[FFe] Update OVN to new 23.09.0 upstream version

Bug #2032605 reported by Frode Nordahl
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ovn (Ubuntu)
Fix Released
High
Unassigned

Bug Description

As detailed in an upstream announcement [0], the OVN 23.09.0 release was delayed. It was released as scheduled on Friday September 15th [1] and the upstream NEWS file has been updated accordingly [2].

This new upstream version includes fixes performance improvements and new features that are important for our community, and we would like to include it in the Ubuntu Mantic release.

OVN 23.09.0 has been uploaded to Debian unstable [3][4].

The package can also be viewed in a PPA for details on how it would look on Ubuntu [5].

As soon as the package has been uploaded to Debian unstable we would like to sync it to Mantic.

0: https://mail.openvswitch.org/pipermail/ovs-dev/2023-July/406804.html
1: https://mail.openvswitch.org/pipermail/ovs-announce/2023-September/000329.html
2: https://github.com/ovn-org/ovn/blob/v23.09.0/NEWS
3: https://salsa.debian.org/openstack-team/third-party/ovn/-/merge_requests/21
4: https://buildd.debian.org/status/package.php?p=ovn
5: https://launchpad.net/~fnordahl/+archive/ubuntu/ovn-dev/+sourcepub/15163667/+listing-archive-extra

CVE References

Frode Nordahl (fnordahl)
Changed in ovn (Ubuntu):
importance: Undecided → High
Revision history for this message
Utkarsh Gupta (utkarsh) wrote :

Hi,

Thanks for filing an FFe. I think this broadly makes sense and ovn releases are pretty stable and tested. As for now, I see the following changelog entries:

Post v23.06.0
-------------
  - Added FDB aging mechanism, that is disabled by default.
    It can be enabled per logical switch with other_config
    "fdb_age_threshold".
  - Add DHCPv6 "fqdn" (39) option, that works similarly to
    DHCPv4 "hostname" (12) option.
  - Support to create/update MAC_Binding when GARP received from VTEP (RAMP)
    switch on l3dgw port.
  - To allow optimizing ovn-controller's monitor conditions for the regular
    VIF case, ovn-controller now unconditionally monitors all sub-ports
    (ports with parent_port set).
  - ECMP routes use L4_SYM dp-hash by default if the datapath supports it.
    Existing sessions might get re-hashed to a different ECMP path when
    OVN detects the algorithm support in the datapath during an upgrade
    or restart of ovn-controller.

Given this is not yet final, I don't think we can take that call right now. I mean, as I said, in broader terms it should be OK but how about this - once this is released and the changelog is finalized, we can circle back on this and take a decision?

Feel free to ping me or release team members on IRC and we'll take another look.

Just to be clear - I am not an official release team member yet. :)

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

I agree with Utkarsh - it's a bit to soon to consider this FFe, blanket FFe's for unreleased releases are a bit problematic. The timing is very important to the feasibility of an FFe.

Some question: how confident are we in the quality of the current snapshot builds? If we give a +1 to the snapshot upload but the actual release is delayed enough that there will be a -1 to the FFe for the new full release, how confident would you be with having the snapshot as the version that we release in 23.10? Is the release likely to slip more beyond September 15?

Changed in ovn (Ubuntu):
status: New → Incomplete
Revision history for this message
Frode Nordahl (fnordahl) wrote :

Thank you for the feedback, we have updated the description with information on the stable branch creation, and recent reiteration of the release date from upstream.

We have also revised our plan towards the Ubuntu release, please have a look and let us know what you think.

description: updated
Changed in ovn (Ubuntu):
status: Incomplete → New
Frode Nordahl (fnordahl)
description: updated
Frode Nordahl (fnordahl)
description: updated
Revision history for this message
Frode Nordahl (fnordahl) wrote :

This bug was fixed in the package ovn - 23.09.0-1

---------------
ovn (23.09.0-1) unstable; urgency=medium

  * Team upload.
  * Update upstream source from tag 'upstream/23.09.0'
    - Add CoPP for the svc_monitor_mac. This addresses CVE-2023-3153.
    (Closes: #1043598)
  * d/p/revert-ovs-python-build-rename.patch: Revert OVN adaption for not
    yet released OVS build system changes (LP: #2036397).
  * d/control: Add python3-scapy build dependency.
  * d/flaky-tests-s390x.txt: Add failing test case.

 -- Frode Nordahl <email address hidden> Mon, 18 Sep 2023 08:34:18 +0200

Changed in ovn (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.