Skip to content

Conversation

@coreydaley
Copy link

No description provided.

@openshift-ci-robot
Copy link
Contributor

@coreydaley: No Bugzilla bug is referenced in the title of this pull request.
To reference a bug, add 'Bug XXX:' to the title of this pull request and request another bug refresh with /bugzilla refresh.

Details

In response to this:

bump(*)

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@coreydaley
Copy link
Author

/assign @adambkaplan

@coreydaley coreydaley changed the title bump(*) Bug 1889954: CVE-2020-8564 Dec 3, 2020
@openshift-ci-robot openshift-ci-robot added bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Dec 3, 2020
@openshift-ci-robot
Copy link
Contributor

@coreydaley: This pull request references Bugzilla bug 1889954, which is invalid:

  • expected dependent Bugzilla bug 1889956 to be in one of the following states: VERIFIED, RELEASE_PENDING, CLOSED (ERRATA), but it is NEW instead

Comment /bugzilla refresh to re-evaluate validity if changes to the Bugzilla bug are made, or edit the title of this pull request to link to a different bug.

Details

In response to this:

Bug 1889954: CVE-2020-8564

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@coreydaley
Copy link
Author

/retest

2 similar comments
@coreydaley
Copy link
Author

/retest

@coreydaley
Copy link
Author

/retest

@coreydaley
Copy link
Author

/bugzilla refresh

@openshift-ci-robot openshift-ci-robot added bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. and removed bugzilla/invalid-bug Indicates that a referenced Bugzilla bug is invalid for the branch this PR is targeting. labels Dec 8, 2020
@openshift-ci-robot
Copy link
Contributor

@coreydaley: This pull request references Bugzilla bug 1889954, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker.

6 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.4.z) matches configured target release for branch (4.4.z)
  • bug is in the state NEW, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)
  • dependent bug Bugzilla bug 1889956 is in the state VERIFIED, which is one of the valid states (VERIFIED, RELEASE_PENDING, CLOSED (ERRATA))
  • dependent Bugzilla bug 1889956 targets the "4.5.z" release, which is one of the valid target releases: 4.5.0, 4.5.z
  • bug has dependents
Details

In response to this:

/bugzilla refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

github.com/opencontainers/runc v1.0.0-rc9
github.com/opencontainers/runtime-spec v1.0.0
github.com/openshift/api v3.9.1-0.20191024142031-e89ff1fddcbe+incompatible
github.com/openshift/api v0.0.0-20200618202633-7192180f496a
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Where did this api bump come from? This appears to be from a later OpenShift release.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That is the latest commit in the release-4.4 branch of the openshift/api repository: openshift/api@7192180

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please indicate in the commit message that you are bumping openshift/api, and the reason for doing so. I assume you did this to get around an "invalid pseudo-version" error? I found something similar in a separate item I was iterating on.

Copy link
Contributor

@adambkaplan adambkaplan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please update the git commit message and PR description to provide more details.

github.com/opencontainers/runc v1.0.0-rc9
github.com/opencontainers/runtime-spec v1.0.0
github.com/openshift/api v3.9.1-0.20191024142031-e89ff1fddcbe+incompatible
github.com/openshift/api v0.0.0-20200618202633-7192180f496a
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please indicate in the commit message that you are bumping openshift/api, and the reason for doing so. I assume you did this to get around an "invalid pseudo-version" error? I found something similar in a separate item I was iterating on.

@adambkaplan
Copy link
Contributor

/approve

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Dec 16, 2020
bumping openshift/api to work around invalid pseudo-version issue
@coreydaley
Copy link
Author

Commit messages updated

@adambkaplan adambkaplan changed the title Bug 1889954: CVE-2020-8564 Bug 1889954: bump(*) to mitigate CVE-2020-8564 Dec 16, 2020
Copy link
Contributor

@adambkaplan adambkaplan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Dec 16, 2020
@wewang58
Copy link

/bugzilla cc-qa

@openshift-ci-robot
Copy link
Contributor

@wewang58: This pull request references Bugzilla bug 1889954, which is valid.

6 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.4.z) matches configured target release for branch (4.4.z)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)
  • dependent bug Bugzilla bug 1889956 is in the state CLOSED (ERRATA), which is one of the valid states (VERIFIED, RELEASE_PENDING, CLOSED (ERRATA))
  • dependent Bugzilla bug 1889956 targets the "4.5.z" release, which is one of the valid target releases: 4.5.0, 4.5.z
  • bug has dependents

Requesting review from QA contact:
/cc @wewang58

Details

In response to this:

/bugzilla cc-qa

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@wewang58
Copy link

/lgtm

@openshift-ci-robot
Copy link
Contributor

@wewang58: The label(s) qe-approved cannot be applied, because the repository doesn't have them

Details

In response to this:

/label qe-approved

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@wewang58
Copy link

wewang58 commented Jan 7, 2021

I see, The repo does not support qe-approve label

@russellb
Copy link

russellb commented Jan 8, 2021

(patch manager) If this is CVE related, the severity should probably be bumped? We typically only merge high/urgent in 4.4 right now

@crawford crawford added the cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. label Jan 21, 2021
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

11 similar comments
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@crawford
Copy link

crawford commented Jan 21, 2021

These failures seem to be pretty common. @coreydaley can you look into this?

[image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image [Top Level] [image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image "registry.redhat.io/rhscl/php-73-rhel7" should print the usage [Suite:openshift]
[image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image [Top Level] [image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image "registry.redhat.io/rhscl/python-27-rhel7" should print the usage [Suite:openshift] 

/hold

@openshift-ci-robot openshift-ci-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jan 21, 2021
@crawford crawford removed the cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. label Jan 21, 2021
@gabemontero
Copy link
Contributor

These failures seem to be pretty common. @coreydaley can you look into this?

[image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image [Top Level] [image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image "registry.redhat.io/rhscl/php-73-rhel7" should print the usage [Suite:openshift]
[image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image [Top Level] [image_ecosystem][Slow] openshift images should be SCL enabled  returning s2i usage when running the image "registry.redhat.io/rhscl/python-27-rhel7" should print the usage [Suite:openshift] 

/hold

ah ... if this PR is hitting that @coreydaley @crawford this was address in master/4.7 via an fix to the test in openshift/origin via openshift/origin#25799

to date it has only been backported to 4.6 via openshift/origin#25804

if we want to hold this on that test, vs. overriding it, we can add a 4.5 cherrypick to the 4.6 PR, get it merged, then do the 4.4 from the merged 4.5 PR

which way do you want to proceed @crawford ?

@crawford
Copy link

@gabemontero let's backport the test. Can you trigger those for me?

@gabemontero
Copy link
Contributor

@gabemontero let's backport the test. Can you trigger those for me?

openshift/origin#25816 up for 4.5 @crawford ... added assignments for requisite approve/lgtm and cherrypick for 4.4 in that PR

@crawford
Copy link

openshift/origin#25817 has merged.

/hold cancel

@openshift-ci-robot openshift-ci-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jan 22, 2021
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@crawford crawford added the cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. label Jan 22, 2021
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-merge-robot openshift-merge-robot merged commit cf54259 into openshift:release-4.4 Jan 22, 2021
@openshift-ci-robot
Copy link
Contributor

@coreydaley: All pull requests linked via external trackers have merged:

Bugzilla bug 1889954 has been moved to the MODIFIED state.

Details

In response to this:

Bug 1889954: bump(*) to mitigate CVE-2020-8564

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. cherry-pick-approved Indicates a cherry-pick PR into a release branch has been approved by the release branch manager. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants