<@marmijo:fedora.im>
16:34:17
!startmeeting fedora_coreos_meeting
<@meetbot:fedora.im>
16:34:19
Meeting started at 2025-02-19 16:34:17 UTC
<@meetbot:fedora.im>
16:34:19
The Meeting name is 'fedora_coreos_meeting'
<@marmijo:fedora.im>
16:34:23
!topic roll call
<@siosm:matrix.org>
16:34:30
!hi
<@zodbot:fedora.im>
16:34:32
TimothΓ©e Ravier (siosm) - he / him / his
<@ydesouza:matrix.org>
16:34:53
Hey, sorry. My internet desconnected for a while here.
<@jdoss:beeper.com>
16:35:04
!hi
<@zodbot:fedora.im>
16:35:06
Joe Doss (jdoss)
<@ydesouza:matrix.org>
16:35:12
!hi
<@zodbot:fedora.im>
16:35:14
No Fedora Accounts users have the @ydesouza:matrix.org Matrix Account defined
<@jdoss:beeper.com>
16:35:20
π
<@pragyanpoudyal:matrix.org>
16:35:21
!hi
<@zodbot:fedora.im>
16:35:23
Pragyan Poudyal (pragyan-poudyal)
<@marmijo:fedora.im>
16:35:31
Yasmin de Souza: π Feel free to host it if you want
<@hricky:fedora.im>
16:35:32
!hi
<@zodbot:fedora.im>
16:35:33
Hristo Marinov (hricky) - he / him / his
<@dustymabe:matrix.org>
16:35:35
!hi
<@zodbot:fedora.im>
16:35:37
Dusty Mabe (dustymabe) - he / him / his
<@ydesouza:matrix.org>
16:35:38
!hi
<@zodbot:fedora.im>
16:35:40
No Fedora Accounts users have the @ydesouza:matrix.org Matrix Account defined
<@jbtrystram:matrix.org>
16:35:47
!hi
<@zodbot:fedora.im>
16:35:49
Jean-Baptiste Trystram (jbtrystram) - he / him / his
<@ydesouza:matrix.org>
16:36:05
I am not sure why zodbot is giving this message. π
<@marmijo:fedora.im>
16:36:06
!hi
<@zodbot:fedora.im>
16:36:07
Michael Armijo (marmijo)
<@siosm:matrix.org>
16:36:14
You can set your matrix account at https://accounts.fedoraproject.org/
<@siosm:matrix.org>
16:36:20
to link it to your Fedora account
<@apiaseck:matrix.org>
16:36:56
!hi
<@zodbot:fedora.im>
16:36:58
Adam Piasecki (c4rt0) - he / him / his
<@ydesouza:matrix.org>
16:37:01
marmijo: could you run this while I am fixing this? Sorry about it.
<@marmijo:fedora.im>
16:37:15
Absolutely!
<@ydesouza:matrix.org>
16:37:28
Thanks! Sorry about it
<@marmijo:fedora.im>
16:37:34
Good morning/afternoon/evening everyone. Looks like we have most people here. I'll give it another minute
<@marmijo:fedora.im>
16:38:34
Alright, let's start
<@marmijo:fedora.im>
16:38:36
!topic Action items from last meeting
<@marmijo:fedora.im>
16:38:55
I see only one action from the last meeting:
<@marmijo:fedora.im>
16:38:56
jdoss to organize high bandwidth meeting with jlebon travier spresti and bri to discuss next steps for ignition/afterburn and proxmox static networking
<@jdoss:beeper.com>
16:39:14
Heck yeahhhh!
<@jdoss:beeper.com>
16:39:57
it is going to be a very proxmox time. Very exciting. Let me tell you.
<@marmijo:fedora.im>
16:40:12
I was out of the loop on this one. Did the meeting happen?
<@jdoss:beeper.com>
16:40:23
the meeting is Tomorrow if you want to join DM me your email.
<@marmijo:fedora.im>
16:40:32
perfect, I'll do that!
<@jdoss:beeper.com>
16:41:02
Thursday, February 20β
11:00am β 12:00pm Central US
<@jdoss:beeper.com>
16:41:09
5PM UTC
<@jlebon:fedora.im>
16:41:35
!hi
<@zodbot:fedora.im>
16:41:36
None (jlebon)
<@marmijo:fedora.im>
16:42:01
That's great. I actually have another meeting at that time, but I could try to catch up afterwards.
<@marmijo:fedora.im>
16:42:15
But if anyone else is interested, DM jdoss!
<@marmijo:fedora.im>
16:42:26
moving on
<@marmijo:fedora.im>
16:42:44
!topic Review Fedora 42 Release Schedule
<@marmijo:fedora.im>
16:42:53
!link https://fedorapeople.org/groups/schedule/f-42/f-42-key-tasks.html
<@marmijo:fedora.im>
16:43:19
We just passed the beta freeze event
<@dustymabe:matrix.org>
16:44:01
Correct. Which means we need to pay close attention to know when beta will get released
<@siosm:matrix.org>
16:44:29
Current target is Tue 2025-03-11
<@dustymabe:matrix.org>
16:44:29
!link https://qa.fedoraproject.org/blockerbugs/milestone/42/beta/buglist
<@siosm:matrix.org>
16:44:49
The GO/No-GO meeting determines if the Beta is Go
<@siosm:matrix.org>
16:45:00
it happens on Thursdays if I'm not mistaken
<@dustymabe:matrix.org>
16:45:13
Correct.
<@dustymabe:matrix.org>
16:45:36
Maybe we should find volunteers each week to attend (or at least keep an eye one it)
<@marmijo:fedora.im>
16:45:51
Early target is 2025-03-11
<@marmijo:fedora.im>
16:45:51
Some dates from the schedule:
<@marmijo:fedora.im>
16:45:51
while "Target Date 1" is a week later: 2025-03-18
<@marmijo:fedora.im>
16:46:33
Anyone want to volunteer to watch the go/no-go meeting as we move closer to beta release?
<@dustymabe:matrix.org>
16:47:06
At the point we think we have probably shipped the last F41 based `next` then we should enable `next-devel` and disable `branched`
<@dustymabe:matrix.org>
16:47:56
marmijo: if no one else volunteers I can, but would encourage others to volunteer too
<@marmijo:fedora.im>
16:48:03
I can plan to watch those meetings also ποΈ
<@siosm:matrix.org>
16:48:27
!link https://fedoraproject.org/wiki/Go_No_Go_Meeting
<@dustymabe:matrix.org>
16:48:37
I will warn you - some of it is really dry.. They discuss lots of details about bugs we often don't care about.. but it's just something to keep an eye on in the background while you do other things
<@jbtrystram:matrix.org>
16:48:39
i am curious !
<@jbtrystram:matrix.org>
16:48:56
if that's a time i am around i'll join
<@dustymabe:matrix.org>
16:49:08
sometimes the bugs are ones we do care a bout and suggested as blockers or freeze exceptions
<@dustymabe:matrix.org>
16:49:29
jbtrystram: unfortunately I think it's usually at a time that would be inconvenient for you :(
<@siosm:matrix.org>
16:49:44
yeah, most of the time we don't care about most of the topics discussed, but it's a good place to bring our topics if we have any
<@jbtrystram:matrix.org>
16:49:54
:(
<@marmijo:fedora.im>
16:50:00
I think I sat in on one or two during the last release cycle
<@siosm:matrix.org>
16:50:16
if we have bugs that we want to highlight then it's the place
<@siosm:matrix.org>
16:51:02
more than attending, I think it would be good if we make sure each week that the list of bugs we care about is correctly reflected in the list of blocking bugs
<@siosm:matrix.org>
16:51:16
https://qa.fedoraproject.org/blockerbugs/
<@siosm:matrix.org>
16:51:42
so if there are no bugs we care about, the person can skip the meeting. If there are some, someone should attend
<@dustymabe:matrix.org>
16:52:30
That's fair
<@marmijo:fedora.im>
16:53:09
Anything else about this topic? We have some new F42 change considerations to discuss if we ant to move to that topic
<@dustymabe:matrix.org>
16:53:15
Looking at the list today I don't see any that we would care about.
<@marmijo:fedora.im>
16:53:48
dustymabe: are you talking about bugs or F42 changes?
<@dustymabe:matrix.org>
16:53:58
proposed blocker bugs
<@marmijo:fedora.im>
16:54:10
gotcha! moving on
<@marmijo:fedora.im>
16:54:51
!topic Review Fedora 42 changes considerations
<@marmijo:fedora.im>
16:54:55
!link https://github.com/coreos/fedora-coreos-tracker/issues/1838
<@marmijo:fedora.im>
16:55:31
I updated the list this morning, but I did it a little fast. So there might be some "notes" missing from certain items that I'll update later.
<@marmijo:fedora.im>
16:55:42
More importantly, there are new change considerations
<@marmijo:fedora.im>
16:56:29
!link https://fedoraproject.org/wiki/Changes/Anaconda_Installer_Using_GPT_on_all_architectures_by_Default
<@marmijo:fedora.im>
16:56:39
Change 129
<@siosm:matrix.org>
16:57:02
As we don't use the Anaconda installer to install FCOS we can ignore this one ποΈ
<@marmijo:fedora.im>
16:57:12
great!
<@siosm:matrix.org>
16:57:32
I think we also already use GPT everywhere? (would need to be confirmed)
<@marmijo:fedora.im>
16:58:18
!link https://fedoraproject.org/wiki/Changes/RemoveFipsModeSetup
<@marmijo:fedora.im>
16:58:18
The last one for system wide changes is 130
<@siosm:matrix.org>
16:58:56
We don't suport FIPS mode in FCOS right now
<@jdoss:beeper.com>
16:59:23
I use FIPS mode in my appliance builds.
<@jdoss:beeper.com>
16:59:28
Does this mean it will get removed?
<@dustymabe:matrix.org>
17:00:22
I think this change is just removing tooling to change an existing system.. basically if you want FIPS you needed to know from creation time
<@siosm:matrix.org>
17:00:40
yes
<@siosm:matrix.org>
17:00:46
See https://fedoraproject.org/wiki/Changes/RemoveFipsModeSetup#Detailed_Description
<@jdoss:beeper.com>
17:01:10
https://github.com/coreos/fedora-coreos-tracker/issues/302#issuecomment-1460506911 is what I do basically.
<@jdoss:beeper.com>
17:01:43
Yeah this is gonna break my bacon I think. Not good.
<@siosm:matrix.org>
17:01:50
As it's been said multiple times, FIPS mode is not supported in Fedora in general
<@siosm:matrix.org>
17:02:00
[https://github.com/coreos/fedora-coreos-tracker/issues/302 & ](https://github.com/coreos/fedora-coreos-tracker/issues/302#issuecomment-2518741080)
<@siosm:matrix.org>
17:02:05
https://github.com/coreos/fedora-coreos-tracker/issues/302#issuecomment-2518741080
<@siosm:matrix.org>
17:02:27
https://fedoraproject.org/wiki/Changes/RemoveFipsModeSetup#Context_information_on_FIPS
<@jdoss:beeper.com>
17:03:13
Right my Enterprise customers need FIPS and since I can't buy RHCOS licenses I have to make due and enable it using what I linked above. So this means I will need to figure out a different path if the tooling is being removed.
<@siosm:matrix.org>
17:03:33
(it's not a technical question but a policy one)
<@siosm:matrix.org>
17:03:40
The tooling is not being removed
<@jlebon:fedora.im>
17:03:51
jdoss: the canonical enablement flag is the karg now
<@siosm:matrix.org>
17:03:52
What you are doing will still work
<@siosm:matrix.org>
17:03:58
it's just not FIPS compliant
<@dustymabe:matrix.org>
17:04:34
> it's just not FIPS compliant
<@dustymabe:matrix.org>
17:04:34
And never was, because Fedora doesn't submit things for review (which is apparently a requirement)
<@dustymabe:matrix.org>
17:04:34
<@jdoss:beeper.com>
17:05:00
Trust me I would not bother with it but I have security people that require FIPS mode be enabled.
<@dustymabe:matrix.org>
17:05:17
well maybe that's all they need then :)
<@jdoss:beeper.com>
17:05:31
I am with you, I don't think it makes anything more secure but Banks for some reason want the FIPS.
<@dustymabe:matrix.org>
17:05:41
do they need "compliance" or do they need "FIPS mode enabled" - notably they aren't the same thing :)
<@jlebon:fedora.im>
17:06:09
jdoss: basically i htink the only change to your flow is to drop the `fips-mode-setup` call in your Containerfile
<@jlebon:fedora.im>
17:06:21
jdoss: basically i think the only change to your flow is to drop the `fips-mode-setup` call in your Containerfile
<@jdoss:beeper.com>
17:06:23
I don't want the FIPS. Please god save me from the FIPS.
<@jdoss:beeper.com>
17:06:35
Thanks guys. Sorry for the noise.
<@jlebon:fedora.im>
17:06:45
on the openshift/os side, this is tracked at https://github.com/openshift/os/issues/1665
<@siosm:matrix.org>
17:07:46
We can move on as this change does not impact FCOS directly and as Jonathan linked, we'll update RHCOS for it
<@marmijo:fedora.im>
17:09:03
232.
<@marmijo:fedora.im>
17:09:03
!link https://fedoraproject.org/wiki/Changes/CoreOSOstree2OCIUpdates
<@marmijo:fedora.im>
17:09:03
There are a lot of changes in the "Self Contained" section. 229-245. It's probably not worth going through each one individually.
<@siosm:matrix.org>
17:09:26
agree, most of them do not apply to us
<@siosm:matrix.org>
17:10:11
We are a bit late for the 232 one so I posted a status update at https://pagure.io/fesco/issue/3364#comment-956339 to let people now that it's still on track
<@marmijo:fedora.im>
17:10:12
Are there any we want to discuss in more detail?
<@siosm:matrix.org>
17:10:33
An update for 243 would be good to have as well
<@marmijo:fedora.im>
17:11:04
243:
<@marmijo:fedora.im>
17:11:04
!link https://fedoraproject.org/wiki/Changes/EROFSforLiveMedia
<@siosm:matrix.org>
17:11:47
I think it's tracked on our side in https://github.com/coreos/fedora-coreos-tracker/issues/1852
<@marmijo:fedora.im>
17:12:36
And Dusty added a comment to the "notify users" tracker https://github.com/coreos/fedora-coreos-tracker/issues/1863#issuecomment-2666677485
<@dustymabe:matrix.org>
17:12:43
yes. I'll update the issue. but the TL;DR is that this is now implemented for rawhide/branched/next-devel
<@dustymabe:matrix.org>
17:13:06
we found (earlier today) that ppc64le ISOs are failing tests. So that would be our final gap I think
<@dustymabe:matrix.org>
17:13:26
Nemric: reported yesterday that a test system on Branched running kubernetes off of live PXE worked well
<@siosm:matrix.org>
17:13:52
Great! Can someone comment in the BZ to mention that this is on track for F42?
<@siosm:matrix.org>
17:14:09
https://bugzilla.redhat.com/show_bug.cgi?id=2346259
<@dustymabe:matrix.org>
17:14:14
yep, but I'll mention I'm only one half of that change request
<@dustymabe:matrix.org>
17:14:24
so I'll ask Conan Kudo to do the update for the other half
<@conan_kudo:matrix.org>
17:14:49
I will merge the PR momentarily
<@siosm:matrix.org>
17:14:59
https://pagure.io/fedora-kiwi-descriptions/pull-request/105
<@dustymabe:matrix.org>
17:15:16
Conan Kudo: FYI we found some issues with ppc64le - so you might see the same.. we'll get an issue opened for it later today or tomorrow morning
<@conan_kudo:matrix.org>
17:15:19
I'm annoyed that now I have ignore CI because Fedora CI is busted
<@conan_kudo:matrix.org>
17:15:44
every run is stalled and timing out after 6 hours
<@conan_kudo:matrix.org>
17:16:25
it's been this way for weeks
<@conan_kudo:matrix.org>
17:16:30
I don't know what happened to break the infrastructure
<@dustymabe:matrix.org>
17:16:45
and now it's frozen!
<@siosm:matrix.org>
17:16:49
have you reported it in https://pagure.io/fedora-ci/general/issues ?
<@dustymabe:matrix.org>
17:17:30
marmijo: we can move on
<@siosm:matrix.org>
17:17:54
Conan Kudo:
<@jdoss:beeper.com>
17:17:55
Have we you tried turning it _off_ then back _on_ again Conan Kudo ??? /s
<@jdoss:beeper.com>
17:18:20
Have you tried turning it _off_ then back _on_ again Conan Kudo ??? /s
<@marmijo:fedora.im>
17:18:36
Sounds good. Are there any other changes that we want to discuss? 237 looked interesting
<@conan_kudo:matrix.org>
17:18:38
I will do this later today
<@marmijo:fedora.im>
17:18:50
!link https://fedoraproject.org/wiki/Changes/Optimized_Binaries_for_the_AMD64_Architecture_v2
<@siosm:matrix.org>
17:20:25
I would say that this should be transparent to us from the description but I'm not 100% sure
<@dustymabe:matrix.org>
17:20:37
seems like it
<@dustymabe:matrix.org>
17:21:11
do we ship `hwcaps-loader` package?
<@marmijo:fedora.im>
17:21:52
doesnt look like it
<@dustymabe:matrix.org>
17:22:28
oh. I see. The proposal is that Fedora packages that up and makes it available
<@dustymabe:matrix.org>
17:23:12
but I don't know if that package is required in order to take advantage of the change
<@dustymabe:matrix.org>
17:23:40
> This is where hwcaps-loader comes in. hwcaps-loader is a very small program which only has a single purpose: execute the best binary supported by the machine.
<@dustymabe:matrix.org>
17:24:11
so yeah. I think we'd need to include that in CoreOS if we wanted it. I guess we can ask some clarifying questions to the proposal owner
<@marmijo:fedora.im>
17:25:51
We've only got a few minutes left. We can move on to open floor now.
<@jbtrystram:matrix.org>
17:25:54
i suppose that if a maintainer found interest in supporting multiples feature flags they would add hwcaps-loader as a dependency to their packages
<@dustymabe:matrix.org>
17:26:15
perhaps
<@marmijo:fedora.im>
17:26:24
!topic Open Floor
<@dustymabe:matrix.org>
17:27:09
!info the Fedora Flock (in Prague in June) CFP is closing soon
<@dustymabe:matrix.org>
17:27:14
!link https://fedoraproject.org/flock/2025/
<@siosm:matrix.org>
17:27:22
Reminder that the CfP for DevConf.cz (https://www.devconf.info/cz/) ends on March 2nd, if folks wants to submit something FCOS related
<@jlebon:fedora.im>
17:27:30
i think it probably makes sense to ship, but it depends on size/deps
<@siosm:matrix.org>
17:27:42
!info The CfP for DevConf.cz (https://www.devconf.info/cz/) ends on March 2nd, if folks wants to submit something FCOS related
<@dustymabe:matrix.org>
17:28:12
I think I'm going to try to submit something
<@dustymabe:matrix.org>
17:28:41
Our Hands on labs are always popular too - so we should try to submit one of those
<@dustymabe:matrix.org>
17:28:50
to both flock and devconf
<@dustymabe:matrix.org>
17:29:30
probably would be a good opportunity to update our hands on lab - especially with our switch to OCI for update payload coming up
<@jlebon:fedora.im>
17:29:48
i'd like to as well to discuss image mode stuff, but not sure yet if i can make it
<@dustymabe:matrix.org>
17:31:17
Jonathan Lebon: yeah. You can probably have a co-presenter and hopefully one of you can make it :)
<@marmijo:fedora.im>
17:32:04
Thanks for joining today everyone. I'll go ahead and close the meeting
<@marmijo:fedora.im>
17:32:14
!endmeeting