Thursday, 2022-09-22

*** dasm is now known as dasm|off04:51
pdeore#startmeeting glance14:00
opendevmeetMeeting started Thu Sep 22 14:00:08 2022 UTC and is due to finish in 60 minutes.  The chair is pdeore. Information about MeetBot at http://wiki.debian.org/MeetBot.14:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
opendevmeetThe meeting name has been set to 'glance'14:00
pdeore#topic roll call14:00
pdeore#link https://etherpad.openstack.org/p/glance-team-meeting-agenda14:00
pdeoreo/14:00
jokke_o/14:00
dansmitho/14:00
croelandto/14:00
pdeorelet's start with the 2nd topic first 14:00
pdeore#topic glance-coresec review 14:00
mrjoshio/14:00
pdeore#link https://launchpad.net/~glance-coresec14:01
pdeoreSo, how we can add/remove core members here ?14:01
croelandtby sending an email on the list? :)14:02
pdeorethis topic is added by Brian14:02
dansmithI think the admins can add people14:02
dansmithhowever, that current list seems okay14:02
jokke_correct, admins are for that14:03
pdeoreok, so the mail should be only to make the Bug public right ?14:03
jokke_Any Private Security bug to be discussed outside of the embargo needs to be coordinated with VMT to be released as Public Security bug14:04
pdeoreok14:05
jokke_the embargo is there for a reason. I can walk you through this offline if you want14:06
pdeorejokke_, so what exactly expected in that email? the bug details only ?14:06
jokke_pdeore: What e-mail?14:06
pdeoreyeah 14:06
dansmithI think pdeore asked how to add people the the coresec list and croelandt said "send an email"14:07
dansmithbut I think the answer is not send an email, but "the admins of that group can add people"14:07
jokke_ah, yeah14:07
dansmiththose being rosmaita and abhi14:08
croelandtI was referring to 2.214:08
dansmithdefinitely no discussion of private security bugs in public email :)14:08
jokke_pdeore: https://security.openstack.org/vmt-process.html is the process with security bugs and coresec should be familiar with this14:08
pdeoreohh yeah, Thanks !!  I was about to ask for this :)14:09
dansmithI've never really seen people get proposed in public for coresec, does that happen?14:09
pdeoreI got confused with the line : PTL can add people, but it's traditional to propose on the ML first so the OpenStack Vulnerabilty Management Team can give input14:10
jokke_I don't think so. It's more of a self governing group of people active on the security space with some coverage in each project14:10
dansmithyeah, that ^14:11
jokke_Yeah, that is just false assumption. There is no even requirement PTL being in that group (I think it's pretty common, but like said, not requirement)14:11
pdeoreahh ok14:11
dansmithfwiw, the nova ptl hasn't been in that group for several cycles, IIRC :)14:11
pdeore:)14:12
jokke_Like it's not bad thing if PTL is active and security aware. Makes life easier, the main thing is that there is enough core power to make sure any patches can be landed swiftly when the embargo gets lifted14:13
dansmithyup14:13
dansmithso tbh, brian has experience there and is familiar with glance,14:13
dansmithso the current list seems okay to me unless he really wants to be off it or there's another reason to change14:13
dansmithjust MHO from a not-on-the-list person :)14:13
jokke_Maybe we should dicuss it with him when he is actually present and move on for now14:14
dansmithsure14:14
dansmiththe other thing to consider,14:15
pdeoreyeah, we can discuss that on glance channel when he is available 14:15
dansmithwhich I sometime forget14:15
dansmithis that you can cc specific people on a private bug, which lets them participate in the private bug directly14:15
dansmithwithout being on the list14:15
dansmithso as long as there's enough cover to rope in the right people for a particular problem, you can dynamically increase the audience as needed14:15
jokke_indeed14:15
jokke_Quite common to bring SMEs as the patch review on Private Security bugs happens in the launchpad bug rather than gerrit when needed.14:16
*** dasm|off is now known as dasm14:17
croelandtHard stops are coming, shall we move on? :)14:17
jokke_++14:17
pdeoreyeah, moving to next :)14:18
pdeore#topic glance-core review14:18
pdeore#link https://review.opendev.org/admin/groups/1d14a0536e224488ae2c442c499ad16dddcdf8b8,members14:18
* croelandt is ok with 3.2.1 and 3.2.2, maybe keep Sean though14:18
jokke_I do agree with the proposed cleanup and can do it right away if that's something we decide to do14:18
croelandtor if Sean is still pretty active in Cinder, maybe ask him whether he still cares aboutGlance first14:19
pdeoreok14:19
dansmithyep, sounds good14:19
jokke_ok, so clean Flavio's bot and nikhil for now?14:19
croelandt+214:20
dansmith+W14:20
pdeore++14:20
jokke_done14:20
pdeoreok, lets move ahead14:20
pdeore#topic release/periodic jobs updates14:20
jokke_Now the real Elephant in this room14:20
jokke_wait :P14:20
jokke_I think while we are reviewing that group there is quite clearly issue with it14:21
jokke_I don't see pdeore there!14:21
pdeorebecause I'm not core yet :P14:21
dansmithI think it's fine for the ptl to not be in the core team, FWIW14:21
jokke_Do we want to have email proposal of that into the mailing list or shall we fix this rather now?14:21
jokke_If that's preferred, fine, but tbh I'd rather have her in core by now. ;)14:22
jokke_Would be first for us anyways14:23
pdeoreSo it would be like I'm proposing myself as a core ? :D14:24
croelandtyes!14:24
jokke_That's kind of where I'm coming from ;)14:24
jokke_we can discuss this later too as we're on clock here14:25
pdeoreyeah :) 14:25
jokke_not urgent thing that needs to happen on this minute14:25
jokke_just wanted to bring that us as we were reviewing the group14:25
pdeoreack, 14:26
jokke_we need to get Abhishek to add you into this group too https://review.opendev.org/admin/groups/3a2d24a98c24482a0371a4762ba0c1b3ade078b8,members14:26
jokke_So you can start merging stuff in the specs repo14:26
pdeoreok14:26
dansmithyeah for sure on that :)14:26
jokke_ok, next topic14:27
pdeoreso next week is RC final release, 14:27
pdeoreand I think we are good for final rc14:27
pdeorePeriodic job all green except TIME_OUT for fips jobs14:28
pdeoremoving to next14:29
pdeore#topic Gate broken for stable yoga/xena14:29
pdeore#link https://review.opendev.org/c/openstack/glance-tempest-plugin/+/85698914:29
pdeoredansmith, I've updated the commit msg as per your suggestion, 14:30
pdeoreall cores, kindly please have a look at this, the patches on stable branches are pending :/14:31
pdeoreso, that's it from me ..14:31
pdeoremoving to open discussions14:33
pdeore#topic Open Discussion14:33
jokke_ack ... I thought that pinning had happened already. 14:33
pdeorenope14:34
jokke_I just wanted to give kudos to croelandt who's been digging out some very old client bugs and worked/working on them. Good quality of life stuff. Thanks!14:34
croelandtuntil we burn the glance client in favor of OSC :D14:34
jokke_I'll just fork it if it comes to that14:34
jokke_said it before, still standing behind that14:34
croelandtlooking forward to that14:35
jokke_tht's all from me ;)14:35
pdeoreanyone has anything else to discuss? 14:36
croelandtnope14:36
pdeoreok, lets wrap up 14:37
pdeoreThanks everyone for joining !!14:37
pdeore#endmeeting14:37
opendevmeetMeeting ended Thu Sep 22 14:37:40 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)14:37
opendevmeetMinutes:        https://meetings.opendev.org/meetings/glance/2022/glance.2022-09-22-14.00.html14:37
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/glance/2022/glance.2022-09-22-14.00.txt14:37
opendevmeetLog:            https://meetings.opendev.org/meetings/glance/2022/glance.2022-09-22-14.00.log.html14:37
*** dasm is now known as dasm|off22:33

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!