*** baojg has quit IRC | 00:10 | |
*** baojg has joined #openstack-meeting | 00:11 | |
*** armax has quit IRC | 00:14 | |
*** yasufum has quit IRC | 00:15 | |
*** yasufum has joined #openstack-meeting | 00:19 | |
*** jmasud has quit IRC | 00:29 | |
*** yasufum has quit IRC | 00:29 | |
*** gyee has quit IRC | 00:56 | |
*** baojg has quit IRC | 00:57 | |
*** baojg has joined #openstack-meeting | 00:58 | |
*** Lucas_Gray has quit IRC | 01:05 | |
*** tdasilva_ has quit IRC | 01:07 | |
*** tdasilva_ has joined #openstack-meeting | 01:08 | |
*** yasufum has joined #openstack-meeting | 01:08 | |
*** Liang__ has joined #openstack-meeting | 01:25 | |
*** baojg has quit IRC | 01:26 | |
*** jmasud has joined #openstack-meeting | 01:41 | |
*** jmasud has quit IRC | 01:43 | |
*** jamesmcarthur has joined #openstack-meeting | 01:49 | |
*** jamesmcarthur has quit IRC | 01:59 | |
*** yasufum has quit IRC | 02:02 | |
*** lhinds has quit IRC | 02:02 | |
*** jamesmcarthur has joined #openstack-meeting | 02:03 | |
*** lhinds has joined #openstack-meeting | 02:03 | |
*** jamesmcarthur has quit IRC | 02:10 | |
*** yasufum has joined #openstack-meeting | 02:13 | |
*** rcernin has quit IRC | 02:26 | |
*** rcernin has joined #openstack-meeting | 02:50 | |
*** rcernin has quit IRC | 02:57 | |
*** rcernin has joined #openstack-meeting | 02:59 | |
*** rcernin has quit IRC | 02:59 | |
*** rcernin has joined #openstack-meeting | 03:00 | |
*** rbudden has joined #openstack-meeting | 03:03 | |
*** baojg has joined #openstack-meeting | 03:26 | |
*** psachin has joined #openstack-meeting | 03:36 | |
*** yasufum has quit IRC | 03:37 | |
*** jamesmcarthur has joined #openstack-meeting | 03:38 | |
*** yasufum has joined #openstack-meeting | 03:43 | |
*** Lucas_Gray has joined #openstack-meeting | 03:57 | |
*** Liang__ has quit IRC | 04:31 | |
*** Liang__ has joined #openstack-meeting | 04:32 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-meeting | 04:33 | |
*** psahoo has joined #openstack-meeting | 04:48 | |
*** ociuhandu has joined #openstack-meeting | 05:01 | |
*** zbr|pto has quit IRC | 05:07 | |
*** njohnston has quit IRC | 05:09 | |
*** ociuhandu has quit IRC | 05:10 | |
*** bnemec has quit IRC | 05:10 | |
*** rbudden has quit IRC | 05:24 | |
*** rbudden has joined #openstack-meeting | 05:24 | |
*** psahoo_ has joined #openstack-meeting | 05:25 | |
*** rbudden has joined #openstack-meeting | 05:25 | |
*** jamesmcarthur has quit IRC | 05:28 | |
*** psahoo has quit IRC | 05:29 | |
*** ricolin has quit IRC | 05:45 | |
*** hyunsikyang__ has joined #openstack-meeting | 05:52 | |
*** hyunsikyang has quit IRC | 05:56 | |
*** slaweq has joined #openstack-meeting | 06:22 | |
*** ralonsoh has joined #openstack-meeting | 06:30 | |
*** slaweq has quit IRC | 06:33 | |
*** dklyle has quit IRC | 06:37 | |
*** viks____ has joined #openstack-meeting | 06:37 | |
*** Lucas_Gray has quit IRC | 06:47 | |
*** zbr has joined #openstack-meeting | 06:49 | |
*** slaweq has joined #openstack-meeting | 06:52 | |
*** whoami-rajat__ has joined #openstack-meeting | 07:07 | |
*** rcernin has quit IRC | 07:39 | |
*** tosky has joined #openstack-meeting | 07:43 | |
*** yamamoto has quit IRC | 07:55 | |
*** yamamoto has joined #openstack-meeting | 07:56 | |
*** yamamoto has quit IRC | 07:57 | |
*** yamamoto has joined #openstack-meeting | 08:04 | |
*** yamamoto has quit IRC | 08:04 | |
*** yamamoto has joined #openstack-meeting | 08:05 | |
*** yamamoto has quit IRC | 08:10 | |
*** moguimar has joined #openstack-meeting | 08:10 | |
*** lpetrut has joined #openstack-meeting | 08:23 | |
*** yamamoto has joined #openstack-meeting | 08:33 | |
*** baojg has quit IRC | 08:51 | |
*** moguimar has quit IRC | 08:52 | |
*** e0ne has joined #openstack-meeting | 08:52 | |
*** baojg has joined #openstack-meeting | 08:52 | |
*** Lucas_Gray has joined #openstack-meeting | 09:11 | |
*** ociuhandu has joined #openstack-meeting | 09:28 | |
*** rcernin has joined #openstack-meeting | 09:38 | |
*** yamamoto has quit IRC | 09:45 | |
*** yamamoto has joined #openstack-meeting | 10:08 | |
*** rcernin has quit IRC | 10:10 | |
*** yamamoto has quit IRC | 10:11 | |
*** Liang__ has quit IRC | 10:14 | |
*** apetrich has joined #openstack-meeting | 10:26 | |
*** yamamoto has joined #openstack-meeting | 10:46 | |
*** yasufum has quit IRC | 10:50 | |
*** yamamoto has quit IRC | 10:54 | |
*** yasufum has joined #openstack-meeting | 11:30 | |
*** yamamoto has joined #openstack-meeting | 11:32 | |
*** yamamoto has quit IRC | 11:37 | |
*** rcernin has joined #openstack-meeting | 11:42 | |
*** raildo has joined #openstack-meeting | 11:52 | |
*** Lucas_Gray has quit IRC | 12:02 | |
*** rfolco|ruck has joined #openstack-meeting | 12:05 | |
*** yasufum has quit IRC | 12:06 | |
*** yasufum has joined #openstack-meeting | 12:12 | |
*** yasufum has quit IRC | 12:13 | |
*** moguimar has joined #openstack-meeting | 12:27 | |
*** njohnston has joined #openstack-meeting | 12:29 | |
*** yamamoto has joined #openstack-meeting | 12:40 | |
*** gmann is now known as gmann_pto | 12:41 | |
*** yamamoto has quit IRC | 12:47 | |
*** Lucas_Gray has joined #openstack-meeting | 13:06 | |
*** mbuil has quit IRC | 13:07 | |
*** mbuil has joined #openstack-meeting | 13:07 | |
*** TrevorV has joined #openstack-meeting | 13:20 | |
*** Lucas_Gray has quit IRC | 13:21 | |
*** rcernin has quit IRC | 13:21 | |
*** hemna has quit IRC | 13:25 | |
*** hemna has joined #openstack-meeting | 13:25 | |
*** TrevorV has quit IRC | 13:26 | |
*** Lucas_Gray has joined #openstack-meeting | 13:28 | |
*** Lucas_Gray has quit IRC | 13:33 | |
*** rbudden has joined #openstack-meeting | 13:34 | |
*** masahito has joined #openstack-meeting | 13:37 | |
*** tdasilva_ has quit IRC | 13:39 | |
*** tdasilva_ has joined #openstack-meeting | 13:40 | |
*** jgriffith has quit IRC | 13:41 | |
*** TrevorV has joined #openstack-meeting | 13:45 | |
*** Lucas_Gray has joined #openstack-meeting | 13:52 | |
*** yamamoto has joined #openstack-meeting | 13:59 | |
*** mlavalle has joined #openstack-meeting | 13:59 | |
slaweq | #startmeeting neutron_drivers | 14:00 |
---|---|---|
openstack | Meeting started Fri Sep 25 14:00:23 2020 UTC and is due to finish in 60 minutes. The chair is slaweq. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: neutron_drivers)" | 14:00 | |
openstack | The meeting name has been set to 'neutron_drivers' | 14:00 |
mlavalle | o/ | 14:00 |
slaweq | welcome after pretty long break on the drivers meeting | 14:01 |
slaweq | :) | 14:01 |
yamamoto | hi | 14:01 |
amotoki | hi | 14:01 |
mlavalle | nothing wrong with that. we are supposed to meet when the community needs it. no need to meet for the sake of meeting | 14:01 |
haleyb | hi | 14:02 |
slaweq | mlavalle: I know, that's why I was cancelling it so many times recently :) | 14:02 |
njohnston | o/ | 14:02 |
slaweq | ralonsoh: are You around? | 14:02 |
slaweq | we are almost all here already | 14:02 |
ralonsoh | sorry yes | 14:02 |
slaweq | ok, now we are all there | 14:03 |
slaweq | :) | 14:03 |
slaweq | ok, so lets start | 14:03 |
slaweq | as I wrote in the email yesterday night, we don't have any new (or updated) rfe to discuss today | 14:03 |
slaweq | but I wanted to talk about one bug related to policy.json | 14:03 |
slaweq | https://bugs.launchpad.net/neutron/+bug/1895933 | 14:04 |
openstack | Launchpad bug 1895933 in neutron "Admin user can do anything without the control of policy.json" [Medium,Confirmed] | 14:04 |
slaweq | basically in neutron it is like it's in the bug description, so we are checking if user is admin and then don't check anything else from the policy file | 14:04 |
amotoki | sorry for not replying this. I was busy for internal stuffs..... | 14:05 |
slaweq | and I wanted to ask You if You think it is a bug which we should fix, or maybe it's like that in all projects and we should keep it like it's now | 14:05 |
amotoki | IIRC we handled 'admin' role specially so we skipped admin check | 14:05 |
slaweq | amotoki: np | 14:05 |
amotoki | but I believe it is time to honor policy check. | 14:05 |
ralonsoh | but the default behaviour will be the current one, correct? | 14:06 |
slaweq | ralonsoh: I think so | 14:06 |
slaweq | by default admin should be able to do everything | 14:07 |
slaweq | but operator should IMHO be able to control that too | 14:07 |
amotoki | agree | 14:07 |
amotoki | at now, role admin and elevated context are considered same but perhaps we need to distinguish these two. | 14:08 |
ralonsoh | yeah, that's a good point | 14:09 |
ralonsoh | we should use elevated one internally only when needed, but should not be the same as admin | 14:09 |
ralonsoh | (could be an opportunity to clean up some parts of the code using admin indiscriminately) | 14:09 |
amotoki | ralonsoh: +1 | 14:10 |
amotoki | policy check provides RBAC at the API level. Internal accesses with elevated context is a different thing. | 14:11 |
slaweq | so it seems that at least me, ralonsoh and amotoki agree that this is an improvement which we should do in our code | 14:14 |
ralonsoh | yes | 14:15 |
slaweq | anyone else has got any thougts about that? | 14:15 |
mlavalle | I'm in agreement | 14:15 |
yamamoto | +1 | 14:15 |
njohnston | so does that mean we need to reevaluate places where we use context.is_admin to see if this is a case where we need elevated context or actual admin role? | 14:15 |
mlavalle | the question is what we do next | 14:16 |
slaweq | njohnston: I think so | 14:16 |
amotoki | IMHO the first step would be to improve the behavior reported in this bug (address scope) | 14:17 |
slaweq | mlavalle: I think I will open BP to track progress on that, and we will need some volunteer(s) to make progress on that | 14:17 |
njohnston | like here: https://opendev.org/openstack/neutron/src/branch/master/neutron/policy.py#L434-L437 | 14:17 |
mlavalle | slaweq: +1 | 14:18 |
njohnston | slaweq: +1 | 14:18 |
ralonsoh | +1 | 14:18 |
amotoki | slaweq: +1 | 14:18 |
*** dklyle has joined #openstack-meeting | 14:18 | |
slaweq | njohnston: place which You pointed to is exactly the "culprit" of the whole issue IMO | 14:18 |
slaweq | so this has to be removed | 14:19 |
slaweq | and we should validate policy even if context.is_admin | 14:19 |
*** masahito has quit IRC | 14:19 | |
amotoki | we may need to revisit the condition of is_admin=true too | 14:19 |
slaweq | ok, so I think we all agreed on what to do with this bug and on the next steps plan | 14:21 |
slaweq | I will sum this up in the LP's comment today | 14:22 |
slaweq | and I will create BP for this | 14:22 |
slaweq | and basically that's all what I had for today | 14:22 |
slaweq | do You have maybe anything else You want to discuss today? | 14:22 |
mlavalle | not from me | 14:23 |
njohnston | no thanks | 14:23 |
amotoki | nothing from me | 14:23 |
ralonsoh | no thanks | 14:23 |
haleyb | not from me | 14:24 |
yamamoto | no | 14:24 |
slaweq | ok, so thx for attending | 14:24 |
slaweq | have a great weekend and see You all next week | 14:24 |
slaweq | o/ | 14:24 |
slaweq | #endmeeting | 14:25 |
ralonsoh | bye! | 14:25 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:25 | |
amotoki | o/ | 14:25 |
openstack | Meeting ended Fri Sep 25 14:24:59 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:25 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/neutron_drivers/2020/neutron_drivers.2020-09-25-14.00.html | 14:25 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/neutron_drivers/2020/neutron_drivers.2020-09-25-14.00.txt | 14:25 |
yamamoto | good night | 14:25 |
openstack | Log: http://eavesdrop.openstack.org/meetings/neutron_drivers/2020/neutron_drivers.2020-09-25-14.00.log.html | 14:25 |
mlavalle | o/ | 14:25 |
njohnston | o/ | 14:25 |
*** mlavalle has quit IRC | 14:32 | |
*** jamesmcarthur has joined #openstack-meeting | 14:32 | |
*** mlavalle has joined #openstack-meeting | 14:33 | |
*** slaweq has quit IRC | 14:37 | |
*** armax has joined #openstack-meeting | 14:41 | |
*** Lucas_Gray has quit IRC | 14:42 | |
*** slaweq has joined #openstack-meeting | 14:44 | |
*** psahoo_ has quit IRC | 14:48 | |
*** dklyle has quit IRC | 15:13 | |
*** dklyle has joined #openstack-meeting | 15:14 | |
*** thiago__ has joined #openstack-meeting | 15:31 | |
*** tdasilva_ has quit IRC | 15:33 | |
*** moguimar has quit IRC | 15:43 | |
*** lpetrut has quit IRC | 15:48 | |
*** yamamoto has quit IRC | 15:51 | |
*** gyee has joined #openstack-meeting | 15:55 | |
*** ralonsoh has quit IRC | 16:11 | |
*** apetrich has quit IRC | 16:13 | |
*** apetrich has joined #openstack-meeting | 16:19 | |
*** ociuhandu has quit IRC | 16:41 | |
*** e0ne has quit IRC | 16:45 | |
*** andrebeltrami has joined #openstack-meeting | 16:47 | |
*** TrevorV has quit IRC | 17:10 | |
*** abhishekk is now known as abhishekk|away | 17:27 | |
*** jamesmcarthur has quit IRC | 18:02 | |
*** jamesmcarthur has joined #openstack-meeting | 18:12 | |
*** ociuhandu has joined #openstack-meeting | 18:33 | |
*** psachin has quit IRC | 18:34 | |
*** ociuhandu has quit IRC | 18:41 | |
*** dklyle has quit IRC | 18:41 | |
*** dklyle has joined #openstack-meeting | 18:42 | |
*** jamesmcarthur has quit IRC | 18:55 | |
*** jamesmcarthur has joined #openstack-meeting | 18:56 | |
*** jamesmcarthur has quit IRC | 18:59 | |
*** jamesmcarthur has joined #openstack-meeting | 18:59 | |
*** thiago__ has quit IRC | 19:13 | |
*** thiago__ has joined #openstack-meeting | 19:14 | |
*** thiago__ has quit IRC | 19:16 | |
*** thiago__ has joined #openstack-meeting | 19:17 | |
*** tdasilva_ has joined #openstack-meeting | 19:31 | |
*** thiago__ has quit IRC | 19:33 | |
*** whoami-rajat__ has quit IRC | 19:54 | |
*** jamesmcarthur has quit IRC | 19:59 | |
*** jamesmcarthur has joined #openstack-meeting | 20:02 | |
*** Lucas_Gray has joined #openstack-meeting | 20:02 | |
*** jamesmcarthur has quit IRC | 20:04 | |
*** jamesmcarthur has joined #openstack-meeting | 20:05 | |
*** jamesmcarthur has quit IRC | 20:16 | |
*** baojg has quit IRC | 20:47 | |
*** baojg has joined #openstack-meeting | 20:48 | |
*** jamesmcarthur has joined #openstack-meeting | 20:52 | |
*** slaweq has quit IRC | 20:54 | |
*** rfolco|ruck has quit IRC | 20:58 | |
*** jamesmcarthur has quit IRC | 21:15 | |
*** jamesmcarthur has joined #openstack-meeting | 21:47 | |
*** apetrich has quit IRC | 21:49 | |
*** yamamoto has joined #openstack-meeting | 22:12 | |
*** Lucas_Gray has quit IRC | 22:26 | |
*** Lucas_Gray has joined #openstack-meeting | 22:26 | |
*** yamamoto has quit IRC | 22:45 | |
*** yamamoto has joined #openstack-meeting | 22:56 | |
*** tosky has quit IRC | 22:58 | |
*** rfolco|ruck has joined #openstack-meeting | 23:02 | |
*** jamesmcarthur has quit IRC | 23:03 | |
*** jamesmcarthur has joined #openstack-meeting | 23:03 | |
*** Lucas_Gray has quit IRC | 23:06 | |
*** mlavalle has quit IRC | 23:07 | |
*** jamesmcarthur has quit IRC | 23:21 | |
*** baojg has quit IRC | 23:21 | |
*** baojg has joined #openstack-meeting | 23:22 | |
*** jamesmcarthur has joined #openstack-meeting | 23:22 | |
*** rfolco|ruck has quit IRC | 23:29 | |
*** yamamoto has quit IRC | 23:32 | |
*** yamamoto has joined #openstack-meeting | 23:33 | |
*** yamamoto has quit IRC | 23:33 | |
*** jamesmcarthur has quit IRC | 23:44 | |
*** jamesmcarthur has joined #openstack-meeting | 23:47 | |
*** jamesmcarthur has quit IRC | 23:51 | |
*** jamesmcarthur has joined #openstack-meeting | 23:53 | |
*** jamesmcarthur has quit IRC | 23:54 | |
*** jamesmcarthur has joined #openstack-meeting | 23:56 | |
*** jamesmcarthur has quit IRC | 23:57 | |
*** ricolin_ has joined #openstack-meeting | 23:57 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!