dustymabe changed the topic of #fedora-coreos to: Fedora CoreOS :: Find out more at https://getfedora.org/coreos/ :: Logs at https://libera.irclog.whitequark.org/fedora-coreos
ravanelli has joined #fedora-coreos
mnguyen has quit [Ping timeout: 246 seconds]
ravanelli has quit [Remote host closed the connection]
jlebon has quit [Quit: leaving]
ravanelli has joined #fedora-coreos
ravanelli has quit [Ping timeout: 255 seconds]
fifofonix has quit [Ping timeout: 272 seconds]
misuto has quit [Remote host closed the connection]
misuto has joined #fedora-coreos
bytehackr has joined #fedora-coreos
saroy has joined #fedora-coreos
bytehackr has quit [Ping timeout: 272 seconds]
paragan has joined #fedora-coreos
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 246 seconds]
bgilbert has quit [Ping timeout: 272 seconds]
bgilbert has joined #fedora-coreos
bgilbert has quit [Ping timeout: 255 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 272 seconds]
jpn has joined #fedora-coreos
jcajka has joined #fedora-coreos
poppajarv has quit [Ping timeout: 272 seconds]
jpn has quit [Ping timeout: 255 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 255 seconds]
jpn has joined #fedora-coreos
saschagrunert has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
saschagrunert has quit [Remote host closed the connection]
saschagrunert has joined #fedora-coreos
<lucab> jlebon: cincinnati deployment updated without issues
Betal has quit [Quit: WeeChat 3.7.1]
c4rt0 has joined #fedora-coreos
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 272 seconds]
jpn has joined #fedora-coreos
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
mnguyen has joined #fedora-coreos
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
paragan has quit [Ping timeout: 248 seconds]
paragan has joined #fedora-coreos
vgoyal has joined #fedora-coreos
fifofonix has joined #fedora-coreos
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
ravanelli has quit [Remote host closed the connection]
saschagrunert has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
crobinso has joined #fedora-coreos
jlebon has joined #fedora-coreos
nb has quit [Quit: Ping timeout (120 seconds)]
paragan has quit [Ping timeout: 248 seconds]
nb has joined #fedora-coreos
paragan has joined #fedora-coreos
dustymabe has quit [Read error: Connection reset by peer]
nalind has joined #fedora-coreos
dustymabe has joined #fedora-coreos
plarsen has joined #fedora-coreos
poppajarv has joined #fedora-coreos
<dustymabe> jlebon: can I get a review on https://github.com/coreos/fedora-coreos-config/pull/2063 ?
mheon has joined #fedora-coreos
<jlebon> dustymabe: stamped
<dustymabe> and the subsequent change: https://github.com/openshift/os/pull/1055
ravanelli has quit [Remote host closed the connection]
ravanelli has joined #fedora-coreos
jcajka has quit [Quit: Leaving]
paragan has quit [Ping timeout: 272 seconds]
paragan has joined #fedora-coreos
<guesswhat> Any idea how to set systemctl set-property init.scope AllowedCPUs=0-2 && systemctl set-property system.slice AllowedCPUs=0-2 && systemctl set-property user.slice AllowedCPUs=0-2 ?
<guesswhat> Seems it wont be effective via Ignition storage file, can I set this as soon as possible ? maybe one shot systemd unit ?
paragan has quit [Ping timeout: 248 seconds]
paragan has joined #fedora-coreos
paragan has quit [Max SendQ exceeded]
paragan has joined #fedora-coreos
paragan has quit [Ping timeout: 246 seconds]
bgilbert has joined #fedora-coreos
c4rt0 has quit [Read error: Connection reset by peer]
<dustymabe> jlebon: drop me a link when each FCOS pipeline PR is ready for another round of review. Ideally we'll tackle them in the order they are in in your local dev branch.
jbrooks has quit [Quit: Ex-Chat]
<jlebon> +1
* jlebon goes for food
<bgilbert> cverna: +1
gursewak_ has quit [Ping timeout: 255 seconds]
<bgilbert> so the remaining OpenSSL container updates are coreos-installer and possibly Butane
<bgilbert> recent Butane containers are based on fedora-minimal because of https://github.com/coreos/butane/pull/338, basically just so bash exists. Butane doesn't make any network requests, and is Go so it doesn't use OpenSSL. do folks think we should update the container anyway?
<bgilbert> this is relevant because
<dustymabe> bgilbert: if the assessment is that we should be safe then don't worry about it
<bgilbert> 2) how should we update the :release tags? I really don't want to do an upstream release for this. should we treat the most recent versioned tag as mutable and update it? or maybe re-push `release` but decouple it from the versioned tag?
<bgilbert> ^ for coreos-installer and potentially Butane
<bgilbert> I might lean keeping the versioned tags immutable (for example, we're not going to go update old versioned tags with new OpenSSL), and just repushing `release`
<bgilbert> `release` is what we actually tell people to use, and we have an established history of moving the tag
gursewak_ has joined #fedora-coreos
<dustymabe> based on your assessment do we need to do anything for this issue. i.e. are you talking about what policy we should adopt in the future?
<bgilbert> for coreos-installer we do need to update. it does HTTPS fetches using OpenSSL
<dustymabe> ahh ok
<dustymabe> yeah updating release is fine with me
<bgilbert> a general policy decision wouldn't hurt, though. in principle Butane might support HTTPS and then we'd need to update for Go CVEs
<jlebon> bgilbert: would it make sense to have a e.g. :v0.16.1-1 tag and alias :release to that?
<jlebon> that way people who want to stay on a versioned tag don't have to fallback to :release
<bgilbert> yeah, probably
<bgilbert> but that wouldn't be a Git tag, right?
<jlebon> i was thinking purely a quay.io tag thing
<jlebon> but if it helps with ops, sure
<bgilbert> I don't like adding a Git tag for it, but that'll require an actions-lib change
<bgilbert> which is the Right Thing, sigh. okay, on it
hiredman has quit [Ping timeout: 246 seconds]
saroy has quit [Quit: Leaving]
gursewak_ has quit [Ping timeout: 268 seconds]
jpn has quit [Ping timeout: 276 seconds]
jpn has joined #fedora-coreos
gursewak has joined #fedora-coreos
jpn has quit [Ping timeout: 246 seconds]
jpn has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
<dustymabe> jlebon: the image build for COSA 4.10 is failing in various places in CI with
<dustymabe> [2022-11-04T20:10:53.981Z] go: finding module for package gopkg.in/alecthomas/kingpin.v2
<dustymabe> [2022-11-04T20:10:53.981Z] pkg/mod/github.com/idubinskiy/schematyper@v0.0.0-20190118213059-f71b40dac30d/generator.go:17:2: cannot find module providing package gopkg.in/alecthomas/kingpin.v2: unrecognized import path "gopkg.in/alecthomas/kingpin.v2": reading https://gopkg.in/alecthomas/kingpin.v2?go-get=1: 502 Bad Gateway
<dustymabe> anyone seen that before?
<jlebon> dustymabe: hmm, it looks like network flake, but odd that it's consistent. i wonder if it could be f35 vs f36, e.g. maybe the go version somehow
<dustymabe> it's definitely consistent
<dustymabe> 4.10 was last build on september 15
<jlebon> would be interesting to see if build-cosa hits this too
<dustymabe> yep it does
<dustymabe> that's where I pulled the logs I pasted above
<dustymabe> i'm doing some hackery to accelerate my testing of backports
<jlebon> ok fun
<jlebon> and that repo hasn't changed in years actually (https://github.com/idubinskiy/schematyper)
<dustymabe> looiks like around sep 12 there was this PR in cosa: 484c148
<jlebon> hmm the "Uptime report" link on the gopkg.in website is a dead link
<jlebon> that does not inspire confidence
<jlebon> yeah, might be simplest to try to backport that. the build itself shouldn't need to run schematyper
jpn has joined #fedora-coreos
<dustymabe> backporting proved to be painful - i just added a new commit that dropped it from the makefile
nalind has quit [Quit: bye for now]
<dustymabe> jlebon: any more PRs you ready for me to look at?
<jlebon> testing one last thing, but the validation bits are tested
<jlebon> dustymabe: were you planning to update https://github.com/coreos/coreos-assembler/pull/3162 ?
vgoyal has quit [Quit: Leaving]
<dustymabe> yeah i'll get back around to them
<dustymabe> been hacking on backports for 4.10
<dustymabe> finally got it building with the nuclear option
<dustymabe> 1,439,378 deletions
<jlebon> ouuff wow
<jlebon> dustymabe: replied in the pipeline PR
<dustymabe> approved
<dustymabe> I don't think so, but any changes needed to the config for that one?
<jlebon> thanks! yeah, no change needed
<jlebon> have a good weekend all!
mheon has quit [Ping timeout: 255 seconds]
nb has quit [Ping timeout: 268 seconds]
nb has joined #fedora-coreos
jpn has quit [Ping timeout: 248 seconds]
jpn has joined #fedora-coreos
crobinso has quit [Remote host closed the connection]
jlebon has quit [Quit: leaving]
ravanelli has quit [Remote host closed the connection]
jpn has quit [Ping timeout: 248 seconds]