releng
LOGS
<@patrikp:matrix.org>
15:00:03
!startmeeting RELENG (2026-06-22)
<@meetbot:fedora.im>
15:00:04
Meeting started at 2026-06-22 15:00:03 UTC
<@meetbot:fedora.im>
15:00:05
The Meeting name is 'RELENG (2026-06-22)'
<@patrikp:matrix.org>
15:00:09
!chair nirik jnsamyak patrikp
<@patrikp:matrix.org>
15:00:09
!info Meeting is 60 minutes long at most. At the end of the hour it stops.
<@patrikp:matrix.org>
15:00:09
!meetingname releng
<@patrikp:matrix.org>
15:00:09
!info Agenda is at https://hackmd.io/vm6biLBcTYKtkQUH5kQkmw.
<@meetbot:fedora.im>
15:00:11
The Meeting Name is now releng
<@jnsamyak:matrix.org>
15:01:06
0/ I'm here, sorry for the slow day today, I'm still struggling to think what did I eat, to have this nasty stomach bug :/
<@patrikp:matrix.org>
15:01:42
Hi. 👋
<@patrikp:matrix.org>
15:02:29
!topic Init process.
<@patrikp:matrix.org>
15:02:29
!info This is a good time to bring up things like tickets that people are stuck on, blockers, tasks, requests, and/or features that require release engineering intervention.
<@nirik:matrix.scrye.com>
15:02:34
morning
<@jnsamyak:matrix.org>
15:03:37
I see folks are back from flock, I hope all had nice time
<@patrikp:matrix.org>
15:04:15
I'm almost done reworking the end of life SOP. The changes are a little more extensive than originally anticipated. I will open a PR very soon and ask for review.
<@patrikp:matrix.org>
15:04:15
I have a couple of quick points for init.
<@patrikp:matrix.org>
15:04:15
After this my highest priority will be the scm-requests migration.
<@patrikp:matrix.org>
15:04:38
And I will very likely be on PTO July 2nd to 7th.
<@jnsamyak:matrix.org>
15:04:45
Oh please have the migration is priority
<@jnsamyak:matrix.org>
15:05:11
Oh please have the migration at priority; docs can be reviewed, pagure is getting decomissioned soon :(
<@patrikp:matrix.org>
15:05:24
Yup, I wanted to ask for a couple of pointers. I want to get it done this sprint.
<@patrikp:matrix.org>
15:06:02
!releng 13369
<@zodbot:fedora.im>
15:06:03
● **Last Updated:** a week ago
<@zodbot:fedora.im>
15:06:03
**releng/tickets #13369** (https://forge.fedoraproject.org/releng/tickets/issues/13369):**[ fedora-scm-requests ] - Update fedpkg**
<@zodbot:fedora.im>
15:06:03
<@zodbot:fedora.im>
15:06:03
● **Opened:** a month ago by humaton
<@zodbot:fedora.im>
15:06:03
● **Assignee:** patrikp
<@patrikp:matrix.org>
15:07:03
Could more context be given for this? Here's the repo:
<@patrikp:matrix.org>
15:07:03
https://forge.fedoraproject.org/packaging/fedpkg
<@patrikp:matrix.org>
15:07:03
<@patrikp:matrix.org>
15:07:03
But I'm unsure what things need to be taken into consideration.
<@patrikp:matrix.org>
15:07:52
Second thing, gotmax raises a good point about Forgejo actions and I was wondering if you had any thoughts on it:
<@patrikp:matrix.org>
15:07:52
https://forge.fedoraproject.org/releng/tickets/issues/13370#issuecomment-823064
<@nirik:matrix.scrye.com>
15:08:23
right now fedpkg files tickets/requests in pagure.io... it needs to file in forge, but... it's also tricky because you can't just change it unless you have the new processing all working... and then you have to wait for maintainers to update...
<@jnsamyak:matrix.org>
15:09:42
Yeah we could it testing it in staging no? But yeah needed to be done anyways before pagure goes away
<@nirik:matrix.scrye.com>
15:09:54
BTW, we also have https://forge.fedoraproject.org/releng/tickets/issues/13108 so perhaps we should close one as a dupe? or are they different levels?
<@jnsamyak:matrix.org>
15:10:12
i think the majority of this migration is updating fedpkg
<@patrikp:matrix.org>
15:10:27
I think the one you linked is a "user story" and the other ones are the actionable tasks. It is done this way on purpose.
<@jnsamyak:matrix.org>
15:10:28
if that is done, we can get others things done
<@nirik:matrix.scrye.com>
15:10:52
I'm not sure about the actions thing. I kinda agree with gotmax23 on that... thats jednorozec's plan... so he would be the one to advocate for it.
<@jnsamyak:matrix.org>
15:11:14
This is an EPIC, and we have creates short actionable items in terms of those tickets
<@nirik:matrix.scrye.com>
15:11:26
ok, fair enough
<@jnsamyak:matrix.org>
15:11:38
This is an EPIC, and we have created short actionable items in terms of those tickets
<@jnsamyak:matrix.org>
15:13:07
Yeah gotmax requests seems valid, it is not set in stone, we can always bring and work on better solutions if it is there.
<@jnsamyak:matrix.org>
15:13:22
actions seemed to be a quick solution to it while filing that ticket
<@patrikp:matrix.org>
15:13:43
What other options are there that could be explored?
<@nirik:matrix.scrye.com>
15:13:53
sure, but adjusting the toddler could work too... and then it's more isolated.
<@nirik:matrix.scrye.com>
15:14:26
just modify the toddler to process both pagure.io and forge ones, get it all working, then switch fedpkg, then drop pagure.io handling.
<@jnsamyak:matrix.org>
15:15:22
toddlers
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
DistGit
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
Ticket Created
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
Fedora Messaging Event
<@jnsamyak:matrix.org>
15:15:22
Instead of
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
Ticket Created
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
Forgejo Action
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
DistGit API
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:22
We Could do:
<@jnsamyak:matrix.org>
15:15:22
<@jnsamyak:matrix.org>
15:15:32
nirik: thoughts?
<@nirik:matrix.scrye.com>
15:15:48
yeah, basically the same as it is now with pagure, just adjusting the toddler.
<@nirik:matrix.scrye.com>
15:15:54
Might be easier. Dunno.
<@jnsamyak:matrix.org>
15:16:13
yes should be a good approach
<@patrikp:matrix.org>
15:16:51
https://forge.fedoraproject.org/apps/toddlers/src/branch/main/toddlers/plugins/scm_request_processor.py
<@patrikp:matrix.org>
15:16:51
Is it this one?
<@nirik:matrix.scrye.com>
15:16:53
we could always move it to actions later if there were advantages there.
<@nirik:matrix.scrye.com>
15:16:58
yep.
<@patrikp:matrix.org>
15:17:18
OK, thanks for the idea, I'll look at it. In any case, that's all I had for init. Anything else?
<@jnsamyak:matrix.org>
15:17:26
Yeah but I think jednorozec wanted to minimize toddlers depdendency on thr process
<@jnsamyak:matrix.org>
15:17:30
but this also works
<@humaton:fedora.im>
15:17:39
Well the biggest advantage is to not depend on toddlers...
<@jnsamyak:matrix.org>
15:18:01
But yeah migration priority before any ops.
<@nirik:matrix.scrye.com>
15:18:15
well, moving it to actions means actions are critical path now, and have to be up all the time. ;)
<@nirik:matrix.scrye.com>
15:18:15
well, we depend on toddlers for a lot already?
<@humaton:fedora.im>
15:18:37
And my plan is to slowly get rid of the dependencies
<@nirik:matrix.scrye.com>
15:19:34
ok, but we need to be careful that whatever is gotten rid of is at least as reliable/secure as what it's replacing.
<@patrikp:matrix.org>
15:21:42
Let's move on?
<@patrikp:matrix.org>
15:22:00
!topic Choose next chair.
<@patrikp:matrix.org>
15:22:00
!info Next chair June 29th: ?
<@jnsamyak:matrix.org>
15:22:34
I might be shifting that day so might be on PTO
<@patrikp:matrix.org>
15:22:51
I can take it and I'll be away the Monday after that.
<@patrikp:matrix.org>
15:23:12
You want July 6th?
<@jnsamyak:matrix.org>
15:23:13
hehe i can do that one
<@jnsamyak:matrix.org>
15:23:22
sure
<@patrikp:matrix.org>
15:23:37
!info Next chair July 6th: Samyak
<@patrikp:matrix.org>
15:23:37
!info Next chair June 29th: Patrik
<@patrikp:matrix.org>
15:23:45
!topic Scheduled actions coming up in the next week.
<@patrikp:matrix.org>
15:23:45
!info Here we discuss items that are due to be done in the next week.
<@patrikp:matrix.org>
15:23:45
<@patrikp:matrix.org>
15:24:26
Mass rebuild is approaching. We discussed with Samyak that I could be the one to take responsibility for it this cycle, if that's OK with everyone.
<@jnsamyak:matrix.org>
15:24:32
release process starting soon
<@jnsamyak:matrix.org>
15:24:55
yeah go ahead, we will be there in background
<@jnsamyak:matrix.org>
15:24:59
in case stuff happens
<@nirik:matrix.scrye.com>
15:25:07
sounds good. Happy to help out any way I can
<@patrikp:matrix.org>
15:25:59
Nice, thanks. I'll prepare the ticket in advance so that we will know it's planned work at the time of sprint planning.
<@patrikp:matrix.org>
15:26:27
Soon enough there will also be "F47 keys are added to fedora-repos and are available in updates-testing" and mass re-signing.
<@nirik:matrix.scrye.com>
15:27:16
I hope to work on deploying the new siguldry in staging soon... not sure it will be in prod by then, but we will see...
<@patrikp:matrix.org>
15:27:59
Anything else that needs to be said about upcoming actions?
<@gotmax23:fedora.im>
15:28:45
Long term FTBFS is coming up soon. I see https://src.fedoraproject.org/rpms/pesign is in that list.
<@gotmax23:fedora.im>
15:29:44
Oh, and I see the scm requests thing was already discussed, didn't see i was mentioned
<@nirik:matrix.scrye.com>
15:29:46
ha, fun.
<@gotmax23:fedora.im>
15:30:00
But yeah, moving it to Forgejo Actions seems questionable
<@patrikp:matrix.org>
15:30:09
I wouldn't mind skipping the tickets section and hearing what you have to say about it.
<@patrikp:matrix.org>
15:30:25
To me it kind of sounds like we should decide it before commencing the actual migration, or?
<@gotmax23:fedora.im>
15:30:40
What I have to say about SCM requests?
<@patrikp:matrix.org>
15:31:09
Yes, in general, or specifically about the Forgejo actions, CI, toddlers.
<@nirik:matrix.scrye.com>
15:31:24
odd. There's no FTBFS bug?
<@gotmax23:fedora.im>
15:31:41
Maybe SRPM build failed?
<@gotmax23:fedora.im>
15:32:30
But re. scm requests, am I missing some context here? Is this "there's something wrong with toddlers" or is it "we just want to try out Forgejo Actions?"
<@patrikp:matrix.org>
15:34:19
jednorozec had this to say regarding toddlers. I would be glad to hear more about the reasoning too.
<@gotmax23:fedora.im>
15:35:40
From my perspective, storing secrets in Forgejo Actions is less secure than the current approach and it sounds like switching to it would be more work than just adjusting the existing toddler code to react to Forgejo ticket messages?
<@gotmax23:fedora.im>
15:36:26
The distgit admin token that would need to be stored in the repo's secrets to create projects on distgit has a lot of power
<@gotmax23:fedora.im>
15:36:39
So if someone exfiltrated it, that would be quite bad...
<@patrikp:matrix.org>
15:37:12
To me, these sound like words of reason.
<@jnsamyak:matrix.org>
15:39:12
Let's move on?
<@patrikp:matrix.org>
15:39:51
Nobody else has something to say? What is your take on this Samyak? Not sure the migration can move forward without this being decided.
<@patrikp:matrix.org>
15:40:11
I was hoping for some more discussion on it because I'm unsure about how to approach it.
<@gotmax23:fedora.im>
15:42:10
I could give advice on how to avoid the worst security issues (linting with zizmor, avoiding unsafe usage of `${{ }}` templating in shell code, managing permissions to the repository that has the workflow, etc.) but it'd probably better to stick with the current system if possible
<@gotmax23:fedora.im>
15:42:43
I could give advice on how to avoid the worst security issues (linting with zizmor, avoiding unsafe usage of `${{ }}` templating in shell code, managing permissions to the repository that has the workflow, etc.) but it'd probably be better to stick with the current system if possible
<@nirik:matrix.scrye.com>
15:42:50
re: pesign... I filed https://bugzilla.redhat.com/show_bug.cgi?id=2491392 on it. It really does fail to build. I wonder if it wasn't filed because it's a package we explicitly exclude from mass rebuilds.
<@jnsamyak:matrix.org>
15:43:21
I think there are a lot of moving parts to this, and not just this. Firstly, we covered toddlers vs actions above, and the fedpkg changes need to be addressed first. And yeah, the toddler seemed to be a more reliable solution - but we can discuss it further tomorrow and try to research more; there should be a way to mitigate things through actions as well.
<@jnsamyak:matrix.org>
15:43:47
I think there are a lot of moving parts to this, and not just this. Firstly, we covered toddlers vs actions above, and the fedpkg changes need to be addressed first. And yeah, the toddler seemed to be a more reliable solution - but we can discuss it further tomorrow and try to research more insteading of finding solution on meeting we need to weigh in what can be a better solution; there should be a way to mitigate things through actions as well.
<@humaton:fedora.im>
15:45:09
In general toddlers was basically "missing pagure features" fix. We are pulling together a bunch of functionaly into yet another app and codebase that needs to be maintained.
<@humaton:fedora.im>
15:45:42
THere have been multiple issues with us forgeting to update something in toddlers...
<@nirik:matrix.scrye.com>
15:45:58
well, toddlers was 'operate on message bus messages' really.
<@humaton:fedora.im>
15:46:14
I am not saying that actions will fix everything. But When we have the chance, especially in this case where ticket is the source of action. Why not?
<@gotmax23:fedora.im>
15:46:49
I mean if you want to get rid of toddlers, this could be re-written as a Forgejo webhook also
<@nirik:matrix.scrye.com>
15:47:59
there's a bunch of things toddlers does...if we are talking about getting rid of it, we need a larger conversation, it's not just doing releng stuff.
<@humaton:fedora.im>
15:48:03
It can be replaced in multiple ways, yeah. i am okey with keeping it as it is, its just unecessary dependency and maintanance.
<@humaton:fedora.im>
15:48:45
Yes there is a bunch of things, but when you look at the codebase scm-requests is becomming the biggest in there.
<@nirik:matrix.scrye.com>
15:49:19
sure, likely because we do a lot of checks to make sure the request is proper...
<@humaton:fedora.im>
15:49:57
Yup, and that was why I mentioned it migh be a good idea to "just" reuse the codebase and put it into the actions.
<@nirik:matrix.scrye.com>
15:51:11
since we are time constrained, it might be best to just adjust the toddler for now and look at actions after?
<@humaton:fedora.im>
15:51:23
And we dont have to replace it, this was just an idea because the migration has to happen. And I put it in the backlog some time ago...
<@humaton:fedora.im>
15:51:51
so sure, if updating toddlers is the easiest way to do the migration...
<@patrikp:matrix.org>
15:52:11
I like the sound of this. Does anybody strongly disagree?
<@nirik:matrix.scrye.com>
15:52:43
yeah, I don't know if thats easiest, but it seems like it might be...
<@patrikp:matrix.org>
15:53:11
Thanks for the input.
<@patrikp:matrix.org>
15:53:23
A ticket or two? Open floor? Wrap?
<@nirik:matrix.scrye.com>
15:54:18
not much time left...
<@patrikp:matrix.org>
15:54:39
Yup.
<@patrikp:matrix.org>
15:54:46
!endmeeting
<@patrikp:matrix.org>
15:54:46
!info Thank you all for coming!