Tuesday, 2015-09-01

*** sdake_ has joined #openstack-security00:08
*** sdake has quit IRC00:11
*** sdake has joined #openstack-security00:18
*** sdake_ has quit IRC00:21
*** sdake_ has joined #openstack-security00:48
*** sdake__ has joined #openstack-security00:50
*** sdake has quit IRC00:50
*** sdake_ has quit IRC00:53
*** daniela has joined #openstack-security00:53
danielahola00:53
*** daniela has left #openstack-security00:53
*** sdake__ is now known as sdake00:54
*** daniela has joined #openstack-security00:54
*** daniela has left #openstack-security00:55
*** sigmavirus24_awa is now known as sigmavirus2401:00
*** daniela has joined #openstack-security01:02
*** daniela has left #openstack-security01:03
*** daniela has joined #openstack-security01:04
*** dave-mccowan has quit IRC01:04
*** daniela has left #openstack-security01:18
*** bknudson has quit IRC02:24
*** daniela has joined #openstack-security03:13
danielahola03:14
*** daniela has left #openstack-security03:15
*** elo1 has joined #openstack-security03:34
*** timkennedy1 has joined #openstack-security03:47
*** timkennedy has quit IRC03:47
*** sigmavirus24 has quit IRC03:48
*** sigmavirus24 has joined #openstack-security03:52
*** sigmavirus24 is now known as sigmavirus24_awa03:59
*** markvoelker has joined #openstack-security04:00
*** markvoelker_ has joined #openstack-security04:02
*** markvoelker has quit IRC04:04
*** elo1 has quit IRC04:08
*** ccneill has joined #openstack-security04:41
*** ccneill has quit IRC04:50
*** jhfeng has joined #openstack-security05:01
*** alex_klimov has joined #openstack-security05:17
*** alex_klimov has quit IRC05:26
*** markvoelker_ has quit IRC05:53
*** sdake_ has joined #openstack-security06:05
*** sdake has quit IRC06:08
*** sdake has joined #openstack-security06:13
*** sdake_ has quit IRC06:15
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add documentation for validators  https://review.openstack.org/21915206:21
*** shohel has joined #openstack-security06:25
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add OID support to extensions validator  https://review.openstack.org/21915806:44
*** b10n1k_ has quit IRC06:46
*** alex_klimov has joined #openstack-security07:02
*** alex_klimov has quit IRC07:10
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/21855507:15
*** alex_klimov has joined #openstack-security07:56
*** shohel has quit IRC08:18
*** shohel has joined #openstack-security08:24
*** shohel has quit IRC09:00
*** el8 has joined #openstack-security09:03
*** el8 has left #openstack-security09:04
*** quie has joined #openstack-security09:26
*** quie has quit IRC09:31
*** dave-mccowan has joined #openstack-security10:06
*** shohel has joined #openstack-security10:42
*** h00327910__ has quit IRC10:43
*** shohel has quit IRC11:05
*** alex_klimov has quit IRC11:17
*** flow has joined #openstack-security11:39
*** flow has quit IRC11:40
*** alex_klimov has joined #openstack-security11:51
*** salv-orlando has quit IRC12:14
*** salv-orlando has joined #openstack-security12:22
*** salv-orl_ has joined #openstack-security12:23
*** salv-orlando has quit IRC12:26
*** salv-orlando has joined #openstack-security12:33
*** salv-orl_ has quit IRC12:37
*** sigmavirus24_awa is now known as sigmavirus2412:51
*** salv-orlando has quit IRC13:04
*** sdake has quit IRC13:17
*** sdake has joined #openstack-security13:21
*** sigmavirus24 is now known as sigmavirus24_awa13:24
*** jhfeng has quit IRC13:31
*** sigmavirus24_awa is now known as sigmavirus2413:39
*** edmondsw has joined #openstack-security13:47
*** zul has quit IRC13:56
*** alex_klimov has quit IRC13:56
*** zul has joined #openstack-security13:56
*** shohel has joined #openstack-security13:59
*** yaya has joined #openstack-security14:04
*** quie has joined #openstack-security14:09
*** jmckind has joined #openstack-security14:11
*** jhfeng has joined #openstack-security14:11
*** shohel has quit IRC14:13
*** dave-mccowan has quit IRC14:13
*** shohel has joined #openstack-security14:19
*** alex_klimov has joined #openstack-security14:23
*** alejandrito has joined #openstack-security14:26
*** alex_klimov has quit IRC14:27
*** alex_klimov has joined #openstack-security14:28
*** dave-mccowan has joined #openstack-security14:28
*** voodookid has joined #openstack-security14:39
*** shohel has quit IRC14:51
*** dave-mccowan has quit IRC14:51
*** sdake_ has joined #openstack-security14:53
*** sdake has quit IRC14:58
*** dave-mccowan has joined #openstack-security14:58
*** yaya has quit IRC14:58
*** bknudson has joined #openstack-security14:59
*** daemontool_ has quit IRC15:01
*** sdake_ is now known as sdake15:06
*** dwyde has joined #openstack-security15:08
*** ccneill has joined #openstack-security15:11
*** salv-orlando has joined #openstack-security15:13
*** yuanying has quit IRC15:13
*** salv-orlando has quit IRC15:18
*** salv-orlando has joined #openstack-security15:19
*** quie has quit IRC15:24
*** salv-orlando has quit IRC15:26
*** yuanying has joined #openstack-security15:30
*** jmckind has quit IRC15:31
*** jmckind has joined #openstack-security15:34
*** salv-orlando has joined #openstack-security15:38
*** tmcpeak has joined #openstack-security15:41
tmcpeaksigmavirus24: around?15:49
bknudsonwhen do we start?15:50
tmcpeakwe're in here already bknudson15:50
tmcpeakyou here?15:50
tmcpeakwe start at 9 though15:50
bknudsontmcpeak: I'll head over.15:50
tmcpeakcool, see you in a bit15:50
*** bknudson has quit IRC15:50
*** sicarie has joined #openstack-security15:55
*** austin987 has quit IRC15:56
*** jian5397 has joined #openstack-security15:58
sicarieelmiko: ping16:03
*** jmckind has quit IRC16:03
*** sicarie has quit IRC16:05
*** sdake_ has joined #openstack-security16:05
*** hyakuhei has joined #openstack-security16:05
sigmavirus24tmcpeak: I am no16:06
sigmavirus24*now16:06
*** sicarie has joined #openstack-security16:06
tmcpeaksigmavirus24: I'm confused about what he's saying we're doing wrong here16:06
*** bknudson has joined #openstack-security16:06
*** tkelsey has joined #openstack-security16:06
tmcpeakI'm ignorant on packaging :(16:06
jian5397pong16:06
*** browne has joined #openstack-security16:06
sigmavirus24tmcpeak: so we have in setup.cfg a section that says `data_files =\n\tetc/bandit = bandit/config/bandit.yaml`16:07
sigmavirus24right?16:07
sigmavirus24or something like that roughly16:07
tmcpeakyep16:07
sigmavirus24So if you build a wheel and install it globally that makes /usr/local/etc/bandit/bandit.yaml16:07
sigmavirus24He's arguing that we're trying to replace him by making packaging decisions for config files16:07
tmcpeakyeah, that seems reasonable16:07
sigmavirus24He wants us to stop doing that16:07
sigmavirus24The gentoo package maintainer is already doing the right thing with this16:08
tmcpeakwhere does he want us to put it? you're installing something globally, seems like it should go there16:08
sigmavirus24In fact, the gentoo package maintainer says we're doing the right thing16:08
sigmavirus24tmcpeak: right, he wants us to not install a config file16:08
sigmavirus24at all16:08
brownei think data files are usually installed by the packager16:08
sigmavirus24To him the only people who matter are debian users and anyone not using linux with a package manager should fuck off and use a real operating system16:08
sigmavirus24(yes he's said that on other non openstack mailing lists)16:08
*** sdake has quit IRC16:09
sigmavirus24browne: except this affects more than just linux users16:09
tmcpeakugg, Daviey plays in this space also, right?16:09
sigmavirus24Daviey: is actually the bandit maintainer afaik16:09
brownesigmavirus24: true, i guess we claim support for mac os16:09
sigmavirus24browne: we do16:09
sigmavirus24We don't claim support for windows but what we do is simple enough at the moment that we effectively support it16:09
sigmavirus24So this also helps windows users (of which openstack has a few)16:10
sigmavirus24tl;dr I'm working on an openstack-spec to make this be the standard because gentoo and fedora maintainers seem to want consistency here and we can provide that through data_files16:10
sigmavirus24Put another way, I'll -2 anything that breaks this for other users simply because zigo's doesn't want to fix something that should be trivial for him to fix as a downstream redistributor16:11
tmcpeaksigmavirus24: ok thanks for the clarity16:12
sigmavirus24tmcpeak: happy to help16:12
tmcpeakI really don't know anything about packaging16:12
sigmavirus24Be happy you don't16:12
tmcpeak:)16:13
sigmavirus24This isn't a particularly happy section of it for setuptools at the moment16:13
tmcpeakpython packaging feels nasty in general, I've intentionally avoided it16:13
sigmavirus24tmcpeak: https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-python/bandit?id=9be7f815a7287b0702923bd2df90006442532a3b16:14
sigmavirus24The second to last line is all zigo has to do16:14
sigmavirus24Or whatever the equivalent would be for debs16:14
tmcpeaksigmavirus24: ahh16:16
tmcpeakso I'm confused also, what is he trying to do? I thought Daviey is packaging it16:16
tmcpeakis he just not happy with the way it's being packaged?16:16
sigmavirus24tmcpeak: I think Daviey maybe didn't get around to updating the packaging for 0.13.216:17
sigmavirus24And lintian complained and Zigo came to complain to us16:17
tmcpeakahh ok, so if we push a new one, this will be resolved?16:17
sigmavirus24tmcpeak: why?16:18
*** jmckind has joined #openstack-security16:18
tmcpeakI'm saying if we/Daviey/whoever repackages Bandit 0.13.2 for debian with that change you mentioned, is that going to resolve his concern?16:19
sigmavirus24tmcpeak: it should16:19
sigmavirus24That said, it's not our bug16:19
tmcpeakok, since we have some time at the midcycle, maybe one of us will JFDI16:20
*** sdake_ is now known as sdake16:21
sigmavirus24hah16:23
sigmavirus24hah16:23
sigmavirus24hah16:23
sigmavirus24Debian packaging is worse than python packaging so good luck with that16:23
tmcpeak:|16:23
tmcpeakwe need Daviey back...16:24
Davieytmcpeak: checking in on my phone.. driving right now16:25
Daviey(not caught up on sxrollback)16:25
tmcpeakno text and drive Daviey :)16:25
Davieytraffic lights. :)16:25
brownedictation16:25
Davieyi have packaged the new one i think.. but not had it uploaded16:26
Davieywhat did zigo complain about?16:26
tmcpeakDaviey: ahh awesome, have you followed along on the LP16:26
Davieyi need a TL;Dr :)16:26
tmcpeakwe're installing config into /usr/etc/bandit16:26
tmcpeakor something16:26
Davieygreen light16:27
tmcpeakallright, catch you in a bit16:27
Davieyoh i know that.. that was the whole reason i did thr appdirs stuff16:27
tmcpeakDaviey: ok so we just need the new package based on 0.13.2 and we should be gtg?16:27
Davieygetting it in broken early > getting it in perfect later16:27
Davieyrelease early, often etc16:28
tmcpeakyep, ok cool16:28
Davieytmcpeak: yeah16:28
tmcpeakgreat, I'll note that in the LP bug16:28
sigmavirus24Daviey: zigo is complaining about lintian bugs16:28
Davieytalk later i/16:28
sigmavirus24bug 149031816:28
openstackbug 1490318 in Bandit "bandit installs config file in /usr" [Undecided,Won't fix] https://launchpad.net/bugs/149031816:28
sigmavirus24later Daviey16:28
tmcpeakDaviey: sounds good, thank you16:30
*** alex_klimov has quit IRC16:34
*** sicarie has left #openstack-security16:39
*** hyakuhei has quit IRC16:48
*** dwyde has quit IRC16:48
*** hyakuhei has joined #openstack-security16:48
tkelseyelmiko: I remember something about password tests from yesterday, take a look at https://review.openstack.org/#/c/202582/ and see what you think16:56
*** dwyde has joined #openstack-security16:57
elmikotkelsey: ack, thanks16:57
*** sdake_ has joined #openstack-security17:06
*** sdake has quit IRC17:06
*** sdake has joined #openstack-security17:07
openstackgerritMerged openstack/anchor: Updated from global requirements  https://review.openstack.org/21890017:08
openstackgerritBrant Knudson proposed openstack/bandit: Update gitignore for coverage  https://review.openstack.org/21936317:09
*** sdake_ has quit IRC17:10
openstackgerritBrant Knudson proposed openstack/bandit: Update gitignore for coverage  https://review.openstack.org/21936317:13
*** b10n1k_ has joined #openstack-security17:22
openstackgerritTravis McPeak proposed openstack/bandit: Refactoring Unit Test Directories  https://review.openstack.org/21937317:22
openstackgerritMerged openstack/bandit: Update gitignore for coverage  https://review.openstack.org/21936317:28
*** elo has joined #openstack-security17:33
*** elo has quit IRC17:40
openstackgerritMerged openstack/bandit: Refactoring Unit Test Directories  https://review.openstack.org/21937317:41
bknudsonhttps://etherpad.openstack.org/p/security-liberty-midcycle-bandit-tests17:42
*** sicarie has joined #openstack-security17:43
bknudsonhttps://etherpad.openstack.org/p/security-liberty-midcycle-bandit-tests17:44
sicariethanks!17:44
*** sigmavirus24 is now known as sigmavirus24_awa17:54
openstackgerritMerged openstack/anchor: Move sample config for tests to one place  https://review.openstack.org/20775218:04
openstackgerritMerged openstack/anchor: Implement new API format  https://review.openstack.org/19047318:04
openstackgerritMerged openstack/anchor: Allow configurable signing backends  https://review.openstack.org/20139418:04
openstackgerritMerged openstack/anchor: Move all plugins to stevedore  https://review.openstack.org/20831118:05
openstackgerritMerged openstack/anchor: Add documentation for validators  https://review.openstack.org/21915218:05
*** hyakuhei has quit IRC18:05
*** hyakuhei has joined #openstack-security18:13
*** quie has joined #openstack-security18:17
*** quie2 has joined #openstack-security18:23
*** quie has quit IRC18:23
*** LelouchV has joined #openstack-security18:24
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/21855518:24
openstackgerritMichael McCune proposed openstack/bandit: Adding a check for call in call_args_count  https://review.openstack.org/21939518:47
*** sicarie has quit IRC18:51
*** LelouchV has quit IRC18:52
*** sicarie has joined #openstack-security18:54
*** LelouchV has joined #openstack-security18:54
*** salv-orlando has quit IRC18:57
openstackgerritBrant Knudson proposed openstack/bandit: Rename core.test_config to test_bandit  https://review.openstack.org/21940218:58
openstackgerritEric Brown proposed openstack/bandit: Remove unused test_basic.py  https://review.openstack.org/21940919:03
*** sigmavirus24_awa is now known as sigmavirus2419:04
openstackgerritMichael McCune proposed openstack/bandit: Adding the key lookup to Context.call_args_string  https://review.openstack.org/21941019:05
*** salv-orlando has joined #openstack-security19:06
*** tjt263 has quit IRC19:06
*** LelouchV has quit IRC19:07
*** sdake_ has joined #openstack-security19:12
*** sdake has quit IRC19:13
*** sdake has joined #openstack-security19:13
*** sdake_ has quit IRC19:18
*** sicarie has quit IRC19:22
*** sicarie has joined #openstack-security19:31
openstackgerritMerged openstack/bandit: Rename core.test_config to test_bandit  https://review.openstack.org/21940219:32
*** ccneill has quit IRC19:34
*** raginbajin has quit IRC19:34
*** goodygum has quit IRC19:34
*** whydidyoustealmy has quit IRC19:34
*** jmckind has quit IRC19:34
*** ccneill has joined #openstack-security19:34
*** raginbajin has joined #openstack-security19:34
*** goodygum has joined #openstack-security19:34
*** whydidyoustealmy has joined #openstack-security19:34
*** whydidyoustealmy has quit IRC19:35
*** whydidyoustealmy has joined #openstack-security19:35
elmikotkelsey: https://review.openstack.org/#/c/181393/19:37
*** jmckind has joined #openstack-security19:38
tkelseyelmiko: ty19:41
openstackgerritNathaniel Dillon proposed openstack/bandit: Add tests/unit/core/test_manager.py  https://review.openstack.org/21942619:45
*** sdake_ has joined #openstack-security19:45
openstackgerritMerged openstack/bandit: Remove unused test_basic.py  https://review.openstack.org/21940919:46
*** ccneill has quit IRC19:47
*** raginbajin has quit IRC19:47
*** goodygum has quit IRC19:47
*** sdake has quit IRC19:49
*** sdake has joined #openstack-security19:49
*** ccneill has joined #openstack-security19:52
*** raginbajin has joined #openstack-security19:52
*** goodygum has joined #openstack-security19:52
*** sdake_ has quit IRC19:53
*** sicarie has quit IRC19:55
*** sicarie has joined #openstack-security19:56
openstackgerritEric Brown proposed openstack/bandit: Better function to count lines in a file  https://review.openstack.org/21943320:05
openstackgerritMarianne Linhares Monteiro proposed openstack/security-doc: There's an grammar error in section "Compartmentalize" of Compliance overview in Security Guide.  https://review.openstack.org/21943920:16
openstackgerritJamie Finnigan proposed openstack/bandit: Remove unused describe_symbol() utility function  https://review.openstack.org/21944020:18
openstackgerritJamie Finnigan proposed openstack/bandit: Remove unused describe_symbol() utility function  https://review.openstack.org/21944020:20
*** salv-orl_ has joined #openstack-security20:20
*** salv-orlando has quit IRC20:24
*** dave-mccowan has quit IRC20:25
openstackgerritMichael Xin proposed openstack/anchor: Remove outdated hashing algorithms and change default hashing algorithm from md5 to sha256  https://review.openstack.org/21944320:27
openstackgerritBrant Knudson proposed openstack/bandit: Unit tests for bandit.core.config  https://review.openstack.org/21944420:28
openstackgerritMichael McCune proposed openstack/bandit: Adding check for node key in Context  https://review.openstack.org/21944520:29
*** dave-mccowan has joined #openstack-security20:38
*** sdake has quit IRC20:53
*** alex_klimov has joined #openstack-security20:56
*** moises has joined #openstack-security21:02
openstackgerritMerged openstack/bandit: Remove unused describe_symbol() utility function  https://review.openstack.org/21944021:07
*** jian5397 is now known as michaelxin21:14
tkelseymichaelxin: https://www.youtube.com/watch?v=Q_ZhrQq-_YM21:14
tkelseymichaelxin: https://www.youtube.com/watch?v=jf_YOzW7I3s21:15
michaelxinjqxin2006@gmail.com21:19
*** moises has quit IRC21:32
openstackgerritMichael Xin proposed openstack/anchor: Remove outdated hashing algorithms  https://review.openstack.org/21944321:45
*** alex_klimov has quit IRC21:51
*** jmckind has quit IRC21:52
*** tjt263 has joined #openstack-security21:53
openstackgerritMerged openstack/bandit: Better function to count lines in a file  https://review.openstack.org/21943322:08
*** sigmavirus24 is now known as sigmavirus24_awa22:18
openstackgerritEric Brown proposed openstack/bandit: WIP: Add unit tests for the formatters  https://review.openstack.org/21947222:25
openstackgerritJamie Finnigan proposed openstack/bandit: Python 3 compat for safe_unicode() function  https://review.openstack.org/21947322:26
*** edmondsw has quit IRC22:28
*** ccneill_ has joined #openstack-security22:32
*** ccneill has quit IRC22:34
*** michaelxin has quit IRC22:36
*** jian5397 has joined #openstack-security22:38
*** alejandrito_ has joined #openstack-security22:43
openstackgerritJamie Finnigan proposed openstack/bandit: Python 3 compat for safe_unicode() function  https://review.openstack.org/21947322:43
*** alejandrito_ has quit IRC22:45
*** alejandrito has quit IRC22:45
*** dwyde has quit IRC22:48
tmcpeakbrowne: https://review.openstack.org/21947322:50
openstackgerritBrant Knudson proposed openstack/bandit: Unit tests for bandit.core.config  https://review.openstack.org/21944422:55
openstackgerritBrant Knudson proposed openstack/bandit: Unit tests for bandit.core.config  https://review.openstack.org/21944422:56
openstackgerritJamie Finnigan proposed openstack/bandit: Remove unused safe_unicode() utility function  https://review.openstack.org/21947322:58
*** Cristian10b has joined #openstack-security23:00
*** Cristian10b has quit IRC23:01
openstackgerritJamie Finnigan proposed openstack/bandit: Remove unused safe_unicode() utility function  https://review.openstack.org/21947323:01
openstackgerritBrant Knudson proposed openstack/bandit: Unit tests for bandit.core.config  https://review.openstack.org/21944423:03
*** voodookid has quit IRC23:05
openstackgerritJamie Finnigan proposed openstack/bandit: Py3 compatibility fix in lines_with_context() util  https://review.openstack.org/21948223:07
openstackgerritBrant Knudson proposed openstack/bandit: Remove unreachable code in config.py  https://review.openstack.org/21948323:07
openstackgerritJamie Finnigan proposed openstack/bandit: Additional unit test coverage for core/utils.py  https://review.openstack.org/21948723:13
openstackgerritTravis McPeak proposed openstack/bandit: Adding test tool for check OpenStack projects' Bandit job  https://review.openstack.org/21948823:16
openstackgerritMerged openstack/bandit: Remove unused safe_unicode() utility function  https://review.openstack.org/21947323:23
openstackgerritMichael McCune proposed openstack/bandit: Adding a check for key in get_call_arg_at_position  https://review.openstack.org/21951023:40
*** quie2 has quit IRC23:41
openstackgerritMerged openstack/bandit: Py3 compatibility fix in lines_with_context() util  https://review.openstack.org/21948223:42
*** salv-orlando has joined #openstack-security23:43
*** salv-orl_ has quit IRC23:47
*** y_sawai has joined #openstack-security23:48
openstackgerritRobert Clark proposed openstack/anchor: Adding some additional high level content. It might not live here forever but words is words - have some words!  https://review.openstack.org/21951223:53
openstackgerritDoug Chivers proposed openstack/anchor: Working config.json  https://review.openstack.org/21951323:53
openstackgerritRobert Clark proposed openstack/anchor: Adding some additional high level content. It might not live here forever but words is words - have some words!  https://review.openstack.org/21951223:54
*** y_sawai has quit IRC23:58

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!