September 19, 2026
Stackers Network Digest — September 19, 2026
The Big Picture
The Hibiscus (2026.2) cycle is winding down, with RC1 tagged for most projects and the coordinated release just two weeks away. The week's dominant themes are the tail end of the release cycle (highlights due, RC exceptions, countdown to R-1), the freshly concluded TC election, and a growing conversation about security posture — from a Swift/Keystone regression in the EC2 credential mitigation, to a Barbican UI revival, to the setuptools 82 fallout ripping through legacy WSGI stacks. Meanwhile, planning for the October PTG in Indri is now official.
Releases & Announcements
Hibiscus (2026.2) is entering the final stretch. Most cycle-with-rc deliverables have tagged RC1. Elõd Illés kicked off the R-1 countdown for Sep 21–25, and Brian Rosmaita called Cinder's final Festival of Reviews of the cycle for Friday to whip RC2 into shape.
October 2026 PTG teams are set. Kendall Nelson published the confirmed project team list: 15 OpenStack service teams plus Eventlet Removal and the TC, alongside Kata, StarlingX, and community WGs. Teams not on the list need to contact [email protected] immediately; moderators will soon be scheduling slots via PTGBot.
Security
Residual EC2 credential exposure breaks Swift's S3 API under the proposed mitigation. Andressa Cabistani did the legwork of testing draft OSSN-0109 — the operator-side policy override to close the EC2 credential gap left over from OSSA-2026-037 — and found that setting identity:s3tokens_validate to "!" breaks every S3 request against Swift with a misleading SignatureDoesNotMatch error. Two other rules (ec2_get_credential, ec2_list_credentials) silently disable Swift's secret caching. She's proposed alternative wording for OSSN-0109 and flagged that Swift/Keystone maintainers should coordinate before the note lands. See the full analysis and bug 2119646.
Infomaniak's bug bounty is open for OpenStack findings. Thomas Goirand reminded researchers that Infomaniak's public cloud (built on OpenStack) accepts responsible disclosure via YesWeHack, with payouts up to €7,000. Duplicates of already-embargoed reports don't qualify — coordinate with the VMT.
Cinder RBAC gap for os-services. Nguyễn Hữu Khôi is asking for reviews on a fix that lets operators actually delegate read-only service listing via policy, instead of requiring full admin credentials for basic monitoring.
Development & Technical Decisions
pkg_resources is gone in setuptools ≥ 82 and it's blowing up the Paste ecosystem. Thomas Goirand warned that with setuptools 84 now in Debian unstable, paste, pastedeploy, pastescript, and calmjs are all broken — which in turn breaks most projects that expose an API and most Horizon plugins. He's fixed several downstream and filed a PR against calmjs, but is arguing this is a fresh reason for OpenStack to pick a blessed API framework rather than letting each project drift into Flask/Paste/Falcon/etc. Expect follow-up.
Proposal: branch requirements at Milestone 3 instead of freezing. Stephen Finucane proposed that starting in Indri, openstack/requirements be branched at M3 (like other non-service deliverables), with services temporarily pointing TOX_CONSTRAINTS_FILE at the outgoing branch and reverting during the "Update master" patch. The goal is to recover the 10–14 weeks per year that Oslo, OSC, ksa, and SDK currently spend "downing tools" during freezes. Tooling patches are up: releases 1005720 plus Neutron examples (1005103, 1005104).
Reviving barbican-ui with a dedicated core team. Barbican PTL Mauricio Harley is proposing a barbican-ui-core Gerrit group to unblock the Django/Horizon-native rewrite led by Ivan Anfimov and Kiran Pawar, since barbican-core lacks frontend expertise. Volunteers welcome; discussion continues at the Barbican meeting on Sep 28.
TC weekly digest. Goutham Pacha Ravi's R-2 summary flagged two ongoing debates worth watching: Keystone's core-team bandwidth is saturated by security work (making drive-by contributions hard, with parts of the codebase in need of redesign), and there's an open governance proposal to add Rust as an official language — a precursor to Keystone rework. A separate thread on the Tacker team surfaces a release-liaison gap and stalled deliverables (tosca-parser, python-tackerclient, tacker-horizon).
Manila / Dell PowerScale behavior questions. Inyong Hong raised two concerns: the PowerScale driver leaves shares world-accessible when no access rules are set (other drivers deny by default), and export locations are built from the OneFS management address rather than data LIFs as NetApp does. Possibly bug-worthy; verified on OneFS 9.13.0.0.
Heads Up / Action Needed
- Cycle highlights due Sep 18. PTLs/DPLs should submit 2026.2 highlights to the
openstack/releasesrepo with hashtag2026.2-cycle-highlights. Goutham is explicitly asking teams to call out "Security & Maintenance Toil" this cycle. - Requirements freeze exception request. Rodolfo Alonso Hernandez is requesting FFEs for 2026.2 releases of neutron-lib (missed TaaS in an API filter validation) and python-openstackclient (was defaulting to sha1, which Neutron deprecated).
- Review requested: Cyril Roelandt is asking for eyes on Glance change 972507 (override urllib User-Agent header).
Community & Events
TC election results are in. Ian Y. Choi announced the four newly elected members for the 2027.1 cycle: Artem Goncharov (gtema), Christian Berendt (berendt), Doug Goldstein (cardoe), and Dr. Jens Harbott (frickler). Full results.
Charms proposes a new stable-maint member. Edward Hope-Morley nominated Seyeong Kim to charms-stable-maint based on a year of active reviewing.
RDO packaging restart continues. The next meeting to resume RDO RPM packaging is on the rdo-volunteers etherpad; coordination is happening in #centos-cloud:fedoraproject.org on Matrix.
This week in code · Week of 2026-09-19
Most active projects
- openstack/swift 37 merges ▲ +72% 🔥
- openstack/neutron 23 merges ▲ +10%
- openstack/kayobe 29 merges ▲ +132% 🔥
- openstack/trove 24 merges ▲ +129% 🔥
- openstack/horizon 16 merges ▲ +156% 🔥