Monday, 2015-08-10

Anne-On-A-MooseHi, was wondering if any of you have experience of bad bios?07:52
*** tkelsey has joined #openstack-security09:12
*** dave-mccowan has joined #openstack-security12:01
*** tmoreira has joined #openstack-security12:08
*** nkinder has joined #openstack-security13:16
*** sdake_ has joined #openstack-security14:23
*** singlethink has joined #openstack-security16:58
elmikohey sec-doc folks =)16:59
pdesaihi elmiko17:00
elmikoDaviey, you around?17:00
elmikohi pdesai , nice work on catching those few extra bugs =)17:00
pdesaisure :)17:01
elmikohey Daviey17:01
elmikook, so let's get rolling17:01
Davieyelmiko: o/17:01
elmikolooks like all the medium bugs have been addressed and merged17:01
pdesaithere is one on block storage i guess17:01
elmikowe've also had a few other bugs fixed which were deployed into rst and xml17:01
elmikopdesai, line# ?17:01
pdesai  Empty (original has 2 paragarphs and a note) (medium) - I see data in the file, so waiting for the below to run checkbuild to validate17:02
pdesaii am not sure what the status is17:02
elmikooh, good call. (missed that one)17:02
elmikohmm, i'm not familiar with this one.17:02
pdesaime neither17:03
elmikoshould the 2 paras from the original be ported to the rst?17:03
pdesaii see the two paras from original in rst17:04
elmikoah, ok17:04
elmikothe next question will be, should we move out of freeze on the rst and are we in a position to freeze out new work on the docbook?17:05
elmikoDaviey, did the sidebar changes get merged yet?17:06
Davieyelmiko: yes17:06
pdesaiwhat is the chage request?17:06
pdesaioh nice17:06
Davieyelmiko: just waiting for the theme to cut a release17:07
Davieyi will chase this tonorrow17:07
elmikoah ok, still waiting on that then. cool, thanks!17:07
elmikoit sounds like we will be on track to switch over when sicarie gets back17:07
*** sdake has quit IRC17:07
elmikoi suppose we could take a few more of the smaller bugs in the etherpad just to fill things out while awaiting our fearless leader's return17:08
elmikoother than that, i'm not aware of other issues.17:08
elmiko(although there are some old bugs that need addressing)17:09
elmikoeither of you have any issues to bring up?17:09
pdesaiand we need to address two things, after we lift a freeze, (1) getting rid of warning on rst (2)17:09
Davieydo we have a hit list?17:10
pdesai(2) moving away from draft on docs site17:10
elmikothe etherpad has a bunch of low-level stuff that we agreed didn't need to be done before the switch over17:10
elmikopdesai, maybe we should focus on hunting warnings this next week then?17:11
pdesaiyup sounds good17:11
elmikoDaviey, not really a hit list, more a low prio trashcan fire list lol17:11
elmikobut i guess, if folks have time, take a look at the warnings generated from the rst build and put up some patches to fix them =)17:12
elmikomaybe we can dump all the warnings into the etherpad just to help coordinate on fixing them?17:12
pdesaiyup that would help17:13
elmikoof course, now that i say that i'm not getting any lol17:13
DavieyConsidering how many times i have built RST locally.. you'd think i'd have noticed we had SOME warnings.. but i don't remember seeing any!17:13
pdesaielmiko, lets talk more then :)17:14
elmikopdesai, are these warnings coming out of the niceness checks?17:14
pdesaii havent seen any warnings17:15
pdesaii generally run tox -e docs17:15
elmikook, until we find warnings, let's focus on getting more of the low/very low bugs out of the way17:15
Davieypdesai: Ah, same here.. might explain why we have been excused the warnings17:16
elmikojust grab some out of the etherpad and post links to reviews, i'll go through and keep them updated17:16
pdesaiyup sounds good17:16
elmikoi just re-ran tox against a fresh build and didn't see any warnings, so let's just move on till we find them =)17:16
elmikosounds good then17:17
pdesaii checked one of the latest review request and did nto find any warnings, niceness or deletions17:17
elmikoi don't have any other topics17:18
Davieyshall we go home?17:18
elmikoi think so17:18
elmikounless pdesai has something?17:18
pdesainope nothing from myside, waiting for the freeze lift :)17:18
Davieypdesai: I don't think you need to wait on content for the freeze lift...17:19
DavieyI *think* we agreed that landing stuff soley in RST was acceptable now.. just not expecting it in prod yet17:19
pdesaioh awesome, didnt catch that17:20
elmikoi don't have an issue accepting reviews for new material to rst only17:20
elmikowe are close enough that i imagine the switch over will happen next week when sicarie is back17:20
elmikoso, makes sense imo to start reviewing new content17:20
elmikoi can confirm with the docs team though just to make sure before we start merging17:21
Davieyelmiko: What needs confirming?17:21
elmikoDaviey, i just want to make sure we're not missing some detail that i'm not aware of17:22
elmikomainly because sicarie has been more involved with the rst conversion efforts upstream17:22
elmikootherwise i'd say we could probably switch over to rst =)17:23
DavieyWell.. i just checked, and the release notes have now been merged for openstacksdocstheme.. so it really is just blocked on someone cutting a release of the theme17:24
DavieySo i'm guessing that will happen today/tomorrow17:24
elmikoDaviey, where to check for when that is released?17:24
Davieyelmiko: i guess pypi or the openstack-docs ML17:25
elmikoack, thanks17:26
Davieyelmiko: Worth looking at ?17:26
DavieyIt renames sections.. but does it in the old and new world17:26
*** yaya has quit IRC17:26
elmikohmm, looks like andreas gave it +A17:27
elmikoi also gave some +A to older changes that fixed rst and xml17:27
elmikobut going forward i think we can start to work on just rst17:27
elmikoi don't think it's a big issue to fix the xml stuff along with the rst stuff, but we should stop doing it soon(TM)17:28
elmikoonce the theme stuff lands we will be in a good position to really cut over and stop accepting xml changes17:29
elmikoagain though, i'd like to sync up with the doc team just make sure we're not moving too fast or over-stepping some boundary i'm not aware of17:30
elmikodoes that make sense?17:30
DavieyDD"Move fast and break stuff" -- somefoo17:30
elmikook, then, we're over time. thanks pdesai and Daviey17:31
Davieythanks elmiko17:32
tmcpeakDaviey: thanks for taking over that change17:32
tmcpeaklooks good17:32
pdesaithanks guys17:32
openstackgerritMerged openstack/security-doc: Renamed Future section and added domain information
*** yaya has joined #openstack-security17:35
Davieyelmiko: Actually, this change triggers a release when it is merged -
elmikoDaviey, oh, very nice!17:37
tmcpeakbknudson: nice!!17:43
tmcpeak(on your testing stuff)17:43
*** browne has quit IRC19:18
*** singleth_ has joined #openstack-security20:55
austin_laptopbandit is warning for chmod 755; this is for a python project that packs system images into a tarball, its pretty common to need to chmod 755, is this warning really necessary (or really a medium severity?)20:59
*** yaya has quit IRC21:00
*** elo has joined #openstack-security21:01
tmcpeakaustin_laptop: the reason it's warning is because it's world readable21:31
tmcpeakthat's generally a bad idea21:31
tmcpeakif it's really not an issue in this case we have the "#nosec" tag which indicates a human has looked at it and deemed that it isn't a security risk that you are creating that file world readable21:32
austin_laptoptmcpeak, okay, thanks21:36
*** JAHoagie has joined #openstack-security21:36
tmcpeakaustin_laptop: sure21:37
*** yaya has joined #openstack-security21:43
*** yaya has quit IRC22:00
austin_laptopso solved now, thanks for the quick replies :)22:38
Davieyaustin_laptop: You can create a profile excluding this test.. but it is pretty cheap to add #nosec IMO22:38
austin_laptopDaviey, yeah, I passed that along to the maintainer of that codebase. It's a small enough issue that it's easier to annotate than blindly disable all22:39
DavieyAnd by adding #nosec to git, you are adding an audit log of your analysis :)22:39
austin_laptopDaviey, though I was curious of the format for doing that22:39
austin_laptopI could only find the default bandit.yaml, wasn't sure how to blacklist that call (for testing)22:39
DavieyIn the latest release the sample bandit.yaml contains a Profile for ALL.. which you can use as a reference22:40
