Thursday, 2023-01-26

rajiv_Hi, is the today's glance meeting cancelled ?14:20
opendevreviewMerged openstack/glance stable/victoria: Enforce image safety during image_conversion  https://review.opendev.org/c/openstack/glance/+/87162314:48
opendevreviewPavlo Shchelokovskyy proposed openstack/glance master: Allow easier admin override in policies  https://review.opendev.org/c/openstack/glance/+/87182614:56
tobias-urdindansmith: would removing vmdk from disk_formats in glance.conf prevent upload/import of vmdk based images to prevent the CVE?15:42
dansmithtobias-urdin: I'd have to look again at the code, but doing that only prevents you from creating an image with disk_format=vmdk, but if you still send it vmdk content, qemu-img will format-detect it unless it's told specifically15:43
dansmithso I'd have to look if we did that before or not15:44
dansmith(I wrote those patches two months ago)15:44
dansmithtobias-urdin: much safer to apply the patch of course15:44
tobias-urdindansmith: yeah, I was just curious had a question internally about that, but yeah codepath might do the wrong thing even before it's determined to be a vmdk15:49
opendevreviewGuillaume Espanel proposed openstack/glance master: Limit CaptureRegion sizes in format_inspector for VMDK and VHDX  https://review.opendev.org/c/openstack/glance/+/87183116:04
gesthis ^ should fix another little bug found when digging around VMDK16:08
opendevreviewCyril Roelandt proposed openstack/glance stable/train: Enforce image safety during image_conversion  https://review.opendev.org/c/openstack/glance/+/87163017:15
*** EugenMayer42 is now known as EugenMayer418:12
*** EugenMayer46 is now known as EugenMayer419:04

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!