Wednesday, 2018-06-06

*** weshay_ has joined #openstack-infra-incident00:28
*** myoung|off has quit IRC00:31
*** weshay has quit IRC00:32
*** myoung has joined #openstack-infra-incident00:33
*** myoung_ has joined #openstack-infra-incident00:43
*** weshay has joined #openstack-infra-incident00:43
*** weshay_ has quit IRC00:44
*** myoung has quit IRC00:44
*** rosmaita has quit IRC02:56
*** rlandy|rover|bbl is now known as rlandy|rover04:10
*** lifeless has quit IRC07:02
*** lifeless has joined #openstack-infra-incident07:02
*** lifeless has quit IRC07:22
*** lifeless has joined #openstack-infra-incident07:28
*** lifeless has quit IRC09:05
*** lifeless has joined #openstack-infra-incident09:42
*** lifeless has quit IRC10:26
*** lifeless has joined #openstack-infra-incident10:27
*** lifeless_ has joined #openstack-infra-incident10:57
*** lifeless has quit IRC10:57
*** rosmaita has joined #openstack-infra-incident11:58
*** lifeless_ has quit IRC13:16
*** myoung_ is now known as myoung13:21
*** myoung is now known as myoung|lunch16:50
clarkbubuntu has packages18:09
clarkbstill no centos packages or tumbleweed packages :/18:10
clarkb2.7.4-0ubuntu1.4 is the pckage we want on ubuntu xenial18:11
clarkbmore accurately 1:2.7.4-0ubuntu1.418:11
clarkbinfra-root I am going to start updating git on zuul infrastructure18:13
clarkbdo we want to run it on a zuul merger for a little while before udpating everything?18:13
clarkb(I don't expect it will cause us problems)18:14
corvusclarkb: context?18:14
clarkbcorvus: git CVE from last week finally patched in ubuntu. Allows arbitrary code execution through carefully crafted submodule config18:14
clarkbjgit is not affected18:14
corvusah, thx18:14
clarkbadditionally they updated git fsck to cehcek for this case so I will run git fsck against my local copy of all the repos18:15
clarkbI updated git on zm0118:17
clarkbwe can let it run for a few there before doing the global update18:17
*** myoung|lunch is now known as myoung18:18
clarkbon zm01 at least the two packages we want to update are git and git-man18:23
clarkbdpkg -l | grep git should show you if there are others on other systems18:23
clarkbhrm maybe I misread that fsck would check for this. Still looking int othat18:32
clarkbok git has been used a bit on zm01 since I updated it I am going to use ansible to update zm* ze* and zuul0118:43
clarkbzuul01, zm* and ze* have updated git18:52
clarkbpuppetmaster too18:52
clarkbI've got a local fsck running now too across all the repos.19:01
clarkbprobably a decent idea for someone else to do this too just to make sure I don't miss something silly and not actualyl verify what we want to verify19:01
clarkblooks like about half or maybe a little more of our instances are already updated by autoupdates19:08
fungithanks for spotting. i just walked back in the door19:12
clarkbfungi: in general I think the important hosts are patched. We should make sure all of them are though19:12
fungii _think_ you needed to set an explicit git option to check for this stuff after updating?19:12
clarkbfungi: you do if accepting pushes from git clients using C git19:13
clarkbfungi: but separate fsck itself seems to have a check for this19:13
fungiahh, that's what it was19:13
fungiso fsck will check that regardless19:13
clarkbhttp://launchpadlibrarian.net/372600366/git_1%3A2.17.0-1ubuntu1_1%3A2.17.1-1ubuntu1.diff.gz grep for 'fsck detects symlinked'19:13
fungiyep, looks right19:14
clarkbmy process was to clone all the repos as of after we got zuul updated, then do a for loop of git remote update && git fsck --full over all of them19:20
clarkbso far it hasn'ed errexited19:20
*** lifeless has joined #openstack-infra-incident19:35
clarkbmy local fsck got through all the projects without erroring19:41
*** myoung is now known as myoung|off21:06
*** lifeless_ has joined #openstack-infra-incident21:22
*** lifeless has quit IRC21:23
*** lifeless_ has quit IRC22:34
*** lifeless has joined #openstack-infra-incident22:34
*** rlandy|rover is now known as rlandy|rover|bbl22:37
*** lifeless has quit IRC23:46
*** lifeless has joined #openstack-infra-incident23:46

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!