Public bug reported:
Please add a new snapshot for Cyborg to Stonking past Feature freeze with
version 16.0.0+snapshot20260903.141.48e1616-0ubuntu1. Currently Cyborg is
shipped from Debian upstream sync. This new snapshot carries the upstream fix
for the autopkgtest regression that currently blocks multiple OpenStack pacages
in Stonking's proposed-migration. This upload is the first Ubuntu-maintained
version and is critical for the OpenStack Hibiscus (2026.2) stack in 26.10.
[ Rationale ]
* Current snapshot from Debian upstream carries the regression that reads a
removed option from `oslo.policy` -- `CONF.oslo_policy.enforce_scope`
(cyborg/common/authorize_wsgi.py:74).
* This test failure caused a cascade of autopkgtest regression, blocking the
migration of multiple OpenStack packages in Stonking's proposed-migration.
Packages affected by this regression are:
(directly) python-oslo.policy, python-oslo.config, python-oslo.context,
python-oslo.db, python-oslo.log, python-oslo.privsep,
python-oslo.upgradecheck, python-oslo.utils,
python-oslo.versionedobjects, stevedore, python-glanceclient,
python-openstackclient, python-os-api-ref,
python-keystonemiddleware, python-oslo.concurrency,
python-oslo.service;
(transitively) python-neutron-lib, neutron-taas, python-os-vif,
python-keystonemiddleware, placement.
[ Scope ]
* Cyborg is currently available in the universe repository package, for six
arch binaries. It currently has no reverse dependencies beyond its own
binaries.
* New upstream version: Based on the Debian snapshot version
16.0.0+git+2026.04.26.b8edfa06f1-1, 87 commits past this snapshot since
b8edfa06f1.
* New commits introduce: MDEV and NVMe device support, device_state
lifecycle (DB migration + online backfill + upgrade check), SRBAC
persona-based policy defaults, Intel NIC device_addresses allow-list,
always-enforced policy scope (the proposed-migration fix), removal of
the never-functional glance signature verification and the unused
[keystone]/[glance] debug options. No new API microversion (stays 2.3).
Full log: https://opendev.org/openstack/cyborg/compare/b8edfa06f1...48e1616
Key commits:
02f10e5 Adapt Cyborg to always-enforced policy scope
2c85d96 Add MdevBusManager for mdev bus discovery
645ef4e Add NVME device type and bump Device object to v1.4
b8655f6 Add device_state field to Device and DriverDevice
eec56f9 Add online data migration and upgrade check for device_state
backfill
389bb97 Migrate ARQ policies to DocumentedRuleDefault
4113395 Add device_addresses allow-list to the Intel NIC driver
69adcd0 Remove broken image signature verification
9c313b0 Fix rule:allow policy bypass on device/deployable/attribute APIs
ebfe437 Enforce project-scoped access for ARQs
[ Documentation ]
* Not a UI Freeze Exception; documentation ships in the cyborg-doc
binary.
[ Regression Potential ]
API clients using system-scoped tokens or the removed "administrator"
role alias could get 403s; cyborg-dbsync upgrade or cyborg-agent device
discovery could fail on the new MDEV/NVMe/device_state changes; in the
worst case cyborg's own autopkgtests fail again and re-block the same 19
packages in proposed-migration.
[ Testing ]
* Smoke test:
- PPA: ppa:himax16/hibiscus-test
- Build: TBD
- Installation: TBD
- Upgrade: TBD (from 16.0.0+git+2026.04.26.b8edfa06f1-1)
- Autopkgtest: N/A
- Does it break other packages: N/A, no reverse-dependencies; packaging
tracked in LP: #2160367
[ Other Info ]
* Snapshot is done now rather than waiting for 17.0.0 final release in
early October to let packages pass in the autopkgtest for Stonking's
proposed.
* Security: the CVE-2026-40213/40214 fixes (backported in the current
Debian sync) are present upstreamed in this snapshot (commits 9c313b0,
ebfe437, 15f72ac, 2a4d365, 9e38e24) -- posture preserved, not regressed.
* Four of the blocked packages have independent fixes in flight
(python-oslo.upgradecheck 0ubuntu2; python-oslo.service s390x +
masakari-monitors armhf; oslo.concurrency pre-existing armhf alwaysfail);
this upload removes the cyborg veto from all of them.
[ Original Description ]
* N/A -- freshly filed.
** Affects: cyborg (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166805
Title:
[FFE] Update Cyborg snapshot on Ubuntu Stonking to resolve autopkgtest
failures
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cyborg/+bug/2166805/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs