*** salv-orl_ has quit IRC | 00:00 | |
*** daniel1 has joined #openstack-security | 00:11 | |
*** daniel1 has quit IRC | 00:11 | |
*** jbasalone has quit IRC | 00:12 | |
*** jbasalone has joined #openstack-security | 00:15 | |
*** jbasalone has quit IRC | 00:28 | |
*** zul has joined #openstack-security | 00:34 | |
*** sdake_ has quit IRC | 00:52 | |
*** salv-orlando has joined #openstack-security | 01:00 | |
*** browne has quit IRC | 01:07 | |
*** Guest48525 has joined #openstack-security | 01:12 | |
Guest48525 | hola | 01:13 |
---|---|---|
*** Guest48525 has left #openstack-security | 01:13 | |
*** salv-orlando has quit IRC | 01:30 | |
*** salv-orlando has joined #openstack-security | 01:31 | |
*** jhfeng has joined #openstack-security | 01:34 | |
*** asd112z has joined #openstack-security | 01:35 | |
*** salv-orlando has quit IRC | 01:36 | |
*** dave-mccowan has quit IRC | 01:56 | |
*** elo1 has quit IRC | 01:59 | |
*** tmcpeak has quit IRC | 02:23 | |
*** tkelsey has joined #openstack-security | 02:36 | |
*** tkelsey has quit IRC | 02:40 | |
*** browne has joined #openstack-security | 02:49 | |
*** sdake has joined #openstack-security | 03:22 | |
*** asd112z has quit IRC | 03:31 | |
*** jhfeng has quit IRC | 03:34 | |
*** jbasalone has joined #openstack-security | 03:44 | |
*** elo1 has joined #openstack-security | 03:47 | |
*** elo2 has joined #openstack-security | 03:49 | |
*** elo1 has quit IRC | 03:52 | |
*** sdake_ has joined #openstack-security | 04:06 | |
*** sdake has quit IRC | 04:10 | |
*** jbasalone has quit IRC | 04:18 | |
*** sdake_ is now known as sdake | 04:18 | |
*** _blue has joined #openstack-security | 04:20 | |
*** _blue has left #openstack-security | 04:25 | |
*** asd112z has joined #openstack-security | 05:32 | |
*** asd112z has quit IRC | 05:51 | |
*** serverascode has quit IRC | 06:12 | |
*** serverascode has joined #openstack-security | 06:15 | |
*** yuanying has quit IRC | 06:25 | |
*** quie has joined #openstack-security | 06:35 | |
*** b10n1k_ has joined #openstack-security | 06:39 | |
*** quie has quit IRC | 06:39 | |
*** quie has joined #openstack-security | 06:41 | |
*** b10n1k_ has quit IRC | 06:44 | |
*** yuanying has joined #openstack-security | 06:44 | |
*** quie has quit IRC | 06:49 | |
*** elo2 has quit IRC | 07:03 | |
*** tkelsey has joined #openstack-security | 07:04 | |
*** tkelsey has quit IRC | 07:08 | |
*** browne has quit IRC | 07:21 | |
*** salv-orlando has joined #openstack-security | 07:47 | |
*** tkelsey has joined #openstack-security | 07:47 | |
*** alex_klimov has joined #openstack-security | 07:54 | |
*** asd112z has joined #openstack-security | 08:03 | |
*** shohel has joined #openstack-security | 08:04 | |
*** shohel has quit IRC | 08:04 | |
*** asd112z has quit IRC | 08:08 | |
*** alex_klimov has quit IRC | 08:40 | |
*** alex_klimov has joined #openstack-security | 08:52 | |
*** tjt263 has quit IRC | 09:25 | |
*** tjt263 has joined #openstack-security | 09:26 | |
*** tjt263 has quit IRC | 09:31 | |
*** tjt263 has joined #openstack-security | 09:32 | |
*** salv-orlando has quit IRC | 10:20 | |
*** dave-mcc_ has joined #openstack-security | 10:23 | |
*** salv-orlando has joined #openstack-security | 10:43 | |
*** asd112z has joined #openstack-security | 11:03 | |
*** asd112z has quit IRC | 11:08 | |
*** shohel has joined #openstack-security | 11:27 | |
*** shohel has quit IRC | 11:43 | |
*** shohel has joined #openstack-security | 11:57 | |
*** tkelsey has quit IRC | 11:57 | |
*** singlethink has joined #openstack-security | 12:22 | |
*** edmondsw has joined #openstack-security | 12:36 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:00 | |
*** tmcpeak has joined #openstack-security | 13:02 | |
*** browne has joined #openstack-security | 13:10 | |
openstackgerrit | Merged openstack/security-doc: Corrected security group documentation https://review.openstack.org/202801 | 13:15 |
*** singlethink has quit IRC | 13:30 | |
*** bapalm has quit IRC | 13:44 | |
*** mpmsimo has joined #openstack-security | 13:49 | |
*** yaya has joined #openstack-security | 14:12 | |
*** mpmsimo has quit IRC | 14:15 | |
*** y_sawai has joined #openstack-security | 14:24 | |
*** bknudson has joined #openstack-security | 14:28 | |
*** jian5397 has joined #openstack-security | 14:29 | |
*** asd112z has joined #openstack-security | 14:32 | |
*** asd112z has quit IRC | 14:33 | |
*** asd112z has joined #openstack-security | 14:33 | |
*** asd112z has quit IRC | 14:34 | |
*** asd112z has joined #openstack-security | 14:34 | |
*** voodookid has joined #openstack-security | 14:34 | |
*** yaya has quit IRC | 14:38 | |
jelle | 16:42:08 * | jelle asked his indian collegues for good dishes but they are all vegetarian │ | 14:42 |
jelle | woops | 14:42 |
sigmavirus24 | lol jelle | 14:42 |
*** yaya has joined #openstack-security | 14:43 | |
elmiko | there are some great vegetarian indian dishes | 14:43 |
jelle | elmiko: probably :) | 14:43 |
elmiko | =) | 14:44 |
sigmavirus24 | there are very good ones | 14:45 |
sigmavirus24 | there are also good ¬vegetarian ones | 14:45 |
elmiko | true | 14:45 |
sigmavirus24 | There are really good vegan korean dishes, and good ones that are ¬vegan | 14:46 |
jelle | well they must have good vegetarian dishes, if they only eat vegetarian :) | 14:46 |
elmiko | there's just some great indian good regardless | 14:46 |
sigmavirus24 | Yep | 14:46 |
elmiko | *food | 14:46 |
elmiko | vegan korean dishes? | 14:46 |
sigmavirus24 | Went to a really good korean restaurant this weekend with a vegan friend and it was delicious | 14:46 |
elmiko | nice | 14:46 |
elmiko | <3 korean food | 14:46 |
elmiko | of course, i <3 indian food too lol | 14:47 |
* sigmavirus24 <3s food | 14:59 | |
elmiko | hehe | 14:59 |
elmiko | what is the security group policy on debug logs, i know this has come up before but i'm blanking on it now | 14:59 |
elmiko | i think i've found another situation where tokens are being leaked through debug logs | 15:00 |
sigmavirus24 | I think "not a big problem, but would be better if it didn't" is what I remember | 15:03 |
sigmavirus24 | but I could be wrong | 15:04 |
sigmavirus24 | The idea being that no one would/should use `debug = true` in prod | 15:04 |
sigmavirus24 | (I take it whoever came up with that has never deployed openstack in productiono =P) | 15:04 |
elmiko | yea, i remember this came up on an ossn i worked on and we thought about issuing a blanket statement about debug mode. iirc we decided not to so that issues didn't get glossed over. | 15:05 |
*** dave-mcc_ has quit IRC | 15:12 | |
sigmavirus24 | fair | 15:14 |
*** jian5397 has quit IRC | 15:17 | |
*** dwyde has joined #openstack-security | 15:19 | |
*** jian5397 has joined #openstack-security | 15:22 | |
elmiko | is there a doc somewhere about addressing security bugs, do we need to submit a patch on the bug report? | 15:25 |
*** dave-mcc_ has joined #openstack-security | 15:26 | |
elmiko | ah, found it | 15:34 |
*** yaya has quit IRC | 15:57 | |
*** jian5397 has quit IRC | 15:58 | |
*** yaya has joined #openstack-security | 16:04 | |
*** alex_klimov has quit IRC | 16:12 | |
*** elo1 has joined #openstack-security | 16:31 | |
*** dwyde has quit IRC | 16:49 | |
*** shohel has quit IRC | 17:10 | |
*** elo2 has joined #openstack-security | 17:11 | |
*** elo1 has quit IRC | 17:15 | |
*** elo1 has joined #openstack-security | 17:17 | |
*** elo2 has quit IRC | 17:17 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Fix URLs https://review.openstack.org/216804 | 17:21 |
*** dwyde has joined #openstack-security | 17:22 | |
*** yaya has quit IRC | 17:24 | |
*** elo2 has joined #openstack-security | 17:30 | |
*** elo1 has quit IRC | 17:32 | |
*** yaya has joined #openstack-security | 17:55 | |
*** singlethink has joined #openstack-security | 17:57 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Link for OpenStack VMT is updated https://review.openstack.org/216824 | 18:01 |
*** browne has quit IRC | 18:06 | |
*** paola has joined #openstack-security | 18:10 | |
*** paola has left #openstack-security | 18:11 | |
*** _sigmavirus24 has joined #openstack-security | 18:17 | |
*** tjt263 has quit IRC | 18:17 | |
*** sigmavirus24 has quit IRC | 18:17 | |
*** _sigmavirus24 is now known as sigmavirus24 | 18:20 | |
*** sigmavirus24 has joined #openstack-security | 18:20 | |
*** b10n1k_ has joined #openstack-security | 18:22 | |
*** yaya has quit IRC | 18:24 | |
*** sdake_ has joined #openstack-security | 18:25 | |
*** juzo has joined #openstack-security | 18:28 | |
juzo | hola | 18:28 |
*** sdake has quit IRC | 18:29 | |
*** juzo has left #openstack-security | 18:33 | |
*** timkennedy has joined #openstack-security | 18:35 | |
tmcpeak | :( I probably encouraged this | 18:45 |
tmcpeak | ^ | 18:45 |
*** yaya has joined #openstack-security | 18:45 | |
elmiko | haha | 18:46 |
elmiko | dude, didn't you know that #openstack-security is *the* place to be for spanish language irc? | 18:47 |
tmcpeak | apparently | 18:48 |
elmiko | no no, aparentemente | 18:48 |
elmiko | we are gonna be so ready for summit in barcelona =) | 18:49 |
tmcpeak | lol | 18:51 |
*** sdake_ is now known as sdake | 18:54 | |
*** sdake_ has joined #openstack-security | 19:15 | |
*** jian5397 has joined #openstack-security | 19:15 | |
*** y_sawai_ has joined #openstack-security | 19:17 | |
*** sdake has quit IRC | 19:18 | |
*** y_sawai has quit IRC | 19:20 | |
*** elo2 has quit IRC | 19:21 | |
*** sdake_ is now known as sdake | 19:23 | |
*** tjt263 has joined #openstack-security | 19:27 | |
*** jian5397 has quit IRC | 19:30 | |
sigmavirus24 | LOL | 19:31 |
elmiko | tmcpeak: do you know what the next step for this bug is? https://bugs.launchpad.net/sahara/+bug/1488559 | 19:32 |
openstack | elmiko: Error: malone bug 1488559 not found | 19:32 |
* tmcpeak looking | 19:32 | |
elmiko | thanks | 19:33 |
tmcpeak | is it private? | 19:33 |
elmiko | oh yea, whoops | 19:33 |
elmiko | i don't think i should have made it private | 19:33 |
elmiko | ok, added you to it | 19:34 |
tmcpeak | ok checking | 19:34 |
elmiko | i should probably make this public security | 19:34 |
tmcpeak | good find | 19:36 |
elmiko | thanks, i'm just not sure how to apply the patch at this point | 19:36 |
elmiko | do i just make a regular review? | 19:36 |
tmcpeak | yeah I think so | 19:37 |
tmcpeak | if it's public you can | 19:37 |
elmiko | well, it's still private security, but the sahara ptl is cool with the patch i posted in the bug | 19:37 |
tmcpeak | I'd keep it private for now | 19:37 |
elmiko | ok | 19:37 |
elmiko | and at some point we make it public security, then release the patch through gerrit? | 19:38 |
tmcpeak | so I guess you'll want to propose patches for the other branches too? | 19:38 |
tmcpeak | Juno/Kilo etc | 19:38 |
elmiko | good point | 19:38 |
elmiko | gotta double check the other branches, i'm not sure when this got introduced | 19:38 |
tmcpeak | I think once all the patches are ready to go you make it public, I'm not sure though | 19:39 |
tmcpeak | gmurphy: ^ | 19:39 |
elmiko | yea, i'm a little fuzzy on the details of how this works | 19:40 |
openstackgerrit | Merged openstack/security-doc: Fix URLs https://review.openstack.org/216804 | 19:51 |
gmurphy | elmiko: the process that we follow is outlined here - https://security.openstack.org/vmt-process.html | 19:52 |
elmiko | gmurphy: thanks, i'll study up ;) | 19:54 |
gmurphy | however in this instance we typically classify that type of bug as c1, or d meaning we typically don't issue an advisory for it. | 19:54 |
gmurphy | so in those cases we open and fix as normal generally. | 19:54 |
elmiko | that makes sense, i know this has come up a bunch recently | 19:54 |
elmiko | ok, cool. i'll prepare the patches and when it goes public i'll send then through the review process | 19:55 |
*** browne has joined #openstack-security | 20:05 | |
*** y_sawai_ has quit IRC | 20:56 | |
*** dave-mcc_ has quit IRC | 21:21 | |
*** singlethink has quit IRC | 21:26 | |
*** yaya has quit IRC | 21:30 | |
*** singlethink has joined #openstack-security | 21:33 | |
*** bknudson has quit IRC | 21:42 | |
*** sdake_ has joined #openstack-security | 21:45 | |
*** sdake has quit IRC | 21:48 | |
*** edmondsw has quit IRC | 21:58 | |
*** sdake_ is now known as sdake | 22:01 | |
*** singlethink has quit IRC | 22:21 | |
*** sdake_ has joined #openstack-security | 22:21 | |
*** sdake has quit IRC | 22:24 | |
*** sdake_ is now known as sdake | 22:24 | |
openstackgerrit | Jamie Finnigan proposed openstack/bandit: Add basic metric generation and associated tests https://review.openstack.org/216885 | 22:24 |
*** singlethink has joined #openstack-security | 22:28 | |
openstackgerrit | Jamie Finnigan proposed openstack/bandit: Add basic metric generation and associated tests https://review.openstack.org/216885 | 22:30 |
*** singlethink has quit IRC | 22:32 | |
*** dwyde has left #openstack-security | 22:54 | |
*** asd112z has quit IRC | 22:59 | |
*** voodookid has quit IRC | 23:06 | |
*** bitblt has joined #openstack-security | 23:28 | |
*** bitblt has quit IRC | 23:28 | |
*** misc has quit IRC | 23:33 | |
*** misc has joined #openstack-security | 23:34 | |
*** profor has joined #openstack-security | 23:44 | |
*** dave-mccowan has joined #openstack-security | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!