Skip to content

Conversation

@miabbott
Copy link
Member

The mitigation path for OCP customers is to reprovision nodes, so we
should bump the boot images on the installer as well.

@openshift-ci-robot openshift-ci-robot added bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. labels Jul 30, 2020
@openshift-ci-robot
Copy link
Contributor

@miabbott: This pull request references Bugzilla bug 1862111, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target release (4.6.0) matches configured target release for branch (4.6.0)
  • bug is in the state NEW, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)
Details

In response to this:

Bug 1862111: bump RHCOS images for CVE-2020-10713

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@miabbott
Copy link
Member Author

miabbott commented Jul 30, 2020

$ ./differ.py -fe api.ci -fr rhcos-4.6/46.82.202007212240-0 -se api.ci -sr rhcos-4.6/46.82.202007291847-0
{
    "sources": {
        "rhcos-4.6/46.82.202007212240-0": "https://releases-art-rhcos.svc.ci.openshift.org/art/storage/releases/rhcos-4.6/46.82.202007212240-0/x86_64/commitmeta.json",
        "rhcos-4.6/46.82.202007291847-0": "https://releases-art-rhcos.svc.ci.openshift.org/art/storage/releases/rhcos-4.6/46.82.202007291847-0/x86_64/commitmeta.json"
    },
    "diff": {
        "NetworkManager": {
            "rhcos-4.6/46.82.202007212240-0": "NetworkManager-1.22.8-5.el8_2.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "NetworkManager-1.22.8-6.el8_2.x86_64"
        },
        "NetworkManager-libnm": {
            "rhcos-4.6/46.82.202007212240-0": "NetworkManager-libnm-1.22.8-5.el8_2.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "NetworkManager-libnm-1.22.8-6.el8_2.x86_64"
        },
        "NetworkManager-ovs": {
            "rhcos-4.6/46.82.202007212240-0": "NetworkManager-ovs-1.22.8-5.el8_2.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "NetworkManager-ovs-1.22.8-6.el8_2.x86_64"
        },
        "NetworkManager-team": {
            "rhcos-4.6/46.82.202007212240-0": "NetworkManager-team-1.22.8-5.el8_2.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "NetworkManager-team-1.22.8-6.el8_2.x86_64"
        },
        "NetworkManager-tui": {
            "rhcos-4.6/46.82.202007212240-0": "NetworkManager-tui-1.22.8-5.el8_2.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "NetworkManager-tui-1.22.8-6.el8_2.x86_64"
        },
        "conmon": {
            "rhcos-4.6/46.82.202007212240-0": "conmon-2.0.17-1.rhaos4.5.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "conmon-2.0.20-1.rhaos4.6.el8.x86_64"
        },
        "coreos-installer": {
            "rhcos-4.6/46.82.202007212240-0": "coreos-installer-0.2.0-4.rhaos4.6.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "coreos-installer-0.4.0-1.rhaos4.6.el8.x86_64"
        },
        "coreos-installer-systemd": {
            "rhcos-4.6/46.82.202007212240-0": "coreos-installer-systemd-0.2.0-4.rhaos4.6.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "Not present"
        },
        "cri-o": {
            "rhcos-4.6/46.82.202007212240-0": "cri-o-1.19.0-41.rhaos4.6.git988f60e.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "cri-o-1.19.0-53.rhaos4.6.git1f9d304.el8.x86_64"
        },
        "grub2-common": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-common-2.02-82.el8_2.1.noarch",
            "rhcos-4.6/46.82.202007291847-0": "grub2-common-2.02-87.el8_2.noarch"
        },
        "grub2-efi-x64": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-efi-x64-2.02-82.el8_2.1.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "grub2-efi-x64-2.02-87.el8_2.x86_64"
        },
        "grub2-pc": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-pc-2.02-82.el8_2.1.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "grub2-pc-2.02-87.el8_2.x86_64"
        },
        "grub2-pc-modules": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-pc-modules-2.02-82.el8_2.1.noarch",
            "rhcos-4.6/46.82.202007291847-0": "grub2-pc-modules-2.02-87.el8_2.noarch"
        },
        "grub2-tools": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-tools-2.02-82.el8_2.1.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "grub2-tools-2.02-87.el8_2.x86_64"
        },
        "grub2-tools-extra": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-tools-extra-2.02-82.el8_2.1.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "grub2-tools-extra-2.02-87.el8_2.x86_64"
        },
        "grub2-tools-minimal": {
            "rhcos-4.6/46.82.202007212240-0": "grub2-tools-minimal-2.02-82.el8_2.1.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "grub2-tools-minimal-2.02-87.el8_2.x86_64"
        },
        "ignition": {
            "rhcos-4.6/46.82.202007212240-0": "ignition-2.3.0-1.rhaos4.6.gitee616d5.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "ignition-2.5.0-1.rhaos4.6.git0d6f3e5.el8.x86_64"
        },
        "openshift-clients": {
            "rhcos-4.6/46.82.202007212240-0": "openshift-clients-4.6.0-202007212120.p0.git.3658.e2f0cb0.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "openshift-clients-4.6.0-202007290214.p0.git.3679.02da520.el8.x86_64"
        },
        "openshift-hyperkube": {
            "rhcos-4.6/46.82.202007212240-0": "openshift-hyperkube-4.6.0-202007110420.p1.git.0.4de1d1d.el8.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "openshift-hyperkube-4.6.0-202007291437.p0.git.93394.55d8983.el8.x86_64"
        },
        "openvswitch2.13": {
            "rhcos-4.6/46.82.202007212240-0": "openvswitch2.13-2.13.0-39.el8fdp.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "openvswitch2.13-2.13.0-48.el8fdp.x86_64"
        },
        "shim-x64": {
            "rhcos-4.6/46.82.202007212240-0": "shim-x64-15-11.x86_64",
            "rhcos-4.6/46.82.202007291847-0": "shim-x64-15-14.el8_2.x86_64"
        },
        "coreos-installer-bootinfra": {
            "rhcos-4.6/46.82.202007212240-0": "Not present",
            "rhcos-4.6/46.82.202007291847-0": "coreos-installer-bootinfra-0.4.0-1.rhaos4.6.el8.x86_64"
        },
        "openssl-pkcs11": {
            "rhcos-4.6/46.82.202007212240-0": "Not present",
            "rhcos-4.6/46.82.202007291847-0": "openssl-pkcs11-0.4.10-2.el8.x86_64"
        }
    }
}

@miabbott
Copy link
Member Author

/test verify-codegen

@cgwalters
Copy link
Member

/approve
Changes look right to me.

@miabbott
Copy link
Member Author

/hold

While we've tested that booting this RHCOS version via qemu using Secure Boot is successful, there are reports of problems booting with the grub2 mitigation in place - https://bugzilla.redhat.com/show_bug.cgi?id=1861977

I'm going to tentatively hold this until we have more confidence

@openshift-ci-robot openshift-ci-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 30, 2020
The mitigation path for OCP customers is to reprovision nodes, so we
should bump the boot images on the installer as well.
@miabbott
Copy link
Member Author

miabbott commented Aug 3, 2020

/unhold

The new RHCOS build includes the fix to shim that addresses BZ#1861977.

Additionally, it notably gained a new coreos-installer and toolbox.

$ ./differ.py -fe api.ci -fr rhcos-4.6/46.82.202007291847-0 -se api.ci -sr rhcos-4.6/46.82.202008030340-0
{
    "sources": {
        "rhcos-4.6/46.82.202007291847-0": "https://releases-art-rhcos.svc.ci.openshift.org/art/storage/releases/rhcos-4.6/46.82.202007291847-0/x86_64/commitmeta.json",
        "rhcos-4.6/46.82.202008030340-0": "https://releases-art-rhcos.svc.ci.openshift.org/art/storage/releases/rhcos-4.6/46.82.202008030340-0/x86_64/commitmeta.json"
    },
    "diff": {
        "containers-common": {
            "rhcos-4.6/46.82.202007291847-0": "containers-common-1.0.0-1.module+el8.2.1+6676+604e1b26.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "containers-common-1.1.1-2.rhaos4.6.el8.x86_64"
        },
        "coreos-installer": {
            "rhcos-4.6/46.82.202007291847-0": "coreos-installer-0.4.0-1.rhaos4.6.el8.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "coreos-installer-0.5.0-1.rhaos4.6.el8.x86_64"
        },
        "coreos-installer-bootinfra": {
            "rhcos-4.6/46.82.202007291847-0": "coreos-installer-bootinfra-0.4.0-1.rhaos4.6.el8.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "coreos-installer-bootinfra-0.5.0-1.rhaos4.6.el8.x86_64"
        },
        "cri-o": {
            "rhcos-4.6/46.82.202007291847-0": "cri-o-1.19.0-53.rhaos4.6.git1f9d304.el8.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "cri-o-1.19.0-61.rhaos4.6.git79c1228.el8.x86_64"
        },
        "openshift-clients": {
            "rhcos-4.6/46.82.202007291847-0": "openshift-clients-4.6.0-202007290214.p0.git.3679.02da520.el8.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "openshift-clients-4.6.0-202008011451.p0.git.3685.3939f2f.el8.x86_64"
        },
        "openshift-hyperkube": {
            "rhcos-4.6/46.82.202007291847-0": "openshift-hyperkube-4.6.0-202007291437.p0.git.93394.55d8983.el8.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "openshift-hyperkube-4.6.0-202008011154.p0.git.93402.577b186.el8.x86_64"
        },
        "openvswitch2.13": {
            "rhcos-4.6/46.82.202007291847-0": "openvswitch2.13-2.13.0-48.el8fdp.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "openvswitch2.13-2.13.0-49.el8fdp.x86_64"
        },
        "shim-x64": {
            "rhcos-4.6/46.82.202007291847-0": "shim-x64-15-14.el8_2.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "shim-x64-15-15.el8_2.x86_64"
        },
        "skopeo": {
            "rhcos-4.6/46.82.202007291847-0": "skopeo-1.0.0-1.module+el8.2.1+6676+604e1b26.x86_64",
            "rhcos-4.6/46.82.202008030340-0": "skopeo-1.1.1-2.rhaos4.6.el8.x86_64"
        },
        "toolbox": {
            "rhcos-4.6/46.82.202007291847-0": "toolbox-0.0.7-1.rhaos4.5.el8.noarch",
            "rhcos-4.6/46.82.202008030340-0": "toolbox-0.0.8-1.rhaos4.6.el8.noarch"
        }
    }
}

@openshift-ci-robot openshift-ci-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Aug 3, 2020
@cgwalters
Copy link
Member

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Aug 3, 2020
@miabbott
Copy link
Member Author

miabbott commented Aug 4, 2020

e2e-openstack has been mostly red for the last 48h, so I don't believe this change is causing the failure there.

e2e-aws-fips has known problems, see openshift/release#10488 and openshift/origin#25362 and openshift/release#10653

e2e-libvirt appears to be pretty flaky; not convinced this change is causing the failure

e2e-metal-ipi has been mostly red in the last 48h; doesn't appear related to this change

e2e-ovirt has been completely red the last 48h; doesn't appear related to this change

e2e-crc has been completely red the last 48h; doesn't appear related to this change

@cgwalters
Copy link
Member

Agree, let's ship this.

@miabbott
Copy link
Member Author

miabbott commented Aug 5, 2020

@abhinavdahiya @sdodson Could one of you have a look here? We like to get this landed so we can land the other boot image bumps for 4.5.z, 4.4.z, and 4.3.z

@sdodson
Copy link
Member

sdodson commented Aug 5, 2020

/test e2e-ovirt
/test e2e-vsphere
/test e2e-gcp

@sdodson
Copy link
Member

sdodson commented Aug 5, 2020

I agree ovirt and libvirt are not providing meaningful signal. Openstack however does seem to at least make it past installation a fair amount so giving it one more shot. GCP wasn't run so running that once.

@sdodson
Copy link
Member

sdodson commented Aug 5, 2020

vSphere died on dns config before install happened, seems common infra problem amongst recent runs.
OpenStack folks are aware of other critical failures going on at this time so lets move forward.
/lgtm
/approve

@openshift-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: cgwalters, sdodson

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 5, 2020
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

3 similar comments
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

1 similar comment
@openshift-bot
Copy link
Contributor

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-ci-robot
Copy link
Contributor

@miabbott: The following tests failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/prow/e2e-libvirt b3c2656 link /test e2e-libvirt
ci/prow/e2e-crc b3c2656 link /test e2e-crc
ci/prow/e2e-vsphere b3c2656 link /test e2e-vsphere
ci/prow/e2e-aws-fips b3c2656 link /test e2e-aws-fips
ci/prow/e2e-ovirt b3c2656 link /test e2e-ovirt
ci/prow/e2e-openstack b3c2656 link /test e2e-openstack
ci/prow/e2e-aws-workers-rhel7 b3c2656 link /test e2e-aws-workers-rhel7
ci/prow/e2e-metal-ipi b3c2656 link /test e2e-metal-ipi

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@openshift-merge-robot openshift-merge-robot merged commit 17ef09d into openshift:master Aug 5, 2020
@openshift-ci-robot
Copy link
Contributor

@miabbott: All pull requests linked via external trackers have merged: openshift/installer#3983. Bugzilla bug 1862111 has been moved to the MODIFIED state.

Details

In response to this:

Bug 1862111: bump RHCOS images for CVE-2020-10713

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. bugzilla/severity-medium Referenced Bugzilla bug's severity is medium for the branch this PR is targeting. bugzilla/valid-bug Indicates that a referenced Bugzilla bug is valid for the branch this PR is targeting. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants