*** diurnalist has joined #openstack-meeting | 00:01 | |
*** rfolco|rover has joined #openstack-meeting | 00:05 | |
*** dmacpher_ has quit IRC | 00:06 | |
*** jamesmcarthur has joined #openstack-meeting | 00:10 | |
*** dmacpher has joined #openstack-meeting | 00:20 | |
*** mlavalle has quit IRC | 00:23 | |
*** jamesmcarthur has quit IRC | 00:24 | |
*** dmacpher has quit IRC | 00:27 | |
*** dmacpher has joined #openstack-meeting | 00:29 | |
*** dmacpher_ has joined #openstack-meeting | 00:37 | |
*** dmacpher has quit IRC | 00:39 | |
*** rfolco|rover has quit IRC | 00:47 | |
*** jamesmcarthur has joined #openstack-meeting | 00:58 | |
*** jamesmcarthur has quit IRC | 01:00 | |
*** jamesmcarthur has joined #openstack-meeting | 01:14 | |
*** jmasud has joined #openstack-meeting | 01:21 | |
*** Liang__ has joined #openstack-meeting | 01:21 | |
*** Liang__ is now known as LiangFang | 01:21 | |
*** rfolco|rover has joined #openstack-meeting | 01:23 | |
*** jmasud has quit IRC | 01:36 | |
*** jamesmcarthur has quit IRC | 01:43 | |
*** jamesmcarthur has joined #openstack-meeting | 02:00 | |
*** jmasud has joined #openstack-meeting | 02:00 | |
*** markmcclain has quit IRC | 02:01 | |
*** yamamoto has joined #openstack-meeting | 02:01 | |
*** markmcclain has joined #openstack-meeting | 02:02 | |
*** tinwood has quit IRC | 02:08 | |
*** tinwood has joined #openstack-meeting | 02:10 | |
*** yamamoto has quit IRC | 02:26 | |
*** yamamoto has joined #openstack-meeting | 02:27 | |
*** yamamoto has quit IRC | 02:27 | |
*** yamamoto has joined #openstack-meeting | 02:27 | |
*** apetrich has quit IRC | 02:41 | |
*** zhuxiaoyu_inspur has quit IRC | 02:43 | |
*** rcernin has quit IRC | 02:48 | |
*** Lucas_Gray has quit IRC | 02:55 | |
*** rcernin has joined #openstack-meeting | 02:59 | |
*** rcernin has quit IRC | 03:05 | |
*** armax has quit IRC | 03:17 | |
*** rcernin has joined #openstack-meeting | 03:21 | |
*** rcernin has quit IRC | 03:22 | |
*** rcernin has joined #openstack-meeting | 03:22 | |
*** manuvakery has joined #openstack-meeting | 03:27 | |
*** ravsingh has joined #openstack-meeting | 03:30 | |
*** psachin has joined #openstack-meeting | 03:37 | |
*** diablo_rojo has quit IRC | 03:41 | |
*** yamamoto has quit IRC | 03:41 | |
*** jmasud has quit IRC | 03:43 | |
*** yamamoto has joined #openstack-meeting | 03:49 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-meeting | 04:33 | |
*** jamesmcarthur has quit IRC | 04:52 | |
*** jamesmcarthur has joined #openstack-meeting | 04:52 | |
*** jamesmcarthur has quit IRC | 04:58 | |
*** jmasud has joined #openstack-meeting | 05:04 | |
*** ociuhandu has joined #openstack-meeting | 05:21 | |
*** ociuhandu has quit IRC | 05:26 | |
*** jamesmcarthur has joined #openstack-meeting | 05:26 | |
*** jamesmcarthur has quit IRC | 05:38 | |
*** links has joined #openstack-meeting | 05:46 | |
*** markvoelker has joined #openstack-meeting | 05:51 | |
*** markvoelker has quit IRC | 05:55 | |
*** links has quit IRC | 06:07 | |
*** links has joined #openstack-meeting | 06:12 | |
*** maciejjozefczyk has joined #openstack-meeting | 06:22 | |
*** links has quit IRC | 06:32 | |
*** rpittau|afk is now known as rpittau | 06:43 | |
*** dklyle has quit IRC | 06:44 | |
*** links has joined #openstack-meeting | 07:01 | |
*** apetrich has joined #openstack-meeting | 07:04 | |
*** ttsiouts has joined #openstack-meeting | 07:06 | |
*** slaweq has joined #openstack-meeting | 07:07 | |
*** jmasud has quit IRC | 07:15 | |
*** ttsiouts has quit IRC | 07:19 | |
*** ttsiouts has joined #openstack-meeting | 07:19 | |
*** maciejjozefczyk has quit IRC | 07:19 | |
*** ralonsoh has joined #openstack-meeting | 07:21 | |
*** LiangFang has quit IRC | 07:31 | |
*** Liang__ has joined #openstack-meeting | 07:34 | |
*** maciejjozefczyk has joined #openstack-meeting | 07:37 | |
*** Liang__ has quit IRC | 07:44 | |
*** Liang__ has joined #openstack-meeting | 07:46 | |
*** rcernin has quit IRC | 07:54 | |
*** ttsiouts has quit IRC | 07:54 | |
*** rcernin_ has joined #openstack-meeting | 07:55 | |
*** ttsiouts has joined #openstack-meeting | 07:58 | |
*** links has quit IRC | 08:00 | |
*** diurnalist has quit IRC | 08:03 | |
*** links has joined #openstack-meeting | 08:10 | |
*** Lucas_Gray has joined #openstack-meeting | 08:12 | |
*** ttsiouts has quit IRC | 08:12 | |
*** ttsiouts has joined #openstack-meeting | 08:13 | |
*** ttsiouts_ has joined #openstack-meeting | 08:16 | |
*** ttsiouts has quit IRC | 08:17 | |
*** e0ne has joined #openstack-meeting | 08:20 | |
*** ravsingh has quit IRC | 08:20 | |
*** rcernin_ has quit IRC | 08:20 | |
*** ravsingh has joined #openstack-meeting | 08:33 | |
*** ttsiouts has joined #openstack-meeting | 08:36 | |
*** ttsiout__ has joined #openstack-meeting | 08:37 | |
*** ttsiouts_ has quit IRC | 08:40 | |
*** ttsiouts has quit IRC | 08:41 | |
*** yamamoto has quit IRC | 08:42 | |
*** yamamoto has joined #openstack-meeting | 08:42 | |
*** ociuhandu has joined #openstack-meeting | 08:42 | |
*** jmasud has joined #openstack-meeting | 08:54 | |
*** manuvakery has quit IRC | 09:00 | |
*** jawad_axd has joined #openstack-meeting | 09:09 | |
*** yamamoto has quit IRC | 09:12 | |
*** yamamoto has joined #openstack-meeting | 09:13 | |
*** yamamoto has quit IRC | 09:13 | |
*** vishalmanchanda has joined #openstack-meeting | 09:17 | |
*** yamamoto has joined #openstack-meeting | 09:23 | |
*** yaawang_ has quit IRC | 09:24 | |
*** jmasud has quit IRC | 09:25 | |
*** links has quit IRC | 09:27 | |
*** links has joined #openstack-meeting | 09:28 | |
*** ttsiouts has joined #openstack-meeting | 09:32 | |
*** ttsiout__ has quit IRC | 09:32 | |
*** jamesmcarthur has joined #openstack-meeting | 09:35 | |
*** yamamoto has quit IRC | 09:40 | |
*** yaawang_ has joined #openstack-meeting | 09:41 | |
*** jamesmcarthur has quit IRC | 09:49 | |
*** ociuhandu has quit IRC | 09:52 | |
*** ociuhandu has joined #openstack-meeting | 09:59 | |
*** diurnalist has joined #openstack-meeting | 10:00 | |
*** rpittau is now known as rpittau|bbl | 10:06 | |
*** e0ne has quit IRC | 10:11 | |
*** e0ne has joined #openstack-meeting | 10:13 | |
*** yamamoto has joined #openstack-meeting | 10:14 | |
*** Liang__ has quit IRC | 10:18 | |
*** yamamoto has quit IRC | 10:20 | |
*** yamamoto has joined #openstack-meeting | 10:20 | |
*** ravsingh has quit IRC | 10:32 | |
*** manuvakery has joined #openstack-meeting | 10:34 | |
*** yamamoto has quit IRC | 10:43 | |
*** yamamoto has joined #openstack-meeting | 10:44 | |
*** yamamoto has quit IRC | 10:44 | |
*** yamamoto has joined #openstack-meeting | 10:48 | |
*** rcernin_ has joined #openstack-meeting | 10:48 | |
*** yamamoto has quit IRC | 10:53 | |
*** yamamoto has joined #openstack-meeting | 10:54 | |
*** yamamoto has quit IRC | 10:59 | |
*** yamamoto has joined #openstack-meeting | 11:16 | |
*** yamamoto has quit IRC | 11:20 | |
*** markvoelker has joined #openstack-meeting | 11:24 | |
*** markvoelker has quit IRC | 11:29 | |
*** belmoreira has joined #openstack-meeting | 11:32 | |
*** yamamoto has joined #openstack-meeting | 11:34 | |
*** ociuhandu has quit IRC | 11:50 | |
*** raildo has joined #openstack-meeting | 11:50 | |
*** ttsiouts has quit IRC | 12:06 | |
*** thgcorrea has joined #openstack-meeting | 12:07 | |
*** ttsiouts has joined #openstack-meeting | 12:07 | |
*** ttsiouts has quit IRC | 12:11 | |
*** yamamoto has quit IRC | 12:12 | |
*** dmacpher_ has quit IRC | 12:17 | |
*** dmacpher_ has joined #openstack-meeting | 12:17 | |
*** rpittau|bbl is now known as rpittau | 12:20 | |
*** ttsiouts has joined #openstack-meeting | 12:28 | |
*** rh-jelabarre has joined #openstack-meeting | 12:28 | |
*** ttsiouts has quit IRC | 12:47 | |
*** jawad_axd has quit IRC | 12:47 | |
*** ttsiouts has joined #openstack-meeting | 12:47 | |
*** bbowen_ has quit IRC | 12:49 | |
*** bbowen_ has joined #openstack-meeting | 12:49 | |
*** ttsiouts has quit IRC | 12:52 | |
*** ttsiouts has joined #openstack-meeting | 12:54 | |
*** seba has joined #openstack-meeting | 13:05 | |
*** ttsiouts has quit IRC | 13:18 | |
*** ttsiouts has joined #openstack-meeting | 13:19 | |
*** psachin has quit IRC | 13:20 | |
*** ttsiouts has quit IRC | 13:23 | |
*** ttsiouts has joined #openstack-meeting | 13:26 | |
*** armax has joined #openstack-meeting | 13:27 | |
*** yamamoto has joined #openstack-meeting | 13:28 | |
*** sluna has quit IRC | 13:30 | |
*** sluna has joined #openstack-meeting | 13:30 | |
*** yamamoto has quit IRC | 13:34 | |
*** TrevorV has joined #openstack-meeting | 13:36 | |
*** jamesmcarthur has joined #openstack-meeting | 13:46 | |
*** jamesmcarthur has quit IRC | 13:51 | |
*** jokke_ has joined #openstack-meeting | 13:58 | |
*** rosmaita has joined #openstack-meeting | 14:00 | |
*** dklyle has joined #openstack-meeting | 14:00 | |
*** jamesmcarthur has joined #openstack-meeting | 14:00 | |
abhishekk | #startmeeting glance | 14:01 |
---|---|---|
openstack | Meeting started Thu Jun 18 14:01:06 2020 UTC and is due to finish in 60 minutes. The chair is abhishekk. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
abhishekk | #topic roll call | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: glance)" | 14:01 | |
openstack | The meeting name has been set to 'glance' | 14:01 |
*** openstack changes topic to "roll call (Meeting topic: glance)" | 14:01 | |
abhishekk | #link https://etherpad.openstack.org/p/glance-team-meeting-agenda | 14:01 |
abhishekk | o/ | 14:01 |
rosmaita | o/ | 14:01 |
jokke_ | o/ | 14:01 |
*** rfolco|rover is now known as rfolco | 14:01 | |
*** e0ne_ has joined #openstack-meeting | 14:01 | |
abhishekk | short agenda today | 14:01 |
*** e0ne has quit IRC | 14:01 | |
abhishekk | lets start | 14:01 |
abhishekk | #topic release/periodic jobs update | 14:01 |
*** openstack changes topic to "release/periodic jobs update (Meeting topic: glance)" | 14:01 | |
abhishekk | V1 milestone this week | 14:02 |
abhishekk | We don't have anything merged so should we skip this milestone release? | 14:02 |
rosmaita | +1 | 14:02 |
jokke_ | ++ no need for it | 14:02 |
abhishekk | or we should release glance as we have modified the registry code? | 14:02 |
abhishekk | same goes with store and python-glanceclient as well | 14:03 |
jokke_ | shouldn't make any difference | 14:03 |
rosmaita | i think sean has a patch up for the glanceclient release | 14:03 |
abhishekk | oh, will have a look and comment on it | 14:04 |
jokke_ | milestone releases are not needed anymore and even tags are cheap, I see no reason fot doing it just for the sake of it | 14:04 |
abhishekk | +1 | 14:04 |
abhishekk | cool, so lets skip this one and focus on milestone 2 | 14:04 |
abhishekk | In next meeting we will finalized M2 priorities | 14:05 |
abhishekk | s/finalized/finalize | 14:05 |
abhishekk | Regarding periodic job, 1 functional-py36 job is failing | 14:06 |
abhishekk | I spent little time to analyze the failure | 14:06 |
abhishekk | One functional test regarding revert logic is failing due to race condition | 14:06 |
abhishekk | I will spend some time in next week to rectify it | 14:07 |
jokke_ | humm | 14:07 |
jokke_ | interesting | 14:07 |
abhishekk | As I am the one who has written that test :D | 14:07 |
rosmaita | :P | 14:07 |
jokke_ | :D | 14:07 |
abhishekk | will ping jokke_ if something is needed | 14:08 |
* jokke_ ducks | 14:08 | |
abhishekk | :P | 14:08 |
* rosmaita laughs | 14:08 | |
abhishekk | moving ahead | 14:08 |
abhishekk | #topic devstack registry | 14:08 |
*** openstack changes topic to "devstack registry (Meeting topic: glance)" | 14:08 | |
abhishekk | registry removal devstack patch merged \o/ | 14:08 |
jokke_ | \\o \o/ o// o/7 | 14:09 |
abhishekk | thanks to jokke_ for the glance patch and dansmith for taking it ahead with devstack team | 14:09 |
jokke_ | I will continue with the cleanup proper | 14:09 |
smcginnis | Yay, finally. | 14:10 |
abhishekk | awesome, thank you | 14:10 |
abhishekk | this means we have one less config file as well :D | 14:10 |
abhishekk | yes, smcginnis thanks for your push as well | 14:10 |
abhishekk | Lets move ahead, | 14:11 |
abhishekk | #topic Specs review | 14:11 |
*** openstack changes topic to "Specs review (Meeting topic: glance)" | 14:11 | |
abhishekk | We need to get on top of this | 14:11 |
abhishekk | Because our milestone 2 is dependent on these reviews | 14:11 |
abhishekk | sparse image upload - https://review.opendev.org/733157 | 14:11 |
abhishekk | Unified limits - https://review.opendev.org/729187 | 14:11 |
abhishekk | Image encryption - https://review.opendev.org/609667 | 14:11 |
abhishekk | Cinder store multiple stores support - https://review.opendev.org/695152 | 14:11 |
rosmaita | sorry, i started reviewing the sparse file upload and got sidetracked looking at sparse files | 14:12 |
abhishekk | These are some specs with top priorities which needs reviews | 14:12 |
* smcginnis gets some tabs open | 14:12 | |
abhishekk | rosmaita, no worries, eye from you and smcginnis will be additional benefit for us | 14:13 |
rosmaita | ok, i will wait for the author to revise that spec as you requested | 14:13 |
abhishekk | then there is one new spec related to duplicate downloads which will be good to have reviews as well | 14:13 |
jokke_ | About that, I had very fruitful discussion with one of the Ceph devs last week this timeslot | 14:14 |
rosmaita | re sparse upload: my thought is that the title is misleading, the action as i understand it would take place after the full image has been staged | 14:14 |
*** rcernin_ has quit IRC | 14:14 | |
abhishekk | that should be sparse image import? | 14:15 |
jokke_ | Really feel like I understand the the traffic much better. | 14:15 |
abhishekk | jokke_, what was your discussion | 14:15 |
jokke_ | Sparse upload is when glance is uploading not when client is | 14:15 |
jokke_ | So i think the topic is accurate, if it was glanceclient spec it would point to the step before :P | 14:16 |
abhishekk | you had discussion with ceph devs related to sparse upload? | 14:17 |
* abhishekk am I disconnected? | 14:18 | |
jokke_ | But yeah so there is couple of ways we can do the sparse upload and save the bandwidth. If the admin wants to fat provision the image but not send all the zeros over the wire, we can do something like buffered write again. Which sends, say 4kB, sample over the wire and then just tells ceph to write that 200k times. Or we can do thin provisioned images by seeking ahead and writing only the data. | 14:18 |
jokke_ | abhishekk: nope, can see you | 14:18 |
abhishekk | ack | 14:18 |
jokke_ | I think we should look both, and have the thin provisioning on/off configurable | 14:19 |
*** masahito has joined #openstack-meeting | 14:20 | |
abhishekk | sounds good to me | 14:20 |
abhishekk | what about filestore? | 14:20 |
jokke_ | So rather than having the config option we talked about in the PTG to turn sparse writes on or off, just flick which way we do the write into ceph | 14:20 |
abhishekk | his proposal talks about both rbd and filestore sparse upload support | 14:21 |
jokke_ | I think same applies, we can call the config option "thin provisioned" and use the sparse writing there | 14:21 |
abhishekk | ok | 14:21 |
abhishekk | could you please add this suggestion on specs, we should get it rolling | 14:22 |
jokke_ | I think the biggest change is really if admin wants to thin provision or not | 14:22 |
jokke_ | sure | 14:22 |
jokke_ | will do that | 14:22 |
abhishekk | thanks | 14:22 |
jokke_ | Had quite a bit clarifications and more understanding/good pointers of other things as well how radoslib handles the I/O | 14:23 |
abhishekk | cool | 14:23 |
jokke_ | but we can discuss them separately | 14:24 |
abhishekk | yes | 14:24 |
jokke_ | I'll try to get bit of a refactring spec together | 14:24 |
abhishekk | that will be great | 14:24 |
abhishekk | I am working on cinder multiple store support PoC | 14:25 |
jokke_ | Nice | 14:26 |
abhishekk | Ok, please spend some time in specs review this week | 14:28 |
abhishekk | Moving in to Open discussion now | 14:28 |
jokke_ | yup, will do | 14:28 |
abhishekk | #topic Open discussion | 14:28 |
*** openstack changes topic to "Open discussion (Meeting topic: glance)" | 14:28 | |
*** hyunsikyang has quit IRC | 14:28 | |
jokke_ | Just couple of quick things around the rbd so I have also note recorded. | 14:28 |
abhishekk | I have uploaded our PTG recordings on google drive and shared link of those in PTG etherpad | 14:29 |
jokke_ | thanks abhishekk!!! | 14:29 |
*** rajivmucheli has joined #openstack-meeting | 14:30 | |
abhishekk | #link https://etherpad.opendev.org/p/glance-victoria-ptg | 14:30 |
*** ttsiouts has quit IRC | 14:30 | |
*** mlavalle has joined #openstack-meeting | 14:30 | |
jokke_ | So first of all, multithreading per se is not a thing. What people are referring with that is async writes. Now my biggest fear of eating all the sockets is happening already. While the rbd client instance is running it maintains the sockets for all the OSDs it accesses with timeout of 900sec | 14:31 |
*** ttsiouts has joined #openstack-meeting | 14:31 | |
abhishekk | oh | 14:32 |
jokke_ | For our usage pattern it also does not make sense to start pooling those rbd clients as main conern there is how long time the auth and handshakes takes, but as we're not dealing with thousands of small objects. it's actually not relevant for our usage pattern and we would need to maintain that pool | 14:32 |
jokke_ | We could have pool of async write slots we could scale based on how many concurrent transfers we have ongoing. That would lessen the impact of high latency links | 14:33 |
abhishekk | that would be big change imo | 14:34 |
jokke_ | but I think the biggest performance improvements we can achieve is by changing the way we write zeros to either that buffered rewrite or sparse seek and by changing how we allocate the size when we don't know image size we're writing | 14:34 |
jokke_ | advice I got was to take the same approach as the ceph client is doing in such situation and just double th size every time resize is needed and trim at the end | 14:35 |
*** rajivmucheli has quit IRC | 14:35 | |
jokke_ | totally safe | 14:35 |
abhishekk | the same we decided earlier for chunks upload? | 14:36 |
*** masahito has quit IRC | 14:36 | |
*** ttsiouts has quit IRC | 14:36 | |
jokke_ | abhishekk: so instead of growing the size by 1GB, the advice was just double the size. So start like 100MB, then 200, 400, 800 ... etc | 14:37 |
abhishekk | ack, got it now | 14:38 |
jokke_ | but conceptually the same idea, just don't worry reserving too much and trim when finished | 14:38 |
abhishekk | so this will be part of rbd refactor | 14:38 |
jokke_ | yep | 14:38 |
jokke_ | small change, should be super easy to do actually | 14:39 |
jokke_ | I might just do it as bugfix before looking into the more risky things | 14:39 |
*** jiaopengju1 has quit IRC | 14:39 | |
abhishekk | cool, I think it will be good if its that much easy as it sounds :D | 14:40 |
jokke_ | yup | 14:40 |
*** jiaopengju1 has joined #openstack-meeting | 14:40 | |
abhishekk | great, So we need to take out multiple rbd thing from our priorities | 14:40 |
jokke_ | much more cofortable doing any changes there now when I know how it actually works and happy to share with anyone interested | 14:41 |
abhishekk | ME | 14:41 |
jokke_ | :) | 14:41 |
abhishekk | we will take this down in next week :D | 14:41 |
jokke_ | that's all from me. Just wanted to share a quick recap so we have it recorded somewhere :D | 14:42 |
abhishekk | thanks | 14:42 |
abhishekk | anything else guys? | 14:42 |
abhishekk | cool, lets wrap up early | 14:43 |
abhishekk | thank you all | 14:43 |
jokke_ | Thanks all! | 14:43 |
abhishekk | have a nice weekend | 14:44 |
abhishekk | #endmeeting | 14:44 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:44 | |
openstack | Meeting ended Thu Jun 18 14:44:09 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:44 |
jokke_ | You too, get better soon budyd | 14:44 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-06-18-14.01.html | 14:44 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-06-18-14.01.txt | 14:44 |
openstack | Log: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-06-18-14.01.log.html | 14:44 |
abhishekk | jokke_, ack, thank you | 14:44 |
*** ttsiouts has joined #openstack-meeting | 14:46 | |
*** ociuhandu has joined #openstack-meeting | 14:50 | |
*** ociuhandu has quit IRC | 14:55 | |
*** andrebeltrami has joined #openstack-meeting | 14:56 | |
gagehugo | #startmeeting security | 15:00 |
openstack | Meeting started Thu Jun 18 15:00:19 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:00 |
*** openstack changes topic to " (Meeting topic: security)" | 15:00 | |
openstack | The meeting name has been set to 'security' | 15:00 |
*** armstrong has joined #openstack-meeting | 15:00 | |
gagehugo | #link https://etherpad.opendev.org/p/security-agenda agenda | 15:00 |
gagehugo | o/ | 15:00 |
*** Luzi has joined #openstack-meeting | 15:01 | |
rosmaita | o/ | 15:02 |
rosmaita | (i have something for open discussion) | 15:03 |
fungi | aloha, y'all | 15:03 |
Luzi | o/ | 15:03 |
gagehugo | #topic follow-up from last week | 15:03 |
*** openstack changes topic to "follow-up from last week (Meeting topic: security)" | 15:03 | |
gagehugo | fungi: I'll reach out to the docs core about adding people for the security-docs today | 15:03 |
*** e0ne has joined #openstack-meeting | 15:04 | |
gagehugo | been pre-occupied this week unfortunately | 15:04 |
*** jamesmcarthur has quit IRC | 15:04 | |
gagehugo | also will attempt to send out a meeting poll for a new meeting time | 15:04 |
*** e0ne_ has quit IRC | 15:04 | |
fungi | sounds great | 15:04 |
gagehugo | that's all I had | 15:05 |
*** mlavalle has quit IRC | 15:05 | |
gagehugo | #topic open discussion | 15:05 |
*** openstack changes topic to "open discussion (Meeting topic: security)" | 15:05 | |
fungi | it's been a quiet week for security bugs too (so far, hope i don't jinx us) | 15:05 |
gagehugo | rosmaita: o/ | 15:05 |
rosmaita | jinx | 15:05 |
* fungi glares at rosmaita | 15:05 | |
rosmaita | ok, this is about ossn-0086 | 15:05 |
rosmaita | https://review.opendev.org/#/q/Ie2db587c3bc379acd53cfd449788d171ae58dec5 | 15:05 |
rosmaita | so, it turns out when you run the os-brick part of the fix under py2.7, it breaks | 15:05 |
fungi | that's probably not so helpful | 15:06 |
rosmaita | so doesn't apply to u or master | 15:06 |
fungi | "breaks" as in fails open or fails secure (just doesn't work at all) | 15:06 |
fungi | ? | 15:06 |
rosmaita | just doesn't work | 15:06 |
rosmaita | so i guess it also doesn't leak info | 15:07 |
*** ttsiouts has quit IRC | 15:07 | |
gagehugo | hmm | 15:07 |
fungi | doesn't work to fix the vulnerability, or renders the driver inoperable? | 15:07 |
*** ttsiouts has joined #openstack-meeting | 15:07 | |
rosmaita | thinking | 15:07 |
rosmaita | i guess just makes it inoperable | 15:08 |
*** diurnalist has quit IRC | 15:08 | |
rosmaita | the cinder side will no longer pass the password to brick | 15:08 |
rosmaita | and brick is unable to get it out of the config file | 15:08 |
fungi | okay, so basically anyone who applied this fix on older releases under python 2 broke their deployments, but it didn't continue to leave them vulnerable to the identified security risk at least | 15:08 |
*** ttsiouts has quit IRC | 15:09 | |
rosmaita | yeah ... though in reality, it broke staging and they didn't update production | 15:09 |
*** mlavalle has joined #openstack-meeting | 15:09 | |
fungi | (so they most likely knowingly backed out the fix, and are aware they're running a vulnerable configuration) | 15:09 |
rosmaita | which would still be vulnerable | 15:09 |
*** ttsiouts has joined #openstack-meeting | 15:09 | |
rosmaita | what fungi said | 15:09 |
fungi | still, far better than having them think they're safe when they're still vulnerable | 15:10 |
rosmaita | so, what i have to do is: get the brick fixes merged, release new brick version, get u-c updated, update cinder requirements, release new cinder | 15:10 |
fungi | sounds right. and then update the ossn and probably send out an errata announcement | 15:10 |
rosmaita | for the EM branches ... rocky gate is hosed ATM, so fix to rocky brick has not merged, and has not been backported to queens | 15:11 |
rosmaita | yeah, that was my plan, update the OSSN as soon as stuff is available | 15:11 |
fungi | those branches also won't get point releases anyway, so it's fine to just point to the patches in review i guess | 15:11 |
rosmaita | ok | 15:11 |
fungi | so long as you're fairly confident they're correct | 15:12 |
rosmaita | well, i added tests to catch this particular problem | 15:12 |
fungi | i mean, for security advisories we always reference teh patches in review (for the sake of expediency) | 15:12 |
rosmaita | the issue is that we rely on the vendor third-party CI for validation | 15:12 |
rosmaita | and we requested that they all run py3 in their CI | 15:13 |
fungi | right, driver patching for proprietary stuff is an imperfect process | 15:13 |
*** armstrong has quit IRC | 15:13 | |
fungi | i mean, they wouldn't be able to test master with python 2 at this point anyway | 15:14 |
rosmaita | so, i guess we do have some validation that this works with py27, from the bug reporter | 15:14 |
fungi | i would consider that "probably good enough" | 15:14 |
*** ttsiouts has quit IRC | 15:14 | |
rosmaita | :) | 15:14 |
rosmaita | ok, i will talk to smcginnis about allowing the queens patch to be posted before rocky merges | 15:15 |
rosmaita | (he really hates that) | 15:15 |
rosmaita | but that will allow me to get the OSSN updated and an announcement out to the ML | 15:15 |
fungi | somebody's gotta troll him, might as well be you | 15:15 |
rosmaita | just wanted to give y'all a heads-up | 15:15 |
fungi | thanks for the detailed explanation! | 15:16 |
*** mlavalle has quit IRC | 15:16 | |
fungi | feel free to reach out if you need my help with any of that | 15:16 |
rosmaita | yeah, sorry about this, it's kind of embarrassing | 15:16 |
rosmaita | for me anyway | 15:16 |
*** diurnalist has joined #openstack-meeting | 15:16 | |
rosmaita | i did write nice unit tests for it though (this time) | 15:16 |
fungi | shouldn't be embarrassing, it's complicated software, made harder trying to work indirectly with third parties for drivers to proprietary products | 15:16 |
rosmaita | i like your attitude! | 15:17 |
rosmaita | ok, that's all from me | 15:17 |
gagehugo | yeah getting that fix working coordinated with 3rd party drivers doesn't sound simple at all lol | 15:18 |
rosmaita | no, and this kind of py3 working fine but not on py27 problem is likely to bite us again | 15:19 |
fungi | Luzi: welcome to the security sig meeting, good to see you here! did you have anything you wanted to discuss (image encryption stuff, something else)? | 15:20 |
Luzi | ah yes, as we would like to add encryption/decryption code in os_brick, it would be nice to have someone look over it, currently its just a WIP-patch to give a sight of what we are doing | 15:22 |
fungi | you're in luck, rosmaita's right here! ;) | 15:22 |
Luzi | https://review.opendev.org/709432 | 15:22 |
rosmaita | yeah, i have been meaning to get to it, but some other stuff has interferred | 15:23 |
fungi | RE THERE OTHER BRICK DEVS WHO WOULD BE GOOD TO TRY TO PULL IN? | 15:23 |
fungi | argh | 15:23 |
fungi | sorry, didn't see caps lock was on | 15:24 |
fungi | hit caps lock instead of a :/ | 15:24 |
gagehugo | haha | 15:24 |
Luzi | rosmaita, no worries :D i will need to talk to the glance guys also - after my vacation | 15:24 |
rosmaita | well, that certainly got your message across! | 15:24 |
fungi | trying to type one-handed while holding lunch | 15:24 |
gagehugo | vacation sounds good | 15:24 |
fungi | i could use one too | 15:25 |
rosmaita | Luzi: when is your vacation? we have cinder mid-cycle next week (wednesday) | 15:26 |
Luzi | the next two weeks | 15:26 |
rosmaita | ok, have a good one! | 15:27 |
Luzi | thank you :) | 15:27 |
*** Lucas_Gray has quit IRC | 15:29 | |
fungi | i suppose this could be a good time to remind folks we have a lot of open (public!) bugs for suspected vulnerabilities, which could use all the help they can get (confirming if there's an actual exploit scenario, identifying duplicates, testing, proposing patches to review....) | 15:30 |
gagehugo | yes | 15:31 |
fungi | #link https://bugs.launchpad.net/ossa/ Suspected Security Vulnerability Reports | 15:31 |
fungi | currently 32 there | 15:31 |
*** slaweq has quit IRC | 15:33 | |
gagehugo | updated the etherpad | 15:34 |
*** diurnalist has quit IRC | 15:34 | |
gagehugo | Does anyone else have anything for this week? | 15:35 |
*** mlavalle has joined #openstack-meeting | 15:35 | |
gagehugo | fungi Luzi rosmaita: thanks! Have a good rest of the week | 15:37 |
gagehugo | #endmeeting | 15:37 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:37 | |
openstack | Meeting ended Thu Jun 18 15:37:18 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:37 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-06-18-15.00.html | 15:37 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2020/security.2020-06-18-15.00.txt | 15:37 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-06-18-15.00.log.html | 15:37 |
Luzi | you too gagehugo | 15:37 |
fungi | thanks gagehugo! | 15:38 |
*** diurnalist has joined #openstack-meeting | 15:40 | |
*** ociuhandu has joined #openstack-meeting | 15:40 | |
*** links has quit IRC | 15:44 | |
*** gyee has joined #openstack-meeting | 15:50 | |
*** e0ne has quit IRC | 15:51 | |
*** e0ne has joined #openstack-meeting | 15:51 | |
*** priteau has joined #openstack-meeting | 15:52 | |
*** diurnalist has quit IRC | 15:58 | |
*** diablo_rojo has joined #openstack-meeting | 15:59 | |
*** Luzi has quit IRC | 16:01 | |
*** e0ne has quit IRC | 16:02 | |
*** armstrong has joined #openstack-meeting | 16:05 | |
*** rosmaita has left #openstack-meeting | 16:07 | |
*** belmoreira has quit IRC | 16:17 | |
*** jamesmcarthur has joined #openstack-meeting | 16:19 | |
*** bbowen_ has quit IRC | 16:24 | |
*** jmasud has joined #openstack-meeting | 16:31 | |
*** manuvakery has quit IRC | 16:33 | |
*** diurnalist has joined #openstack-meeting | 16:35 | |
*** armstrong has quit IRC | 16:40 | |
*** jamesmcarthur has quit IRC | 16:43 | |
*** moguimar has quit IRC | 16:44 | |
*** moguimar has joined #openstack-meeting | 16:46 | |
*** armax has quit IRC | 16:48 | |
*** armax has joined #openstack-meeting | 16:49 | |
*** jamesmcarthur has joined #openstack-meeting | 16:51 | |
*** bbowen has joined #openstack-meeting | 16:58 | |
*** rpittau is now known as rpittau|afk | 17:00 | |
*** jamesmcarthur has quit IRC | 17:08 | |
*** jamesmcarthur has joined #openstack-meeting | 17:08 | |
*** jmasud has quit IRC | 17:24 | |
*** jmasud has joined #openstack-meeting | 17:26 | |
*** ralonsoh has quit IRC | 17:57 | |
*** jmasud has quit IRC | 18:01 | |
*** jmasud has joined #openstack-meeting | 18:04 | |
*** manuvakery has joined #openstack-meeting | 18:04 | |
*** jmasud has quit IRC | 18:15 | |
*** bbowen has quit IRC | 18:37 | |
*** bbowen has joined #openstack-meeting | 18:37 | |
*** maciejjozefczyk has quit IRC | 18:52 | |
*** vishalmanchanda has quit IRC | 18:55 | |
*** jmasud has joined #openstack-meeting | 19:16 | |
*** gmann is now known as gmann_afk | 19:22 | |
*** yamamoto has joined #openstack-meeting | 19:32 | |
*** diurnalist has quit IRC | 19:36 | |
*** gmann_afk is now known as gmann | 19:37 | |
*** jmasud has quit IRC | 19:37 | |
*** yamamoto has quit IRC | 19:37 | |
*** diurnalist has joined #openstack-meeting | 19:41 | |
*** jmasud has joined #openstack-meeting | 19:44 | |
*** e0ne has joined #openstack-meeting | 19:57 | |
*** e0ne has quit IRC | 19:59 | |
*** e0ne has joined #openstack-meeting | 19:59 | |
*** e0ne has quit IRC | 19:59 | |
*** jmasud has quit IRC | 20:08 | |
*** e0ne has joined #openstack-meeting | 20:08 | |
*** gmann is now known as gmann_afk | 20:10 | |
*** jmasud has joined #openstack-meeting | 20:15 | |
*** slaweq has joined #openstack-meeting | 20:23 | |
*** e0ne has quit IRC | 20:26 | |
*** manuvakery has quit IRC | 20:31 | |
*** priteau has quit IRC | 20:34 | |
*** haleyb has quit IRC | 20:47 | |
*** TrevorV has quit IRC | 20:48 | |
*** maciejjozefczyk has joined #openstack-meeting | 20:48 | |
*** rfolco has quit IRC | 20:52 | |
*** haleyb has joined #openstack-meeting | 20:54 | |
*** raildo has quit IRC | 21:10 | |
*** moguimar has joined #openstack-meeting | 21:32 | |
*** rcernin_ has joined #openstack-meeting | 21:55 | |
*** markvoelker has joined #openstack-meeting | 21:58 | |
*** markvoelker has quit IRC | 22:02 | |
*** gmann_afk is now known as gmann | 22:04 | |
*** tonyb has joined #openstack-meeting | 22:05 | |
*** eharney has quit IRC | 22:08 | |
*** armax has quit IRC | 22:09 | |
*** jmasud has quit IRC | 22:11 | |
*** jmasud has joined #openstack-meeting | 22:13 | |
*** rcernin_ has quit IRC | 22:13 | |
*** slaweq has quit IRC | 22:13 | |
*** slaweq has joined #openstack-meeting | 22:24 | |
*** slaweq has quit IRC | 22:28 | |
*** jmasud has quit IRC | 22:30 | |
*** jmasud has joined #openstack-meeting | 22:46 | |
*** armax has joined #openstack-meeting | 22:55 | |
*** dmacpher_ has quit IRC | 23:05 | |
*** dmacpher_ has joined #openstack-meeting | 23:05 | |
*** rcernin has joined #openstack-meeting | 23:16 | |
*** yamamoto has joined #openstack-meeting | 23:34 | |
*** yamamoto has quit IRC | 23:39 | |
*** jamesmcarthur has quit IRC | 23:43 | |
*** tetsuro has joined #openstack-meeting | 23:47 | |
*** ykatabam has joined #openstack-meeting | 23:52 | |
*** diurnalist has quit IRC | 23:55 | |
*** rfolco has joined #openstack-meeting | 23:58 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!