| eolivare | hi there, any known issue? https://zuul.opendev.org/t/openstack/builds?result=POST_FAILURE&skip=0 | 10:52 |
|---|---|---|
| sean-k-mooney | based on the faileure im also seeign i woudl have to assume one fo the swift provider we use has an issue | 11:29 |
| opendevreview | Stephen Finucane proposed openstack/openstack-zuul-jobs master: Add openstack-tox-py315 job https://review.opendev.org/c/openstack/openstack-zuul-jobs/+/992771 | 11:47 |
| opendevreview | Stephen Finucane proposed openstack/openstack-zuul-jobs master: Add openstack-python3-next-jobs template https://review.opendev.org/c/openstack/openstack-zuul-jobs/+/993337 | 11:47 |
| opendevreview | Stephen Finucane proposed openstack/openstack-zuul-jobs master: Add openstack-python3-client-library-jobs template https://review.opendev.org/c/openstack/openstack-zuul-jobs/+/992769 | 11:48 |
| opendevreview | Stephen Finucane proposed openstack/openstack-zuul-jobs master: Test python3.15 (non-voting) for clients, libraries in 2026.2 https://review.opendev.org/c/openstack/openstack-zuul-jobs/+/992772 | 11:48 |
| -opendevstatus- NOTICE: Recent POST_FAILURE job results with no logs were due to upload errors in one of our providers, which has been temporarily disabled now so rechecking those should be safe | 12:44 | |
| *** iurygregory_ is now known as iurygregory | 13:46 | |
| opendevreview | Monty Taylor proposed openstack/project-config master: Add repos for drizzle website and sysadmin automation https://review.opendev.org/c/openstack/project-config/+/993214 | 15:35 |
| sean-k-mooney | was the docs site down brifly or was that perhas impacted by the swift issues in ovh? | 17:46 |
| sean-k-mooney | https://docs.openstack.org/api-ref/network/v2/index.html seam to be workign fine now | 17:47 |
| sean-k-mooney | but it took abotu 5 minutes for that to load before | 17:47 |
| fungi | sean-k-mooney: it was down briefly, we're seeing a new army of crawkers making millions of requests, discussion is in #opendev:opendev.org matrix | 17:51 |
| sean-k-mooney | fungi: no worries | 17:51 |
| fungi | it's been coming and going but i've proposed https://review.opendev.org/c/opendev/system-config/+/993428 to hopefully stop it | 17:51 |
| sean-k-mooney | i was just wondering if it was related to the previous ovh issue or not | 17:51 |
| fungi | nah, the ovh swift issues were restricted to zuul log uploads/serving | 17:52 |
| fungi | docs.openstack.org (and most of the other static content sites we host) are in afs with a vm serving as an apache frontend to a read-only afs replica | 17:52 |
| sean-k-mooney | speakign of bot i swa that "Openstack server hack" mail you replied too but i did not see the orginal mail on the list | 17:53 |
| fungi | s/crawkers/crawlers/ but maybe i invented a new word | 17:53 |
| fungi | sean-k-mooney: looks like it's there in the archive at least... https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/ZMJJY4J73SAXWYH4C566BO7GF4XBQ5JB/ | 17:54 |
| sean-k-mooney | the first thing that came to midn for me was, if that vm is wan facign and you have not update you glance iamges with the mitgation for copy fail ectra its just as vulnerbale as anything else on the internet | 17:54 |
| sean-k-mooney | i dont know if they confirm that it hapeps with --no-network or not | 17:55 |
| fungi | yes, though booting with networking disabled would in theory mitigate that | 17:55 |
| fungi | right | 17:55 |
| fungi | the report was somewhat vague | 17:55 |
| fungi | they also replied to the thread, which you might also not have received? | 17:55 |
| sean-k-mooney | i got there reply | 17:56 |
| fungi | in this case, my mua states that the dkim signature in the initial e-mail validates successfully, so it's at least not a dmarc problem | 17:56 |
| sean-k-mooney | i would not be surpsied if our IT has some filter on hacked and servers taht intercepted it | 17:56 |
| fungi | yeah, there's a ton of substrings in there which could appear in trojan malware | 17:57 |
| fungi | i wouldn't be surprised either | 17:57 |
| fungi | people who receive e-mail about security problems need a different kind of inbound message filtering than corporate executives | 17:58 |
| sean-k-mooney | they have been very i was going t say paranoid but its not paranoia if the threat is real of late | 17:58 |
| fungi | one-size-fits-all mail scanning doesn't really work for us | 17:58 |
| fungi | this is why i run a personal mailserver, so i have fine-grained control over what gets delivered to my inbox and an audit trail and quarantine for things that don't get to my inbox | 17:59 |
| fungi | but i've also been a mailserver admin since the 90s, so it's not that much of a lift for me | 18:00 |
| sean-k-mooney | ya i pay google to do that for me.. i shoudl use anything else btu the thign is that google also give you google auth | 18:01 |
| fungi | i'm sure gmail's great until things don't get to your inbox that you're expecting (or worse, that you aren't expected but wanted to receive), and there's no mailserver log you can go to in order to figure out what happened and where it went instead | 18:02 |
| sean-k-mooney | so i coudl move my personal email but i dont want to have to fix sign in with google on everywhere i currenly use that | 18:02 |
| fungi | mmm, i have google accounts tied to non-gmail e-mail addresses, fwiw | 18:03 |
| sean-k-mooney | oh i do too | 18:03 |
| sean-k-mooney | i just dont knwo if i can move my personal buisness accont with a custom domain a | 18:04 |
| sean-k-mooney | and honesly its cheap so i dont feel like it right now :) | 18:04 |
| fungi | though i've closed most of those down now that i'm involved with 3 different nonprofits that all host their e-mail on gmail and have an abundance of gmail-associated accounts to sign into things with if i need that | 18:05 |
| fungi | most of the old google accounts were not originally google, but for companies they acquired over the years and became google accounts whether i liked it or not | 18:05 |
| * fungi is really not a google fanboy, in case that wasn't obvious | 18:06 | |
| sean-k-mooney | i think the only one that applies to is perhasp my youtube account | 18:07 |
| fungi | i definitely had one of those that is now a google account, yes | 18:10 |
| fungi | or had, i think i closed it | 18:10 |
| TheJulia | Seeing the discussion from earlier, it seems a little weird when they talked about using ssh to login anyway... | 20:35 |
| fungi | i tried to be generous with interpretation because it seemed like they were struggling to find how to express their situation in english | 20:37 |
| fungi | i'm sure i'd do far worse attempting to find and ask for help in their primary language | 20:38 |
| fungi | their response clarified that they're actually running a (personal/private?) openstack cloud, which wasn't obvious from the initial message... so maybe they're in a position to also look into outdated kvm/qemu and processor firmware related vulnerabilities that could result in one compromised guest infecting the host and other guests | 20:40 |
| sean-k-mooney | fungi: yes they refered to them seleve as the cloud provier or soemthign along those lines | 21:02 |
| sean-k-mooney | not sure how big or small but more operarotr trying to udner stand thing then enduser or developer was my impression | 21:03 |
| fungi | yes, if i was interpreting their initial message correctly it's a very small (personal or sandbox) deployment. if someone wanted to follow up, next questions might be how they deployed openstack on what platform, in order to determine if one of our deployment projects might have a supply-chain compromise e.g. in a dependency | 21:05 |
| fungi | but so far there's no real indication that's the problem | 21:05 |
| sean-k-mooney | its cernly posible. | 21:10 |
| sean-k-mooney | arch(AUR) and npm have had plenty of late | 21:11 |
| sean-k-mooney | there have also been suply chain attach via gitub prs recently | 21:11 |
| sean-k-mooney | github does nto show large diffs by default | 21:11 |
| sean-k-mooney | so attachekr have been mesisng with renovate pr or prs that have generated content adn injectign code into them | 21:12 |
| sean-k-mooney | fungi: you linked ot a ui on github | 21:12 |
| sean-k-mooney | so that could have a bad dep somewhere | 21:13 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!