform - send it however you'd like, even on the ML if you want to | 17:28 |
| gouthamr | any preferences? if survey, i could probably bother fungi/oif/opendev folks because we've done some surveys in the past.. this would be as "light" as the contributor/maintainer surveys | 17:30 |
| fungi | i would recommend against having the foundation staff set up a survey for that, sounds like you could use something lightweight and free like limesurvey.org | 17:32 |
| fungi | since you only have, what, 9 people participating? | 17:33 |
| gouthamr | i would personally like more | 17:33 |
| gouthamr | i want people invested in the community to also have a voice in this.. not diluting the TC's voices, but, felt like even a few volunteers would express sentiments that the TC would appreciate having | 17:35 |
| spotz[m] | I will say the diversity survey was not heavily responded to last go round so I understand where fungi is coming from | 17:35 |
| fungi | ah, okay you had said something about gathering feedback from tc members, i didn't realize you meant the whole community | 17:36 |
| fungi | i misunderstood what you meant by "a survey link that the TC can view/access" | 17:36 |
| gouthamr | hoping we all see this as mandatory for TC members themselves :) | 17:37 |
| gouthamr | alright, looks like we spent some time on it.. let's move on to other things and table this for a post-meeting discussion if warranted | 17:39 |
| gouthamr | that's all the action items i was tracking, was anyone here working on something to note this week? | 17:39 |
| gouthamr | oh, all the DPL teams from last cycle voted to keep their DPL votes | 17:41 |
| gouthamr | an important thing is we merged DPL changes to release management and freezer during the process | 17:41 |
| gouthamr | i dropped oslo's proposal without stephenfin's vote on it - because i was aware he's away, and, he'd let us know if he'd not continue | 17:42 |
| gouthamr | and it's okay to spin up a patch to fix that | 17:42 |
| gouthamr | i also dropped the release management change with ttx in it, and the release folks chatted about this.. there's redundancy in the liaisons on that team | 17:43 |
| gouthamr | so if ttx were to be dropped, the team can adjust that at any time | 17:43 |
| gouthamr | that's all i had, got a couple of items for the open discussion if we have time | 17:43 |
| gouthamr | anything else for $topic? | 17:44 |
| gouthamr | #topic A check on gate health | 17:44 |
| gouthamr | anything to note wrt the gate this week? | 17:45 |
| bauzas | looked apparently good | 17:46 |
| bauzas | but we will have milestone-3 in a few weeks, so... :D | 17:47 |
| gouthamr | if not, i wanted to note a cool thing that the manila team's doing, motivated by virtiofs integration in concert with the nova team.. for a long time, the test jobs used heavy ubuntu based images to mount filesystems in scenario tests, we badly needed a CirrOS like image, and finally committed to bringing it to reality: | 17:48 |
| gouthamr | #link https://review.opendev.org/q/project:openstack/manila-test-image | 17:48 |
| gouthamr | just for CI, but, it cut down CI run times from ~2 hours to ~40 minutes - allowed us to increase parallelism, and stop wasting ci cycles by "recheck"-ing failures because SSH or spawning failed | 17:48 |
| gouthamr | the image is not for public consumption, but, ~16mb qcow2 replacing a 450mb qcow2 saves a lot of CI/opendev cycles/space for us.. | 17:50 |
| gouthamr | anything else regarding $topic? | 17:51 |
| gouthamr | #topic Open Discussion and Reviews | 17:52 |
| fungi | the earlier mention of the cursive repo not being created on github yet, i confirmed that the maintain-github-openstack-mirror job which should do that has been failing, and frickler reminded me that it was broken ever since the zuul key rotation back in january (the replacement seems to have been encoded incorrectly) | 17:54 |
| gouthamr | ah! | 17:54 |
| fungi | i'll see if i have access to an account with sufficient permissions to generate another one | 17:54 |
| gouthamr | ++ thank you fungi frickler | 17:54 |
| gouthamr | i invited jlarriba here to chat about the telemetry team.. the VMT has started seeing vulnerability reports filed against some telemetry projects, but, project contacts seemed out of date, and we were confused what is being tracked where | 17:54 |
| jlarriba | yeah, I was informed about this just yesterday and it is pretty concerning | 17:56 |
| gouthamr | jlarriba: there is no coresec team for "telemetry" on launchpad, and i'm not sure whether all projects are using launchpad, or some of them are on storyboard | 17:56 |
| gouthamr | we tried https://launchpad.net/~ceilometer-coresec/+members#active | 17:56 |
| gouthamr | but that's woefully out of date | 17:56 |
| jlarriba | it is indeed | 17:56 |
| jlarriba | so, all telemetry projects should be using launchpad | 17:56 |
| fungi | spot-checking our metadata for gerrit projects, at least ceilometer and aodh do correctly indicate they're using launchpad for defect tracking | 17:57 |
| fungi | so maybe some spring cleaning on the lp side is in order | 17:57 |
| gouthamr | i see! good clarification, ty.. | 17:57 |
| fungi | the easy way to check is to go to e.g. https://opendev.org/openstack/aodh and see where the "issues" link at the top takes you | 17:58 |
| gouthamr | openstack-admins owns that coresec group, so with my TC hat, we can ask fungi to add you jlarriba, and you can clean up the group and see who else to add | 17:58 |
| gouthamr | i'm using https://github.com/openstack/governance/blob/7fb733a503d59ca976c3cc552866174ddb8582a7/reference/projects.yaml#L2494-L2522 as the list of official repos | 17:58 |
| jlarriba | indeed, if you add me i will add the correct members for the team | 17:58 |
| jlarriba | but maybe the team needs to be renamed to "telemetry-coresec" and be applied to all telemetry projects? | 17:59 |
| gouthamr | that would be helpful | 17:59 |
| fungi | done | 17:59 |
| fungi | as far as adding you, i mean | 17:59 |
| fungi | (i also made you an administrator) | 17:59 |
| jlarriba | fungi thanks | 17:59 |
| fungi | any time! | 18:00 |
| gouthamr | awesome, glad to have your attention on it | 18:00 |
| jlarriba | so, I understand that all telemetry-related security embargoed issues should be visible to the members of this group | 18:00 |
| fungi | yes | 18:00 |
| jlarriba | but how do we get that list? | 18:00 |
| gouthamr | yes, so keep the group small (i.e., a subset of your core reviewers) and keep it active (i.e., add/remove folks often as the team's dynamics change) | 18:01 |
| jlarriba | its just the ones in the "bugs" section? | 18:01 |
| fungi | advanced search in the bugs view and select the "private security" bug type if you only want to see those | 18:01 |
| fungi | otherwise they'll just be mixed in with the project's normal bugs if you're logged into an account with permission to see them | 18:02 |
| jlarriba | ack | 18:02 |
| gouthamr | perfect, we're over the meeting time | 18:02 |
| gouthamr | is there anything to mention for the minutes today? | 18:02 |
| mharley[m] | Hey, gouthamr. | 18:03 |
| spotz[m] | Submit talks to OpenInfra NA and volunteer to review! | 18:04 |
| mharley[m] | Time to talk about that subject? | 18:04 |
| gouthamr | mharley[m]: i suppose you wanted to chat about PQC, i didn't see a topic on the wiki.. please note, i try to freeze the agenda <24 hours before the meeting and let the community know on the openstack-discuss mailing list | 18:05 |
| spotz[m] | https://sessionize.com/OpenInfra2026/ and https://forms.gle/bwdPJVfZaB4s1JFb6 | 18:05 |
| gouthamr | any late topics can be added to Open Discussion, but, we don't get there sometimes, due to lack of time | 18:05 |
| gouthamr | mharley[m]: so, please do add your topics to the agenda now for next week | 18:05 |
| gouthamr | spotz[m]: ty for that call out! | 18:05 |
| mharley[m] | Absolutely. | 18:05 |
| gouthamr | alright, let's wrap it up here.. thank you all for participating! | 18:05 |
| gouthamr | #endmeeting | 18:06 |
| opendevmeet | Meeting ended Tue Jul 28 18:06:01 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 18:06 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.html | 18:06 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.txt | 18:06 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/tc/2026/tc.2026-07-28-17.01.log.html | 18:06 |
| gouthamr | mharley[m]: i've updated https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee#Next_Meeting ; feel free to edit | 18:06 |
| * bauzas leaves now as fried as a fish | 18:06 | |
| mharley[m] | Great. Will do. Thank you, gouthamr. | 18:22 |
| gouthamr | ++ | 19:28 |
| *** Unknown is now known as Mike-- | 20:16 | |
| opendevreview | Goutham Pacha Ravi proposed openstack/governance master: Seed security liaison data from VMT wiki https://review.opendev.org/c/openstack/governance/+/996563 | 20:39 |
| gouthamr | tc-members: ^ the security liaisons change has been moving along.. lots of involvement over the month that it's been active.. i think we can merge what we have and start using this data formally | 20:41 |
| gouthamr | there are 14 teams where i haven't had a response yet.. but, i can follow up with them on the ML now, or in direct pings rather than waiting | 20:44 |
| spotz[m] | +1 | 21:01 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!