)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"a78d9b34fce1c21805deecddf3dbd6be4b003cd5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f161b161_411c71fe","updated":"2026-08-13 19:59:25.000000000","message":"LGTM, please merge if you think Ironic folks are okay with it","commit_id":"9e30a58d326dcba3d371838628a122c38a01be02"}],"security-notes/OSSN-0107":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"b6e8ba1a5087fb53fdfd2418903486c80ca1ded0","unresolved":true,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"This initial implementation had several security flaws and was"},{"line_number":27,"context_line":"implemented in such a way that we could not backport fixes without"},{"line_number":28,"context_line":"breaking existing use cases. These issues included ignoring"},{"line_number":29,"context_line":"the value of the ``[container]/allow_arbitrary_containers`` safety"},{"line_number":30,"context_line":"mechanism."},{"line_number":31,"context_line":""}],"source_content_type":"application/octet-stream","patch_set":2,"id":"d3927985_b54e8031","line":28,"updated":"2026-08-12 22:46:15.000000000","message":"s/use cases/deployments/","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"26b0a3209b8a770aa506a2f85991144024b6e460","unresolved":false,"context_lines":[{"line_number":25,"context_line":""},{"line_number":26,"context_line":"This initial implementation had several security flaws and was"},{"line_number":27,"context_line":"implemented in such a way that we could not backport fixes without"},{"line_number":28,"context_line":"breaking existing use cases. These issues included ignoring"},{"line_number":29,"context_line":"the value of the ``[container]/allow_arbitrary_containers`` safety"},{"line_number":30,"context_line":"mechanism."},{"line_number":31,"context_line":""}],"source_content_type":"application/octet-stream","patch_set":2,"id":"4398180b_236f90f5","line":28,"in_reply_to":"d3927985_b54e8031","updated":"2026-08-13 19:54:19.000000000","message":"Done","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"450a3f72612de613cbb7a7ad041648b82ec09019","unresolved":true,"context_lines":[{"line_number":37,"context_line":"  the fixed version in OpenStack 2026.2 or later."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"* Operators who are using ramdisks with ``docker`` or ``podman``"},{"line_number":40,"context_line":"  installed, but are not interested in the Container HWM should"},{"line_number":41,"context_line":"  add ``deploy.container_clean_step`` and ``deploy.generic_container_step`` to"},{"line_number":42,"context_line":"  ``[api]/disallow_service_steps``, ``[api]/disallow_clean_steps``,"},{"line_number":43,"context_line":"  and ``[api]/disallow_deploy_steps``. This will disable the insecure"}],"source_content_type":"application/octet-stream","patch_set":2,"id":"c22f8982_d9a7c022","line":40,"updated":"2026-08-12 22:54:30.000000000","message":"is it worth adding here something like:\n\n  Operators who are using ramdisks with ``docker`` or ``podman`` installed (such as via the ironic-python-agent-podman ironic-python-agent-builder element)","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"26b0a3209b8a770aa506a2f85991144024b6e460","unresolved":false,"context_lines":[{"line_number":37,"context_line":"  the fixed version in OpenStack 2026.2 or later."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"* Operators who are using ramdisks with ``docker`` or ``podman``"},{"line_number":40,"context_line":"  installed, but are not interested in the Container HWM should"},{"line_number":41,"context_line":"  add ``deploy.container_clean_step`` and ``deploy.generic_container_step`` to"},{"line_number":42,"context_line":"  ``[api]/disallow_service_steps``, ``[api]/disallow_clean_steps``,"},{"line_number":43,"context_line":"  and ``[api]/disallow_deploy_steps``. This will disable the insecure"}],"source_content_type":"application/octet-stream","patch_set":2,"id":"11843f09_daac7bcd","line":40,"in_reply_to":"c22f8982_d9a7c022","updated":"2026-08-13 19:54:19.000000000","message":"Done","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"e4cac14a1dfbe2372ffb85206fcd86636e885176","unresolved":true,"context_lines":[{"line_number":41,"context_line":"  add ``deploy.container_clean_step`` and ``deploy.generic_container_step`` to"},{"line_number":42,"context_line":"  ``[api]/disallow_service_steps``, ``[api]/disallow_clean_steps``,"},{"line_number":43,"context_line":"  and ``[api]/disallow_deploy_steps``. This will disable the insecure"},{"line_number":44,"context_line":"  code."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"* Operators currently using the Container HWM or who wish to use"},{"line_number":47,"context_line":"  it should backport the patches from"}],"source_content_type":"application/octet-stream","patch_set":2,"id":"efab2811_5e4cc01a","line":44,"updated":"2026-08-12 22:45:39.000000000","message":"Should I link to https://security.openstack.org/ossa/OSSA-2026-025.html or the patch adding disallow_*_step in here?","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"26b0a3209b8a770aa506a2f85991144024b6e460","unresolved":false,"context_lines":[{"line_number":41,"context_line":"  add ``deploy.container_clean_step`` and ``deploy.generic_container_step`` to"},{"line_number":42,"context_line":"  ``[api]/disallow_service_steps``, ``[api]/disallow_clean_steps``,"},{"line_number":43,"context_line":"  and ``[api]/disallow_deploy_steps``. This will disable the insecure"},{"line_number":44,"context_line":"  code."},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"* Operators currently using the Container HWM or who wish to use"},{"line_number":47,"context_line":"  it should backport the patches from"}],"source_content_type":"application/octet-stream","patch_set":2,"id":"cc4aed81_e4424d9c","line":44,"in_reply_to":"efab2811_5e4cc01a","updated":"2026-08-13 19:54:19.000000000","message":"Done","commit_id":"b57803431109b4c896a2f101038e3ad970f32e16"}]}
