Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Gowtham Sundara
Oh, the code doesn't look very different in 3.9. I can send a PR to that
branch, but without the CI infra, might be hard to guage the impact.

The only alternative is run the rather scary rpm builder locally or I can
build the go binaries for master and node. (assuming it all works well)

On Thu, Dec 6, 2018 at 9:06 PM Clayton Coleman  wrote:

> At this point i didn’t have a plan to backport to 3.9.  The ci infra has
> atrophied somewhat and so I can’t be sure it can be done.
>
> On Dec 6, 2018, at 10:28 AM, Daniel Comnea  wrote:
>
>
>
> On Thu, Dec 6, 2018 at 3:25 PM Gowtham Sundara <
> gowtham.sund...@rapyuta-robotics.com> wrote:
>
>> Hello,
>> Is there a ci build for version 3.9? (can't seem to find one, so I am
>> assuming not). Could you please cut a minor release for 3.9 too as Daniel
>> suggested.
>>
>> [DC]: the K8 fix was backported down to 1.10 and so our RH fellows did
> the same. I doubt there will be anything for < 3.10 (not on OKD i suspect)
>
>
>> Thanks
>>
>> On Thu, Dec 6, 2018 at 8:50 PM Daniel Comnea 
>> wrote:
>>
>>> Cheers for chime in Clayton.
>>>
>>> In this case you fancy cutting new minor release for 3.10/ 3.11 and then
>>> i'll take it over?
>>>
>>> Dani
>>>
>>> On Thu, Dec 6, 2018 at 3:18 PM Clayton Coleman 
>>> wrote:
>>>
 This are the correct PRa

 On Dec 6, 2018, at 10:14 AM, Daniel Comnea 
 wrote:

 I'll chime in to get some clarity 

 The CentOS rpms are built by the PaaS SIG and is based on the Origin
 tag release.
 As such in order to have new origin rpms built/ pushed into CentOS
 repos we will need:


- the fix to make it into 3.11/3.10 Origin branches => done [1]
however i am just guessing those are the right PRs, someone from RH
will need to confirm/ refute
- a new Origin release to be cut for 3.11/3.10
- then i can start with the PaaS Sig work

 You can also see some details on [2] but again i have not validated
 myself

 Hope this get some clarity


 Dani

 [1]
 https://github.com/openshift/origin/pull/21600 (3.11)
 https://github.com/openshift/origin/pull/21601 (3.10)

 [2] https://github.com/openshift/origin/issues/21606

 On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
 mateus.caruc...@getupcloud.com> wrote:

> On top of that is anyone here building publicly accessible rpms/srpms?
>
>
> Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
> gowtham.sund...@rapyuta-robotics.com escreveu:
>
>> Hello,
>> The RPMs for Openshift origin need to be updated because of the
>> recent vulnerability. Is there a release schedule for this?
>>
>> --
>> Gowtham Sundara
>> Site Reliability Engineer
>>
>> Rapyuta Robotics “empowering lives with connected machines”
>> rapyuta-robotics.com 
>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
 ___
 dev mailing list
 dev@lists.openshift.redhat.com
 http://lists.openshift.redhat.com/openshiftmm/listinfo/dev

 ___
>>> dev mailing list
>>> dev@lists.openshift.redhat.com
>>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>>
>>
>>
>> --
>> Gowtham Sundara
>> Site Reliability Engineer
>>
>> Rapyuta Robotics “empowering lives with connected machines”
>> rapyuta-robotics.com 
>>
>

-- 
Gowtham Sundara
Site Reliability Engineer

Rapyuta Robotics “empowering lives with connected machines”
rapyuta-robotics.com 
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Clayton Coleman
At this point i didn’t have a plan to backport to 3.9.  The ci infra has
atrophied somewhat and so I can’t be sure it can be done.

On Dec 6, 2018, at 10:28 AM, Daniel Comnea  wrote:



On Thu, Dec 6, 2018 at 3:25 PM Gowtham Sundara <
gowtham.sund...@rapyuta-robotics.com> wrote:

> Hello,
> Is there a ci build for version 3.9? (can't seem to find one, so I am
> assuming not). Could you please cut a minor release for 3.9 too as Daniel
> suggested.
>
> [DC]: the K8 fix was backported down to 1.10 and so our RH fellows did the
same. I doubt there will be anything for < 3.10 (not on OKD i suspect)


> Thanks
>
> On Thu, Dec 6, 2018 at 8:50 PM Daniel Comnea 
> wrote:
>
>> Cheers for chime in Clayton.
>>
>> In this case you fancy cutting new minor release for 3.10/ 3.11 and then
>> i'll take it over?
>>
>> Dani
>>
>> On Thu, Dec 6, 2018 at 3:18 PM Clayton Coleman 
>> wrote:
>>
>>> This are the correct PRa
>>>
>>> On Dec 6, 2018, at 10:14 AM, Daniel Comnea 
>>> wrote:
>>>
>>> I'll chime in to get some clarity 
>>>
>>> The CentOS rpms are built by the PaaS SIG and is based on the Origin
>>> tag release.
>>> As such in order to have new origin rpms built/ pushed into CentOS repos
>>> we will need:
>>>
>>>
>>>- the fix to make it into 3.11/3.10 Origin branches => done [1]
>>>however i am just guessing those are the right PRs, someone from RH
>>>will need to confirm/ refute
>>>- a new Origin release to be cut for 3.11/3.10
>>>- then i can start with the PaaS Sig work
>>>
>>> You can also see some details on [2] but again i have not validated
>>> myself
>>>
>>> Hope this get some clarity
>>>
>>>
>>> Dani
>>>
>>> [1]
>>> https://github.com/openshift/origin/pull/21600 (3.11)
>>> https://github.com/openshift/origin/pull/21601 (3.10)
>>>
>>> [2] https://github.com/openshift/origin/issues/21606
>>>
>>> On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
>>> mateus.caruc...@getupcloud.com> wrote:
>>>
 On top of that is anyone here building publicly accessible rpms/srpms?


 Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
 gowtham.sund...@rapyuta-robotics.com escreveu:

> Hello,
> The RPMs for Openshift origin need to be updated because of the recent
> vulnerability. Is there a release schedule for this?
>
> --
> Gowtham Sundara
> Site Reliability Engineer
>
> Rapyuta Robotics “empowering lives with connected machines”
> rapyuta-robotics.com 
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
 ___
 dev mailing list
 dev@lists.openshift.redhat.com
 http://lists.openshift.redhat.com/openshiftmm/listinfo/dev

>>> ___
>>> dev mailing list
>>> dev@lists.openshift.redhat.com
>>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>>
>>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
>
>
> --
> Gowtham Sundara
> Site Reliability Engineer
>
> Rapyuta Robotics “empowering lives with connected machines”
> rapyuta-robotics.com 
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Gowtham Sundara
Hello,
Is there a ci build for version 3.9? (can't seem to find one, so I am
assuming not). Could you please cut a minor release for 3.9 too as Daniel
suggested.

Thanks

On Thu, Dec 6, 2018 at 8:50 PM Daniel Comnea  wrote:

> Cheers for chime in Clayton.
>
> In this case you fancy cutting new minor release for 3.10/ 3.11 and then
> i'll take it over?
>
> Dani
>
> On Thu, Dec 6, 2018 at 3:18 PM Clayton Coleman 
> wrote:
>
>> This are the correct PRa
>>
>> On Dec 6, 2018, at 10:14 AM, Daniel Comnea  wrote:
>>
>> I'll chime in to get some clarity 
>>
>> The CentOS rpms are built by the PaaS SIG and is based on the Origin tag
>> release.
>> As such in order to have new origin rpms built/ pushed into CentOS repos
>> we will need:
>>
>>
>>- the fix to make it into 3.11/3.10 Origin branches => done [1]
>>however i am just guessing those are the right PRs, someone from RH
>>will need to confirm/ refute
>>- a new Origin release to be cut for 3.11/3.10
>>- then i can start with the PaaS Sig work
>>
>> You can also see some details on [2] but again i have not validated
>> myself
>>
>> Hope this get some clarity
>>
>>
>> Dani
>>
>> [1]
>> https://github.com/openshift/origin/pull/21600 (3.11)
>> https://github.com/openshift/origin/pull/21601 (3.10)
>>
>> [2] https://github.com/openshift/origin/issues/21606
>>
>> On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
>> mateus.caruc...@getupcloud.com> wrote:
>>
>>> On top of that is anyone here building publicly accessible rpms/srpms?
>>>
>>>
>>> Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
>>> gowtham.sund...@rapyuta-robotics.com escreveu:
>>>
 Hello,
 The RPMs for Openshift origin need to be updated because of the recent
 vulnerability. Is there a release schedule for this?

 --
 Gowtham Sundara
 Site Reliability Engineer

 Rapyuta Robotics “empowering lives with connected machines”
 rapyuta-robotics.com 
 ___
 dev mailing list
 dev@lists.openshift.redhat.com
 http://lists.openshift.redhat.com/openshiftmm/listinfo/dev

>>> ___
>>> dev mailing list
>>> dev@lists.openshift.redhat.com
>>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>>
>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
>> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>


-- 
Gowtham Sundara
Site Reliability Engineer

Rapyuta Robotics “empowering lives with connected machines”
rapyuta-robotics.com 
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Daniel Comnea
Cheers for chime in Clayton.

In this case you fancy cutting new minor release for 3.10/ 3.11 and then
i'll take it over?

Dani

On Thu, Dec 6, 2018 at 3:18 PM Clayton Coleman  wrote:

> This are the correct PRa
>
> On Dec 6, 2018, at 10:14 AM, Daniel Comnea  wrote:
>
> I'll chime in to get some clarity 
>
> The CentOS rpms are built by the PaaS SIG and is based on the Origin tag
> release.
> As such in order to have new origin rpms built/ pushed into CentOS repos
> we will need:
>
>
>- the fix to make it into 3.11/3.10 Origin branches => done [1]
>however i am just guessing those are the right PRs, someone from RH
>will need to confirm/ refute
>- a new Origin release to be cut for 3.11/3.10
>- then i can start with the PaaS Sig work
>
> You can also see some details on [2] but again i have not validated myself
>
> Hope this get some clarity
>
>
> Dani
>
> [1]
> https://github.com/openshift/origin/pull/21600 (3.11)
> https://github.com/openshift/origin/pull/21601 (3.10)
>
> [2] https://github.com/openshift/origin/issues/21606
>
> On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
> mateus.caruc...@getupcloud.com> wrote:
>
>> On top of that is anyone here building publicly accessible rpms/srpms?
>>
>>
>> Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
>> gowtham.sund...@rapyuta-robotics.com escreveu:
>>
>>> Hello,
>>> The RPMs for Openshift origin need to be updated because of the recent
>>> vulnerability. Is there a release schedule for this?
>>>
>>> --
>>> Gowtham Sundara
>>> Site Reliability Engineer
>>>
>>> Rapyuta Robotics “empowering lives with connected machines”
>>> rapyuta-robotics.com 
>>> ___
>>> dev mailing list
>>> dev@lists.openshift.redhat.com
>>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>>
>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Clayton Coleman
This are the correct PRa

On Dec 6, 2018, at 10:14 AM, Daniel Comnea  wrote:

I'll chime in to get some clarity 

The CentOS rpms are built by the PaaS SIG and is based on the Origin tag
release.
As such in order to have new origin rpms built/ pushed into CentOS repos we
will need:


   - the fix to make it into 3.11/3.10 Origin branches => done [1] however
   i am just guessing those are the right PRs, someone from RH will need to
   confirm/ refute
   - a new Origin release to be cut for 3.11/3.10
   - then i can start with the PaaS Sig work

You can also see some details on [2] but again i have not validated myself

Hope this get some clarity


Dani

[1]
https://github.com/openshift/origin/pull/21600 (3.11)
https://github.com/openshift/origin/pull/21601 (3.10)

[2] https://github.com/openshift/origin/issues/21606

On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
mateus.caruc...@getupcloud.com> wrote:

> On top of that is anyone here building publicly accessible rpms/srpms?
>
>
> Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
> gowtham.sund...@rapyuta-robotics.com escreveu:
>
>> Hello,
>> The RPMs for Openshift origin need to be updated because of the recent
>> vulnerability. Is there a release schedule for this?
>>
>> --
>> Gowtham Sundara
>> Site Reliability Engineer
>>
>> Rapyuta Robotics “empowering lives with connected machines”
>> rapyuta-robotics.com 
>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Daniel Comnea
I'll chime in to get some clarity 

The CentOS rpms are built by the PaaS SIG and is based on the Origin tag
release.
As such in order to have new origin rpms built/ pushed into CentOS repos we
will need:


   - the fix to make it into 3.11/3.10 Origin branches => done [1] however
   i am just guessing those are the right PRs, someone from RH will need to
   confirm/ refute
   - a new Origin release to be cut for 3.11/3.10
   - then i can start with the PaaS Sig work

You can also see some details on [2] but again i have not validated myself

Hope this get some clarity


Dani

[1]
https://github.com/openshift/origin/pull/21600 (3.11)
https://github.com/openshift/origin/pull/21601 (3.10)

[2] https://github.com/openshift/origin/issues/21606

On Thu, Dec 6, 2018 at 10:07 AM Mateus Caruccio <
mateus.caruc...@getupcloud.com> wrote:

> On top of that is anyone here building publicly accessible rpms/srpms?
>
>
> Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
> gowtham.sund...@rapyuta-robotics.com escreveu:
>
>> Hello,
>> The RPMs for Openshift origin need to be updated because of the recent
>> vulnerability. Is there a release schedule for this?
>>
>> --
>> Gowtham Sundara
>> Site Reliability Engineer
>>
>> Rapyuta Robotics “empowering lives with connected machines”
>> rapyuta-robotics.com 
>> ___
>> dev mailing list
>> dev@lists.openshift.redhat.com
>> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>>
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Clayton Coleman
Rpms from CI are here

https://artifacts-openshift-release-3-11.svc.ci.openshift.org/repo/

I forgot srpms aren’t created via this process, there’s not an easy way to
add them due to the size increase.

The centos paas sig was also creating them (and they have srpms) and would
be where I would recommend pulling from.

On Dec 6, 2018, at 5:07 AM, Mateus Caruccio 
wrote:

On top of that is anyone here building publicly accessible rpms/srpms?


Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
gowtham.sund...@rapyuta-robotics.com escreveu:

> Hello,
> The RPMs for Openshift origin need to be updated because of the recent
> vulnerability. Is there a release schedule for this?
>
> --
> Gowtham Sundara
> Site Reliability Engineer
>
> Rapyuta Robotics “empowering lives with connected machines”
> rapyuta-robotics.com 
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Neale Ferguson
Will the github repo be tagged with v3.11.1 or retagged with v3.11.0?

___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev


Re: Openshift Origin builds for CVE-2018-1002105

2018-12-06 Thread Mateus Caruccio
On top of that is anyone here building publicly accessible rpms/srpms?


Em Qui, 6 de dez de 2018 07:36, Gowtham Sundara <
gowtham.sund...@rapyuta-robotics.com escreveu:

> Hello,
> The RPMs for Openshift origin need to be updated because of the recent
> vulnerability. Is there a release schedule for this?
>
> --
> Gowtham Sundara
> Site Reliability Engineer
>
> Rapyuta Robotics “empowering lives with connected machines”
> rapyuta-robotics.com 
> ___
> dev mailing list
> dev@lists.openshift.redhat.com
> http://lists.openshift.redhat.com/openshiftmm/listinfo/dev
>
___
dev mailing list
dev@lists.openshift.redhat.com
http://lists.openshift.redhat.com/openshiftmm/listinfo/dev