| *** nkinder has joined #openstack-security | 00:05 | |
| *** shohel02 has joined #openstack-security | 00:41 | |
| *** shohel02 has quit IRC | 00:46 | |
| *** tmcpeak has quit IRC | 01:02 | |
| *** salv-orlando has quit IRC | 01:04 | |
| *** tmcpeak has joined #openstack-security | 01:33 | |
| *** tmcpeak has quit IRC | 01:35 | |
| *** shohel02 has joined #openstack-security | 01:41 | |
| *** dave-mccowan has joined #openstack-security | 01:41 | |
| *** shohel02 has quit IRC | 01:46 | |
| *** bpokorny has joined #openstack-security | 01:51 | |
| *** bpokorny has quit IRC | 02:17 | |
| *** dave-mccowan has quit IRC | 02:40 | |
| *** dave-mccowan has joined #openstack-security | 02:40 | |
| *** shohel02 has joined #openstack-security | 02:41 | |
| *** hyakuhei has quit IRC | 02:45 | |
| *** shohel02 has quit IRC | 02:46 | |
| *** bpokorny has joined #openstack-security | 03:23 | |
| *** shohel02 has joined #openstack-security | 03:41 | |
| *** shohel02 has quit IRC | 03:46 | |
| *** dave-mccowan has quit IRC | 04:12 | |
| *** hyakuhei has joined #openstack-security | 04:29 | |
| *** _et has joined #openstack-security | 04:36 | |
| *** _et has left #openstack-security | 04:37 | |
| *** _et has joined #openstack-security | 04:37 | |
| chair6 | just noticed some weirdness in the online version of the security guide | 04:39 |
|---|---|---|
| chair6 | links in the ToC on the left, and urls associated with each page, do not map to chapter number / title | 04:39 |
| chair6 | for example, in the ToC the text '29. Message queuing architecture' points to URL http://docs.openstack.org/security-guide/content/ch037_risks.html | 04:40 |
| chair6 | then the content at http://docs.openstack.org/security-guide/content/ch037_risks.html has heading 'Chapter 29. Message queuing architecure' | 04:40 |
| chair6 | something funky going on.. | 04:41 |
| *** shohel02 has joined #openstack-security | 04:41 | |
| chair6 | looks like google has indexed content with those mismatched URLs as well | 04:43 |
| *** shohel02 has quit IRC | 04:46 | |
| *** bpokorny has quit IRC | 04:47 | |
| _et | chair6: file a bug? | 04:48 |
| *** bpokorny has joined #openstack-security | 04:54 | |
| *** subscope_ has joined #openstack-security | 04:55 | |
| *** bpokorny has quit IRC | 04:56 | |
| _et | https://bugs.launchpad.net/openstack-manuals/+bug/1395974 | 04:57 |
| *** bpokorny has joined #openstack-security | 04:57 | |
| _et | chair6: done. | 04:57 |
| *** bpokorny has quit IRC | 05:01 | |
| chair6 | thanks _et | 05:06 |
| *** jamielennox has quit IRC | 05:11 | |
| *** jamielennox has joined #openstack-security | 05:11 | |
| *** _et has quit IRC | 05:14 | |
| *** subscope_ has quit IRC | 05:25 | |
| *** shohel02 has joined #openstack-security | 05:41 | |
| *** shohel02 has quit IRC | 05:46 | |
| *** shohel02 has joined #openstack-security | 06:41 | |
| *** shohel02 has quit IRC | 06:46 | |
| *** shohel02 has joined #openstack-security | 07:41 | |
| openstackgerrit | Merged openstack/security-doc: Fix recommendations post-POODLE https://review.openstack.org/135844 | 07:45 |
| *** shohel02 has quit IRC | 07:46 | |
| *** jamielennox is now known as jamielennox|away | 07:49 | |
| *** salv-orlando has joined #openstack-security | 08:08 | |
| *** shohel02 has joined #openstack-security | 08:14 | |
| *** salv-orlando has quit IRC | 10:00 | |
| *** salv-orlando has joined #openstack-security | 10:02 | |
| openstackgerrit | Abu Shohel Ahmed proposed openstack/security-doc: Adds OpenStack security threat analysis folder https://review.openstack.org/121034 | 10:14 |
| *** salv-orlando has quit IRC | 10:57 | |
| *** salv-orlando has joined #openstack-security | 11:02 | |
| *** salv-orlando has quit IRC | 11:11 | |
| *** salv-orlando has joined #openstack-security | 11:11 | |
| *** shohel02 has quit IRC | 11:57 | |
| *** shohel02 has joined #openstack-security | 12:02 | |
| *** salv-orlando has quit IRC | 12:25 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 13:07 |
| *** LinStatSDR has quit IRC | 13:18 | |
| *** LinStatSDR has joined #openstack-security | 13:18 | |
| *** shohel02 has quit IRC | 13:21 | |
| *** dave-mccowan has joined #openstack-security | 13:35 | |
| *** tmcpeak has joined #openstack-security | 13:40 | |
| *** shohel02 has joined #openstack-security | 13:43 | |
| *** salv-orlando has joined #openstack-security | 13:53 | |
| *** shohel02 has quit IRC | 13:59 | |
| *** shohel02 has joined #openstack-security | 14:06 | |
| *** shohel02 has quit IRC | 14:12 | |
| *** paulmo has joined #openstack-security | 14:13 | |
| *** nkinder has quit IRC | 14:14 | |
| *** shohel02 has joined #openstack-security | 14:19 | |
| *** dave-mccowan_ has joined #openstack-security | 14:29 | |
| *** dave-mccowan has quit IRC | 14:32 | |
| *** dave-mccowan_ is now known as dave-mccowan | 14:32 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 14:44 |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 14:46 |
| *** dave-mccowan has quit IRC | 14:47 | |
| *** dave-mccowan has joined #openstack-security | 15:01 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:02 |
| *** nkinder has joined #openstack-security | 15:06 | |
| *** LinStatSDR has quit IRC | 15:14 | |
| *** voodookid has joined #openstack-security | 15:23 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:27 |
| *** shohel02 has quit IRC | 15:41 | |
| *** sicarie has joined #openstack-security | 15:47 | |
| openstackgerrit | Merged stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:52 |
| *** shohel02 has joined #openstack-security | 15:55 | |
| *** bpokorny has joined #openstack-security | 15:56 | |
| tmcpeak | nkinder: you around? | 16:04 |
| *** tmcpeak has quit IRC | 16:58 | |
| *** salv-orlando has quit IRC | 17:01 | |
| *** LinStatSDR has joined #openstack-security | 17:03 | |
| *** bpokorny has quit IRC | 17:06 | |
| *** bpokorny has joined #openstack-security | 17:22 | |
| bknudson | I tried running bandit using http://git.openstack.org/cgit/stackforge/bandit/tree/README.md#n39 but it fails with a bunch of errors | 17:25 |
| bknudson | AttributeError: 'Name' object has no attribute 'value' | 17:25 |
| bknudson | I tried running the tests and those all passed | 17:26 |
| *** edmondsw has joined #openstack-security | 17:30 | |
| *** tmcpeak has joined #openstack-security | 17:35 | |
| *** shohel02 has quit IRC | 17:39 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Fixing an oversight when processing none-attr nodes. https://review.openstack.org/137153 | 17:40 |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Fixing an oversight when processing none-attr nodes https://review.openstack.org/137153 | 17:44 |
| openstackgerrit | Merged stackforge/bandit: Fixing an oversight when processing none-attr nodes https://review.openstack.org/137153 | 18:04 |
| chair6 | thanks bknudson, that bug should be fixed | 18:05 |
| bknudson | I'll try it. | 18:06 |
| bknudson | that helped but getting a different error running against keystone | 18:08 |
| bknudson | http://paste.openstack.org/show/138298/ | 18:08 |
| *** jamielennox|away is now known as jamielennox | 18:11 | |
| nkinder | tmcpeak: hey, what's up? | 18:11 |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node. https://review.openstack.org/137165 | 18:25 |
| tmcpeak | nkinder: was going to check about what I should do to make a nicely formatted ML post | 18:25 |
| tmcpeak | but hyakuhei pointed me to the ML etiquette link | 18:26 |
| nkinder | tmcpeak: ok, cool | 18:27 |
| *** bpokorny_ has joined #openstack-security | 18:27 | |
| *** bpokorny has quit IRC | 18:31 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node. https://review.openstack.org/137165 | 18:31 |
| *** bpokorny has joined #openstack-security | 18:32 | |
| *** salv-orlando has joined #openstack-security | 18:33 | |
| *** bpokorn__ has joined #openstack-security | 18:33 | |
| *** bpokorny_ has quit IRC | 18:35 | |
| openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node https://review.openstack.org/137165 | 18:36 |
| *** bpokorny has quit IRC | 18:37 | |
| openstackgerrit | Merged stackforge/bandit: Graceful degradation when failing to full qualify an attr node https://review.openstack.org/137165 | 18:40 |
| chair6 | bknudson: ^ that should do it, try again .. the joys of trying to get one last feature in before 'announcing' :( | 18:41 |
| bknudson | chair6: how do I mark a line (use of random) as safe? | 18:42 |
| bknudson | I need to get it to not look at test code | 18:42 |
| chair6 | for an individual line, add a trailing # nosec | 18:43 |
| tmcpeak | bknudson: do you think a formal way to exclude a directory would be more useful? | 18:45 |
| *** bpokorny has joined #openstack-security | 18:45 | |
| tmcpeak | I guess the same thing could be done with a find command, or by running Bandit on individual directories though… | 18:46 |
| bknudson | tmcpeak: we'll need a way to run it for a project (e.g., keystone) and the project should be able to say what directories to exclude | 18:46 |
| tmcpeak | bknudson: yeah, totally | 18:46 |
| bknudson | the the directory is keystone/test and we want to exclude just that directory. | 18:46 |
| tmcpeak | do you think running Bandit through find like this: find ~/openstack-repo/keystone -name '*.py' | xargs bandit -n 1 and then using some find magic to exclude that directory would be a good solution, or do you think we should build it into Bandit itself? | 18:47 |
| bknudson | I think it should be built into bandit... you'll need a config file anyways | 18:48 |
| *** bpokorn__ has quit IRC | 18:49 | |
| tmcpeak | bknudson: cool, should be easy enough to add | 18:49 |
| tmcpeak | config file already there, just need to add that | 18:49 |
| tmcpeak | bknudson: I'll add that to the queue | 18:50 |
| *** jimhoagland has joined #openstack-security | 19:40 | |
| *** gabriela has joined #openstack-security | 20:33 | |
| *** gabriela has left #openstack-security | 20:36 | |
| *** jimhoagland has quit IRC | 20:46 | |
| *** gabriela has joined #openstack-security | 21:02 | |
| gabriela | hola | 21:08 |
| *** gabriela has left #openstack-security | 21:19 | |
| *** sicarie_ has joined #openstack-security | 21:21 | |
| *** jamielennox is now known as jamielennox|away | 21:23 | |
| *** LinStatSDR has quit IRC | 21:25 | |
| *** jamielennox|away is now known as jamielennox | 21:28 | |
| *** paulmo has quit IRC | 21:45 | |
| *** dave-mccowan has quit IRC | 21:51 | |
| *** tmcpeak has quit IRC | 22:13 | |
| *** tmcpeak has joined #openstack-security | 22:14 | |
| *** tmcpeak has quit IRC | 23:09 | |
| *** edmondsw has quit IRC | 23:12 | |
| *** tmcpeak has joined #openstack-security | 23:15 | |
| *** nkinder has quit IRC | 23:18 | |
| *** sicarie_ has quit IRC | 23:29 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!