Security update for ansible1, ardana-ansible, ardana-cluster, ardana-db, ardana-extensions-nsx, ardana-glance, ardana-input-model, ardana-installer-ui, ardana-manila, ardana-monasca, ardana-neutron, a

Announcement ID: SUSE-SU-2019:2562-1
Rating: moderate
References:
Affected Products:
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE OpenStack Cloud 9
  • SUSE OpenStack Cloud Crowbar 9

An update that contains 68 features and has nine security fixes can now be installed.

Description:

This update for ansible1, ardana-ansible, ardana-cluster, ardana-db, ardana-extensions-nsx, ardana-glance, ardana-input-model, ardana-installer-ui, ardana-manila, ardana-monasca, ardana-neutron, ardana-nova, ardana-octavia, ardana-opsconsole-ui, ardana-osconfig, ardana-service, ardana-tls, crowbar-core, crowbar-ha, crowbar-openstack, crowbar-ui, grafana, novnc, openstack-cinder, openstack-dashboard, openstack-designate, openstack-glance, openstack-heat, openstack-horizon-plugin-heat-ui, openstack-horizon-plugin-monasca-ui, openstack-ironic, openstack-ironic-python-agent, openstack-keystone, openstack-manila, openstack-neutron, openstack-neutron-gbp, openstack-nova, openstack-octavia, openstack-sahara, openstack-tempest, openstack-watcher, python-ardana-configurationprocessor, python-cinder-tempest-plugin, python-urllib3, rubygem-easy_diff contains the following fixes:

  • 0004-add_ipv6_support_to_synchronize_action_plugin.patch fixes: bsc#1145967

IPv6 addreses need to be wrapped when used in scp command in the form scp user@[ipv6address]:port SOC-10117

  • Update to version 9.0+git.1568385829.54601ac:
  • Enable Cloud9 parallelised upgrade workflow (SOC-10484)

  • Update to version 9.0+git.1568379640.07c5144:

  • Enable DB upgrade in ardana-update.yml (SOC-10094)

  • Update to version 9.0+git.1567617871.4426809:

  • Ensure tls-upgrade.yml called by ardana-update.yml (SOC-9942)

  • Update to version 9.0+git.1566486136.e2f6b0f:

  • Add deprecations cleanup support (SOC-10275)

  • Update to version 9.0+git.1568150980.027f167:

  • Enable auth_openidc Apache2 module (SOC-10509)

  • Update to version 9.0+git.1568382922.6f2cea4:

  • Use galera-upgrade.yml for update/upgrade workflow (SOC-10521)

  • Update to version 9.0+git.1568830037.2eea267:

  • Add missing DHCP options for NSX-T (SOC-5838)

  • Update to version 9.0+git.1568307751.d68a198:

  • Add NSX-T QoS service definition (SOC-10479)

  • Update to version 9.0+git.1567606893.85b4d54:

  • Add NSX-T LBaaS service definition (SOC-9900)

  • Update to version 9.0+git.1567416354.e45fd54:

  • Add missing policies for NSX-T (SOC-5831)

  • Update to version 9.0+git.1567196895.2e056b5:

  • Add NSX-T VPNaaS service definition (SOC-9935)
  • Add NSX-T FWaaS service definition (SOC-9935)

  • Update to version 9.0+git.1567196861.0ca4cc9:

  • Add the NSX-T DNS service definition (SOC-9912)

  • Update to version 9.0+git.1567196262.39a7dd0:

  • Improvements over initial NSX-T support (SOC-5831)

  • Update to version 9.0+git.1566918834.1b7a49a:

  • Update policy json templates for vmware-nsx (SOC-10254)

  • Update to version 9.0+git.1567000146.4569d10:

  • Cloud 8to9 upgrade enhancements for glance (SOC-10043)

  • Update to version 9.0+git.1566409257.eec6360:

  • Add neutron-fwaas.json when neutron-l3-agent is deployed (SOC-10280)

  • Update to version 9.0+git.1569535129.ca87ef0:

  • Add support for running in Docker container (SOC-8524) (#350)

  • Update to version 9.0+git.1567797529.273abf2:

  • Use IPv6 validator on baremetal (SOC-10251)

  • Update to version 9.0+git.1568835830.10c9689:

  • Ensure Manila services don't auto start on reboot (SOC-10641)

  • Update to version 9.0+git.1567695427.5974ab2:

  • Stop existing mon-api services during upgrade (SOC-10470)

  • Update to version 9.0+git.1568817582.a4813e2:

  • Fix neutron-ovsvapp-agent status (SOC-10637)

  • Update to version 9.0+git.1567606982.697a2bf:

  • Let SDNs configure LB service provider (SOC-9900)

  • Update to version 9.0+git.1567606981.c612be8:

  • API extension paths separated by colon (SOC-10447)

  • Update to version 9.0+git.1567000278.309171b:

  • Neutron 8to9 upgrade workflow (SOC-10080)

  • Update to version 9.0+git.1566503987.df6961f:

  • Add policy.d/neutron-fwaas.json.j2 (SOC-10280)

  • Update to version 9.0+git.1567630824.aa6dc2d:

  • api_db sync needed before db_expand.yml (SOC-10023)

  • Update to version 9.0+git.1567125466.9b151d6:

  • Enable tls channel for vnc on compute VM (SOC-9942)

  • Update to version 9.0+git.1566826931.741980f:

  • Install libosinfo package (SOC-10295)

  • Update to version 9.0+git.1568362662.7fba216:

  • Make octavia heartbeat frequency options configurable (SOC-9285)

  • Update to version 9.0+git.1566374458.f58d2bb:

  • Include SES variables when configuring image (SOC-9285)

  • Update to version 9.0+git.1566593422.813e56c:

  • Update ip address validator (SOC-9679)

  • Update to version 9.0+git.1567630791.5ca70a6:

  • Revert Ansible 2.x compatibility change (SOC-10452)

  • Update to version 9.0+git.1567553292.5991a87:

  • Configured openvswitch logrotate user based on system settings (SOC-10282)

  • Update to version 9.0+git.1569439941.6800991:

  • Re-enable streaming of playbook logs (SOC-10720)

  • Update to version 9.0+git.1569257240.456c4fc:

  • Add condition to avoid case with no compute (SOC-10692)

  • Update to version 9.0+git.1568075665.a627f71:

  • Fix missing key error for c9 update (SOC-10476)

  • Update to version 9.0+git.1567640139.61bbe4e:

  • Add support for redhat compute (SOC-9942)

  • Update to version 9.0+git.1567530252.4b0dc66:

  • Generate vnc server cert on compute host (SOC-9942)

  • Update to version 6.0+git.1569587091.3f083d63c:

  • barclamp_lib: Sync timeout with other barclamps (SOC-10513, SOC-10011)
  • Revert "batch: Use easy_merge for merging (SOC-10505)"
  • batch: Use easy_merge for merging (SOC-10505)

  • Update to version 6.0+git.1569357869.75e2690cc:

  • Update input group to be more specific (SOC-10644)

  • Update to version 6.0+git.1569231374.0fa522d5d:

  • Revert "batch: Use easy_merge for merging (SOC-10505)"

  • Update to version 6.0+git.1568968829.f21efcf5e:

  • batch: Use easy_merge for merging (SOC-10505)

  • Update to version 6.0+git.1568744770.09e7a1fe1:

  • upgrade: Fix pie chart colors on dashboard (SOC-10619)

  • Update to version 6.0+git.1568201547.4dfc6ffec:

  • gems: Update easy_diff to 1.0.0 (SOC-10505)

  • Update to version 6.0+git.1567846948.0f169d133:

  • upgrade: Reload nova services early (SOC-10273)
  • upgrade: Update release name (trivial)
  • upgrade: Upgrade compute services early (SOC-10273)

  • Update to version 6.0+git.1567731275.6019e8f62:

  • IPV6:Expose methods in chef NetworkHelper to crowbar_framework (SOC-6397)

  • Update to version 6.0+git.1567694723.1a9df112d:

  • Allow designate rndc for all nodes (SOC-10339)

  • Update to version 6.0+git.1567599465.9b1ea2814:

  • upgrade: dump Monasca, Grafana databases (SOC-9772)

  • Update to version 6.0+git.1567195728.44b7cf1d0:

  • Public ips for dns nodes when designate integration is in use (SOC-9635)

  • Update to version 6.0+git.1567161357.ba5de8885:

  • network: Check existing upper layers before bond setup (bsc#1120657)
  • network: never plug two interface into the same ovs bridge (bsc#1120657)
  • network: Avoid plugging the same interface to two ovs bridges (bsc#1120657)
  • nic library: some helper for identifying base interface (bsc#1120657)
  • network: Rework the vlan port replugging code (bsc#1120657)
  • network: DRY out "kill_nic_files" (noref)
  • network: override sysctl netfilter param(SOC-6229)

  • Update to version 6.0+git.1567094352.24e2a710d:

  • upgrade: Re-run upgrade on non-compute nodes (SOC-10072)

  • Update to version 6.0+git.1566808212.3e1e65b69:

  • allow user to ask for FQDN as public hostname (SOC-9616)

  • Update to version 6.0+git.1567673476.1342c3d:

  • Fix typo in error message

  • Update to version 6.0+git.1569805311.a94583476:

  • Designate: Add dns_domain_ports config (SOC-10740)

  • Update to version 6.0+git.1569429613.2b29fd9d6:

  • horizon: add back horizon service reload (SOC-10191)
  • helper:move config_for_role_exists from horizon to crowbar-openstack(SOC-10191)
  • tempest: don't rely on service catalogue (SOC-10633)

  • Update to version 6.0+git.1569343076.e8ca90fd9:

  • enable LDAP chase_referrals configuration (SOC-7364)

  • Update to version 6.0+git.1569255523.d14bb0d9d:

  • nova: Don't autoselect nodes for Xen (continued) (bsc#1147144)

  • Update to version 6.0+git.1569053948.d0e638900:

  • Add pci passthrough filter (SOC-10624)
  • glance: don't reuse sync mark names (SOC-10348)
  • nova: Don't autoselect nodes for Xen (bsc#1147144)
  • database: fix no-op migration 302 (SOC-10623)
  • Fix Cloud 8 no-op migrations (SOC-10623)

  • Update to version 6.0+git.1568986202.bae13ce05:

  • designate: Fix the keys syntax error on migrations (SOC-10660)

  • Update to version 6.0+git.1568968817.8df296f0c:

  • upgrade: restore Monasca/Grafana DB (SOC-9772)

  • Update to version 6.0+git.1568904766.a7e023933:

  • Revert "designate: Mark as user managed (SOC-10233)"
  • nova: set default attribute for max_threads_per_process
  • Add tempest filter for designate (SOC-10288)
  • Allow setting ElasticSearch path.repo from Crowbar (SOC-10440, bsc#1148158)

  • Update to version 6.0+git.1568735102.940794f57:

  • Use source load balancing for OpenID Connect (SOC-10551)

  • Update to version 6.0+git.1568676694.b4ebc087b:

  • designate: Mark as user managed (SOC-10233)
  • Octavia: Hide UI until complete (SOC-10550)

  • Update to version 6.0+git.1568650755.8399d83e9:

  • IPV6: Barclamp horizon make IPV6 compliant (SOC-6397)

  • Update to version 6.0+git.1568325876.a82d6c3c6:

  • designate: Correct missing variable (SOC-10549)

  • Update to version 6.0+git.1568242913.38fe0574a:

  • designate: cleanup producer HA deployment (SOC-9766)

  • Update to version 6.0+git.1568130776.de1686df9:

  • designate: No longer care about master/slave (SOC-10456)
  • tempest: remove manila test from blacklist (SOC-9298)
  • nova: raise neutron client timeout to 5 minutes
  • neutron: Small cleanup to neutron_lbaas.conf template
  • neutron-lbaas: remove loadbalancer/pool limit

  • Update to version 6.0+git.1568004341.35d132726:

  • Designate default Bind9 pool config (SOC-10339)

  • Update to version 6.0+git.1567626408.bd1a24326:

  • nova: Don't put nova-compute roles on monasca node (SOC-10373)

  • Update to version 6.0+git.1567522813.05041a6eb:

  • Fix OpenID migration (SOC-9616)

  • Update to version 6.0+git.1567383972.eeae4cf86:

  • designate: Update ns_records with all nameservers (SOC-9636)

  • Update to version 6.0+git.1567095011.0d080dce4:

  • support OpenID Connect WebSSO (SOC-9616)

  • Update to version 6.0+git.1566925661.1e127bf66:

  • designate: Deploy producer on a server node (SOC-9766)

  • Update to version 6.0+git.1566851961.bda2f922c:

  • database: Hardcode ruby version for package installation (SOC-10010)

  • Update to version 6.0+git.1566629500.bbc0dd82f:

  • rabbitmq: Turn off hipe compile
  • designate: initialize email in default designate proposal

  • Update to version 6.0+git.1566553393.e01147258:

  • memcache: lookup memcached servers port only on local node (SOC-10173)

  • Update to version 1.3.0+git.1568396400.0344a727:

  • upgrade: Add missing precheck titles

  • spec file change:

  • alter permissions of /etc/grafana and /var/lib/grafana to 755
  • alter owner of /etc/grafana/provisioning/dashboards tree to root:root
  • this allows installing dashboards via rpms without these rpms depending on this rpm

  • Update to version 6.2.5:

  • release 6.2.5
  • Panel: Fully escape html in drilldown links (was only sanitized before) (#17731)
  • Grafana-CLI: Wrapper for grafana-cli within RPM/DEB packages and config/homepath are now global flags (#17695)
  • config: fix connstr for remote_cache (#17675)
  • TablePanel: fix annotations display (#17646)
  • middleware: fix Strict-Transport-Security header (#17644)
  • Elasticsearch: Fix empty query request to send properly (#17488)
  • release 6.2.4
  • grafana-cli: Fix receiving flags via command line (#17617)
  • HTTPServer: Fix X-XSS-Protection header formatting (#17620)
  • release 6.2.3
  • cli: grafana-cli should receive flags from the command line (#17606)
  • AuthProxy: Optimistic lock pattern for remote cache Set (#17485)
  • OAuth: Fix for wrong user token updated on OAuth refresh in DS proxy (#17541)
  • middleware: add security related HTTP(S) response headers (#17522)
  • remote_cache: Fix redis (#17483)
  • auth_proxy: non-negative cache TTL (#17495)

  • Update to version 6.2.2:

  • Security Fix: Prevent csv formula injection attack
  • PluginConfig: Fixed plugin config page navigation when using subpath
  • Explore: Update time range before running queries
  • Perf: Fix slow dashboards ACL query
  • Database: Initialize xorm with an empty schema for postgres
  • CloudWatch: Avoid exception while accessing results

  • Remove phantomjs dependency

  • Modified: Makefile
  • Update to version 6.2.1
  • Bug Fixes
    • Auth Proxy: Resolve database is locked errors.
    • Database: Retry transaction if sqlite returns database is locked error.
    • Explore: Fixes so clicking in a Prometheus Table the query is filtered by clicked value.
    • Singlestat: Fixes issue with value placement and line wraps.
    • Tech: Update jQuery to 3.4.1 to fix issue on iOS 10 based browers as well as Chrome 53.x.
  • Features / Enhancements
    • CLI: Add command to migrate all datasources to use encrypted password fields.
    • Gauge/BarGauge: Improvements to auto value font size.
  • Modified: README
  • Update to version 6.2.0
  • Bug Fixes
    • BarGauge: Fix for negative min values.
    • Gauge/BarGauge: Fix for issues editing min & max options.
    • Search: Make only folder name only open search with current folder filter.
    • AzureMonitor: Revert to clearing chained dropdowns.
    • Dashboard: Fixes blank dashboard after window resize with panel without title.
    • Dashboard: Fixes lazy loading & expanding collapsed rows on mobile.
    • Dashboard: Fixes scrolling issues for Edge browser.
    • Dashboard: Show refresh button in first kiosk(tv) mode.
    • Explore: Fix empty result from datasource should render logs container.
    • Explore: Fixes so clicking in a Prometheus Table the query is filtered by clicked value.
    • Explore: Makes it possible to zoom in Explore/Loki/Graph without exception.
    • Gauge: Fixes orientation issue after switching from BarGauge to Gauge.
    • GettingStarted: Fixes layout issues in getting started panel.
    • InfluxDB: Fix HTTP method should default to GET.
    • Panels: Fixed alert icon position in panel header.
    • Panels: Fixes panel error tooltip not showing.
    • Plugins: Fix how datemath utils are exposed to plugins.
    • Singlestat: fixed centering issue for very small panels.
    • Search: Scroll issue in dashboard search in latest Chrome.
    • Docker: Prevent a permission denied error when writing files to the default provisioning directory.
    • Gauge: Adds background shade to gauge track and improves height usage.
    • RemoteCache: Avoid race condition in Set causing error on insert. .
    • Build: Fix bug where grafana didn't start after mysql on rpm packages.
    • CloudWatch: Fixes query order not affecting series ordering & color.
    • CloudWatch: Use default alias if there is no alias for metrics.
    • Config: Fixes bug where timeouts for alerting was not parsed correctly.
    • Elasticsearch: Fix view percentiles metric in table without date histogram.
    • Explore: Prevents histogram loading from killing Prometheus instance.
    • Graph: Allow override decimals to fully override.
    • Mixed Datasource: Fix error when one query is disabled.
    • Search: Fixes search limits and adds a page parameter.
    • Security: Responses from backend should not be cached.
  • Breaking Changes
    • Plugins: Data source plugins that process hidden queries need to add a "hiddenQueries: true" attribute in plugin.json.
    • Gauge Panel: The suffix / prefix options have been removed from the new Gauge Panel (introduced in v6.0). #16870.
  • Features / Enhancements

    • Plugins: Support templated urls in plugin routes.
    • Packaging: New MSI windows installer package**.
    • Admin: Add more stats about roles.
    • Alert list panel: Support variables in filters.
    • Alerting: Adjust label for send on all alerts to default .
    • Alerting: Makes timeouts and retries configurable.
    • Alerting: No notification when going from no data to pending.
    • Alerting: Pushover alert, support for different sound for OK.
    • Auth: Enable retries and transaction for some db calls for auth tokens .
    • AzureMonitor: Adds support for multiple subscriptions per datasource.
    • Bar Gauge: New multi series enabled gauge like panel with horizontal and vertical layouts and 3 display modes.
    • Build: Upgrades to golang 1.12.4.
    • CloudWatch: Update AWS/IoT metric and dimensions.
    • Config: Show user-friendly error message instead of stack trace.
    • Dashboard: Enable filtering dashboards in search by current folder.
    • Dashboard: Lazy load out of view panels .
    • DataProxy: Restore Set-Cookie header after proxy request.
    • Datasources: Add pattern validation for time input on datasource config pages.
    • Elasticsearch: Add 7.x version support.
    • Explore: Adds reconnect for failing datasource.
    • Explore: Support user timezone.
    • InfluxDB: Add support for POST HTTP verb.
    • Loki: Search is now case insensitive.
    • OAuth: Update jwt regexp to include =.
    • Panels: No title will no longer make panel header take up space.
    • Prometheus: Adds tracing headers for Prometheus datasource.
    • Provisioning: Add API endpoint to reload provisioning configs.
    • Provisioning: Do not allow deletion of provisioned dashboards.
    • Provisioning: Interpolate env vars in provisioning files.
    • Security: Add new setting allow_embedding.
    • Security: Store datasource passwords encrypted in secureJsonData.
    • UX: Improve Grafana usage for smaller screens.
    • Units: Add angle units, Arc Minutes and Seconds.
  • Update to version 6.1.6

  • Security: Bump jQuery to 3.4.0
  • Playlist: Fix loading dashboards by tag.
  • Update to version 6.0.2:
  • Fixed issue with alert links in alert list panel causing panel not found errors, fixes #15680
  • Improved error handling when rendering dashboard panels, fixes #15913
  • fix allow anonymous server bind for ldap search
  • add nil/length check when delete old login attempts
  • fix discord notifier so it doesn't crash when there are no image generated
  • fix only users that can edit a dashboard should be able to update panel json
  • move to new component to handle focus
  • added state to not set focus on search every render
  • Snapshots update
  • Use app config directly in ButtonRow instead of passing datasources page URL via prop
  • Update snapshots
  • Fixed url of back button in datasource edit page, when root_url configured
  • release: Bumped version
  • Update to version 6.0.1:
  • Bug Fixes:
    • utils: show string errors
    • Viewers with viewers_can_edit should be able to access /explore
    • log phantomjs output even if it timeout and include orgId when render alert
  • Update to version 6.0.0:
  • Breaking Changes:
    • Text Panel: The text panel does no longer by default allow unsantizied HTML. This means that if you have text panels with scripts tags they will no longer work as before. To enable unsafe javascript execution in text panels enable the settings disable_sanitize_html under the section [panels] in your Grafana ini file, or set env variable GF_PANELS_ABLE_SANITIZE_HTML=true.
    • Dashboard: Panel property minSpan replaced by maxPerRow. Dashboard migration will automatically migrate all dashboard panels using the minSpan property to the new maxPerRow property
    • Internal Metrics Edition has been added to the build_info metric. This will break any Graphite queries using this metric. Edition will be a new label for the Prometheus metric.
  • New Features:
    • Alerting: Adds support for Google Hangouts Chat notifications
    • Elasticsearch: Support bucket script pipeline aggregations
    • Influxdb: Add support for time zone (tz) clause
    • Snapshots: Enable deletion of public snapshot
    • Provisioning: Provisioning support for alert notifiers
    • Explore: A whole new way to do ad-hoc metric queries and exploration. Split view in half and compare metrics & logs and much much more. Read more here
    • Auth: Replace remember me cookie solution for Grafana's builtin, LDAP and OAuth authentication with a solution based on short-lived tokens
    • AzureMonitor: Enable alerting by converting Azure Monitor API to Go
    • Explore A new query focused workflow for ad-hoc data exploration and troubleshooting.
    • Grafana Loki Integration with the new open source log aggregation system from Grafana Labs.
    • Gauge Panel A new standalone panel for gauges.
    • New Panel Editor UX improves panel editing and enables easy switching between different visualizations.
    • Google Stackdriver Datasource is out of beta and is officially released.
    • React Plugin support enables an easier way to build plugins.
    • Named Colors in our new improved color picker.
    • Removal of user session storage makes Grafana easier to deploy & improves security.
  • Bug Fixes:
    • Metrics: Fixes broken usagestats metrics for /metrics
    • Dashboard: Fixes kiosk mode should have &kiosk appended to the url
    • Dashboard: Fixes kiosk=tv mode with autofitpanels should respect header
    • Image rendering: Fixed image rendering issue for dashboards with auto refresh,
    • Dashboard: Fix only users that can edit a dashboard should be able to update panel json.
    • LDAP: fix allow anonymous initial bind for ldap search.
    • UX: Fixed scrollbar not visible initially (only after manual scroll).
    • Datasource admin TestData
    • Dashboard: Fixed scrolling issue that caused scroll to be locked to bottom.
    • Explore: Viewers with viewers_can_edit should be able to access /explore.
    • Security fix: limit access to org admin and alerting pages.
    • Panel Edit minInterval changes did not persist
    • Teams: Fixed bug when getting teams for user.
    • Stackdriver: fix for float64 bounds for distribution metrics
    • Stackdriver: no reducers available for distribution type
    • Influxdb: Add support for alerting on InfluxDB queries that use the non_negative_difference function
    • Alerting: Fix percent_diff calculation when points are nulls
    • Alerting: Fixed handling of alert urls with true flags
    • Gauge: Fix issue with gauge requests being cancelled
    • Gauge: Accept decimal inputs for thresholds
    • UI: Fix error caused by named colors that are not part of named colors palette
    • Search: Bug pressing special regexp chars in input fields
    • Permissions: No need to have edit permissions to be able to "Save as"
    • Search: Fix for issue with scrolling the "tags filter" dropdown
    • Prometheus: Query for annotation always uses 60s step regardless of dashboard range
    • Annotations: Fix creating annotation when graph panel has ata points position the popup outside viewport
    • Piechart/Flot: Fixes multiple piechart instances with donut bug
    • plus many minor changes and fixes
  • Update to version 5.4.3:
  • Fixes:
    • Alerting Invalid frequency causes division by zero in alert scheduler
    • Dashboard Dashboard links do not update when time range changes
    • Limits Support more than 1000 datasources per org
    • Backend fix signed in user for orgId=0 result should return active org id
    • Provisioning Adds orgId to user dto for provisioned dashboards
  • Update to version 5.4.2:
  • Fixes:
    • Datasource admin: Fix for issue creating new data source when same name exists
    • OAuth: Fix for oauth auto login setting, can now be set using env variable
    • Dashboard search: Fix for searching tags in tags filter dropdown.
  • Update to version 5.4.1:
  • Fixes:
    • Stackdriver: Fixes issue with data proxy and Authorization header
    • Units: fixedUnit for Flow:l/min and mL/min
    • Logging: Fix for issue where data proxy logged a secret when debug logging was enabled, now redacted.
    • InfluxDB: Add support for alerting on InfluxDB queries that use the cumulative_sum function.
    • Plugins: Panel plugins should no receive the panel-initialized event again as usual.
    • Embedded Graphs: Iframe graph panels should now work as usual.
    • Postgres: Improve PostgreSQL Query Editor if using different Schemas,
    • Quotas: Fixed for updating org & user quotas.
    • Cloudwatch: Add the AWS/SES Cloudwatch metrics of BounceRate and ComplaintRate to auto complete list.
    • Dashboard Search: Fixed filtering by tag issues.
    • Graph: Fixed time region issues,
    • Graph: Fixed issue with series color picker popover being placed outside window.
  • Update to version 5.4.0:
  • Breaking Changes:
    • Postgres/MySQL/MSSQL datasources now per default uses max open connections = unlimited (earlier 10), max idle connections = 2 (earlier 10) and connection max lifetime = 4 hours (earlier unlimited).
  • Features:
    • Alerting: Introduce alert debouncing with the FOR setting.
    • Alerting: Option to disable OK alert notifications
    • Postgres/MySQL/MSSQL: Adds support for configuration of max open/idle connections and connection max lifetime. Also, panels with multiple SQL queries will now be executed concurrently
    • MySQL: Graphical query builder
    • MySQL: Support connecting thru Unix socket for MySQL datasource
    • MSSQL: Add encrypt setting to allow configuration of how data sent between client and server are encrypted
    • Stackdriver: Not possible to authenticate using GCE metadata server
    • Teams: Team preferences (theme, home dashboard, timezone) support
    • Graph: Time regions support enabling highlight of weekdays and/or certain timespans
    • OAuth: Automatic redirect to sign-in with OAuth
    • Stackdriver: Template query editor
  • Fixes:
    • Cloudwatch: Fix invalid time range causes segmentation fault
    • Cloudwatch: AWS/CodeBuild metrics and dimensions
    • MySQL: Fix $__timeFrom() and $__timeTo() should respect local time zone
    • Graph: Fix legend always visible even if configured to be hidden
    • Elasticsearch: Fix regression when using datasource version 6.0+ and alerting
  • Update to version 5.3.4:
  • minor bug fixes

  • Fix patch novnc-1.0.0-fix-interpreter.patch

  • Renamed to patch novnc-1.1.0-fix-interpreter.patch
  • Update to 1.1.0: Application:

    • New translations for Russian, Korean, Czech and Chinese (traditional) languages
    • Fixed an issue where you didn't get scrollbn your browser on Windows if you had a touch screen.
    • Added the Super/Windows key to the toolbar.
    • Added an option to show a dot when there otherwise wouldn't be a visible cursor.
    • View drag is no longer available when in scaling mode. Library:
    • A large number of coding style changes has been made to make the code easier to read and better to work with.
    • Many keyboard issues has been fixed.
    • Local cursor is now available on all platforms.
    • Fixed a number of crashes related to clipboard.
    • Fixed issues that occurred if data from the server was being received slowly.
    • A problem has been fixed where the display module would incorrectly handle high DPI systems causing scrollbars to show when they shouldn't.
  • require python3-websockify for recent distros (bsc#1119737)

  • Update to version cinder-13.0.7.dev16:

  • Dell EMC SC: Handle the mappings of multiattached volume

  • Update to version cinder-13.0.7.dev14:

  • 3PAR: Add config for NSP single path attach

  • Update to version cinder-13.0.7.dev12:

  • Fix VolumeAttachment is not bound to a Session
  • Fix ceph: only close rbd image after snapshot iteration is finished

  • Update to version cinder-13.0.7.dev8:

  • Fix NFS volume retype with migrate

  • Update to version cinder-13.0.7.dev7:

  • Remove experimental openSUSE 42.3 job

  • Update to version cinder-13.0.7.dev5:

  • Fixing 404's and broken links

  • Update to version cinder-13.0.7.dev16:

  • Dell EMC SC: Handle the mappings of multiattached volume

  • Update to version cinder-13.0.7.dev14:

  • 3PAR: Add config for NSP single path attach

  • Update to version cinder-13.0.7.dev12:

  • Fix VolumeAttachment is not bound to a Session
  • Fix ceph: only close rbd image after snapshot iteration is finished

  • Update to version cinder-13.0.7.dev8:

  • Fix NFS volume retype with migrate

  • Update to version cinder-13.0.7.dev7:

  • Remove experimental openSUSE 42.3 job

  • Update to version cinder-13.0.7.dev5:

  • Fixing 404's and broken links

  • Update to version horizon-14.0.4.dev11:

  • Fix listing security groups when no rules

  • Update to version horizon-14.0.4.dev9:

  • Fix quoting in zuul for tempest plugins
  • Allow creating ICMPV6 rules

  • Update to version horizon-14.0.4.dev6:

  • Ensure to call patch_middleware_get_user() in api.test_base

  • Update to version horizon-14.0.4.dev5:

  • Fixing broken links

  • Update to version designate-7.0.1.dev22:

  • Fixing 404 link

  • Update to version designate-7.0.1.dev22:

  • Fixing 404 link

  • Update to version glance-17.0.1.dev30:

  • Fix manpage building and remove glance-cache-manage

  • Update to version glance-17.0.1.dev28:

  • Fix doc build after removal of glance-cache-manage man page

  • Update to version glance-17.0.1.dev26:

  • Updating Ceph 404 URLs

  • Update to version glance-17.0.1.dev24:

  • Remove experimental openSUSE 42.3 job
  • OpenDev Migration Patch

  • Update to version glance-17.0.1.dev22:

  • Failure in web-dowload kept image in importing state
  • Replace openstack.org git:// URLs with https://
  • Data remains in staging area if 'file' store is not enabled
  • Removed glancecachemanage.rst and updated header.txt

  • Update to version glance-17.0.1.dev30:

  • Fix manpage building and remove glance-cache-manage

  • Rebased patches:

  • 0001-Fix-manpage-building-and-remove-glance-cache-manage.patch dropped (merged upstream)

  • Update to version glance-17.0.1.dev28:

  • Fix doc build after removal of glance-cache-manage man page

  • Update to version glance-17.0.v26:

  • Updating Ceph 404 URLs

  • Update to version glance-17.0.1.dev24:

  • Remove experimental openSUSE 42.3 job
  • OpenDev Migration Patch

  • Add 0001-Drop-glance-cache-manage-entrypoint-from-setup.cfg.patch (SOC-6366) This removes the broken entrypoint for /usr/bin/glance-cache-manage The code behind the executable was already removed upstream so the executable was not usable

  • Update to version glance-17.0.1.dev22:

  • Failure in web-dowload kept image in importing state
  • Replace openstack.org git:// URLs with https://
  • Data remains in staging area if 'file' store is not enabled
  • Removed glancecachemanage.rst and updated header.txt
  • Add 0001-Fix-manpage-building-and-remove-glance-cache-manage.patch This fixes the manpage build which is needed after the removal of glancecachemanage.rst by upstream

  • Update to version openstack-heat-11.0.3.dev23:

  • Add retries when loading keystone data and fetching endpoints

  • Update to version openstack-heat-11.0.3.dev22:

  • Use connect_retries when creating clients

  • Update to version openstack-heat-11.0.3.dev20:

  • Add retry for sync_point_update_input_data

  • Update to version openstack-heat-11.0.3.dev23:

  • Add retries when loading keystone data and fetching endpoints

  • Update to version openstack-heat-11.0.3.dev22:

  • Use connect_retries when creating clients

  • Update to version openstack-heat-11.0.3.dev20:

  • Add retry for sync_point_update_input_data

  • Include heat_policy.json (bsc#1152032)

  • Fixed the unexpected error in Horizon when Heat dashboard is enabed

  • update to version 1.14.1~dev9

  • Hide Graph Metric action of alarm when Grafana is not available
  • OpenDev Migration Patch

  • Update to version ironic-11.1.4.dev15:

  • Fix typo in handling of exception FailedToGetIPAddressOnPort

  • Update to version ironic-11.1.4.dev14:

  • DRAC: Fix OOB introspection to use pxe_enabled flag in idrac driver
  • iLO firmware update fails with 'update_firmware_sum' clean step

  • Update to version ironic-11.1.4.dev10:

  • CI: remove quotation marks from TEMPEST_PLUGINS variable

  • Update to version ironic-11.1.4.dev15:

  • Fix typo in handling of exception FailedToGetIPAddressOnPort

  • Update to version ironic-11.1.4.dev14:

  • DRAC: Fix OOB introspection to use pxe_enabled flag in idrac driver
  • iLO firmware update fails with 'update_firmware_sum' clean step

  • Update to version ironic-11.1.4.dev10:

  • CI: remove quotation marks from TEMPEST_PLUGINS variable

  • Update to version ironic-python-agent-3.3.3.dev5:

  • Fix compatibility with Pint 0.5

  • Update to version keystone-14.1.1.dev16:

  • Fixing 404 URLs for Rocky

  • Update to version keystone-14.1.1.dev15:

  • Updating mapping rule link

  • Update to version keystone-14.1.1.dev13:

  • Fix python3 compatibility on LDAP search DN from id
  • Fixing dn_to_id function for cases were id is not in the DN

  • Update to version keystone-14.1.1.dev9:

  • Remove experimental openSUSE 42.3 job

  • Update to version keystone-14.1.1.dev16:

  • Fixing 404 URLs for Rocky

  • Update to version keystone-14.1.1.dev15:

  • Updating mapping rule link

  • Update to version keystone-14.1.1.dev13:

  • Fix python3 compatibility on LDAP search DN from id
  • Fixing dn_to_id function for cases were id is not in the DN

  • Update to version keystone-14.1.1.dev9:

  • Remove experimental openSUSE 42.3 job

  • Update to version manila-7.3.1.dev6:

  • Unmount NetApp active share after replica promote

  • Update to version manila-7.3.1.dev4:

  • Fixing broken links

  • Updateon manila-7.3.1.dev6:

  • Unmount NetApp active share after replica promote

  • Update to version manila-7.3.1.dev4:

  • Fixing broken links

  • Update to version neutron-13.0.5.dev50:

  • DVR: Cleanup ml2 dvr portbindings on migration

  • Update to version neutron-13.0.5.dev49:

  • Avoid unnecessary operation of ovsdb and flows

  • Update to version neutron-13.0.5.dev48:

  • Increase timeouts for OVSDB in functional tests

  • Update to version neutron-13.0.5.dev46:

  • Fix creation of vlan network with segmentation_id set to 0
  • Add info log about ready DHCP config for ports

  • Update to version neutron-13.0.5.dev42:

  • Check the namespace is ready in test_mtu_update tests
  • Create _mech_context before delete to avoid race

  • Update to version neutron-13.0.5.dev39:

  • ML2 plugin: extract and postpone limit in port query
  • Increase TestDhcpAgentHA.agent_down_time to 30 seconds

  • Update to version neutron-13.0.5.dev35:

  • Use created subnet in port generator in "test_port_ip_update_revises"

  • Update to version neutron-13.0.5.dev34:

  • Increase number of retries in _process_trunk_subport_bindings

  • Update to version neutron-13.0.5.dev33:

  • Filter placement API endpoint by type too

  • Update to version neutron-13.0.5.dev31:

  • Remove experimental openSUSE 42.3 job
  • Initialize phys bridges before setup_rpc
  • Populate binding levels when concurrent ops fail
  • Make sure the port still in port map when prepare_port_filter
  • [DVR] Add lock during creation of FIP agent gateway port

  • Update to version neutron-13.0.5.dev50:

  • DVR: Cleanup ml2 dvr portbindings on migration

  • Update to version neutron-13.0.5.dev49:

  • Avoid unnecessary operation of ovsdb and flows

  • Update to version neutron-13.0.5.dev48:

  • Increase timeouts for OVSDB in functional tests

  • Update to version neutron-13.0.5.dev46:

  • Fix creation of vlan network with segmentation_id set to 0
  • Add info log about ready DHCP config for ports

  • Update to version neutron-13.0.5.dev42:

  • Check the namespace is ready in test_mtu_update tests
  • Create _mech_context before delete to avoid race

  • Update to version neutron-13.0.5.dev39:

  • ML2 plugin: extract and postpone limit in port query
  • Increase TestDhcpAgentHA.agent_down_time to 30 seconds

  • Update to version neutron-13.0.5.dev35:

  • Use created subnet in port generator in "test_port_ip_update_revises"

  • Update to version neutron-13.0.5.dev34:

  • Increase number of retries in _process_trunk_subport_bindings

  • Update to version neutron-13.0.5.dev33:

  • Filter placement API endpoint by type too

  • Update to version neutron-13.0.5.dev31:

  • Remove experimental openSUSE 42.3 job
  • Initialize phys bridges before setup_rpc
  • Populate binding levels when concurrent ops fail
  • Make sure the port still in port map when prepare_port_filter
  • [DVR] Add lock during creation of FIP agent gateway port

  • Update to version group-based-policy-5.0.1.dev472:

  • [AIM] Fix HAIP RPC query

  • Update to version group-based-policy-5.0.1.dev471:

  • Fix implicit ICMPv6 Security Group Rules

  • Update to version group-based-policy-5.0.1.dev470:

  • Fixed snat port status to be ACTIVE and UP

  • Update to version group-based-policy-5.0.1.dev468:

  • Revert "Make DHCP provisioning blocks conditional"
  • Some refactoring regarding merge aim statuses

  • Update to version group-based-policy-5.0.1.dev464:

  • Verify aim_epg exists before proceeding

  • Update to version group-based-policy-5.0.1.dev462:

  • Bulk extension support for

  • Update to version group-based-policy-5.0.1.dev461:

  • [AIM] Eliminate redundant router extension content

  • Update to version group-based-policy-5.0.1.dev460:

  • Fix for Commit 564905e49a0d418bc891f12b560e291a9fdc4acb 1. The method _track_connectivity returns nothing, so, self.track_success is updated in the method itself

  • Update to version nova-18.2.3.dev22:

  • lxc: make use of filter python3 compatible
  • Fix rebuild of baremetal instance when vm_state is ERROR
  • Fix wrong assertions in unit tests
  • Fix 'has_calls' method calls in unit tests
  • Fix non-existent method of Mock
  • Retrun 400 if invalid query parameters are specified

  • Update to version nova-18.2.3.dev10:

  • doc: Fix a broken reference link

  • Update to version nova-18.2.3.dev9:

  • Restore soft-deleted compute node with same uuid
  • Add functional regression recreate test for bug 1839560
  • rt: only map compute node if we created it

  • Update to version nova-18.2.3.dev3:

  • Remove experimental job on openSUSE 42.3

  • Update to version nova-18.2.3.dev2:

  • Fix misuse of nova.objects.base.obj_equal_prims 18.2.2
  • Don't generate service UUID for deleted services
  • Add 'path' query parameter to console access url
  • Replace non-nova server fault message
  • Avoid logging traceback when detach device not found
  • Fix python3 compatibility of rbd get_fsid
  • Add functional regression test for bug 1778305
  • Add functional recreate test for bug 1764556
  • Cleanup when hitting MaxRetriesExceeded from no host_available
  • Add functional regression test for bug 1837955
  • Revert "[libvirt] Filter hypervisor_type by virt_type"
  • Avoid crashing while getting libvirt capabilities with unknown arch names
  • libvirt: move checking CONF.my_ip to init_host()
  • Revert resize: wait for events according to hybrid plug
  • docs: Correct issues with 'openstack quota set' commands
  • doc: Fix a parameter of NotificationPublisher
  • Perf: Use dicts for ProviderTree roots
  • Fix type error on call to mount device
  • Drop source node allocations if finish_resize fails
  • Add functional recreate test for regression bug 1825537
  • Stabilize unshelve notification sample tests
  • Ignore hw_vif_type for direct, direct-physical vNIC types
  • Fix double word hacking test
  • Disable limit if affinity(anti)/same(different)host is requested
  • Delete resource providers for all nodes when deleting compute service

  • Update to version nova-18.2.3.dev22:

  • lxc: make use of filter python3 compatible
  • Fix rebuild of baremetal instance when vm_state is ERROR
  • Fix wrong assertions in unit tests
  • Fix 'has_calls' method calls in unit tests
  • Fix non-existent method of Mock
  • Retrun 400 if invalid query parameters are specified

  • Update to version nova-18.2.3.dev10:

  • doc: Fix a broken reference link

  • Allow to attach more than 26 volumes (bsc#1118900)

  • This is a forward port from SOC7
  • Add 0001-Add-method-to-generate-device-names-universally.patch
  • Add 0002-Raise-403-instead-of-500-error-from-attach-volume-AP.patch
  • Add 0003-Add-configuration-of-maximum-disk-devices-to-attach.patch

  • Update to version nova-18.2.3.dev9:

  • Restore soft-deleted compute node with same uuid
  • Add functional regression recreate test for bug 1839560
  • rt: only map compute node if we created it

  • Update to version nova-18.2.3.dev3:

  • Remove experimental job on openSUSE 42.3

  • Update to version nova-18.2.3.dev2:

  • Fix misuse of nova.objects.base.obj_equal_prims
  • Don't generate service UUID fed services
  • Add 'path' query parameter to console access url
  • Replace non-nova server fault message
  • Avoid logging traceback when detach device not found
  • Fix python3 compatibility of rbd get_fsid
  • Add functional regression test for bug 1778305
  • Add functional recreate test for bug 1764556
  • Cleanup when hitting MaxRetriesExceeded from no host_available
  • Add functional regression test for bug 1837955
  • Revert "[libvirt] Filter hypervisor_type by virt_type"
  • Avoid crashing while getting libvirt capabilities with unknown arch names
  • libvirt: move checking CONF.my_ip to init_host()
  • Revert resize: wait for events according to hybrid plug
  • docs: Correct issues with 'openstack quota set' commands
  • doc: Fix a parameter of NotificationPublisher
  • Perf: Use dicts for ProviderTree roots
  • Fix type error on call to mount device
  • Drop source node allocations if finish_resize fails
  • Add functional recreate test for regression bug 1825537
  • Stabilize unshe