Minutes:
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
Minutes (text):
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
Log:
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
=====================================
# #meeting-1:fedoraproject.org: fedora_coreos_meeting
=====================================
Meeting started by @angelcr:matrix.org at 2026-05-20 15:30:09
Meeting summary
---------------
* TOPIC: roll call (@angelcr:matrix.org, 15:30:42)
* TOPIC: Action items from last meeting (@angelcr:matrix.org, 15:34:26)
* TOPIC: Review Fedora 45 Release Schedule (@angelcr:matrix.org, 15:37:06)
* LINK:
https://fedorapeople.org/groups/schedule/f-45/f-45-key-tasks.html (@angelcr:
matrix.org, 15:37:16)
* TOPIC: Rework and evaluate kola-upgrade testing strategy (@angelcr:
matrix.org, 15:42:20)
* LINK: https://github.com/coreos/fedora-coreos-tracker/issues/2146
(@angelcr:matrix.org, 15:42:36)
* TOPIC: use chunkah to split container images and increase max layers
(@angelcr:matrix.org, 16:14:26)
* LINK: https://github.com/coreos/fedora-coreos-tracker/issues/2145
(@angelcr:matrix.org, 16:15:04)
* AGREED: we will try to use chunkah for chunking up our container
layers and experiment rolling out a relatively high limit for the number of
layers. we'll start in rawhide and next to see if there are any issues
(@angelcr:matrix.org, 16:31:21)
Meeting ended at 2026-05-20 16:32:45
Action items
------------
People Present (lines said)
---------------------------
* @dustymabe:matrix.org (64)
* @siosm:fedora.im (24)
* @angelcr:matrix.org (24)
* @jbtrystram:matrix.org (16)
* @marmijo:fedora.im (12)
* @zodbot:fedora.im (10)
* @ydesouza:fedora.im (2)
* @meetbot:fedora.im (2)
* @peytonrobertson:matrix.org (2)
* @thilofm:matrix.org (1)
* @nemric:relativit.fr (1)
* @spresti:fedora.im (1)
* @rapneset:matrix.org (1)
The "Fragnesia" (CVE-2026-46300) [1] and "ssh-keysign-pwn"
(CVE-2026-46333) [2] vulnerabilities have been resolved in the
following Fedora CoreOS releases:
- next: 44.20260510.1.3
- testing: 44.20260510.2.3
Since the fixed kernels are 7.0 kernels, a `stable` stream fix will be
promoted when `testing` is promoted to `stable` next week. In the
meantime, we recommend applying the mitigations below to `stable` stream
nodes.
== Fragnesia (CVE-2026-46300) ==
This vulnerability can be mitigated by disabling the affected kernel
modules via the following Butane config snippet:
storage:
files:
- path: /etc/modprobe.d/dirtyfrag.conf
contents:
inline: |
install esp4 /bin/false
install esp6 /bin/false
install rxrpc /bin/false
blacklist esp4
blacklist esp6
blacklist rxrpc
alias net-pf-33 off
alias xfrm-type-2-50 off
alias xfrm-type-10-50 off
or by creating the same file on already running systems.
If the impacted modules are already loaded on the system then a reboot
will be required and the functionality (IPsec and AFS) will be
disabled. Otherwise, the mitigation will be effective immediately.
== ssh-keysign-pwn (CVE-2026-46333) ==
This vulnerability can be mitigated by disabling ptrace access via the
following Butane config snippet:
storage:
files:
- path: /etc/sysctl.d/10-default-yama-scope.conf
contents:
inline: |
kernel.yama.ptrace_scope = 3
or by creating the same file on already running systems and running:
/usr/lib/systemd/systemd-sysctl 10-default-yama-scope.conf
== Reference ==
For detailed information regarding these CVEs, see our tracking
issues [1] [2].
Michael Armijo
for The Fedora CoreOS Team
[1] https://github.com/coreos/fedora-coreos-tracker/issues/2144
[2] https://github.com/coreos/fedora-coreos-tracker/issues/2147
Minutes:
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
Minutes (text):
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
Log:
https://meetbot-raw.fedoraproject.org/meeting-1_matrix_fedoraproject-org/20…
=====================================
# #meeting-1:fedoraproject.org: fedora_coreos_meeting
=====================================
Meeting started by @marmijo:fedora.im at 2026-04-29 15:30:11
Meeting summary
---------------
* TOPIC: roll call (@marmijo:fedora.im, 15:30:16)
* TOPIC: Action items from last meeting (@marmijo:fedora.im, 15:34:03)
* INFO: There are no action items from the last meeting. (@marmijo:
fedora.im, 15:34:26)
* TOPIC: Review Fedora 44 Release Schedule (@marmijo:fedora.im, 15:34:47)
* LINK:
https://fedorapeople.org/groups/schedule/f-44/f-44-key-tasks.html (@marmijo:
fedora.im, 15:34:52)
* INFO: Fedora 44 was released yesterday, 2026-04-28! 🎉 (@marmijo:
fedora.im, 15:35:12)
* LINK: https://github.com/coreos/fcos-meeting-action/issues/231
(@marmijo:fedora.im, 15:41:52)
* LINK: https://github.com/coreos/fedora-coreos-tracker/issues/2055
(@marmijo:fedora.im, 15:42:12)
* TOPIC: Meeting Agenda (@marmijo:fedora.im, 15:43:25)
* INFO: There are no issues with the meeting label this week (@marmijo:
fedora.im, 15:43:39)
* TOPIC: systemd-oomd for Fedora CoreOS (@marmijo:fedora.im, 15:46:30)
* LINK: https://github.com/coreos/fedora-coreos-tracker/issues/840
(@marmijo:fedora.im, 15:46:43)
* INFO: This discussion is about both
https://github.com/coreos/fedora-coreos-tracker/issues/840 and
https://github.com/coreos/fedora-coreos-tracker/issues/859 (@marmijo:
fedora.im, 15:54:45)
* LINK: https://github.com/coreos/fedora-coreos-tracker/issues/859
(@marmijo:fedora.im, 15:54:49)
* INFO: [proposed]: We will revert the accidental enablement of
`systemd-oomd` for current releases. For Fedora 45, we will submit a formal
Change Proposal to enable both `swap-on-zram` and `systemd-oomd` together
to align with Fedora defaults while providing documented "best practices"
or "things to consider" for Kubernetes node stability. (@marmijo:fedora.im,
16:18:11)
* AGREED: We will revert the accidental enablement of `systemd-oomd`
for current releases. For Fedora 45, we will submit a formal Change
Proposal to enable both `swap-on-zram` and `systemd-oomd` together to align
with Fedora defaults while providing documented "best practices" or "things
to consider" for Kubernetes node stability. (@marmijo:fedora.im, 16:22:13)
* INFO: We need a volunteer to write and own the Fedora 45 Change
Proposal, and draft the K8s "best practices" documentation. (@marmijo:
fedora.im, 16:24:56)
* TOPIC: Open Floor (@marmijo:fedora.im, 16:26:13)
Meeting ended at 2026-04-29 16:29:31
Action items
------------
People Present (lines said)
---------------------------
* @marmijo:fedora.im (36)
* @dustymabe:matrix.org (24)
* @siosm:fedora.im (23)
* @zodbot:fedora.im (10)
* @nemric:relativit.fr (8)
* @jbtrystram:matrix.org (5)
* @meetbot:fedora.im (2)
* @hricky:fedora.im (2)
* @rapneset:matrix.org (2)
* @jcapitao:matrix.org (2)
* @cadejacobson:matrix.org (1)
* @peytonrobertson:matrix.org (1)
* @angelcr:matrix.org (1)