Wednesday, 2020-12-16

*** tosky has quit IRC00:04
*** LinPeiWen has joined #openstack-sdks01:04
*** khomesh24 has joined #openstack-sdks01:05
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: Add network tests for versioned args  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76601301:20
*** enriquetaso has joined #openstack-sdks01:20
*** khomesh24 has quit IRC01:58
*** artom has quit IRC02:12
*** enriquetaso has quit IRC02:15
*** khomesh24 has joined #openstack-sdks02:17
*** dasp has quit IRC02:20
*** dasp has joined #openstack-sdks02:21
*** mordred has quit IRC02:38
*** mordred has joined #openstack-sdks02:42
*** LinPeiWen has quit IRC02:45
*** mgoddard has quit IRC02:58
*** LinPeiWen has joined #openstack-sdks03:05
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: Run images tests  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76726503:22
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: Run images tests  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76726503:22
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: Separate volume tests from servers tests  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76726803:28
*** udesale has joined #openstack-sdks05:22
*** evrardjp has quit IRC05:33
*** evrardjp has joined #openstack-sdks05:33
*** khomesh24 has quit IRC05:58
*** ricolin has joined #openstack-sdks05:59
*** khomesh24 has joined #openstack-sdks06:00
*** khomesh24 has quit IRC07:31
openstackgerritPolina Gubina proposed openstack/ansible-collections-openstack master: Enable update for recordset and add tests for dns and recordset module  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76652807:34
*** slaweq has joined #openstack-sdks08:00
*** gtema has joined #openstack-sdks08:02
openstackgerritMerged openstack/openstacksdk master: Change nodepool job to build CentOS-8-stream (unblock gate)  https://review.opendev.org/c/openstack/openstacksdk/+/76712608:16
*** rpittau|afk is now known as rpittau08:18
*** tosky has joined #openstack-sdks08:33
*** jawad_axd has joined #openstack-sdks08:43
*** mgoddard has joined #openstack-sdks08:46
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: Add network tests for versioned args  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76601308:52
*** jpich has joined #openstack-sdks09:03
*** mgoddard has quit IRC09:06
*** mgoddard has joined #openstack-sdks09:07
*** gtema has quit IRC09:18
*** gtema has joined #openstack-sdks09:19
*** jawad_axd has quit IRC09:30
*** jawad_axd has joined #openstack-sdks09:30
*** tosky_ has joined #openstack-sdks09:47
*** tosky is now known as Guest2437209:49
*** tosky_ is now known as tosky09:49
*** Guest24372 has quit IRC09:50
openstackgerritMerged openstack/ansible-collections-openstack master: Run images tests  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76726509:57
*** dtantsur|afk is now known as dtantsur09:59
*** lbragstad has quit IRC10:31
*** lbragstad has joined #openstack-sdks10:31
*** jpich has quit IRC10:53
*** tkajinam has quit IRC10:54
*** jpich has joined #openstack-sdks10:54
*** artom has joined #openstack-sdks11:13
*** udesale_ has joined #openstack-sdks11:24
*** udesale has quit IRC11:26
*** holser has joined #openstack-sdks11:37
*** jpich has quit IRC11:47
*** jpich has joined #openstack-sdks11:48
*** mgariepy has quit IRC12:02
*** brinzhang_ has joined #openstack-sdks12:17
*** LinPeiWen has quit IRC12:20
*** brinzhang has quit IRC12:21
*** jpich has quit IRC12:50
*** jpich has joined #openstack-sdks12:50
*** mgariepy has joined #openstack-sdks13:09
*** brinzhang_ has quit IRC13:29
*** brinzhang_ has joined #openstack-sdks13:29
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: WIP add designate to install with devstack  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76735213:36
*** gtema has quit IRC13:45
*** lbragstad has quit IRC13:54
*** lbragstad has joined #openstack-sdks13:57
*** lbragstad has quit IRC13:57
*** lbragstad has joined #openstack-sdks13:58
*** enriquetaso has joined #openstack-sdks14:01
*** lbragstad_ has joined #openstack-sdks14:03
*** gtema has joined #openstack-sdks14:04
*** lbragstad has quit IRC14:05
*** brinzhang_ has quit IRC14:31
*** brinzhang_ has joined #openstack-sdks14:32
*** belmoreira has joined #openstack-sdks15:01
*** ralonsoh has quit IRC15:15
*** ralonsoh has joined #openstack-sdks15:15
*** ricolin_ has joined #openstack-sdks15:15
*** ade_lee has joined #openstack-sdks15:58
ade_leefungi, hey - I need to add some changes to allow openstacksdk to work under fips -- in particular to handle md5()16:00
ade_leefungi, for example this is what we did for glance --- https://review.opendev.org/c/openstack/glance/+/75615816:01
fungilooking16:01
ade_leein that we referenced an encapsulation of md5() which we had put into oslo16:01
ade_leeoslo.utils16:01
ade_leebut I see there are no references to oslo in openstacksdk - and I'm gusessing thats deliberate?16:02
mordredvery16:03
ade_leeI figured that -- I can put in an implementation of that then -- just like I did for swift16:03
*** mgariepy has quit IRC16:04
mordredade_lee: you said python hashlib.md5 has been updaed with the notforsecurity param?16:04
ade_leeas in https://review.opendev.org/c/openstack/swift/+/751966/16/swift/common/utils.py  (line 4864 -> 4888)16:05
ade_leemordred, not everywhere yet16:05
mordredade_lee: nod. well - yeah - I thnik what you've got in swift would be fine - the uses in openstacksdk are also not for security16:06
ade_leemordred, cool - I'll get up a patch soon.16:07
fungiade_lee: so, putting on my paranoid security wonk afdb for a moment, it's entirely possible that the image checksums in glance are relied on for security, and could even be susceptible to exploiting collision attacks, however the exploit scenarios i can think of are a bit specious (if someone has the ability to substitute an image with a malicious alternative, then they've almost certainly also got16:08
fungimore direct ways to compromiose the entire system)16:08
mordredfungi: yeah - the only think we use image checksums for is just to avoid duplicate uploads. as in "have I already uploaded this image"16:09
fungii think as long as we document that checksums are being used to spot file corruption/truncation and that users should not rely on them to catch malicious activity, then it's fine16:09
mordredand the REAL reason we use them is that we've been putting them there long enough that they're part of the contract. we also do sha256 sums16:10
mordred++16:10
mordredlike, we cannot remove them16:10
fungior, yeah, for process optimization in your example16:10
mordredbut we can document their appropriate uses16:10
fungibut if we're going to be tacking on the notforsecurity flag in our uses of md5() we do need to be very clear to users that these checksums are internal implementation details and not security mechanisms16:10
fungiit's also worth noting that the currently feasible exploits known for md5 would essentially require the malicious actor to create the original image as well so that (using a chosen prefix attack) they could create a second compromised image and then pull a bait-and-switch after users had inspected the original16:15
fungiand even that's a bit theoretical, since it would depend on them being able to choose prefixes which still produce usable image files16:16
*** camelCaser has quit IRC16:20
*** ccamel has joined #openstack-sdks16:21
*** jawad_axd has quit IRC16:23
*** ricolin_ has quit IRC16:31
*** mgariepy has joined #openstack-sdks16:41
*** udesale_ has quit IRC16:56
openstackgerritMerged openstack/ansible-collections-openstack master: Migrating network from AnsibleModule to OpenStackModule  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76441116:59
*** ralonsoh is now known as ralonsoh|afk17:00
*** jpich has quit IRC17:04
*** jpich has joined #openstack-sdks17:05
*** rpittau is now known as rpittau|afk17:11
openstackgerritMerged openstack/ansible-collections-openstack master: Add network tests for versioned args  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76601317:11
openstackgerritPolina Gubina proposed openstack/ansible-collections-openstack master: Enable update for recordset and add tests for dns and recordset module  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76652817:21
*** jpich has quit IRC17:26
*** belmoreira has quit IRC17:34
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: WIP add designate to install with devstack  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76735217:39
openstackgerritArtem Goncharov proposed openstack/openstacksdk master: Modify cloud.get_aggregate to use proxy.find  https://review.opendev.org/c/openstack/openstacksdk/+/76717618:12
*** gtema has quit IRC18:47
*** dtantsur is now known as dtantsur|afk18:50
*** gtema has joined #openstack-sdks19:10
*** gtema has quit IRC19:20
*** brtknr has quit IRC19:37
*** brtknr has joined #openstack-sdks19:40
*** lbragstad_ is now known as lbragstad19:54
openstackgerritAde Lee proposed openstack/openstacksdk master: encapsulate md5 calls for fips  https://review.opendev.org/c/openstack/openstacksdk/+/76741120:03
openstackgerritAde Lee proposed openstack/openstacksdk master: encapsulate md5 calls for fips  https://review.opendev.org/c/openstack/openstacksdk/+/76741120:27
*** enriquetaso has quit IRC20:49
*** brinzhang0 has joined #openstack-sdks21:42
*** brinzhang_ has quit IRC21:45
openstackgerritShnaidman Sagi (Sergey) proposed openstack/ansible-collections-openstack master: WIP add designate to install with devstack  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76735221:50
*** ralonsoh|afk has quit IRC22:09
openstackgerritEmilien Macchi proposed openstack/ansible-collections-openstack master: networking/port: add support for tags  https://review.opendev.org/c/openstack/ansible-collections-openstack/+/76721922:39
*** slaweq has quit IRC22:42
*** tkajinam has joined #openstack-sdks22:59

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!