SDN-5544: Unpin libreswan version#1771
SDN-5544: Unpin libreswan version#1771openshift-merge-bot[bot] merged 1 commit intoopenshift:masterfrom
Conversation
|
/assign @zshi-redhat @huiran0826 |
|
/retest |
1 similar comment
|
/retest |
|
/hold i'm still testing the changes. |
| # pin to 4.6-3.el9_0.3 for now for https://issues.redhat.com/browse/OCPBUGS-43498 | ||
| # we can revert once that's fixed in latest libreswan | ||
| - libreswan-4.6-3.el9_0.3 | ||
| - libreswan-5.2-1.el9fdp |
There was a problem hiding this comment.
Instead of binding the version this way, we should just remove the pin here, i.e. remove the version. Once libreswan 5 is available in FDP, it will be automatically installed and we'll consume all the bug fixes automatically once they are available. Pinning a specific version is not a good long term solution.
|
/retest |
|
/assign @trozet |
This would enable to consume libreswan 5 version from FDP repository. Signed-off-by: Periyasamy Palanisamy <pepalani@redhat.com>
d14c6bd to
9bb575a
Compare
|
/hold cancel |
|
CI OKD failure looks unrelated /override ci/prow/okd-scos-e2e-aws-ovn /lgtm Do you have an associated Jira card with this? If so, can you add that in the title? |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: jlebon, pperiyasamy, travier The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@jlebon: Overrode contexts on behalf of jlebon: ci/prow/okd-scos-e2e-aws-ovn DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/hold |
|
@pperiyasamy: This pull request references SDN-5544 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.19.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
@jlebon sure, added the corresponding JIRA to the PR.
yes, we have libreswan 4.6 version pinning until OCP 4.14, so will have to backport this change all the way to 4.14. |
And I assume the risks of bumping to a new major version all the way back to 4.14 has been evaluated? |
For some context on the hold: |
@jlebon I thought access to libreswan 4.6 is removed completely for OCP, but as per @igsilya previous comment, this issue seems to be temporary. so let's test libreswan 5.2 with OCP 4.19 after this PR is merged, if everything is good, then we can think about backporting it, is that correct, @igsilya ? |
Yes, the 4.6 build should return to the rhocp repository somewhere soon (I see it already appeared in some of the versions). For the 5.2, the plan is to wait for the official build released in FDP (approx. Apr 3rd), then get it into 4.19, then we can let it soak for a bit, and then we'll need to backport this change all the way down to 4.14. The reason is that we want to move away from that specific 4.6 pinned build, as it is not sustainable to support it. It was just a hot fix for an immediate issue we had and it's not a long term solution. Note: Backporting to OCP 4.15 and 4.14 will also depend on #1774, because we need OVS 3.3 for compatibility with Libreswan 5. |
|
I can now see bot cluster is deploying libreswan 5.2 with this PR. |
|
Do we still need to hold this one? |
|
/label acknowledge-critical-fixes-only |
@jlebon sure, we can merge this PR now. need to open a followup PR in mco and need to get ovnk PR openshift/ovn-kubernetes#2498 to be merged as well. will do it ASAP. |
@pperiyasamy don't we need a "regex" fix first to avoid the connection wait service failures? Also, the errata is not released yet. I'd prefer if we just wait for the official process even if the unreleased libreswn-5.2 build is cross-tagged into OCP. |
Without "regex" fix, the connection wait service introduces 60s delay for the startup, overall not having a problem for ipsec upgrade. but anyway raised a PR now: openshift/machine-config-operator#4959.
sure, let's wait then. |
|
Think this is as official as it gets: |
@joepvd I'm a little lost, how is that related to libreswan? The mentioned CVE seems to be for some Go library. |
OK, AFAIU, it's mentioned because it was cross-tagged and it is in fact in the compose. But that's fine since we're not actually installing that package. False alarm. But I'm still not sure how these erratas are related to this PR otherwise. |
|
pre-merge test PR from build
|
|
OK, with the openshift/machine-config-operator#4959 merged, FDP errata https://errata.devel.redhat.com/advisory/147278 shipped and testing done in #1771 (comment) , let's remove the hold. /remove-hold |
|
@pperiyasamy: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
This would enable to consume libreswan 5 version from FDP repository.
https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=66972299