*** jhfeng has quit IRC | 00:19 | |
*** tmcpeak1 has quit IRC | 00:36 | |
*** elo has joined #openstack-security | 01:39 | |
*** hyakuhei has quit IRC | 01:40 | |
*** hyakuhei has joined #openstack-security | 01:41 | |
*** markvoelker has quit IRC | 01:44 | |
*** browne has quit IRC | 01:54 | |
*** sdake_ has joined #openstack-security | 01:55 | |
*** sdake has quit IRC | 01:59 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Allow configurable signing backends https://review.openstack.org/201394 | 02:01 |
---|---|---|
*** sdake has joined #openstack-security | 02:25 | |
*** sdake_ has quit IRC | 02:29 | |
*** sdake_ has joined #openstack-security | 02:40 | |
*** sdake has quit IRC | 02:44 | |
*** markvoelker has joined #openstack-security | 02:54 | |
*** markvoelker has quit IRC | 02:55 | |
*** markvoelker has joined #openstack-security | 02:55 | |
*** browne has joined #openstack-security | 02:55 | |
*** tmcpeak has joined #openstack-security | 03:04 | |
openstackgerrit | Jamie Finnigan proposed openstack/bandit: Add tool for reporting Bandit OpenStack coverage https://review.openstack.org/200383 | 03:39 |
*** sdake has joined #openstack-security | 04:03 | |
*** sdake_ has quit IRC | 04:07 | |
*** sdake_ has joined #openstack-security | 04:10 | |
*** sdake has quit IRC | 04:13 | |
*** sdake_ is now known as sdake | 04:13 | |
*** sdake has quit IRC | 04:22 | |
*** dave-mccowan has quit IRC | 04:25 | |
*** markvoelker_ has joined #openstack-security | 04:48 | |
*** markvoelker has quit IRC | 04:50 | |
*** markvoelker_ has quit IRC | 04:52 | |
*** markvoelker has joined #openstack-security | 04:57 | |
*** markvoelker has quit IRC | 05:03 | |
*** tmcpeak has quit IRC | 05:05 | |
*** markvoelker has joined #openstack-security | 05:08 | |
*** markvoelker has quit IRC | 05:16 | |
*** markvoelker has joined #openstack-security | 05:22 | |
*** markvoelker has quit IRC | 05:28 | |
*** shohel has joined #openstack-security | 06:05 | |
*** shohel has quit IRC | 06:10 | |
*** elo has quit IRC | 06:11 | |
*** dlitz has quit IRC | 06:19 | |
*** dlitz has joined #openstack-security | 06:22 | |
*** hyakuhei1 has joined #openstack-security | 07:21 | |
*** hyakuhei has quit IRC | 07:21 | |
*** browne has quit IRC | 07:41 | |
*** alex_klimov has joined #openstack-security | 07:50 | |
*** sdake has joined #openstack-security | 07:51 | |
*** sdake has quit IRC | 07:58 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Allow configurable signing backends https://review.openstack.org/201394 | 08:21 |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Add tests for higher coverage https://review.openstack.org/201464 | 08:55 |
*** tkelsey has joined #openstack-security | 08:59 | |
*** eternus has joined #openstack-security | 09:46 | |
*** eternus has left #openstack-security | 09:47 | |
*** shohel has joined #openstack-security | 10:07 | |
*** salv-orlando has quit IRC | 10:16 | |
*** openstackgerrit has quit IRC | 11:09 | |
*** openstackgerrit has joined #openstack-security | 11:09 | |
*** alex_klimov has quit IRC | 11:21 | |
*** hyakuhei has joined #openstack-security | 11:21 | |
*** hyakuhei1 has quit IRC | 11:21 | |
*** alex_klimov has joined #openstack-security | 11:29 | |
*** hyakuhei has quit IRC | 11:52 | |
*** hyakuhei has joined #openstack-security | 11:52 | |
*** salv-orlando has joined #openstack-security | 12:08 | |
*** edmondsw has joined #openstack-security | 12:09 | |
*** openstack has joined #openstack-security | 12:13 | |
*** edmondsw has quit IRC | 12:14 | |
*** edmondsw has joined #openstack-security | 12:19 | |
*** ig0r_ has joined #openstack-security | 12:23 | |
*** dave-mccowan has joined #openstack-security | 12:38 | |
*** markvoelker has joined #openstack-security | 12:43 | |
*** markvoelker has quit IRC | 12:47 | |
*** shohel has quit IRC | 12:53 | |
*** markvoelker has joined #openstack-security | 12:57 | |
*** markvoelker has quit IRC | 13:01 | |
*** markvoelker has joined #openstack-security | 13:01 | |
*** markvoelker has quit IRC | 13:06 | |
*** shohel has joined #openstack-security | 13:09 | |
*** markvoelker has joined #openstack-security | 13:10 | |
*** elo has joined #openstack-security | 13:11 | |
*** shohel has quit IRC | 13:13 | |
*** singlethink has joined #openstack-security | 13:18 | |
*** shohel has joined #openstack-security | 13:27 | |
*** singleth_ has joined #openstack-security | 13:30 | |
*** singlethink has quit IRC | 13:33 | |
*** tmcpeak has joined #openstack-security | 13:40 | |
*** singlethink has joined #openstack-security | 13:52 | |
*** singleth_ has quit IRC | 13:56 | |
*** singleth_ has joined #openstack-security | 13:56 | |
*** singlet__ has joined #openstack-security | 13:59 | |
*** singlethink has quit IRC | 13:59 | |
*** markvoelker_ has joined #openstack-security | 14:00 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:01 | |
*** singleth_ has quit IRC | 14:01 | |
*** markvoelker has quit IRC | 14:04 | |
*** jhfeng has joined #openstack-security | 14:10 | |
openstackgerrit | Merged openstack/bandit: Add tool for reporting Bandit OpenStack coverage https://review.openstack.org/200383 | 14:12 |
*** jhfeng has quit IRC | 14:12 | |
*** browne has joined #openstack-security | 14:18 | |
*** sdake_ has joined #openstack-security | 14:24 | |
*** jhfeng has joined #openstack-security | 14:29 | |
*** voodookid has joined #openstack-security | 14:29 | |
*** sdake_ is now known as sdae | 14:37 | |
*** sdae is now known as sdake | 14:37 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Modifying Parmiko Injection plugin https://review.openstack.org/201598 | 14:45 |
openstackgerrit | Travis McPeak proposed openstack/bandit: Modifying Parmiko Injection plugin https://review.openstack.org/201598 | 14:46 |
*** markvoelker_ has quit IRC | 14:49 | |
*** markvoelker has joined #openstack-security | 14:50 | |
*** sdake has quit IRC | 14:51 | |
*** sdake has joined #openstack-security | 14:51 | |
*** markvoelker has quit IRC | 14:55 | |
*** shohel has quit IRC | 15:04 | |
*** ig0r_ has quit IRC | 15:10 | |
*** ig0r__ has joined #openstack-security | 15:11 | |
*** ig0r_ has joined #openstack-security | 15:17 | |
*** ig0r__ has quit IRC | 15:19 | |
*** markvoelker has joined #openstack-security | 15:26 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Modifying Paramiko Injection plugin https://review.openstack.org/201598 | 15:35 |
*** hyakuhei has quit IRC | 15:38 | |
*** hyakuhei has joined #openstack-security | 15:39 | |
*** bpokorny has joined #openstack-security | 15:39 | |
*** ig0r__ has joined #openstack-security | 15:40 | |
*** ig0r_ has quit IRC | 15:43 | |
*** singlethink has joined #openstack-security | 15:52 | |
*** jhfeng has quit IRC | 15:53 | |
*** jesusjl has joined #openstack-security | 15:55 | |
*** jesusjl has left #openstack-security | 15:56 | |
*** singlet__ has quit IRC | 15:56 | |
Daviey | sigmavirus24: Good feedback, that is much cleaner. I'll do that in a few hours. | 16:11 |
sigmavirus24 | Daviey: too much indentation annoys me =P | 16:12 |
sigmavirus24 | Also checking for a string to be substituted ain't always fool proof =P | 16:12 |
*** singlethink has quit IRC | 16:13 | |
Daviey | sigmavirus24: Yeah, i was annoyed on both of those parts.. it felt dirty | 16:13 |
sigmavirus24 | Also that requirements job just gets more and more pedantic, huh? | 16:14 |
Daviey | Yeah, i thought licence was optional | 16:15 |
sigmavirus24 | Daviey: me too. | 16:15 |
sigmavirus24 | Also, lol at a mechanism for keeping projects co-installable when the community is moving towards virtualenv and container based installs which will not have those issues at all | 16:15 |
*** alex_klimov has quit IRC | 16:16 | |
*** shohel has joined #openstack-security | 16:19 | |
Daviey | sigmavirus24: Distro's very much still have that problem, and it isn't a bad workflow to standardize IMO | 16:29 |
sigmavirus24 | Daviey: it'd make more sense if we actually tested with versions in the range that aren't just the latest | 16:29 |
sigmavirus24 | i.e., if we had periodic jobs that tested against lowest constraints etc. | 16:30 |
sigmavirus24 | I've seen a few bugs out of Debian/Ubuntu packages relying on the lower limit value in g-r that was wrong and so the wrong version of a dependency was packaged for it | 16:30 |
*** singlethink has joined #openstack-security | 16:52 | |
openstackgerrit | Merged openstack/bandit: Modifying Paramiko Injection plugin https://review.openstack.org/201598 | 16:58 |
*** browne has quit IRC | 17:04 | |
*** bpokorny has quit IRC | 17:08 | |
*** bpokorny has joined #openstack-security | 17:09 | |
*** shohel has quit IRC | 17:25 | |
*** dwyde has joined #openstack-security | 17:28 | |
*** shohel has joined #openstack-security | 17:47 | |
*** dlitz has quit IRC | 17:47 | |
*** dlitz has joined #openstack-security | 17:51 | |
*** browne has joined #openstack-security | 17:53 | |
*** bpokorny_ has joined #openstack-security | 17:54 | |
*** openstackgerrit has quit IRC | 17:56 | |
*** openstackgerrit has joined #openstack-security | 17:56 | |
*** bpokorny has quit IRC | 17:56 | |
*** tkelsey has quit IRC | 17:59 | |
*** bpokorny has joined #openstack-security | 18:01 | |
*** bpokorny has quit IRC | 18:01 | |
*** bpokorny has joined #openstack-security | 18:01 | |
*** jmckind has joined #openstack-security | 18:01 | |
*** jmckind has quit IRC | 18:02 | |
*** jmckind has joined #openstack-security | 18:02 | |
*** bpokorny_ has quit IRC | 18:04 | |
*** dlitz has quit IRC | 18:13 | |
*** dlitz has joined #openstack-security | 18:16 | |
*** bpokorny has quit IRC | 18:25 | |
*** bpokorny has joined #openstack-security | 18:25 | |
*** mgagne_ has joined #openstack-security | 18:29 | |
*** sigmavirus24 has quit IRC | 18:30 | |
*** sigmavirus24 has joined #openstack-security | 18:30 | |
*** hyakuhei has quit IRC | 18:30 | |
*** mgagne has quit IRC | 18:30 | |
*** mgagne_ has left #openstack-security | 18:33 | |
*** janonymous_ has joined #openstack-security | 18:38 | |
janonymous_ | Please could someone review : https://review.openstack.org/#/c/196395/\ | 18:39 |
*** dlitz has quit IRC | 18:40 | |
*** mgagne_ has joined #openstack-security | 18:41 | |
*** dlitz has joined #openstack-security | 18:44 | |
* sigmavirus24 waves to dlitz | 18:50 | |
dlitz | hi sigmavirus24 | 18:51 |
sigmavirus24 | Do you work on OpenStack now? | 18:51 |
dlitz | not at the moment, but I should probably learn it sooner or later :) | 18:51 |
sigmavirus24 | Fair enough | 18:52 |
*** openstackgerrit has quit IRC | 18:56 | |
*** openstackgerrit has joined #openstack-security | 18:56 | |
openstackgerrit | Merged openstack/bandit: Adding test for Try, Except, Pass https://review.openstack.org/199582 | 18:59 |
*** elo has quit IRC | 19:05 | |
*** elo has joined #openstack-security | 19:06 | |
tmcpeak | janonymous_: I'll take a look | 19:22 |
janonymous_ | Thanks a lot, i have configured according to swift | 19:23 |
janonymous_ | once merged new api's could be supported | 19:23 |
*** bpokorny_ has joined #openstack-security | 19:28 | |
*** hyakuhei has joined #openstack-security | 19:29 | |
*** bpokorny has quit IRC | 19:30 | |
*** jmckind has quit IRC | 19:42 | |
janonymous_ | tmcpeak : https://review.openstack.org/#/c/196395/5/bandit.yaml | 19:42 |
janonymous_ | i have disabled these as per requirement of swift community | 19:43 |
janonymous_ | they want to pass the bandit job, without showing errors. and this was the only way i could do that . | 19:44 |
tmcpeak | janonymous_: it would be far better to actually correct these errors as these are severe findings | 19:44 |
janonymous_ | I asked about that but for now they want them to be ignored ... | 19:45 |
tmcpeak | hmmm… ok | 19:45 |
tmcpeak | so we don't need the severity level filtering anymore since we're using a specific set of tests, is that right? | 19:46 |
janonymous_ | i am sorry about that. But i am thankful about your continous support | 19:46 |
janonymous_ | yes | 19:46 |
tmcpeak | janonymous_: this is good work you're doing, it's better to have -a- bandit gate with limited checks than no bandit gate | 19:46 |
tmcpeak | janonymous_: update your commit message to take out the severity filtering and I'll +2 | 19:47 |
tmcpeak | err +1 | 19:47 |
janonymous_ | :) thanks i'll do it | 19:47 |
tmcpeak | I haven't actually tested it mind you, I assume you and the rest of the swift cores will take care of that :) | 19:48 |
janonymous_ | I'm sorry for trouble again but could you suggest this , i'll update | 19:48 |
tmcpeak | janonymous_: done | 19:49 |
Daviey | sigmavirus24: Hey, do you think .insert is going to be a problem of a list of 3-4 max elements ? | 19:49 |
sigmavirus24 | Daviey: it really shouldn't be, but we don't necessarily have to insert | 19:50 |
sigmavirus24 | we can also add `'.:'` to the start of the string returned from appdirs | 19:50 |
sigmavirus24 | I'm not really particular on that point | 19:50 |
Daviey | fair enough | 19:50 |
sigmavirus24 | And my confidence in my memory of the performance of insert is shakey at best right now | 19:51 |
sigmavirus24 | Inserting at the head of a linked list should be O(1) but for some reason I think Python does something weird and it isn't | 19:51 |
sigmavirus24 | Also having shaved off 10s of runtime for bandit recently it shouldn't be a big deal | 19:52 |
sigmavirus24 | And if it is an issue, we always have the spec that I have to write to add multiprocessing as an option | 19:52 |
*** jmckind has joined #openstack-security | 19:54 | |
janonymous_ | tmcpeak: Please review, please feel free to add features and enhancements in swift bandit . Thanks | 19:56 |
tmcpeak | janonymous_: features and enhancements? | 20:01 |
*** bpokorny_ has quit IRC | 20:01 | |
janonymous_ | fot bandit updates in future releases if any.. | 20:02 |
*** bpokorny has joined #openstack-security | 20:02 | |
tmcpeak | sorry, I'm not clear on what you're asking, you're asking to add what where? :) | 20:02 |
janonymous_ | ohh.. i am sorry, I meant if there is an update in bandit and tht change needs to be reflected in .yaml file in future , please feel free to suggest such changes | 20:05 |
tmcpeak | ahh ok | 20:05 |
janonymous_ | \m | 20:06 |
janonymous_ | thank you | 20:06 |
tmcpeak | sure, thanks for your work on this | 20:06 |
tmcpeak | janonymous_: so next step is the infra change to add the gate | 20:07 |
tmcpeak | you know how to do that? | 20:07 |
janonymous_ | yes once it is approved i'll proceed to the change.. | 20:07 |
tmcpeak | great | 20:08 |
janonymous_ | :) | 20:09 |
Daviey | sigmavirus24: TIL that % is invalud syntax in YAML | 20:17 |
Daviey | invalid* | 20:17 |
sigmavirus24 | whuh?! | 20:17 |
sigmavirus24 | what about quoting it? | 20:17 |
sigmavirus24 | "%(foo)s/bar/bogus" | 20:17 |
Daviey | That would work | 20:18 |
openstackgerrit | Dave Walker proposed openstack/bandit: Install word_list, raise exception if cannot find https://review.openstack.org/201053 | 20:22 |
tmcpeak | Daviey: this is cool, I never knew about appdirs before | 20:24 |
Daviey | tmcpeak: Yeah, seems to be a pretty graceful way of dealing with FHS type locations with distro differences | 20:26 |
Daviey | Standard and Distro's in the same sentence #lolz #trollz | 20:26 |
*** dave-mccowan has quit IRC | 20:27 | |
tmcpeak | LOOOL | 20:27 |
Daviey | Silly question, but is anyone else finding that bandit plugins don't get installed by default with pip install ? | 20:28 |
*** dave-mccowan has joined #openstack-security | 20:29 | |
tmcpeak | emmm, no | 20:30 |
tmcpeak | that would be bad :) | 20:30 |
Daviey | Sorry, ignore that.. It is when i am running it from local tox env | 20:30 |
tmcpeak | try "pip uinstall bandit" until it says it can't find it | 20:30 |
tmcpeak | Daviey: bad news bears on that change, Bandit goes nuts if it can't find the wordlist | 20:31 |
Daviey | So it does.. you'd think i'd have checked that | 20:32 |
*** jmckind has quit IRC | 20:33 | |
tmcpeak | :) | 20:33 |
*** sdake has quit IRC | 20:36 | |
Daviey | tmcpeak: So I'm not quite sure how to solve this.. We want to avoid sys.ext on error, but also not be bombarded with errors with each test invocation. | 20:44 |
tmcpeak | Daviey: yeah, it's an interesting puzzle | 20:45 |
Daviey | tmcpeak: I don't have a smart way of saying, raise once - then be silent. | 20:45 |
*** bpokorny_ has joined #openstack-security | 20:45 | |
tmcpeak | yeah, and we don't have to push something specific to this wordlist problem into generic Bandit code | 20:45 |
tmcpeak | all things considered, exit might be appropriate.. since you are explicitly running the wordlist plugin and there isn't a wordlist, something is jacked up with your config. Better to know about it and act appropriately | 20:46 |
sigmavirus24 | So | 20:46 |
sigmavirus24 | I agree with your last statement tmcpeak | 20:46 |
Daviey | tmcpeak: Well, I was thinking of having a "on_plugin_error: raise_and_continue|explode_the_world" for a more generic thing | 20:46 |
sigmavirus24 | If we want to warn once, though, the default setting for the warnings module is warn once (per unique warning string) and then stfu | 20:47 |
tmcpeak | sigmavirus24: that sounds ideal | 20:47 |
tmcpeak | warn once then STFU | 20:47 |
tmcpeak | what warnings module though? | 20:47 |
sigmavirus24 | standard library | 20:48 |
sigmavirus24 | import warnings; warnings.warn("message", WarningClass) | 20:48 |
*** bpokorny has quit IRC | 20:48 | |
tmcpeak | ahh | 20:49 |
tmcpeak | this is good | 20:49 |
tmcpeak | Daviey: what do you think of that? | 20:49 |
Daviey | sigmavirus24: well.. logger.warn is infact doing it with each string tested | 20:49 |
sigmavirus24 | Daviey: you mean warning that teh file is missing? | 20:49 |
Daviey | sigmavirus24: I almost added logger.warn("Using relative wordlist"), but i was seeing it for each test string | 20:49 |
sigmavirus24 | Daviey: logger.warn != warnings.warn | 20:50 |
Daviey | oh | 20:50 |
sigmavirus24 | warnings.warn /can/ be told to write to the log though | 20:50 |
*** janonymous_ has quit IRC | 20:50 | |
*** mgagne_ is now known as mgagne | 20:50 | |
Daviey | Cool | 20:50 |
tmcpeak | the problem seems to be what is getting warned is indeed unique: | 20:50 |
tmcpeak | [tester]ERRORBandit internal error running: hardcoded_password on file /Users/travismcpeak/Documents/projects/OpenStack_projects/keystone/keystone/assignment/core.py at line 568: Could not substitute '%(site_data_dir)s' to a path with a valid word_list fileTraceback (most recent call last): | 20:50 |
Daviey | so that throws UserWarning | 20:51 |
Daviey | That is perfect | 20:51 |
tmcpeak | because the warning is being done after the module returns, we just log whatever went wrong with it | 20:51 |
tmcpeak | if we instead log in the module itself, then we can ensure that it is unique | 20:51 |
Daviey | I can massage that | 20:51 |
tmcpeak | cool | 20:51 |
openstackgerrit | Dave Walker proposed openstack/bandit: Install word_list, raise exception if cannot find https://review.openstack.org/201053 | 21:13 |
*** singlethink has quit IRC | 21:16 | |
*** dwyde has quit IRC | 21:20 | |
*** sdake has joined #openstack-security | 21:21 | |
*** dwyde has joined #openstack-security | 21:21 | |
*** sdake_ has joined #openstack-security | 21:40 | |
*** elo has quit IRC | 21:41 | |
*** sdake has quit IRC | 21:41 | |
*** shakamunyi has joined #openstack-security | 21:58 | |
*** edmondsw has quit IRC | 22:08 | |
*** kutija has quit IRC | 22:13 | |
openstackgerrit | Dave Walker proposed openstack/bandit: Consider other hardcoded tmp paths https://review.openstack.org/200882 | 22:16 |
*** kutija has joined #openstack-security | 22:20 | |
*** dwyde has quit IRC | 22:31 | |
*** sdake_ is now known as sdake | 22:34 | |
*** kutija_ has joined #openstack-security | 22:36 | |
*** kutija has quit IRC | 22:39 | |
openstackgerrit | Dave Walker proposed openstack/bandit: Consider other hardcoded tmp paths https://review.openstack.org/200882 | 22:44 |
*** dowlesbu has joined #openstack-security | 22:45 | |
*** dwyde has joined #openstack-security | 22:47 | |
*** dwyde has quit IRC | 22:47 | |
*** bpokorny_ has quit IRC | 22:49 | |
*** bpokorny has joined #openstack-security | 22:49 | |
*** Aka_coder has joined #openstack-security | 23:00 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:01 | |
*** voodookid has quit IRC | 23:04 | |
*** Aka_coder has left #openstack-security | 23:05 | |
*** Aka_coder has joined #openstack-security | 23:07 | |
*** Aka_coder has left #openstack-security | 23:10 | |
*** shohel has quit IRC | 23:24 | |
*** hyakuhei has quit IRC | 23:31 | |
*** bitblt has joined #openstack-security | 23:31 | |
*** hyakuhei has joined #openstack-security | 23:33 | |
*** barra204 has joined #openstack-security | 23:35 | |
*** shakamunyi has quit IRC | 23:36 | |
*** dlitz has quit IRC | 23:52 | |
*** tmcpeak has quit IRC | 23:54 | |
*** dlitz has joined #openstack-security | 23:54 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!