Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
> Can Paul (in CC) please have a look at the last patch set, as you are the one > who found the main drawback in the firsts iterations... The latest patchset (as currently merged) looks good to me. -Paul __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
On 03/12/2015 07:33 AM, Ihar Hrachyshka wrote: > For OSSA patch, there seems to be some concerns and issues with the > patch that was developed under embargo. It seems it will take more > time than expected to merge it in master. It may mean we will actually > miss the backport for 2014.1.4. The master review is now in the gate pipeline and should be merged anytime soon. Considering the lengthy backlog for this bug, I would prefer having people actually test the proposed solution before pushing the stable backports. Can Paul (in CC) please have a look at the last patch set, as you are the one who found the main drawback in the firsts iterations... Regards, Tristan signature.asc Description: OpenPGP digital signature __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/11/2015 12:21 PM, Alan Pevec wrote: > Hi, > > next Icehouse stable point release 2014.1.4 has been slipping last > few weeks due to various gate issues, see "Recently closed" section > in https://etherpad.openstack.org/p/stable-tracker for details. > Branch looks good enough now to push the release tomorrow > (Thursdays are traditional release days) and I've put freeze -2s on > the open reviews. I'm sorry about the short freeze period but > branch was effectively frozen last two weeks due to gate issues and > further delay doesn't make sense. Attached is the output from the > stable_freeze script for thawing after tags are pushed. > > At the same time I'd like to propose following freeze exceptions > for the review by stable-maint-core: > > * https://review.openstack.org/144714 - Eventlet green threads not > released back to pool Justification: while not OSSA fix, it does > have SecurityImpact tag > > * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket > Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) > Justification: pending merge on master and juno > For OSSA patch, there seems to be some concerns and issues with the patch that was developed under embargo. It seems it will take more time than expected to merge it in master. It may mean we will actually miss the backport for 2014.1.4. /Ihar -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJVAXlsAAoJEC5aWaUY1u57Fa8IAOYzNnim6mivd+Ch8WjCWtZv dsqjyYfD0RpNlYNG8yEn+ppKTEAOrZ7AmvqqFK8Rkpkq7vOodvNn28FCkC7/QAk6 TLXshUy+Ugnm2lNu7VqbY9BuurJIVHwXMeYWJ5/aUKrIwnaMeZnYZ6GG1kH325+k UtTh/9Tg1adVcDAb5crA6nfOGWQUVSC+7E9sxTR1vjuFiHK9u9hnzbOpBcygg3t0 Ukfa4FZCcpf5pNqMEAT9Ue9iuvmLnPi2puts3gTDdM/KfMX1DQj9KBq8b8Klmi9z euLM44vdjVdcyKrytRCuSOv/NmJ+WKuO69TrDdW1mA/So0xYSaCRanqE+n7IRUc= =yBm2 -END PGP SIGNATURE- __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
On 11/03/15 12:46 +0100, Ihar Hrachyshka wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/11/2015 12:21 PM, Alan Pevec wrote: Hi, next Icehouse stable point release 2014.1.4 has been slipping last few weeks due to various gate issues, see "Recently closed" section in https://etherpad.openstack.org/p/stable-tracker for details. Branch looks good enough now to push the release tomorrow (Thursdays are traditional release days) and I've put freeze -2s on the open reviews. I'm sorry about the short freeze period but branch was effectively frozen last two weeks due to gate issues and further delay doesn't make sense. Attached is the output from the stable_freeze script for thawing after tags are pushed. At the same time I'd like to propose following freeze exceptions for the review by stable-maint-core: * https://review.openstack.org/144714 - Eventlet green threads not released back to pool Justification: while not OSSA fix, it does have SecurityImpact tag * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) Justification: pending merge on master and juno +2 to both exceptions, especially the OSSA one. All distributions will be interested in including the patch in their packages, so it's better to do it once in upstream. +2 from me too! Cheers, Alan __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJVACsoAAoJEC5aWaUY1u57bYgH/0D1PSy0lJ5yyfkWWKDCDsz7 2Uk6jMOiH6g0nS3o+mJHiukBTbCCpsx4mnVKTtejyAJN8Fc8vW3UaWNWxsZDJykn MplR+l6dO2jVmn3RZYH3FudeP9BtTOohUZahzTsXcnZ2+S9WvFiTX8NRmqzgWPgY J7GioQ3XcGk2Q22LEBWhhJFCNm7mLsdKjVQds4glyZPMbuH5gNw4fKwU2xFikWOr RRBPplSL+DJOfNjqPc2w4CCbXyWuN+j398/GGHEi4QRnKf97fSn99x95uyiLM5EY S/qg7MbWcNFWzjsVtzQyAp6DaQRH4/YK6/Rt8oQpGPtfyFAPb0/3Z50yZ128bxg= =WBlx -END PGP SIGNATURE- __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev -- @flaper87 Flavio Percoco pgp0yyprOQl7a.pgp Description: PGP signature __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
Big +2 on both those, but will leave it up to Alan make the final call Cheers On Wed, Mar 11, 2015 at 3:42 PM, Ihar Hrachyshka wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 03/11/2015 12:21 PM, Alan Pevec wrote: > > Hi, > > > > next Icehouse stable point release 2014.1.4 has been slipping last > > few weeks due to various gate issues, see "Recently closed" section > > in https://etherpad.openstack.org/p/stable-tracker for details. > > Branch looks good enough now to push the release tomorrow > > (Thursdays are traditional release days) and I've put freeze -2s on > > the open reviews. I'm sorry about the short freeze period but > > branch was effectively frozen last two weeks due to gate issues and > > further delay doesn't make sense. Attached is the output from the > > stable_freeze script for thawing after tags are pushed. > > > > At the same time I'd like to propose following freeze exceptions > > for the review by stable-maint-core: > > > > * https://review.openstack.org/144714 - Eventlet green threads not > > released back to pool Justification: while not OSSA fix, it does > > have SecurityImpact tag > > > > * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket > > Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) > > Justification: pending merge on master and juno > > > > > > There seems to be a regression [1] introduced into Icehouse and Juno > trees by backporting [2] that may leave instances in db that are not > deletable (and we have no force-delete in Icehouse). The fix is merged > in master and backported to both stable branches [3]. I suggest we > consider it as an exception for the upcoming release to avoid the > regression in it. > > [1]: https://bugs.launchpad.net/nova/+bug/1423952 > [2]: > > https://review.openstack.org/#/q/Ife712c43c5a61424bc68b2f5ab47cefdb46ac168,n,z > [3]: > > https://review.openstack.org/#/q/I70f464120c798422f9a3d601b7cdf3b0a8320690,n,z > > Comments? > > Thanks, > /Ihar > -BEGIN PGP SIGNATURE- > Version: GnuPG v1 > > iQEcBAEBAgAGBQJVAMTyAAoJEC5aWaUY1u57l5AIAKEheCCCzifZgg0jJymDKL4w > mUST3axIxTK/SlgkU83yw7ies2zMFYv1vhu+D4MH9B/Vl+j3wVL79YgBKn9jeJFu > CU5+5f+98QW897Ba06GEXZ1HjvKwYGCII9MZsnQ3k2185OpCZvsW7jOZPbMKbmIH > cN66RJWYpLOhtYjznRCx5KLjOHz0Lp+C36oR29DICUosrTAKfQyE3jFebLSAnxgq > cpWGG7sfkbkob5YUijtmkYc8loLwC95s6ScGT8riLj/JKqyJ8JotEdfsmAfA3Bfg > ZmY+bFzLLGFIjyNfX+j5nfmfDYEEbGhhNoh2JzOL9uuP/FOhDp6s+NvZPqDmMDQ= > =WkTB > -END PGP SIGNATURE- > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/11/2015 12:21 PM, Alan Pevec wrote: > Hi, > > next Icehouse stable point release 2014.1.4 has been slipping last > few weeks due to various gate issues, see "Recently closed" section > in https://etherpad.openstack.org/p/stable-tracker for details. > Branch looks good enough now to push the release tomorrow > (Thursdays are traditional release days) and I've put freeze -2s on > the open reviews. I'm sorry about the short freeze period but > branch was effectively frozen last two weeks due to gate issues and > further delay doesn't make sense. Attached is the output from the > stable_freeze script for thawing after tags are pushed. > > At the same time I'd like to propose following freeze exceptions > for the review by stable-maint-core: > > * https://review.openstack.org/144714 - Eventlet green threads not > released back to pool Justification: while not OSSA fix, it does > have SecurityImpact tag > > * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket > Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) > Justification: pending merge on master and juno > > There seems to be a regression [1] introduced into Icehouse and Juno trees by backporting [2] that may leave instances in db that are not deletable (and we have no force-delete in Icehouse). The fix is merged in master and backported to both stable branches [3]. I suggest we consider it as an exception for the upcoming release to avoid the regression in it. [1]: https://bugs.launchpad.net/nova/+bug/1423952 [2]: https://review.openstack.org/#/q/Ife712c43c5a61424bc68b2f5ab47cefdb46ac168,n,z [3]: https://review.openstack.org/#/q/I70f464120c798422f9a3d601b7cdf3b0a8320690,n,z Comments? Thanks, /Ihar -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJVAMTyAAoJEC5aWaUY1u57l5AIAKEheCCCzifZgg0jJymDKL4w mUST3axIxTK/SlgkU83yw7ies2zMFYv1vhu+D4MH9B/Vl+j3wVL79YgBKn9jeJFu CU5+5f+98QW897Ba06GEXZ1HjvKwYGCII9MZsnQ3k2185OpCZvsW7jOZPbMKbmIH cN66RJWYpLOhtYjznRCx5KLjOHz0Lp+C36oR29DICUosrTAKfQyE3jFebLSAnxgq cpWGG7sfkbkob5YUijtmkYc8loLwC95s6ScGT8riLj/JKqyJ8JotEdfsmAfA3Bfg ZmY+bFzLLGFIjyNfX+j5nfmfDYEEbGhhNoh2JzOL9uuP/FOhDp6s+NvZPqDmMDQ= =WkTB -END PGP SIGNATURE- __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
Re: [openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/11/2015 12:21 PM, Alan Pevec wrote: > Hi, > > next Icehouse stable point release 2014.1.4 has been slipping last > few weeks due to various gate issues, see "Recently closed" section > in https://etherpad.openstack.org/p/stable-tracker for details. > Branch looks good enough now to push the release tomorrow > (Thursdays are traditional release days) and I've put freeze -2s on > the open reviews. I'm sorry about the short freeze period but > branch was effectively frozen last two weeks due to gate issues and > further delay doesn't make sense. Attached is the output from the > stable_freeze script for thawing after tags are pushed. > > At the same time I'd like to propose following freeze exceptions > for the review by stable-maint-core: > > * https://review.openstack.org/144714 - Eventlet green threads not > released back to pool Justification: while not OSSA fix, it does > have SecurityImpact tag > > * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket > Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) > Justification: pending merge on master and juno > +2 to both exceptions, especially the OSSA one. All distributions will be interested in including the patch in their packages, so it's better to do it once in upstream. > > Cheers, Alan > > > > __ > > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: > openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBAgAGBQJVACsoAAoJEC5aWaUY1u57bYgH/0D1PSy0lJ5yyfkWWKDCDsz7 2Uk6jMOiH6g0nS3o+mJHiukBTbCCpsx4mnVKTtejyAJN8Fc8vW3UaWNWxsZDJykn MplR+l6dO2jVmn3RZYH3FudeP9BtTOohUZahzTsXcnZ2+S9WvFiTX8NRmqzgWPgY J7GioQ3XcGk2Q22LEBWhhJFCNm7mLsdKjVQds4glyZPMbuH5gNw4fKwU2xFikWOr RRBPplSL+DJOfNjqPc2w4CCbXyWuN+j398/GGHEi4QRnKf97fSn99x95uyiLM5EY S/qg7MbWcNFWzjsVtzQyAp6DaQRH4/YK6/Rt8oQpGPtfyFAPb0/3Z50yZ128bxg= =WBlx -END PGP SIGNATURE- __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
[openstack-dev] [stable] Icehouse 2014.1.4 freeze exceptions
Hi, next Icehouse stable point release 2014.1.4 has been slipping last few weeks due to various gate issues, see "Recently closed" section in https://etherpad.openstack.org/p/stable-tracker for details. Branch looks good enough now to push the release tomorrow (Thursdays are traditional release days) and I've put freeze -2s on the open reviews. I'm sorry about the short freeze period but branch was effectively frozen last two weeks due to gate issues and further delay doesn't make sense. Attached is the output from the stable_freeze script for thawing after tags are pushed. At the same time I'd like to propose following freeze exceptions for the review by stable-maint-core: * https://review.openstack.org/144714 - Eventlet green threads not released back to pool Justification: while not OSSA fix, it does have SecurityImpact tag * https://review.openstack.org/163035 - [OSSA 2015-005] Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259) Justification: pending merge on master and juno Cheers, Alan stable_freeze.txt-2014.1.4 Description: Binary data __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev