*** rcernin has joined #tripleo | 00:00 | |
openstackgerrit | Takashi Kajinami proposed openstack/tripleo-heat-templates master: Enforce pep8/pyflakes rule on python codes https://review.opendev.org/679240 | 00:13 |
---|---|---|
openstackgerrit | Takashi Kajinami proposed openstack/tripleo-heat-templates master: Enforce pep8/pyflakes rule on python codes https://review.opendev.org/679240 | 00:20 |
openstackgerrit | Takashi Kajinami proposed openstack/tripleo-heat-templates master: Enforce pep8/pyflakes rule on python codes https://review.opendev.org/679240 | 00:59 |
*** spsurya has joined #tripleo | 01:29 | |
*** klemorali has quit IRC | 01:32 | |
openstackgerrit | Steve Baker proposed openstack/tripleo-heat-templates master: Revert "Revert "Fixes for deploying nova-less undercloud"" https://review.opendev.org/679581 | 01:40 |
*** tkajinam has quit IRC | 01:45 | |
*** tkajinam has joined #tripleo | 01:47 | |
*** holser has joined #tripleo | 04:26 | |
*** holser has quit IRC | 04:43 | |
*** ricolin has joined #tripleo | 04:47 | |
*** ykarel has joined #tripleo | 04:52 | |
*** ykarel is now known as ykarel|away | 04:53 | |
*** jtomasek has joined #tripleo | 05:02 | |
*** yprokule has joined #tripleo | 05:20 | |
*** yprokule has quit IRC | 05:20 | |
*** yprokule has joined #tripleo | 05:21 | |
*** radeks has joined #tripleo | 05:25 | |
*** ksambor has joined #tripleo | 05:29 | |
*** ksambor has quit IRC | 05:30 | |
*** ksambor has joined #tripleo | 05:38 | |
*** marios has joined #tripleo | 05:39 | |
*** jfrancoa has joined #tripleo | 06:02 | |
*** jfrancoa has quit IRC | 06:06 | |
*** hamdyk has joined #tripleo | 06:15 | |
*** florianf has joined #tripleo | 06:18 | |
*** jfrancoa has joined #tripleo | 06:20 | |
*** psachin has joined #tripleo | 06:24 | |
*** jbadiapa has joined #tripleo | 06:37 | |
*** bogdando has joined #tripleo | 06:49 | |
*** holser has joined #tripleo | 06:53 | |
*** kopecmartin has joined #tripleo | 06:53 | |
*** tesseract has joined #tripleo | 06:56 | |
*** gfidente has joined #tripleo | 06:56 | |
*** chem has joined #tripleo | 06:57 | |
*** holser has quit IRC | 06:58 | |
*** slaweq has joined #tripleo | 06:59 | |
*** cylopez has joined #tripleo | 06:59 | |
*** apetrich has joined #tripleo | 07:02 | |
*** rcernin has quit IRC | 07:08 | |
*** holser has joined #tripleo | 07:09 | |
*** hberaud has joined #tripleo | 07:16 | |
*** egonzalez has joined #tripleo | 07:19 | |
*** rcernin has joined #tripleo | 07:25 | |
*** holser has quit IRC | 07:27 | |
*** ccamacho has joined #tripleo | 07:34 | |
*** tosky_ has joined #tripleo | 07:34 | |
*** hamdyk has quit IRC | 07:39 | |
*** hamdyk has joined #tripleo | 07:39 | |
*** jpich has joined #tripleo | 07:41 | |
*** ccamacho has quit IRC | 07:44 | |
*** ccamacho has joined #tripleo | 07:44 | |
*** jpena|off is now known as jpena | 07:45 | |
*** hamdyk has quit IRC | 07:46 | |
*** rcernin has quit IRC | 07:48 | |
*** pcaruana has joined #tripleo | 07:49 | |
*** lucasagomes has joined #tripleo | 07:49 | |
*** holser has joined #tripleo | 07:49 | |
*** hamdyk has joined #tripleo | 07:58 | |
*** pierreprinetti has joined #tripleo | 08:00 | |
openstackgerrit | Luca Miccini proposed openstack/puppet-pacemaker master: Extend deep_compare to stonith resources https://review.opendev.org/679407 | 08:07 |
*** pkopec has joined #tripleo | 08:08 | |
Tengu | zbr: heya! there's apparently some issues in CI while getting delorean.repo: https://zuul.opendev.org/t/openstack/build/119d802f88ff4374a9b4c241ef1b039c/log/job-output.txt#3435 | 08:10 |
holser | thanks Tengu | 08:11 |
*** marios has quit IRC | 08:12 | |
*** arxcruz is now known as arxcruz_pto | 08:19 | |
openstackgerrit | Sergii Golovatiuk proposed openstack/tripleo-heat-templates master: Replace include_tasks with import_tasks https://review.opendev.org/679517 | 08:20 |
*** tkajinam has quit IRC | 08:21 | |
*** panda|rover|off is now known as panda|rover | 08:23 | |
*** dtantsur|afk is now known as dtantsur | 08:26 | |
*** alexmcleod has joined #tripleo | 08:27 | |
*** avivgts has joined #tripleo | 08:28 | |
*** tosky_ is now known as tosky | 08:32 | |
*** jaosorior has joined #tripleo | 08:34 | |
openstackgerrit | Harald Jensås proposed openstack/tripleo-common master: [WIP] role_net_cidr_map https://review.opendev.org/679410 | 08:37 |
openstackgerrit | Harald Jensås proposed openstack/python-tripleoclient master: [WIP] role_net_cidr_map https://review.opendev.org/679412 | 08:38 |
*** derekh has joined #tripleo | 08:39 | |
*** paramite has joined #tripleo | 08:43 | |
*** lmiccini has joined #tripleo | 08:55 | |
openstackgerrit | Lukas Bezdicka proposed openstack/tripleo-upgrade stable/queens: Generate the network data and roles via jq https://review.opendev.org/670346 | 08:58 |
*** florianf has quit IRC | 08:59 | |
openstackgerrit | Luca Miccini proposed openstack/puppet-pacemaker master: Extend deep_compare to stonith resources https://review.opendev.org/679407 | 08:59 |
*** avivgts has quit IRC | 09:01 | |
openstackgerrit | Luca Miccini proposed openstack/puppet-pacemaker master: Extend deep_compare to stonith resources https://review.opendev.org/679407 | 09:03 |
*** holser has quit IRC | 09:08 | |
*** suuuper has joined #tripleo | 09:08 | |
*** jistr has quit IRC | 09:09 | |
*** jistr has joined #tripleo | 09:10 | |
*** holser has joined #tripleo | 09:11 | |
*** apetrich has quit IRC | 09:13 | |
openstackgerrit | François Charlier proposed openstack/tripleo-quickstart-extras master: Restore ignore_errors for tempest-results tasks https://review.opendev.org/676196 | 09:14 |
*** avivgts has joined #tripleo | 09:15 | |
*** xek has joined #tripleo | 09:17 | |
*** marios has joined #tripleo | 09:28 | |
openstackgerrit | Jose Luis Franco proposed openstack/tripleo-upgrade master: Enable system upgrade and upgrade run per host. https://review.opendev.org/674050 | 09:30 |
openstackgerrit | Luca Miccini proposed openstack/puppet-pacemaker master: Extend deep_compare to stonith resources https://review.opendev.org/679407 | 09:33 |
*** avivgts has quit IRC | 09:43 | |
*** avivgts has joined #tripleo | 09:44 | |
*** florianf has joined #tripleo | 09:45 | |
*** hberaud is now known as hberaud|lunch | 09:58 | |
*** Garyx has joined #tripleo | 10:08 | |
openstackgerrit | Sorin Sbarnea proposed openstack/tripleo-quickstart master: Resolve multiple warnings https://review.opendev.org/679618 | 10:09 |
openstackgerrit | Sorin Sbarnea proposed openstack/tripleo-quickstart master: Resolve multiple warnings https://review.opendev.org/679618 | 10:12 |
Tengu | jpich: heya! would you have a moment today for a quick discussion about https://github.com/redhat-openstack/openstack-selinux/blob/master/local_settings.sh.in#L77-L108 ? We might need to update it a bit. Also, are you the right person to ping for that? :) | 10:23 |
openstackgerrit | Sorin Sbarnea proposed openstack/tripleo-docs master: Fix trunk.rdoproject.org url https://review.opendev.org/679621 | 10:23 |
jpich | Tengu: Probably, what's the story?? Is there an issue? | 10:24 |
*** jaosorior has quit IRC | 10:24 | |
*** rascasoft has joined #tripleo | 10:24 | |
Tengu | jpich: so a BZ is being created now by chem and/of dciabrin - there's an issue during minor update on stein/osp-15, "some" of the content in /var/log/containers is re-labeled to var_log_t and, well, it breaks like everything.... | 10:24 |
Tengu | jpich: so I think it would be a good move to add something setting /var/log/containers to var_log_t, its content to container_file_t, and 1-2 exceptions to var_log_t (haproxy iirc). wdyt? | 10:25 |
Tengu | jpich: and we could pin the fault on openstack-selinux - updating this only package changes labels in /var/log/containers :/. | 10:26 |
Tengu | it's probably due to https://github.com/redhat-openstack/openstack-selinux/blob/master/local_settings.sh.in#L43-L57 | 10:27 |
Tengu | #food | 10:31 |
jpich | Tengu: I'm not sure we own /var/log/containers, that sounds like it might be something to do with container-selinux? We don't want to create conflicting policies | 10:31 |
*** xek has quit IRC | 10:35 | |
jpich | Tengu: I think I will look when the bug is created, I haven't worked much with file contexts so far so I need more time to absorb the full context. The line you linked to hasn't changed in a long time so it seems surprising it starts causing issues only now. Enjoy your meal! | 10:35 |
jpich | That line seems to restore the file contexts to whatever it is defined as in the policy | 10:38 |
chem | jpich: https://bugzilla.redhat.com/show_bug.cgi?id=1747948 | 10:43 |
openstack | bugzilla.redhat.com bug 1747948 in openstack-selinux "Updating the overcloud causes rabbitmq to not restart on bootstrap node." [Unspecified,Assigned] - Assigned to sathlang | 10:43 |
jpich | thanks | 10:43 |
chem | jpich: hi, this is totally convoluted :) | 10:43 |
openstackgerrit | Luca Miccini proposed openstack/puppet-pacemaker master: Extend deep_compare to stonith resources https://review.opendev.org/679407 | 10:45 |
Tengu | chem: thanks for the link as well :) | 10:46 |
Tengu | jpich: would love to participate if you have some discussions/test/others :). | 10:46 |
jpich | I have nothing, but I'd try first to see what the original/correct file contexts are defined - are we missing a package? What other selinux packages get updated during the update? What happens when running restorecon on one of these directory on the controller that works? | 10:48 |
* jpich wrapping up another SELinux patch before switching focus to that one | 10:48 | |
Tengu | jpich: we can have a quick talk when you're ready :). either here, or bjs, as you want. | 10:48 |
*** holser has quit IRC | 10:50 | |
chem | jpich: Tengu : hum, I forgot to log which exact package package were updated. But not a lot, and that was the only one with "selinux" in it. I'm going to eat and get back with that info | 11:01 |
Tengu | chem: ok! | 11:03 |
jpich | Thanks! | 11:04 |
*** lucasagomes has quit IRC | 11:04 | |
*** csmart has quit IRC | 11:08 | |
*** apetrich has joined #tripleo | 11:09 | |
*** csmart has joined #tripleo | 11:14 | |
Tengu | chem: anyway, we could see that the openstack-selinux one is messing with the labels. Not sure any other package is involved :/ | 11:15 |
*** jjoyce has quit IRC | 11:20 | |
*** hberaud|lunch is now known as hberaud | 11:21 | |
*** jjoyce has joined #tripleo | 11:21 | |
*** ykarel|away has quit IRC | 11:22 | |
*** jaosorior has joined #tripleo | 11:22 | |
*** holser has joined #tripleo | 11:33 | |
*** jpena is now known as jpena|lunch | 11:39 | |
openstackgerrit | Harald Jensås proposed openstack/tripleo-common master: [WIP] role_net_cidr_map https://review.opendev.org/679410 | 11:48 |
jpich | chem: Tengu: I would be curious what happens when running restorecon -Rv on one of the directory that was changed to var_log_t. Does the context revert to the correct container_file_t? | 11:54 |
* jpich goes to grab some food | 11:54 | |
chem | jpich: -Rv does nothing because it says that it won't touch a context that has been modified by an admin | 11:58 |
chem | jpich: -RFv does destroy everything by restoring the virt_file_t | 11:58 |
*** rfolco has joined #tripleo | 12:04 | |
jpich | chem: Are you running it on everything or just one of those paths? var_log_t should be the default for /var/log/<blah>, not virt_file_t? | 12:10 |
chem | jpich: yeah, sorry, it's var_log_t | 12:10 |
jpich | my guess would be that var_log_t is the policy defined both on disk and in the kernel then... we'd need to find what originally sets those files as container_file_t and make sure it's set in a way that persists through restorecon | 12:12 |
*** panda|rover is now known as panda|rover|eat | 12:13 | |
jpich | Lon would be a great contact for that sort of questions, and has historical context on the pieces of code that were linked to earlier as well. But unfortunately not today :/ | 12:13 |
Tengu | jpich: we can provide some example env if you want (and chem allows it ;)) | 12:13 |
chem | Tengu: np for an env. Currently re-running undercloud update, but we can look into the overcloud before update | 12:16 |
chem | jpich: ^ | 12:16 |
Tengu | chem: good. So let's wait for jpich and let's do a quick demo. | 12:17 |
jpich | chem: Thanks. I'm a bit stuck to be honest. Are these directories mounted within the containers with :z? | 12:17 |
Tengu | jpich: nope, no ":z". They are created using tripleo-heat-templates, and there we set the setype | 12:18 |
jpich | Tengu: Right. I think that'd be useful info to add to the bug | 12:19 |
Tengu | jpich: for instance: https://github.com/openstack/tripleo-heat-templates/blob/master/deployment/memcached/memcached-container-puppet.yaml#L174-L180 | 12:19 |
Tengu | jpich: lemme add that. | 12:20 |
jpich | Tengu: I think that means the SELinux policy module has no way to refer back to it, so we're always one restorecon away from everything blowing up | 12:23 |
chem | jpich: Tengu do you want to bj ? | 12:23 |
chem | jpich: Tengu I need to be a mtg in 6 min though | 12:24 |
*** cylopez has quit IRC | 12:24 | |
Tengu | jpich: right... so in this case I see two possiblities: either edit within the openstack-selinux, or edit the reference file used by the post-install script | 12:24 |
Tengu | chem: hmm, I have that same mtg in 5 | 12:25 |
jpich | Tengu: Could you clarify what you mean with "edit the reference file used by the post-install script"? What is that? | 12:26 |
Tengu | jpich: /etc/selinux/targeted/contexts/files/file_contexts | 12:26 |
Tengu | as it's used here: https://github.com/redhat-openstack/openstack-selinux/blob/master/local_settings.sh.in#L43-L57 | 12:26 |
Tengu | not sure what package provides it, nor the extend of such an edition though | 12:26 |
*** cylopez has joined #tripleo | 12:27 | |
*** xek has joined #tripleo | 12:28 | |
jpich | Tengu: Right, that's provided by the generic SELinux policy package so not something we can modify to set generic var_log directories like "mysql" to container_file_t | 12:29 |
Tengu | "yay". but we should probably get something like that somewhere. Care to continue in about 30 minutes? I'm on an mtg now | 12:29 |
hjensas | panda|rover|eat: https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/logs_10/679410/3/check/tripleo-ci-centos-7-containers-multinode/83177d7/job-output.txt | 12:30 |
hjensas | panda|rover|eat: 2019-09-02 12:16:43.003569 | primary | RuntimeError: Failed to retrieve repo file from http://mirror.dfw.rax.opendev.org:8080/rdo/centos7-master/current/delorean.repo after 20 retries | 12:30 |
jpich | Tengu: Sure, that gives me time to think and poke around some more | 12:31 |
Tengu | jpich: perfect :) | 12:32 |
*** jpena|lunch is now known as jpena | 12:32 | |
*** xek has quit IRC | 12:35 | |
panda|rover|eat | hjensas: propagation will be slow | 12:36 |
*** panda|rover|eat is now known as panda|rover | 12:36 | |
*** jjoyce has quit IRC | 12:36 | |
*** jjoyce has joined #tripleo | 12:36 | |
*** tkajinam has joined #tripleo | 12:38 | |
hjensas | panda|rover: ok, I'll try to have patience then. :) | 12:39 |
Tengu | jpich: ok, I'm available. Do you want to jump on a bluejeans session maybe? | 12:43 |
jpich | Tengu: I can, if you think that'd be useful! | 12:47 |
jpich | I think I understand the problem, just not quite sure about which way forward yet | 12:47 |
Tengu | jpich: you tell me ;). | 12:47 |
Tengu | jpich: ok, same for me regarding the "what to do with that". | 12:47 |
Tengu | jpich: I still think it should be edited within openstack-selinux | 12:47 |
jpich | Quite probably | 12:50 |
Tengu | question is "how"... MAYBE we should inject a reference file that the restorcon and/or setfiles will be able to eat and apply. | 12:50 |
Tengu | that would make things a bit easier and cleaner. | 12:50 |
jpich | Tengu: The problem we have with file contexts is that if there's a conflict, it chokes up and nothing gets applied. That's why we have to use local_settings.sh rather than the handy .fc files. My guess is that a reference file won't work for the same reason, because we're redefining and changing contexts that already exist | 12:55 |
Tengu | jpich: ok. so maybe best to edit that local_settings.sh thing and add what we want? | 12:57 |
*** tkajinam has quit IRC | 12:58 | |
*** tkajinam has joined #tripleo | 12:59 | |
jpich | Tengu: Probably. I see a *ton* of setype defs in THT though? | 12:59 |
Tengu | jpich: mostly for the logs in fact. | 12:59 |
jpich | The fun thing is by fixing it to actually apply the file context correctly, we also made the install an order of magnitude slower. But seems like there is not much choice. And cool enough if it's just the logs yeah :) | 13:00 |
Tengu | jpich: as said: /var/log/containers should be var_log_t, most of /var/log/containers/* should be s_virt_sandbox_file_t, and SOME directories might need to be var_log_t - I have haproxy in mind, mosly | 13:00 |
jpich | Yeah that should work | 13:00 |
Tengu | jpich: so, it should represent something like 3, maybe 4 restorcon max | 13:01 |
jpich | Oh I didn't catch that this was all under /var/log/containers from the description... then it's just one stateemnt? | 13:01 |
jpich | or 4 | 13:01 |
jpich | Yeah that seems totally doable | 13:01 |
jpich | Also, back to my first question but are we the ones to create /var/log/containers? Do we fully own it? | 13:02 |
Tengu | jpich: I think we do, yes. | 13:02 |
Tengu | 1 | 13:02 |
Tengu | 1s | 13:02 |
Tengu | jpich: https://github.com/openstack/tripleo-heat-templates/blob/94fd8052a2c4f4b27457910326dd641d858a721e/common/deploy-steps-tasks.yaml#L31 | 13:03 |
jpich | Tengu: Awesome. Yeah if it's ours we can do whatever we want then :) | 13:03 |
Tengu | jpich: one thing I've detected though, apparently openshift does use that same location.... Not sure what will happen with an "openshift on openstack" model, if baremetal is involved :/. | 13:04 |
Tengu | since it should get the openstack-selinux package, + something else | 13:04 |
Tengu | logs in openshift are managed in another way | 13:04 |
Tengu | maybe mandre would be a person to ping about that specific thing. | 13:05 |
Tengu | so many questions :). | 13:05 |
jpich | Ouch. If they expect a different label than container_file_t there then that sounds like trouble yeah. Though that sounds like a sensible for context for a path with a name like that, and that's what the type should have been so far? | 13:06 |
*** tkajinam has quit IRC | 13:06 | |
jpich | wonder if those policies are defined in container-selinux or elsewhere | 13:07 |
Tengu | jpich: so usually openshift container don't write log files in a bind-mounted directory, iirc it should be handled by host syslog, which will require the var_log_t :/ | 13:07 |
mandre | jpich, Tengu: the tripleo-deployed-openshift was removed recently, wasn't it? | 13:07 |
Tengu | mandre: maybe? didn't really follow, to be fair..... | 13:08 |
jpich | And I see a container_log_t type as well though I'm not sure when that's used | 13:08 |
*** mmethot has joined #tripleo | 13:08 | |
jpich | mandre: Wondering if openshift does anything with/in /var/log/containers | 13:09 |
mandre | jpich: it doesn't anymore, we've switched to a new way to install openshift that doesn't use tripleo | 13:09 |
jpich | mandre: Oh, ok! So that /var/log/containers directory was only used in that case, then? When used in combination with TripleO? | 13:10 |
mandre | so unless you want to backport your code to Stein, there is no risk you're going to break deployment of openshift :) | 13:10 |
Tengu | weeeelll.... | 13:11 |
jpich | hm... we were talking about Stein actually | 13:11 |
Tengu | we'll need it into OSP-15. | 13:11 |
Tengu | namely: Stein | 13:11 |
Tengu | "woopsy" | 13:11 |
jpich | also openstack-selinux doesn't branch like upstream | 13:11 |
mandre | sorry, I meant the previous one, Rocky, OSP14 | 13:11 |
chem | jpich: Tengu just fyi the env is toasted ... respinning it | 13:11 |
Tengu | chem: wokay. | 13:11 |
Tengu | mandre: \o/ | 13:11 |
Tengu | chem: maybe we won't need it in the end. | 13:12 |
jpich | openstack-selinux isn't branched though | 13:12 |
jpich | but if everything was container_file_t before I imagine openshift would be expecting it too... mandre, you wouldn't happen to know of such an environment existing somewhere, where someone could run ls -lZ on /var/log/containers and see what comes back? | 13:13 |
chem | EmilienM: hey, I've got the feeling that it's a known issue https://bugzilla.redhat.com/show_bug.cgi?id=1747885#c1 | 13:13 |
openstack | bugzilla.redhat.com bug 1747885 in rhosp-director "[UPDATE] undercloud update failed with error "ERROR configuring mysql"" [Urgent,Assigned] - Assigned to sathlang | 13:13 |
jpich | Tengu: chem: Might still be good to have an env to test the fix at some point? | 13:13 |
chem | jpich: Tengu I will have one, np | 13:14 |
chem | jpich: Tengu in a couple of hours though | 13:14 |
openstackgerrit | Jose Luis Franco proposed openstack/tripleo-upgrade master: Enable system upgrade and upgrade run per host. https://review.opendev.org/674050 | 13:15 |
Tengu | chem: :) | 13:15 |
jpich | Tengu: Is the 'setype' in THT an ansible thing, or something else? | 13:18 |
Tengu | jpich: yeah, it's a "file" module parameter | 13:19 |
jpich | Ok, thanks | 13:20 |
Tengu | jpich: do you want me to make a patch maybe? I have a clear idea of the needs in this location :) | 13:21 |
jpich | Tengu: Yes, please! Thank you. I am going to try to summarise the conversation in a comment. I would still like Lon to review this tomorrow if possible | 13:22 |
Tengu | jpich: ok! I hope I'll get the time today. It's a pretty terrible Monday. | 13:23 |
jpich | Yeah I've had better ones too, sorry to hear | 13:23 |
*** gbarros has joined #tripleo | 13:25 | |
chem | Tengu: jpich it's Monday, what did you expect :) | 13:25 |
openstackgerrit | Harald Jensås proposed openstack/tripleo-heat-templates stable/rocky: Allow overlay tunnel endpoints on IPv6 address https://review.opendev.org/679645 | 13:32 |
openstackgerrit | Harald Jensås proposed openstack/tripleo-heat-templates stable/queens: Allow overlay tunnel endpoints on IPv6 address https://review.opendev.org/679646 | 13:32 |
*** xek has joined #tripleo | 13:42 | |
*** ykarel has joined #tripleo | 13:46 | |
*** gbarros has quit IRC | 13:55 | |
Tengu | jpich, chem, dciabrin : https://github.com/redhat-openstack/openstack-selinux/pull/40 | 13:57 |
Tengu | lemme know if I missed something, or if the commit message isn't clear enough, or.. :) | 13:58 |
Tengu | and of course, testing is mandatory. | 13:58 |
*** ricolin_ has joined #tripleo | 13:59 | |
Tengu | jpich: not sure how to build an actual RPM for that one though. | 14:00 |
*** ricolin has quit IRC | 14:02 | |
jpich | Tengu: spacing issues again ;) Also, any reason for not using container_file_t? I think it reads clearer and it is an alias | 14:02 |
Tengu | jpich: soooo... when I edited the t-h-t content, I was told to use the svirt_sandbox_file_t :D | 14:04 |
Tengu | as for spacing..... I copied the lines and edited them X( | 14:04 |
Tengu | jpich: spacing should be good now. good catch | 14:05 |
Tengu | jpich: so yeah.... svirt_sandbox_file_t is an alias, not sure what docker world actually uses? | 14:06 |
Tengu | iirc docker uses another one, and svirt_sandbox_file_t will resolve to the right one maybe? not sure. meh. let's wait for comments :) | 14:06 |
jpich | Tengu: I think it's fine to use container_file_t in openstack-selinux, they are literally aliases. container_file_t is recommended now: https://danwalsh.livejournal.com/79191.html | 14:07 |
Tengu | oook. gimme a minute then | 14:07 |
Tengu | jpich: updated. | 14:08 |
jpich | Thanks! | 14:09 |
Tengu | jpich: well, thank you for the heads-up :) | 14:09 |
dciabrin | Tengu ack thx | 14:12 |
jpich | Tengu: Hm the regex doesn't seem to apply correctly for me locally | 14:17 |
jpich | line 13 has invalid regex /var/log/containers/(*)?: REGEX back-end error: At offset 18: quantifier does not follow a repeatable item | 14:18 |
*** hberaud is now known as hberaud|school-r | 14:20 | |
* jpich pokes | 14:20 | |
Tengu | jpich: hm.... maybe it's lacking a "." before the *? | 14:21 |
Tengu | jpich: it is lacking a . | 14:21 |
Tengu | jpich: update in place. sorry for that. | 14:21 |
Tengu | doing 2 things in // is probably bad for my brain ;). | 14:21 |
*** ricolin_ is now known as ricolin | 14:22 | |
*** hamdyk has quit IRC | 14:32 | |
Tengu | jpich: omg, so apparently it's OK with my patch ? yaaay | 14:33 |
jpich | I think so, but would still like Lon's eyes on things before going ahead with merging | 14:34 |
jpich | I think mounting with :z wherever possible in the future would avoid the issue, but that might be thoughts for another time | 14:35 |
*** hberaud|school-r is now known as hberaud | 14:35 | |
Tengu | jpich: not sure what would happen if :Z + restorcon... | 14:36 |
jpich | small :z | 14:37 |
Tengu | hmm maybe? Z might be good if we don't mount in different container right? | 14:37 |
jpich | What I'm reading suggests that it persists | 14:37 |
jpich | but we usually do, no? multiple nova services logging etc | 14:38 |
*** cylopez has quit IRC | 14:38 | |
jpich | also seems less likely to break things in general | 14:38 |
Tengu | hmm. maybe. | 14:38 |
openstackgerrit | Lukas Bezdicka proposed openstack/tripleo-upgrade stable/queens: Generate the network data and roles via jq https://review.opendev.org/670346 | 14:42 |
Tengu | jpich: wondering if paunch shouldn't take care of that "add :z for log paths". | 14:48 |
Tengu | that way we can automate this change. But still..... I'm not that happy with auto-relabelling :/ | 14:48 |
openstackgerrit | Jose Luis Franco proposed openstack/tripleo-upgrade master: Add else statement when running leapp without SKIP_DEVEL. https://review.opendev.org/679011 | 14:50 |
*** xek has quit IRC | 14:52 | |
*** kopecmartin is now known as kopecmartin|off | 14:54 | |
jpich | Tengu: I don't know much of anything about paunch so I couldn't say | 14:58 |
Tengu | jpich: will investigate later.- | 15:01 |
*** lmiccini has quit IRC | 15:03 | |
*** psachin has quit IRC | 15:03 | |
*** pkopec has quit IRC | 15:04 | |
openstackgerrit | Merged openstack/tripleo-upgrade stable/queens: Generate the network data and roles via jq https://review.opendev.org/670346 | 15:15 |
*** egonzalez has quit IRC | 15:17 | |
openstackgerrit | Tom Barron proposed openstack/tripleo-heat-templates master: DNM - exploring running scenario004 w/o pacemaker for manila https://review.opendev.org/679365 | 15:21 |
*** pkopec has joined #tripleo | 15:22 | |
chem | jpich: hey, how can I test https://github.com/redhat-openstack/openstack-selinux/pull/40/commits/1b8a97c1b2ccb4573cc4a38edee07545f5b26bef in a way that make sense ? | 15:25 |
jpich | Hm... | 15:26 |
jpich | chem: I could try to remember how to do a scratch-build with an in-flight patch, and then we could dnf update the package manually on the controller like you did in the description to confirm the issue? | 15:29 |
jpich | I don't think we can try a proper update until it's properly available in a repo/puddle somewhere? | 15:30 |
chem | jpich: yes, we need a repo/puddle somewhere, but .. let's say I have a package, then I update that one manually before update, then run the update. That would bring some confidence that it work | 15:32 |
chem | jpich: all depends on how long it takes to land in phase1 relative to the scratch-build | 15:32 |
chem | jpich: :) | 15:32 |
chem | jpich: or maybe I can learn somewhere to make the scratch build ? | 15:33 |
*** pierreprinetti has quit IRC | 15:34 | |
*** marios is now known as marios|out | 15:34 | |
*** bogdando has quit IRC | 15:35 | |
jpich | chem: I can try to prepare something tonight/tomorrow morning so it can potentially be tested tomorrow morning? But if you're somewhat familiar with the process already please be my guest, I have to dig out docs | 15:36 |
jpich | I think I should be able to have something ready before my EOD | 15:37 |
* jpich famous last words | 15:37 | |
chem | jpich: not familiar at all ... but I can read doc too. Anyway tomorrow will be very nice in anycase :) | 15:38 |
jpich | I guess there's also the thing where it worked fine on other nodes so this might be some strange ordering issue... | 15:38 |
chem | jpich: that's why I would like to torture test it a little before it get to phase2 :) | 15:38 |
*** jfrancoa has quit IRC | 15:39 | |
chem | jpich: anyway I'm near eod too, so let's do that tomorrow. If you have some pointer doc, we can try to do that together tomorrow ? | 15:40 |
jpich | Sure! | 15:40 |
chem | cool, I've always felt that core were always better when you're more than one :) | 15:41 |
chem | s/core/chore/ | 15:42 |
jpich | I like shared suffering too :D | 15:42 |
jpich | Ok, that sounds good | 15:42 |
*** marios|out has quit IRC | 15:43 | |
*** pkopec has quit IRC | 15:45 | |
*** dtantsur is now known as dtantsur|afk | 15:45 | |
*** zbr is now known as zbr|ooo | 15:52 | |
*** pkopec has joined #tripleo | 16:01 | |
*** xek has joined #tripleo | 16:02 | |
*** alexmcleod has quit IRC | 16:19 | |
*** mmethot has quit IRC | 16:29 | |
*** yprokule has quit IRC | 16:33 | |
openstackgerrit | Sergii Golovatiuk proposed openstack/tripleo-heat-templates master: Replace include_tasks with import_tasks https://review.opendev.org/679517 | 16:36 |
*** holser has quit IRC | 16:38 | |
*** jpich has quit IRC | 16:43 | |
*** spsurya has quit IRC | 16:44 | |
*** hberaud is now known as hberaud|gone | 16:44 | |
*** avivgts has quit IRC | 16:55 | |
*** derekh has quit IRC | 17:00 | |
*** jpena is now known as jpena|off | 17:25 | |
*** tesseract has quit IRC | 17:30 | |
*** jtomasek has quit IRC | 17:44 | |
*** zbr|ooo is now known as zbr | 17:53 | |
*** suuuper has quit IRC | 17:58 | |
*** jtomasek has joined #tripleo | 17:59 | |
*** jtomasek has quit IRC | 17:59 | |
*** jtomasek has joined #tripleo | 18:00 | |
*** gfidente is now known as gfidente|afk | 18:05 | |
*** ykarel has quit IRC | 18:18 | |
*** pcaruana has quit IRC | 18:19 | |
*** pcaruana has joined #tripleo | 18:19 | |
*** rfolco is now known as rfolco|doctor | 18:28 | |
openstackgerrit | Martin Mágr proposed openstack/puppet-tripleo master: [WIP] Add collectd-sensubility configuration https://review.opendev.org/678863 | 18:59 |
*** holser has joined #tripleo | 19:11 | |
openstackgerrit | Martin Mágr proposed openstack/puppet-tripleo master: [WIP] Add collectd-sensubility configuration https://review.opendev.org/678863 | 19:11 |
*** pkopec has quit IRC | 19:26 | |
*** holser has quit IRC | 19:31 | |
*** holser has joined #tripleo | 19:41 | |
openstackgerrit | Harald Jensås proposed openstack/tripleo-heat-templates master: Don't add IpList for disabled networks https://review.opendev.org/679354 | 19:42 |
*** sshnaidm|pto has quit IRC | 19:47 | |
*** holser has quit IRC | 19:50 | |
*** sshnaidm|pto has joined #tripleo | 19:51 | |
*** holser has joined #tripleo | 19:55 | |
*** gfidente|afk has quit IRC | 20:02 | |
*** gfidente has joined #tripleo | 20:02 | |
*** gfidente has quit IRC | 20:14 | |
openstackgerrit | Martin Mágr proposed openstack/puppet-tripleo master: [WIP] Add collectd-sensubility configuration https://review.opendev.org/678863 | 20:24 |
*** florianf has quit IRC | 20:28 | |
*** pcaruana has quit IRC | 20:36 | |
*** holser has quit IRC | 20:57 | |
*** gfidente has joined #tripleo | 21:04 | |
openstackgerrit | Harald Jensås proposed openstack/tripleo-heat-templates master: Don't add IpList for disabled networks https://review.opendev.org/679354 | 21:10 |
*** gfidente is now known as gfidente|afk | 21:17 | |
*** gbarros has joined #tripleo | 21:24 | |
openstackgerrit | Harald Jensås proposed openstack/tripleo-common master: [WIP] role_net_cidr_map https://review.opendev.org/679410 | 21:33 |
*** rfolco|doctor is now known as rfolco | 21:35 | |
*** slaweq has quit IRC | 21:45 | |
*** paramite|clone has joined #tripleo | 22:02 | |
*** tosky_ has joined #tripleo | 22:04 | |
*** chem` has joined #tripleo | 22:04 | |
*** chem has quit IRC | 22:06 | |
*** paramite has quit IRC | 22:06 | |
*** tosky has quit IRC | 22:06 | |
*** tosky_ is now known as tosky | 22:09 | |
*** gfidente|afk has quit IRC | 22:18 | |
*** rcernin has joined #tripleo | 22:54 | |
*** tkajinam has joined #tripleo | 22:56 | |
*** dpeacock has quit IRC | 23:40 | |
*** owalsh has quit IRC | 23:43 | |
*** dpeacock has joined #tripleo | 23:44 | |
*** owalsh has joined #tripleo | 23:51 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!