*** amotoki has joined #openstack-sdks | 00:16 | |
*** salv-orl_ has quit IRC | 00:19 | |
*** gildub has joined #openstack-sdks | 00:19 | |
*** chlong has joined #openstack-sdks | 00:25 | |
*** gildub has quit IRC | 00:33 | |
*** Qiming has joined #openstack-sdks | 00:42 | |
*** gildub has joined #openstack-sdks | 00:50 | |
*** gildub has quit IRC | 00:58 | |
*** dims has quit IRC | 01:01 | |
*** chlong has quit IRC | 01:03 | |
*** gildub has joined #openstack-sdks | 01:15 | |
*** salv-orlando has joined #openstack-sdks | 01:19 | |
*** dims has joined #openstack-sdks | 01:24 | |
*** gouthamr has joined #openstack-sdks | 01:27 | |
*** gouthamr has quit IRC | 01:39 | |
*** dims has quit IRC | 01:46 | |
*** salv-orlando has quit IRC | 01:50 | |
*** gouthamr has joined #openstack-sdks | 02:03 | |
*** gouthamr has quit IRC | 02:05 | |
*** chlong has joined #openstack-sdks | 02:06 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/277232 | 02:39 |
---|---|---|
*** oomichi has quit IRC | 02:43 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-openstackclient: Updated from global requirements https://review.openstack.org/277253 | 02:44 |
*** dims has joined #openstack-sdks | 03:13 | |
*** gildub has quit IRC | 03:25 | |
*** dims has quit IRC | 03:35 | |
*** dims has joined #openstack-sdks | 03:42 | |
*** gildub has joined #openstack-sdks | 03:58 | |
*** dims has quit IRC | 04:08 | |
*** amotoki has quit IRC | 04:13 | |
*** amotoki has joined #openstack-sdks | 04:27 | |
*** david-lyle has quit IRC | 04:30 | |
*** dstanek has quit IRC | 04:31 | |
*** dstanek has joined #openstack-sdks | 04:33 | |
*** eliqiao_ has quit IRC | 04:38 | |
*** amotoki has quit IRC | 04:39 | |
*** eliqiao_ has joined #openstack-sdks | 04:40 | |
*** amotoki has joined #openstack-sdks | 04:40 | |
*** salv-orlando has joined #openstack-sdks | 04:44 | |
*** david-lyle has joined #openstack-sdks | 04:45 | |
*** amotoki has quit IRC | 04:56 | |
*** salv-orlando has quit IRC | 04:56 | |
stevemar | jamielennox: no openstack-specs repo, we just use BPs | 05:04 |
stevemar | jamielennox: we brought it up once when spec repos were first being created, and decided we weren't big time enough to have one | 05:05 |
stevemar | jamielennox: maybe it's time to revisit that argument | 05:05 |
jamielennox | stevemar: i don't mind, i have something i was going to write up and am now so used to specs | 05:06 |
*** eliqiao_ has quit IRC | 05:06 | |
stevemar | jamielennox: toss up a bp for now i guess | 05:07 |
jamielennox | stevemar: ok, will email you and dtroyer with the details as it's newly formed and noone reads blueprints | 05:08 |
*** eliqiao_ has joined #openstack-sdks | 05:08 | |
*** amotoki has joined #openstack-sdks | 05:11 | |
*** dfflanders has quit IRC | 05:40 | |
openstackgerrit | Merged openstack/python-openstackclient: Updated from global requirements https://review.openstack.org/277253 | 05:49 |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/277232 | 05:51 |
*** lhcheng has quit IRC | 05:55 | |
*** amotoki_ has joined #openstack-sdks | 06:08 | |
*** amotoki has quit IRC | 06:11 | |
*** petertr7_away has quit IRC | 06:25 | |
*** petertr7_away has joined #openstack-sdks | 06:26 | |
*** petertr7_away is now known as petertr7 | 06:26 | |
*** salv-orlando has joined #openstack-sdks | 06:48 | |
*** salv-orlando has quit IRC | 06:55 | |
*** gildub has quit IRC | 06:56 | |
*** lhcheng has joined #openstack-sdks | 07:01 | |
*** chlong has quit IRC | 07:03 | |
openstackgerrit | Merged openstack/python-openstackclient: Move security_groups mock definition to FakeComputev2Client https://review.openstack.org/276082 | 07:10 |
openstackgerrit | Merged openstack/python-openstackclient: Define security_group_rules mock in FakeComputev2Client https://review.openstack.org/276085 | 07:10 |
openstackgerrit | Merged openstack/python-openstackclient: Remove identity_client.projects definition in TestSecurityGroup https://review.openstack.org/276083 | 07:11 |
*** oomichi has joined #openstack-sdks | 07:12 | |
*** salv-orlando has joined #openstack-sdks | 08:07 | |
openstackgerrit | Merged openstack/python-openstackclient: Add unit tests for "hypervisor show" command https://review.openstack.org/277110 | 08:10 |
*** salv-orlando has quit IRC | 08:12 | |
openstackgerrit | Merged openstack/python-openstackclient: Compute: Fix DisplayCommandBase comments for cliff Command subclass tests https://review.openstack.org/276983 | 08:25 |
openstackgerrit | Merged openstack/python-openstackclient: Compute: Fix DisplayCommandBase comments for cliff Lister subclass tests https://review.openstack.org/276984 | 08:25 |
*** chlong has joined #openstack-sdks | 08:48 | |
*** amotoki_ has quit IRC | 08:55 | |
*** openstackgerrit has quit IRC | 09:02 | |
*** openstackgerrit has joined #openstack-sdks | 09:03 | |
*** lucas-dinner is now known as lucasagomes | 09:09 | |
*** amotoki has joined #openstack-sdks | 09:14 | |
*** salv-orlando has joined #openstack-sdks | 09:31 | |
*** amotoki has quit IRC | 09:32 | |
openstackgerrit | Tang Chen proposed openstack/python-openstackclient: Floating IP: Implementation "ip floating delete" command https://review.openstack.org/258519 | 10:17 |
*** gildub has joined #openstack-sdks | 10:28 | |
*** salv-orl_ has joined #openstack-sdks | 10:40 | |
*** cdent has joined #openstack-sdks | 10:42 | |
*** salv-orlando has quit IRC | 10:43 | |
*** e0ne has joined #openstack-sdks | 10:53 | |
*** lhcheng has quit IRC | 10:59 | |
*** thrash|g0ne is now known as thrash | 11:39 | |
openstackgerrit | Tang Chen proposed openstack/python-openstackclient: Floating IP: Implementation "ip floating delete" command https://review.openstack.org/258519 | 11:52 |
*** jaypipes has joined #openstack-sdks | 11:56 | |
*** erlon has joined #openstack-sdks | 12:01 | |
*** lucasagomes is now known as lucas-hungry | 12:07 | |
*** dims has joined #openstack-sdks | 12:07 | |
*** amotoki has joined #openstack-sdks | 12:13 | |
*** salv-orl_ has quit IRC | 12:18 | |
*** dims has quit IRC | 12:20 | |
*** gildub has quit IRC | 12:21 | |
*** dims has joined #openstack-sdks | 12:22 | |
*** rtheis has joined #openstack-sdks | 12:30 | |
*** amotoki has quit IRC | 12:35 | |
*** krotscheck_dcm is now known as krotscheck | 12:39 | |
*** salv-orlando has joined #openstack-sdks | 12:42 | |
*** amotoki has joined #openstack-sdks | 12:58 | |
*** krotscheck has quit IRC | 13:06 | |
*** lucas-hungry is now known as lucasagomes | 13:12 | |
*** amotoki has quit IRC | 13:15 | |
*** krotscheck has joined #openstack-sdks | 13:18 | |
*** annegentle has joined #openstack-sdks | 14:01 | |
*** gouthamr has joined #openstack-sdks | 14:05 | |
*** annegentle has quit IRC | 14:19 | |
*** annegentle has joined #openstack-sdks | 14:20 | |
*** salv-orlando has quit IRC | 14:41 | |
*** jose4183 has joined #openstack-sdks | 14:51 | |
*** jose4183 has quit IRC | 14:51 | |
*** annegentle has quit IRC | 14:53 | |
*** salv-orlando has joined #openstack-sdks | 14:55 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:01 | |
*** jaypipes has quit IRC | 15:09 | |
*** jose4183 has joined #openstack-sdks | 15:10 | |
*** jose4183 has quit IRC | 15:11 | |
openstackgerrit | Sergey Nikitin proposed openstack/api-wg: Added tags restrictions to the tagging guidelines https://review.openstack.org/276709 | 15:11 |
openstackgerrit | Sergey Nikitin proposed openstack/api-wg: Added tags restrictions to the tagging guidelines https://review.openstack.org/276709 | 15:15 |
*** annegentle has joined #openstack-sdks | 15:15 | |
sahilsinha | anyone home? | 15:17 |
*** jose4183 has joined #openstack-sdks | 15:19 | |
*** jose4183 has quit IRC | 15:19 | |
annegentle | sahilsinha: what's up? | 15:19 |
*** amotoki has joined #openstack-sdks | 15:24 | |
sahilsinha | hey annegentle: nice to see you again | 15:25 |
sahilsinha | talked with someone in openstack-security and we thought i might have stumbled on a bug | 15:25 |
sahilsinha | obv not sure | 15:25 |
sahilsinha | let me pull up the desc | 15:26 |
annegentle | sure | 15:26 |
sahilsinha | set up openstack with cryptographic separation and with the public endpoint on a public ip | 15:27 |
sahilsinha | token issue works everywhere | 15:27 |
sahilsinha | other commands work on the internal/admin endpoints | 15:27 |
sahilsinha | to get password set to work for a remote client on the public endpoint you have to specify os-interface public if you don't the public client leaks internal endpoint info | 15:28 |
sahilsinha | eg https://controller:35357 | 15:28 |
sahilsinha | that info is revealed to a client that only accessed port 5000 on a public ip | 15:29 |
sahilsinha | i think that sums it up | 15:29 |
briancurtin | sahilsinha: you’ll have to be more clear about whatever it is that you’re disclosing. where’s the bug? as in what project? | 15:29 |
sahilsinha | i believe openstack client | 15:30 |
sahilsinha | it is leaking information about internal/admin endpoints | 15:30 |
sahilsinha | this is just mine and one person in openstack-security's thinking obv not sure if its a real bug | 15:30 |
annegentle | sahilsinha: have you logged it in launchpad? You can mark as security bug | 15:30 |
annegentle | sahilsinha: and then dtroyer can triage | 15:30 |
sahilsinha | annegentle: i have not i wanted to understand better about the endpoint selection | 15:31 |
sahilsinha | i blew up the environment today and will try to recreate | 15:31 |
annegentle | sahilsinha: it's not super clear to anyone what internal or admin endpoints are supposed to be used for, so providers may use them differently | 15:31 |
annegentle | sahilsinha: still, both endpoints are mostly meant for not-public-consumption | 15:31 |
sahilsinha | annegentle: right which is why leaking it to someone on the public is concerning, i think the question is how does the openstack client fallback to that | 15:33 |
sahilsinha | i looked at service.py and catalog.py but not sure if i was in the right place | 15:33 |
annegentle | sahilsinha: you'll have to ask dtroyer and he may not be up yet | 15:33 |
sahilsinha | np ill be working on it and trying to reproduce - thanks for assistance | 15:34 |
*** jaypipes has joined #openstack-sdks | 15:34 | |
annegentle | sahilsinha: sure thing, thanks for asking | 15:34 |
sahilsinha | annegentle: should i open a bug or wait to discuss with dtroyer? | 15:35 |
*** annegentle has quit IRC | 15:35 | |
sahilsinha | ;p | 15:35 |
elmiko | i'd say, talk with dtroyer, he knows the client | 15:36 |
sahilsinha | hey elmiko | 15:36 |
elmiko | hey ;) | 15:36 |
*** annegentle has joined #openstack-sdks | 15:36 | |
annegentle | sahilsinha: I'd go ahead and log the bug, mark it security, to keep working asynch | 15:36 |
sahilsinha | ok ill just confirm it on a fresh environment first and open it up | 15:36 |
annegentle | sahilsinha: cool | 15:37 |
*** jose4183 has joined #openstack-sdks | 15:42 | |
*** jose4183 has quit IRC | 15:42 | |
*** amotoki has quit IRC | 15:46 | |
openstackgerrit | Everett Toews proposed openstack/python-openstacksdk: Make metadata handling consistent in Object Store https://review.openstack.org/275441 | 15:47 |
dtroyer | sahilsinha: (catching up) OSC has a last-resort default interface type of 'public', but that is only asserted when a service asks the SC for an endpoint and doesn't supply an interface type. The Identity client in OSC does not call this method, it simply uses the value passed in from —os-interface directly. | 15:54 |
dtroyer | The next place to look is in keystoneauth to see how it defaults. I suspect public, IIRC getting a token is (nearly) the only operation you could do on the public endpoint in Identity v2. Identity v3 doesn't use port 5000. | 15:55 |
dtroyer | This is from memory, I haven't looked through ksa in detail in a couple of months | 15:56 |
openstackgerrit | Tang Chen proposed openstack/python-openstackclient: Floating IP: Implementation "ip floating delete" command https://review.openstack.org/258519 | 16:04 |
sahilsinha | dtroyer: thanks for catching up - if we're defaulting to public i don't understand how the info could leak unless -os-interface defaults to admin | 16:05 |
sahilsinha | dtroyer: v3 doesn't use 5000? my understanding is currently for endpoints we have to specify v2.0 | 16:06 |
*** gouthamr has quit IRC | 16:11 | |
openstackgerrit | Sergey Nikitin proposed openstack/api-wg: Added tags restrictions to the tagging guidelines https://review.openstack.org/276709 | 16:12 |
*** gouthamr has joined #openstack-sdks | 16:20 | |
openstackgerrit | Merged openstack/python-openstackclient: Compute: Fix DisplayCommandBase comments for cliff ShowOne subclass tests https://review.openstack.org/276985 | 16:21 |
*** Qiming has quit IRC | 16:28 | |
*** gouthamr has quit IRC | 16:33 | |
*** gouthamr has joined #openstack-sdks | 16:34 | |
*** salv-orl_ has joined #openstack-sdks | 16:40 | |
*** salv-orlando has quit IRC | 16:43 | |
*** jgriffith_away is now known as jgriffith | 16:45 | |
*** devth_ has joined #openstack-sdks | 16:54 | |
*** devth has quit IRC | 16:58 | |
*** annegentle has quit IRC | 16:59 | |
*** annegentle has joined #openstack-sdks | 17:00 | |
*** jgriffith is now known as jgriffith_away | 17:00 | |
*** jgriffith_away is now known as jgriffith | 17:04 | |
*** annegentle has quit IRC | 17:04 | |
*** salv-orl_ has quit IRC | 17:05 | |
*** salv-orlando has joined #openstack-sdks | 17:05 | |
*** dims has quit IRC | 17:14 | |
*** lhcheng has joined #openstack-sdks | 17:17 | |
*** lhcheng_ has joined #openstack-sdks | 17:21 | |
*** lhcheng has quit IRC | 17:23 | |
openstackgerrit | Richard Theis proposed openstack/python-openstackclient: Add NetworkAndCompute Lister and ShowOne classes https://review.openstack.org/276888 | 17:24 |
*** dims has joined #openstack-sdks | 17:32 | |
etoews | terrylhowe: you around? i'd like to ask you about this gem in the swift api https://bugs.launchpad.net/python-openstacksdk/+bug/1488269/ | 17:33 |
openstack | Launchpad bug 1488269 in OpenStack SDK "Object get needs to be smarter about what headers it sends" [Undecided,New] | 17:33 |
*** boris-42 has quit IRC | 17:43 | |
*** e0ne has quit IRC | 17:46 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:59 | |
*** annegentle has joined #openstack-sdks | 18:00 | |
*** petertr7 is now known as petertr7_away | 18:03 | |
*** petertr7_away is now known as petertr7 | 18:08 | |
*** petertr7 is now known as petertr7_away | 18:17 | |
*** annegentle has quit IRC | 18:22 | |
*** annegentle has joined #openstack-sdks | 18:26 | |
*** lucasagomes is now known as lucas-dinner | 18:28 | |
*** jose4183 has joined #openstack-sdks | 18:40 | |
*** jose4183 has quit IRC | 18:40 | |
*** jose4183 has joined #openstack-sdks | 18:41 | |
*** jose4183 has quit IRC | 18:41 | |
*** jose4183 has joined #openstack-sdks | 18:41 | |
*** jose4183 has quit IRC | 18:42 | |
*** jose4183 has joined #openstack-sdks | 18:44 | |
*** e0ne has joined #openstack-sdks | 18:44 | |
*** jose4183 has quit IRC | 18:44 | |
*** salv-orl_ has joined #openstack-sdks | 18:58 | |
*** salv-orlando has quit IRC | 19:01 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 19:02 | |
*** petertr7_away is now known as petertr7 | 19:08 | |
*** jgriffith is now known as jgriffith_away | 19:16 | |
*** jose4183 has joined #openstack-sdks | 19:27 | |
*** jose4183 has quit IRC | 19:27 | |
*** annegentle has quit IRC | 19:32 | |
*** salv-orl_ has quit IRC | 19:53 | |
*** woodster_ has joined #openstack-sdks | 20:02 | |
*** annegentle has joined #openstack-sdks | 20:04 | |
*** jgriffith_away is now known as jgriffith | 20:13 | |
*** gildub has joined #openstack-sdks | 20:14 | |
*** salv-orlando has joined #openstack-sdks | 20:27 | |
*** annegentle has quit IRC | 20:31 | |
*** annegentle has joined #openstack-sdks | 20:32 | |
*** salv-orlando has quit IRC | 20:36 | |
*** jose4183 has joined #openstack-sdks | 20:37 | |
*** jose4183 has quit IRC | 20:38 | |
*** jose4183 has joined #openstack-sdks | 20:38 | |
*** jose4183 has quit IRC | 20:38 | |
*** dims_ has joined #openstack-sdks | 20:51 | |
*** dims has quit IRC | 20:52 | |
*** annegentle has quit IRC | 20:58 | |
*** annegentle has joined #openstack-sdks | 20:59 | |
*** salv-orlando has joined #openstack-sdks | 21:01 | |
*** annegentle has quit IRC | 21:04 | |
openstackgerrit | guang-yee proposed openstack/python-openstackclient: Support unscoped token request https://review.openstack.org/277563 | 21:06 |
*** petertr7 is now known as petertr7_away | 21:08 | |
*** petertr7_away is now known as petertr7 | 21:12 | |
openstackgerrit | guang-yee proposed openstack/python-openstackclient: Support unscoped token request https://review.openstack.org/277563 | 21:15 |
*** dims has joined #openstack-sdks | 21:26 | |
*** dims_ has quit IRC | 21:29 | |
*** annegentle has joined #openstack-sdks | 21:37 | |
*** boris-42 has joined #openstack-sdks | 21:58 | |
*** e0ne has quit IRC | 22:03 | |
*** petertr7 is now known as petertr7_away | 22:05 | |
*** rtheis has quit IRC | 22:07 | |
*** jgriffith is now known as jgriffith_away | 22:10 | |
*** cdent has quit IRC | 22:11 | |
openstackgerrit | Dina Belova proposed openstack/python-openstackclient: Add shell --profile option to trigger osprofiler from CLI https://review.openstack.org/255861 | 22:14 |
*** jgriffith_away is now known as jgriffith | 22:17 | |
*** annegentle has quit IRC | 22:29 | |
*** dims has quit IRC | 22:31 | |
*** lhcheng has joined #openstack-sdks | 22:32 | |
*** lhcheng_ has quit IRC | 22:32 | |
*** lhcheng has quit IRC | 22:37 | |
*** lhcheng has joined #openstack-sdks | 22:38 | |
sahilsinha | dtroyer: i was able to recreate it am going to file a bug. any command used as a public client returns admin endpoint info | 22:45 |
*** annegentle has joined #openstack-sdks | 22:49 | |
*** dims_ has joined #openstack-sdks | 22:51 | |
*** annegentle has quit IRC | 22:53 | |
*** annegentle has joined #openstack-sdks | 22:57 | |
*** lhcheng has quit IRC | 23:03 | |
*** lhcheng has joined #openstack-sdks | 23:03 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:04 | |
*** annegentle has quit IRC | 23:10 | |
*** annegentle has joined #openstack-sdks | 23:11 | |
*** dims_ has quit IRC | 23:14 | |
*** salv-orlando has quit IRC | 23:14 | |
*** gouthamr has quit IRC | 23:15 | |
*** gouthamr has joined #openstack-sdks | 23:15 | |
*** salv-orlando has joined #openstack-sdks | 23:15 | |
*** annegent_ has joined #openstack-sdks | 23:16 | |
*** annegentle has quit IRC | 23:19 | |
*** dims_ has joined #openstack-sdks | 23:19 | |
*** annegent_ has quit IRC | 23:21 | |
openstackgerrit | Dean Troyer proposed openstack/python-openstackclient: Add shell --profile option to trigger osprofiler from CLI https://review.openstack.org/255861 | 23:31 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!