)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"f2fd0093179bd2fb7fdba4d1beee924c87730c8c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"ed73b8d1_6f3221b1","updated":"2024-04-09 12:16:28.000000000","message":"let\u0027s wait for a CI run first I think.\n\nI hope the versionlock stuff survives the docker build (it drops afaik files in /etc/dnf/versionlock or something, I didn\u0027t test locally with a complete kolla-build if that works in our special build procedure, but it does work with a plain docker container at least)","commit_id":"05b25c89e0ce8d171e79078742bd4eaeee2b3d46"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"af43533cc517571d418a45dfe54cf4a594ba9913","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b7935a8a_ab060560","updated":"2024-04-09 12:14:46.000000000","message":"tested the versionlock stuff locally in a rocky 9 container with opensearch, not with the dashboard, but I verified the NVRA dashboard information at least, so should work.\n\nsee upstream docs on versionlock: https://dnf-plugins-core.readthedocs.io/en/latest/versionlock.html","commit_id":"05b25c89e0ce8d171e79078742bd4eaeee2b3d46"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"1c07519f2f8c686a3652417f4395e8b87bab827f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"2a9eacd0_10a3cb7e","updated":"2024-04-11 08:02:52.000000000","message":"recheck grafana upstream mirror should be fixed now","commit_id":"8e954f3e2c1bd912d7f9cba52681620ce7594fcd"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"17b2b8a80418d4d7cbbdbbef0d57bd8a6138be3c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"28098910_dde2f558","updated":"2024-04-10 11:44:32.000000000","message":"recheck kolla-build-debian error during grafana build \"Package grafana is not available\"","commit_id":"8e954f3e2c1bd912d7f9cba52681620ce7594fcd"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"aaa1fd098a81a0134fb9f9b0f2c1a5bf8d49ffff","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"30bed809_07cb332d","updated":"2024-04-10 12:20:24.000000000","message":"recheck kolla-build-debian error during grafana build \"Package grafana is not available\" (I rechecked too fast)","commit_id":"8e954f3e2c1bd912d7f9cba52681620ce7594fcd"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"ad23e16ae55c46e4e04333ce3711d098cb185dc9","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"82e467fc_9cf5ca9f","updated":"2024-04-10 13:36:38.000000000","message":"trying to reproduce grafana build failure locally.","commit_id":"8e954f3e2c1bd912d7f9cba52681620ce7594fcd"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"e9fcae343c647ab4671a29857f937a30acbc6cc7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"6b7924c5_6ce2f8cd","in_reply_to":"82e467fc_9cf5ca9f","updated":"2024-04-11 07:02:46.000000000","message":"it\u0027s an upstream issue: https://github.com/grafana/grafana/issues/85827","commit_id":"8e954f3e2c1bd912d7f9cba52681620ce7594fcd"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"796f3a4387bcec0be0c53c8c60a20083d7e6c7c4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"02a4b69f_96c10573","updated":"2024-04-12 10:31:12.000000000","message":"Great job Sven, I think this is an important step forward in general.\n\nIf we agree on keeping the pin around in the future, it might be nice to parameterise the release to install (if easily done).","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"a3db78f71a4d4f31c1a434e8782e80332529076e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"80f6dc2f_4adf8391","updated":"2024-04-12 10:13:47.000000000","message":"recheck grafan upstream apt repo problem should be fixed: https://github.com/grafana/grafana/issues/85827","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"5dbe2e19923b1894e89c5dc64721ab9082a239d0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"81e92aaf_07529e86","updated":"2024-04-15 06:14:13.000000000","message":"Approving to unblock CI, but I agree with Michal\u0027s concern, needs to be amended if it doesn\u0027t get reverted soon.\n\nAlso please remember to set RP+2 for gate fixes.","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"76286aec7701a2a9f728474e72867a502f51d6d0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"9a127dbc_ef5139da","updated":"2024-04-15 14:42:33.000000000","message":"Does this need to be backported?","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"2b9c74f2e0df9a5b29b31818f856f8ad0c484d35","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"55900d0a_9b1ed720","updated":"2024-04-15 16:52:47.000000000","message":"We can\u0027t backport this. You\u0027ll get a trackback explaining that the old version of OpenSearch can\u0027t read the data. Eg.\n\n```\nCaused by: org.apache.lucene.index.IndexFormatTooNewException: Format version is not supported (resource BufferedChecksumIndexInput(NIOFSIndexInput(path\u003d\"/var/lib/opensearch/data/nodes/0/_state/_q.cfs\") [slice\u003d_q.fnm])): 1 (needs to be between 0 and 0)\n```","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"277243de9d652c4bcf0c1f94d4a7940b9bf00752","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"6079d676_f956a735","updated":"2024-04-15 16:41:27.000000000","message":"afaik https://review.opendev.org/#/q/Id9c7e59e6ae1dd98176c68b14a2aff1985306751 should be backported ?","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"aa1999cadfea4a5bb1f3cf1e714086e369ca2fae","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"05ae0128_3b89872c","in_reply_to":"6079d676_f956a735","updated":"2024-04-15 16:55:20.000000000","message":"Agree, that should be backported (and is low risk).","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"92a0adddca80a2c52112675ba0ae54bf256fc11a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"6447c24c_f96a29a1","in_reply_to":"9a127dbc_ef5139da","updated":"2024-04-15 16:30:55.000000000","message":"Sven set -1 for backport as I can see.","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"}],"docker/base/apt_preferences.debian":[{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"796f3a4387bcec0be0c53c8c60a20083d7e6c7c4","unresolved":true,"context_lines":[{"line_number":11,"context_line":"Pin: release n\u003dbookworm-backports"},{"line_number":12,"context_line":"Pin-Priority: -1000"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"# NOTE (SvenKieske): pin until we have proper authentication"},{"line_number":15,"context_line":"# between haproxy and opensearch-dashboard in CI"},{"line_number":16,"context_line":"# see bug https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":17,"context_line":"Package: opensearch*"}],"source_content_type":"application/octet-stream","patch_set":4,"id":"bdd74e65_2150b1da","line":14,"updated":"2024-04-12 10:31:12.000000000","message":"I think we should go one step further and pin it indefinitely. There was another recent issue with the new discover UI, which became mandatory (and less functional). This was then reverted in a later release [1]. \n\n[1] https://github.com/opensearch-project/OpenSearch-Dashboards/pull/5789","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"ddde66f27587563536f8b84b2e1b2cd62a915c3a","unresolved":true,"context_lines":[{"line_number":11,"context_line":"Pin: release n\u003dbookworm-backports"},{"line_number":12,"context_line":"Pin-Priority: -1000"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"# NOTE (SvenKieske): pin until we have proper authentication"},{"line_number":15,"context_line":"# between haproxy and opensearch-dashboard in CI"},{"line_number":16,"context_line":"# see bug https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":17,"context_line":"Package: opensearch*"}],"source_content_type":"application/octet-stream","patch_set":4,"id":"6666ddcc_953f089f","line":14,"in_reply_to":"afb0bed0_3f804521","updated":"2024-04-12 16:13:40.000000000","message":"I take your point about security patches. I\u0027d assumed they would come in patch releases, but it appears not. We have no option but to sign up for the ride.","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"654491b7b97ac1cf8bed3cee6c4e8ba1c1654491","unresolved":true,"context_lines":[{"line_number":11,"context_line":"Pin: release n\u003dbookworm-backports"},{"line_number":12,"context_line":"Pin-Priority: -1000"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"# NOTE (SvenKieske): pin until we have proper authentication"},{"line_number":15,"context_line":"# between haproxy and opensearch-dashboard in CI"},{"line_number":16,"context_line":"# see bug https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":17,"context_line":"Package: opensearch*"}],"source_content_type":"application/octet-stream","patch_set":4,"id":"afb0bed0_3f804521","line":14,"in_reply_to":"bdd74e65_2150b1da","updated":"2024-04-12 13:47:37.000000000","message":"we need to keep in mind that we are using upstream repositories here, so as long as they don\u0027t pull old versions from the repo, we are fine and can ping the software longer, from a technical perspective.\n\nFrom what I looked at, this does not seem to be the case. But I still think it\u0027s important to keep this in mind.\n\nBut, as mentioned in the linked bug report by me, this release fixes some CVEs[1].\nI didn\u0027t analyze those, but in general I don\u0027t think pinning any software to any version is a long term solution when it comes to necessary security updates, especially so if said software offers a service that is reachable via a network.\n\n[1]: https://bugs.launchpad.net/kolla/+bug/2060668/comments/2","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"}],"docker/opensearch/opensearch-dashboards/Dockerfile.j2":[{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"796f3a4387bcec0be0c53c8c60a20083d7e6c7c4","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# (SvenKieske): Workaround for https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":14,"context_line":"{% if base_package_type \u003d\u003d \u0027rpm\u0027 %}"},{"line_number":15,"context_line":"RUN dnf -y install \u0027dnf-command(versionlock)\u0027 \u0026\u0026 \\"},{"line_number":16,"context_line":"    dnf versionlock add opensearch-dashboards-0:2.12.0-1"},{"line_number":17,"context_line":"{% endif %}"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"{% set opensearch_dashboards_packages \u003d [\u0027opensearch-dashboards\u0027] %}"}],"source_content_type":"text/x-jinja2","patch_set":4,"id":"69691124_1d51aae6","line":16,"updated":"2024-04-12 10:31:12.000000000","message":"Can you pin it to allow new patch releases? `2.12.*`? See [1]\n\n[1] https://dnf-plugins-core.readthedocs.io/en/latest/versionlock.html#options","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"654491b7b97ac1cf8bed3cee6c4e8ba1c1654491","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# (SvenKieske): Workaround for https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":14,"context_line":"{% if base_package_type \u003d\u003d \u0027rpm\u0027 %}"},{"line_number":15,"context_line":"RUN dnf -y install \u0027dnf-command(versionlock)\u0027 \u0026\u0026 \\"},{"line_number":16,"context_line":"    dnf versionlock add opensearch-dashboards-0:2.12.0-1"},{"line_number":17,"context_line":"{% endif %}"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"{% set opensearch_dashboards_packages \u003d [\u0027opensearch-dashboards\u0027] %}"}],"source_content_type":"text/x-jinja2","patch_set":4,"id":"f88e3da4_21e906d1","line":16,"in_reply_to":"69691124_1d51aae6","updated":"2024-04-12 13:47:37.000000000","message":"sure, but given that CVEs seem to only be fixed(?) in new minor releases I doubt there will be a new patch release, but it surely doesn\u0027t hurt.","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"2e1131c281fa08e2de34b437eea584362d9640c5","unresolved":false,"context_lines":[{"line_number":13,"context_line":"# (SvenKieske): Workaround for https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":14,"context_line":"{% if base_package_type \u003d\u003d \u0027rpm\u0027 %}"},{"line_number":15,"context_line":"RUN dnf -y install \u0027dnf-command(versionlock)\u0027 \u0026\u0026 \\"},{"line_number":16,"context_line":"    dnf versionlock add opensearch-dashboards-0:2.12.0-1"},{"line_number":17,"context_line":"{% endif %}"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"{% set opensearch_dashboards_packages \u003d [\u0027opensearch-dashboards\u0027] %}"}],"source_content_type":"text/x-jinja2","patch_set":4,"id":"a5c14531_0a52fe92","line":16,"in_reply_to":"f88e3da4_21e906d1","updated":"2024-04-12 13:52:17.000000000","message":"Done","commit_id":"e9ec425544be2cd6d0adda7a4a9bd667e38b661e"},{"author":{"_account_id":22629,"name":"Michal Nasiadka","email":"mnasiadka@gmail.com","username":"mnasiadka"},"change_message_id":"9229e00cb6689cf824ff5d4cfcec2c16fa10b559","unresolved":true,"context_lines":[{"line_number":12,"context_line":""},{"line_number":13,"context_line":"# (SvenKieske): Workaround for https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":14,"context_line":"{% if base_package_type \u003d\u003d \u0027rpm\u0027 %}"},{"line_number":15,"context_line":"RUN dnf -y install \u0027dnf-command(versionlock)\u0027 \u0026\u0026 \\"},{"line_number":16,"context_line":"    dnf versionlock add  --raw \u0027opensearch-dashboards-0:2.12.*\u0027"},{"line_number":17,"context_line":"{% endif %}"},{"line_number":18,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"aba6ee89_bd02bc66","line":15,"updated":"2024-04-12 13:59:47.000000000","message":"do we really need versionlock? nobody is going to update that after build\nWe usually just used version number in package name - e.g. opensearch-2.12.* and it worked","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"},{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"ddde66f27587563536f8b84b2e1b2cd62a915c3a","unresolved":true,"context_lines":[{"line_number":12,"context_line":""},{"line_number":13,"context_line":"# (SvenKieske): Workaround for https://bugs.launchpad.net/kolla/+bug/2060668"},{"line_number":14,"context_line":"{% if base_package_type \u003d\u003d \u0027rpm\u0027 %}"},{"line_number":15,"context_line":"RUN dnf -y install \u0027dnf-command(versionlock)\u0027 \u0026\u0026 \\"},{"line_number":16,"context_line":"    dnf versionlock add  --raw \u0027opensearch-dashboards-0:2.12.*\u0027"},{"line_number":17,"context_line":"{% endif %}"},{"line_number":18,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":5,"id":"6c4ba9a8_83956df0","line":15,"in_reply_to":"aba6ee89_bd02bc66","updated":"2024-04-12 16:13:40.000000000","message":"Agree, although I suppose we are going to revert this sooner or later.","commit_id":"19a004e0a500ea4839fa1e089e1c50c953cec3b3"}]}
