Wednesday, 2022-11-30

opendevreviewVishal Manchanda proposed openstack/horizon master: Add Image "architecture" details in Image Detail View Page  https://review.opendev.org/c/openstack/horizon/+/86617314:41
vishalmanchanda#startmeeting horizon15:00
opendevmeetMeeting started Wed Nov 30 15:00:12 2022 UTC and is due to finish in 60 minutes.  The chair is vishalmanchanda. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'horizon'15:00
vishalmanchandahello, anyone around for horizon weekly meeting?15:01
vishalmanchandaLooks like no one around.15:05
rdopierao/15:05
rdopierabut I don't really have anything...15:05
vishalmanchandardopiera: np.15:06
vishalmanchandaI got two updates15:06
vishalmanchandaagenda of meeting can be found here https://etherpad.opendev.org/p/horizon-release-priorities#L3115:06
vishalmanchandaI have no announcement for this week.15:06
vishalmanchandamoving to Release priorities topic15:07
vishalmanchanda#topic Release priorities15:07
vishalmanchandaPatch to migrate CI job to 2023.1 runtime https://review.opendev.org/c/openstack/horizon/+/865453 is ready for review15:07
vishalmanchandardopiera: please take a look15:07
vishalmanchandaI have migrated nodeset to Debian 11 which pass the CI jobs15:08
vishalmanchandaIt is also runtime for 2023.1 cycle.15:09
vishalmanchandahttps://governance.openstack.org/tc/reference/runtimes/2023.1.html15:09
rdopieravishalmanchanda: what is firefox-esr?15:09
vishalmanchandardopiera: you mean why these job not fail on debian?15:10
vishalmanchandardopiera: actually some issue with snap package with firefox on ubuntu.15:11
rdopierano, you are adding an extra entry in bindep.txt15:11
rdopieraI know why firefox is failing on ubuntu, and I'm pretty happy about switching to debian15:11
rdopierasnaps are cancer15:11
vishalmanchandardopiera: ok, that is because in case of debian firefox package avaialble as 'firefox-esr' 15:12
rdopieraoh, I see, thanks15:13
vishalmanchandaPlease add your vote and suggestion on the patch.15:13
vishalmanchandamoving to next topic.15:14
vishalmanchandaDrop nodejs 16 jobs 15:14
vishalmanchandaAs you can see in patch https://review.opendev.org/c/openstack/horizon/+/86529315:15
vishalmanchandanodejs18 passing in horizon and all plugins.15:15
vishalmanchandaSo now we can drop nodejs 16 jobs.15:15
vishalmanchandahere is patch for that https://review.opendev.org/c/openstack/horizon/+/86566115:16
vishalmanchandaplease take a look once you have time.15:16
vishalmanchandathat's all update from my side for this week.15:17
vishalmanchandamoving to next topic15:17
vishalmanchanda#topic open-discussion15:17
vishalmanchandaI have one patch to discuss.15:17
vishalmanchandaI was thinking if should migrate django to 4.0 version15:18
vishalmanchandaInitial patch for that is https://review.opendev.org/c/openstack/horizon/+/85126115:19
vishalmanchandardopiera: Could you take a look at it and once it merged. I will resolve merge conflict for other 2 patches in series.15:20
rdopieradidn't we just migrate to 3.015:20
rdopieraI'm not ready15:20
vishalmanchandardopiera: hehe yeah that was in last cycle I guess.15:21
vishalmanchandardopiera: I was asking because if we support django 4.x then horizon can also support FIP.15:22
rdopieraI suppose the earier we do it, the less painful it will be15:23
rdopieraby the way, did you see that security issue about websso and the referer headers?15:24
vishalmanchandatrue, but there is no harm in doing it now.15:24
vishalmanchandardopiera: nope, I forgot15:25
rdopieraI wanted to look into it, but I can't find any documentation on websso itself15:25
vishalmanchandardopiera: is it a private bug?15:25
rdopieraso I am not sure if it actually requires the referer15:26
rdopierait's launchpad 198034915:26
amotokiI think there is no document on websso implementation15:26
rdopieraI mean the specification for the protocol15:27
rdopieranot our implementatin15:27
rdopierao15:27
amotokiI tried to understand the implementation when I glanced that bug, but could have enough time :-(15:27
amotokigot it15:27
rdopierawe know what our code does, but how do we know if that's correct?15:28
vishalmanchandardopiera: sorry, I completely forgot about this bug. will a look at it tomorrow.15:30
vishalmanchandardopiera: are you able to reproduce this bug?15:33
rdopieraNo , I don't have a setup with websso15:34
rdopierabut looking at the code, I see no reason why the exploit wouldn't work15:35
amotokiit seems https://review.opendev.org/c/openstack/keystone-specs/+/133529/ is the original design of our websso.15:35
amotokicommit 7b57608ad000bd099f29ee9f9fa31d36b725cfea implemented it in horizon15:35
rdopieragreat find, thank you15:36
vishalmanchandaamotoki: thanks for the links15:37
amotokivishalmanchanda: back to Django 4.0 topic, why do we need to migrate to Django 4.0?15:38
amotokiDjango 4.0 is NOT an LTS version, so we should keep the support for Django 3.2 at least.15:38
amotokiextra support of Django 4.0 is okay (as long as we have a bandwidth to do it) but it is completely optional15:39
vishalmanchandaamotoki: the only reason I am asking is because we can support FIPs tests then15:41
vishalmanchandahttps://review.opendev.org/c/openstack/horizon/+/82587515:41
vishalmanchandaif django 4.0 support is added in horizon15:41
vishalmanchandaThere is some issue with django and FIPS which is fixed in django 4.015:43
vishalmanchandathat's why I am asking15:43
amotokiI am okay with either. Perhaps my patch series fixes UT at least. I don't know more though.15:44
vishalmanchandaDoes anyone have any other topic to discuss?15:46
vishalmanchandaif nothing more to discuss, let's end this meeting.15:48
vishalmanchandaThanks everyone for joing!15:48
vishalmanchanda#endmeeting15:49
opendevmeetMeeting ended Wed Nov 30 15:49:05 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:49
opendevmeetMinutes:        https://meetings.opendev.org/meetings/horizon/2022/horizon.2022-11-30-15.00.html15:49
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/horizon/2022/horizon.2022-11-30-15.00.txt15:49
opendevmeetLog:            https://meetings.opendev.org/meetings/horizon/2022/horizon.2022-11-30-15.00.log.html15:49
*** Guest305 is now known as atmark21:07

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!