Thursday, 2015-09-03

*** sicarie has joined #openstack-security00:00
*** maraletrcanaima has joined #openstack-security00:00
*** maraletrcanaima has quit IRC00:01
openstackgerritBrant Knudson proposed openstack/bandit: Use testtools rather than unittest  https://review.openstack.org/21992100:02
openstackgerritMerged openstack/bandit: Additional unit test coverage for core/utils.py  https://review.openstack.org/21948700:02
openstackgerritShellee Arnold proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992200:04
openstackgerritBrant Knudson proposed openstack/bandit: Use testtools rather than unittest  https://review.openstack.org/21992100:05
openstackgerritBrant Knudson proposed openstack/bandit: Use addCleanup rather than tearDown  https://review.openstack.org/21992300:05
*** gmurphy has left #openstack-security00:05
openstackgerritMichael McCune proposed openstack/security-doc: Add OSSN-0053  https://review.openstack.org/21989800:11
openstackgerritBrant Knudson proposed openstack/bandit: Update .gitignore for docs  https://review.openstack.org/21992600:11
openstackgerritEric Brown proposed openstack/bandit: Add a new check for weak RSA and DSA key sizes  https://review.openstack.org/21080600:13
*** goodygum has quit IRC00:19
openstackgerritBrant Knudson proposed openstack/bandit: Generate module docs  https://review.openstack.org/21993000:20
*** goodygum has joined #openstack-security00:21
chair6        for score_type in scores:00:21
chair6            total = total + sum(scores[score_type][self.sev_level:])00:21
chair6        return total00:21
elmikoan interesting spec, https://review.openstack.org/#/c/204073/00:22
openstackgerritMerged openstack/bandit: Adding documentation for test plugins  https://review.openstack.org/20550500:23
elmikohyakuhei: see the spec i posted above00:23
*** tmcpeak has quit IRC00:24
openstackgerritStanislaw Pitucha proposed openstack/anchor: Return CA for a given instance  https://review.openstack.org/19822200:26
*** tkelsey has quit IRC00:30
openstackgerritDoug Chivers proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992200:32
openstackgerritDoug Chivers proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992200:36
*** hyakuhei has quit IRC00:42
*** sicarie has quit IRC00:43
*** bknudson has quit IRC00:44
*** browne has quit IRC00:46
*** jian5397 has quit IRC00:46
openstackgerritMichael McCune proposed openstack/security-doc: Add OSSN-0058  https://review.openstack.org/21993900:52
openstackgerritMichael McCune proposed openstack/security-doc: Add OSSN-0058  https://review.openstack.org/21993900:54
openstackgerritMichael McCune proposed openstack/security-doc: Add OSSN-0058  https://review.openstack.org/21993900:57
*** browne has joined #openstack-security00:58
*** tkelsey has joined #openstack-security01:00
openstackgerritJamie Finnigan proposed openstack/bandit: Introduce wildcards to blacklist_calls plugin  https://review.openstack.org/21994301:06
*** ducnc has joined #openstack-security01:07
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "hardcoded_bind_all_interfaces" documentation  https://review.openstack.org/20847501:10
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "execute_with_run_as_root_equals_true" documentation  https://review.openstack.org/20847001:11
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "exec_used" documentation  https://review.openstack.org/20711001:11
openstackgerritJamie Finnigan proposed openstack/bandit: Adding assert_used documentation  https://review.openstack.org/20710401:11
openstackgerritJamie Finnigan proposed openstack/bandit: Adding any_other_function_with_shell_equals_true documentation  https://review.openstack.org/20709901:11
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "hardcoded_tmp_directory" documentation  https://review.openstack.org/20848201:12
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "hardcoded_sql_expressions" documentation  https://review.openstack.org/20848001:12
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "hardcoded_password" documentation  https://review.openstack.org/20847901:12
*** zul has quit IRC01:14
*** zul has joined #openstack-security01:17
openstackgerritMerged openstack/bandit: Update .gitignore for docs  https://review.openstack.org/21992601:17
openstackgerritMerged openstack/bandit: Add a new check for weak RSA and DSA key sizes  https://review.openstack.org/21080601:18
openstackgerritMerged openstack/bandit: Adding "hardcoded_bind_all_interfaces" documentation  https://review.openstack.org/20847501:20
*** jhfeng has joined #openstack-security01:20
*** sdake has quit IRC01:36
openstackgerritTim Kelsey proposed openstack/bandit: Simplifying Result Store  https://review.openstack.org/21995501:57
openstackgerritEric Brown proposed openstack/bandit: Add unit tests for the formatters  https://review.openstack.org/21947202:03
openstackgerritTim Kelsey proposed openstack/bandit: meta-ast is only needed if we are in debug mode  https://review.openstack.org/21995702:03
*** sdake has joined #openstack-security02:28
openstackgerritTim Kelsey proposed openstack/bandit: Dont read the wordlist file in on every test call, cache it  https://review.openstack.org/21996202:30
*** sdake_ has joined #openstack-security02:31
*** sdake has quit IRC02:34
openstackgerritTim Kelsey proposed openstack/bandit: Improved tests for hardcoded passwords  https://review.openstack.org/20258203:12
*** sigmavirus24 has quit IRC03:30
*** sigmavirus24 has joined #openstack-security03:33
*** sigmavirus24 is now known as sigmavirus24_awa03:34
*** sdake_ is now known as sdake03:42
*** tkelsey has quit IRC03:54
*** LelouchV has quit IRC04:02
*** tkelsey has joined #openstack-security04:21
*** jhfeng has quit IRC04:21
*** tkelsey has quit IRC04:25
*** Sandra has joined #openstack-security04:32
Sandraholq04:33
Sandrahola daviey04:34
*** Sandra has left #openstack-security04:35
*** ducnc is now known as ducnguyen04:55
*** sdake_ has joined #openstack-security05:13
*** sdake has quit IRC05:17
*** ducnguyen has quit IRC05:44
*** sdake has joined #openstack-security05:48
*** sdake_ has quit IRC05:52
*** sdake_ has joined #openstack-security05:54
*** sdake has quit IRC05:57
*** shohel has joined #openstack-security06:22
*** quie has joined #openstack-security06:35
*** quie has quit IRC06:39
*** quie has joined #openstack-security06:40
*** alex_klimov has joined #openstack-security06:55
*** shohel has quit IRC06:58
*** browne has quit IRC07:07
*** browne has joined #openstack-security07:09
*** browne has quit IRC07:09
*** shohel has joined #openstack-security07:15
*** y_sawai has joined #openstack-security07:18
*** shohel has quit IRC07:34
*** y_sawai has quit IRC07:45
*** b10n1k_ has quit IRC07:45
*** browne has joined #openstack-security07:53
*** lexholden has joined #openstack-security07:55
*** y_sawai has joined #openstack-security08:03
*** y_sawai has quit IRC08:08
*** y_sawai has joined #openstack-security08:10
*** y_sawai has quit IRC08:10
*** y_sawai has joined #openstack-security08:11
*** y_sawai has quit IRC08:15
*** y_sawai has joined #openstack-security08:27
*** browne has quit IRC08:35
*** y_sawai has quit IRC08:46
*** y_sawai has joined #openstack-security08:49
*** y_sawai has quit IRC08:54
*** alex_klimov has quit IRC09:15
*** alex_klimov has joined #openstack-security09:15
*** y_sawai has joined #openstack-security09:50
*** y_sawai_ has joined #openstack-security09:51
*** y_sawai has quit IRC09:54
*** y_sawai_ has quit IRC09:56
DavieyWho is Sandra?10:16
*** tjt263 has joined #openstack-security10:47
*** y_sawai has joined #openstack-security11:03
*** y_sawai has quit IRC11:05
*** y_sawai has joined #openstack-security11:05
*** y_sawai has quit IRC11:10
*** y_sawai has joined #openstack-security11:18
*** y_sawai has quit IRC11:23
*** alex_klimov has quit IRC11:26
*** lexholden has quit IRC11:28
*** tkelsey has joined #openstack-security11:34
*** y_sawai has joined #openstack-security11:39
*** tkelsey has quit IRC11:40
*** y_sawai has quit IRC11:43
*** y_sawai has joined #openstack-security11:43
*** y_sawai_ has joined #openstack-security11:47
*** y_sawai has quit IRC11:48
*** y_sawai_ has quit IRC11:51
*** lexholden has joined #openstack-security11:57
*** shohel has joined #openstack-security12:01
*** alex_klimov has joined #openstack-security12:05
*** y_sawai has joined #openstack-security12:43
openstackgerritbruce-benjamin proposed openstack/security-doc: [security-guide] Ephemeral encryption setup  https://review.openstack.org/21895612:45
*** y_sawai has quit IRC12:48
*** edmondsw has joined #openstack-security13:13
*** y_sawai has joined #openstack-security13:44
*** y_sawai has quit IRC13:49
*** sigmavirus24_awa is now known as sigmavirus2413:59
*** jian5397 has joined #openstack-security14:00
*** jhfeng has joined #openstack-security14:07
*** jian5397 has quit IRC14:16
*** dave-mccowan has quit IRC14:18
*** tkelsey has joined #openstack-security14:19
*** jmckind has joined #openstack-security14:27
*** browne has joined #openstack-security14:31
*** dave-mccowan has joined #openstack-security14:31
*** bknudson has joined #openstack-security14:41
openstackgerritTim Kelsey proposed openstack/bandit: Dont read the wordlist file in on every test call, cache it  https://review.openstack.org/21996214:43
*** y_sawai has joined #openstack-security14:45
*** voodookid has joined #openstack-security14:46
*** y_sawai has quit IRC14:50
*** hyakuhei has joined #openstack-security14:52
*** tkelsey has quit IRC14:53
*** y_sawai has joined #openstack-security14:54
*** y_sawai has quit IRC14:59
openstackgerritShellee Arnold proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992215:02
*** jhfeng has quit IRC15:05
*** markvoelker has joined #openstack-security15:08
*** sigmavirus24 is now known as sigmavirus24_awa15:12
*** sigmavirus24_awa is now known as sigmavirus2415:13
*** dwyde has joined #openstack-security15:15
*** shohel has quit IRC15:16
*** tmcpeak has joined #openstack-security15:20
tmcpeaknkinder: you around?15:21
*** tkelsey has joined #openstack-security15:21
nkindertmcpeak: in a meeting15:21
tmcpeaknkinder: cool, ping me when you get a chance please.  I want to synch up with you regarding the OSSG recruiting15:22
tmcpeakalso if you have any materials you can send over please do :)15:22
openstackgerritJamie Finnigan proposed openstack/bandit: Introduce wildcards to blacklist_calls plugin  https://review.openstack.org/21994315:23
openstackgerritRobert Clark proposed openstack/anchor: Adding some additional high level content  https://review.openstack.org/21951215:31
openstackgerritEric Brown proposed openstack/bandit: Remove redundant quotes in bandit.yaml  https://review.openstack.org/22020215:34
tmcpeaksigmavirus24: you around?15:34
sigmavirus24sort of15:35
tmcpeakI'd like to sort out this issue Thomas is reporting with Bandit packaging15:35
tmcpeakwhat's the easiest path forward to JFDI his concerns away?15:35
sigmavirus24tmcpeak: break bandit for everyone else15:35
sigmavirus24that's the easiest thing15:35
tmcpeakwell that's not happening15:36
tmcpeakother options?15:36
sigmavirus24nope15:36
sigmavirus24thank pbr for not having other options15:36
tmcpeakso he's asking us to detect if it's being installed by pip, correct?15:36
sigmavirus24Which we can't do with pbr15:36
tmcpeak:|15:37
tmcpeakhow are other OpenStack properties dealing with this?15:37
sigmavirus24They aren't15:37
tmcpeaksurely there's nothing special about our use case15:37
*** y_sawai has joined #openstack-security15:37
sigmavirus24They're mostly broken (see bash completions discussion on the ML from a couple months ago)15:37
sigmavirus24tmcpeak: there isn't15:37
sigmavirus24zigo threw a fit on the ML when that was discussed15:37
sigmavirus24People are still moving forward with it though15:37
tmcpeakhmm ok, I guess I should dig that up for better context15:38
*** y_sawai has quit IRC15:38
sigmavirus24There really is nothing we can do15:38
tmcpeakahh ok cool15:38
tmcpeakI'll read that thread for context but I definitely defer to your judgement here15:39
tmcpeakthanks man15:39
sigmavirus24If we were not managing setup.py through setup.cfg, we could write code to make zigo happy15:39
sigmavirus24It would be really really really bad form for the general python community15:39
tmcpeakthat's a pbr thing though, right?15:39
sigmavirus24Yep15:40
dstufftmy life was signifcantly happier when I was just ignoring what random downstreams wanted15:40
tmcpeakdstufft: lol, sounds like I should resume doing that15:41
sigmavirus24tmcpeak: it's better for all of our health15:41
sigmavirus24then I don't have to pay attention to zigo's threatening private emails15:41
tmcpeaklol, fair enough15:41
*** markvoelker_ has joined #openstack-security15:42
dstuffttmcpeak: I recommend it15:42
dstufftunless you're trying to compete for how many hills you can find to die on15:43
tmcpeakI'll pass :)15:43
ccneill_hey guys, got a question for ya if anyone has a second15:45
*** markvoelker has quit IRC15:45
*** jian5397 has joined #openstack-security15:45
ccneill_while testing a project's admin features, my colleague found that he could trigger a DoS via user-supplied regex15:46
ccneill_has anyone found a good way to prevent catastrophic backtracking with user-supplied regexes?15:46
ccneill_in this case it's an admin-only feature, so it's not as bad as it could be, but I'm kind of stuck as far as providing ideas to prevent the issue entirely15:46
*** gmurphy has joined #openstack-security15:48
*** browne has quit IRC15:54
*** bknudson has quit IRC15:55
*** quie has quit IRC15:59
*** browne has joined #openstack-security16:06
tmcpeakccneill_: interesting question16:07
tmcpeakgenerally regex's can be pretty computationally expensive.  In this case it doesn't seem like much of an issue because there are worse things admins can do to mess up their cloud16:09
tmcpeakI'd definitely recommend not executing regexs from less privileged users16:10
tmcpeakaside from that, giving users some sort of computational ceiling is probably the best you can do16:10
*** alex_klimov has quit IRC16:11
tmcpeakwe've (HP) has found similar issues in some of our threat analysis16:11
openstackgerritMerged openstack/bandit: Adding "execute_with_run_as_root_equals_true" documentation  https://review.openstack.org/20847016:13
openstackgerritMerged openstack/bandit: Adding any_other_function_with_shell_equals_true documentation  https://review.openstack.org/20709916:14
openstackgerritMerged openstack/anchor: Adding some additional high level content  https://review.openstack.org/21951216:22
openstackgerritMichael McCune proposed openstack/bandit: Adding unit tests for bandit.core.context.Context  https://review.openstack.org/21951916:25
elmikochair6, tmcpeak, rebased that and fixed the missing safe_str issue ^16:25
tmcpeakelmiko: cool, I'll take a look16:26
ccneill_tmcpeak: unfortunately, the suggestion I've seen for limiting computation time is essentially spinning up child processes that get killed after some time interval16:32
ccneill_but my concern is that a bad user could do lots of requests that might hang, create lots of procs that are spinning their wheels, etc.16:33
ccneill_the functionality is for blacklisting domains in Designate v2, so only admins can add the regexes, but users' zone creation requests get run through the blacklists16:33
tmcpeakhmm, whitelist would probably be more effective16:34
tmcpeakccneill_: it probably makes sense to limit the number of simultaneous processes a user can start, even for admins16:36
tkelseybrowne: http://paste.openstack.org/show/444468/16:37
ccneill_I'm just worried that the complexity of supporting regexes in their entirety is always going to be this kind of cat-and-mouse game, so my thought at this point is to propose using substrings instead of regexes to at least cut down on the computational expense16:37
*** bknudson has joined #openstack-security16:37
*** sicarie has joined #openstack-security16:38
tmcpeakccneill_: yeah that seems like a safer approach16:38
elmikotmcpeak: https://wiki.openstack.org/wiki/CrossProjectLiaisons16:39
ccneill_tmcpeak: thanks for the help. needed someone to sanity check me and make sure I haven't missed some obvious solution :)16:40
tmcpeakccneill_: sure, if you want further input in getting the change or reviews or something I'm usually here16:40
ccneill_cool cool, yeah I just started lurking in here but I'm sure I'll have lots of fun questions like this one :)16:41
tmcpeakawesome16:41
ccneill_on another note, I wrote this little utility to read in bandit findings in JSON format and spit out customizable HTML reports: https://github.com/cneill/bandit-buddy16:42
ccneill_if anyone's interested16:42
openstackgerritRobert Clark proposed openstack/anchor: Changed readme so that example retrieves certificate  https://review.openstack.org/21991916:42
ccneill_I would submit it as a CR to bandit, but I imagine that's a little beyond the scope of bandit itself16:42
tmcpeakccneill_: oh yeah, Michael mentioned this, looks pretty cool16:42
tmcpeakwould probably make a nice output formatter too if you're interested in porting it16:42
ccneill_even links to Github source now :)16:42
openstackgerritMerged openstack/bandit: Adding unit tests for bandit.core.context.Context  https://review.openstack.org/21951916:43
ccneill_I'll look into adding it as an output formatter the next time I have some down time16:44
tmcpeaksounds good16:44
*** dwyde has quit IRC16:48
sigmavirus24tmcpeak: are we having the meeting this week or is it cancelled because midcycle?16:58
sicariesigmavirus24: no meeting this week, hyakuhei sentout a notice on the -dev ml16:58
tmcpeaksigmavirus24: cancelled this week16:58
sigmavirus24Ah, missed it. Guess I'll grab lunch then.16:59
openstackgerritEric Brown proposed openstack/bandit: WIP: manager has no attribute '_init_logger'  https://review.openstack.org/22024117:05
openstackgerritEric Brown proposed openstack/bandit: WIP: manager has no attribute '_init_logger'  https://review.openstack.org/22024117:07
*** dwyde has joined #openstack-security17:16
*** markvoelker_ has quit IRC17:16
*** tjt263 has quit IRC17:17
*** tjt263 has joined #openstack-security17:18
openstackgerritEric Brown proposed openstack/bandit: WIP: manager has no attribute '_init_logger'  https://review.openstack.org/22024117:24
openstackgerritMerged openstack/anchor: Changed readme so that example retrieves certificate  https://review.openstack.org/21991917:25
*** zul has quit IRC17:26
*** zul has joined #openstack-security17:27
*** zul has quit IRC17:27
openstackgerritMerged openstack/bandit: Remove redundant quotes in bandit.yaml  https://review.openstack.org/22020217:28
*** zul has joined #openstack-security17:28
openstackgerritMerged openstack/bandit: Use testtools rather than unittest  https://review.openstack.org/21992117:28
openstackgerritMerged openstack/bandit: Use addCleanup rather than tearDown  https://review.openstack.org/21992317:29
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024117:30
openstackgerritJamie Finnigan proposed openstack/bandit: Introduce wildcards to blacklist_calls plugin  https://review.openstack.org/21994317:47
*** daniela has joined #openstack-security17:52
danielahola17:55
*** daniela has left #openstack-security17:55
openstackgerritMichael McCune proposed openstack/security-doc: Add OSSN-0058  https://review.openstack.org/21993917:56
*** sicarie has quit IRC17:57
*** LelouchV has joined #openstack-security17:57
*** tjt263 has quit IRC18:01
openstackgerritMichael Xin proposed openstack/security-doc: Adding an OSSN for bug 1456228 - Trusted VM powered on untrusted host  https://review.openstack.org/22026318:08
openstackbug 1456228 in OpenStack Security Notes "Trusted vm can be powered on untrusted host" [Medium,Confirmed] https://launchpad.net/bugs/1456228 - Assigned to Michael Xin (michael-xin)18:08
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992218:08
brownetkelsey: what module is etree.XML from?18:11
openstackgerritMerged openstack/bandit: Introduce wildcards to blacklist_calls plugin  https://review.openstack.org/21994318:14
*** sicarie has joined #openstack-security18:18
*** lexholden has quit IRC18:21
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992218:25
*** tmcpeak1 has joined #openstack-security18:28
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992218:31
*** tmcpeak has quit IRC18:31
*** localloop127 has joined #openstack-security18:31
*** dwyde has quit IRC18:39
openstackgerritJamie Finnigan proposed openstack/bandit: Add basic metric generation and associated tests  https://review.openstack.org/21688518:42
*** elo has joined #openstack-security18:43
brownehttp://paste.openstack.org/show/444574/18:43
*** timkennedy1 has quit IRC18:46
*** sicarie has quit IRC18:46
*** sicarie has joined #openstack-security18:49
openstackgerritEric Brown proposed openstack/bandit: Add unit tests for the formatters  https://review.openstack.org/21947218:59
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992219:05
openstackgerritTim Kelsey proposed openstack/bandit: Removing class level variables  https://review.openstack.org/22028119:05
tkelseychair6: https://review.openstack.org/#/c/220281/19:06
*** b10n1k_ has joined #openstack-security19:15
openstackgerritMerged openstack/bandit: meta-ast is only needed if we are in debug mode  https://review.openstack.org/21995719:18
openstackgerritMerged openstack/bandit: Removing class level variables  https://review.openstack.org/22028119:21
*** alex_klimov has joined #openstack-security19:23
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024119:27
openstackgerritNathaniel Dillon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992219:27
openstackgerritEric Brown proposed openstack/bandit: Add unit tests for the formatters  https://review.openstack.org/21947219:28
ccneill_goodness, y'all get some hardcore gerrit spam lol19:28
chair6heh .. this is not partcularly normal, we're into day 3 of our midcycle so this is a lot more activity than usual :)19:29
tkelseyhackathon FTW :)19:29
* sicarie wants to stick bamboo splinters in his ears at that word19:30
tkelseysicarie: sorry :(19:30
tkelseysynonym?19:31
tmcpeak1brogramming?19:31
tmcpeak1we're into day 3 of bro'ing it down19:31
tkelseysee, now hackathon dont seem so bad :P19:32
chair6aren't i supposed to be bumping hiphop in my obnoxiously large Beats By Dre (TM) if i'm brogramming?19:33
sicarieOnly if it’s up loud enough for everyone to hear it outside your headphones19:34
openstackgerritNathaniel Dillon proposed openstack/security-doc: Adding OSSN-0052  https://review.openstack.org/21990319:35
* ccneill_ sheepishly turns down his vibrating headphones with attached headphone amplifier19:37
ccneill_<_<19:37
openstackgerritJamie Finnigan proposed openstack/bandit: Raise exceptions from BanditConfig rather than exit  https://review.openstack.org/21991719:38
*** tjt263 has joined #openstack-security19:43
openstackgerritRobert Clark proposed openstack/anchor: Changes to allow sphinx to build correctly  https://review.openstack.org/22028919:45
openstackgerritMerged openstack/bandit: Raise exceptions from BanditConfig rather than exit  https://review.openstack.org/21991719:45
openstackgerritEric Brown proposed openstack/bandit: Add unit tests for the formatters  https://review.openstack.org/21947219:50
*** sicarie has quit IRC19:50
openstackgerritBrant Knudson proposed openstack/bandit: Generate module docs  https://review.openstack.org/21993019:51
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024119:59
*** quie has joined #openstack-security20:01
*** dave-mccowan has quit IRC20:06
*** localloop127 has quit IRC20:07
*** LelouchV has quit IRC20:09
*** localloop127 has joined #openstack-security20:11
*** sicarie has joined #openstack-security20:13
*** hyakuhei has quit IRC20:13
*** hyakuhei has joined #openstack-security20:14
elmikobknudson: https://github.com/swagger-api/swagger-spec20:25
*** sdake has joined #openstack-security20:25
*** sdake_ has quit IRC20:29
jian5397https://github.com/rackerlabs/syntribos20:30
*** jian5397 is now known as michaelxin20:30
michaelxinhttps://github.com/rackerlabs/syntribos is the link20:30
hyakuheimichaelxin: http://docs.openstack.org/infra/manual/creators.html20:32
*** dave-mccowan has joined #openstack-security20:32
elmikobknudson: https://review.openstack.org/#/c/214817/20:32
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024120:37
*** jmckind has quit IRC20:38
*** jmckind has joined #openstack-security20:42
chair6tkelsey: https://review.openstack.org/#/c/219472/20:42
*** localloop127 has quit IRC20:44
*** localloop127 has joined #openstack-security20:45
openstackgerritMerged openstack/bandit: Add unit tests for the formatters  https://review.openstack.org/21947220:46
*** localloop127 has quit IRC20:49
*** sicarie has quit IRC20:50
*** sicarie has joined #openstack-security20:51
*** elo has quit IRC21:14
*** jmckind has quit IRC21:34
*** daniela has joined #openstack-security21:37
danielahelo21:38
danielahello21:38
*** tmcpeak1 is now known as tmcpeak21:39
*** ChanServ sets mode: +o tmcpeak21:39
daniela;-)21:40
*** localloop127 has joined #openstack-security21:51
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992221:54
*** localloop127 has quit IRC21:59
*** daniela has left #openstack-security22:06
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992222:08
*** tkelsey has quit IRC22:13
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024122:15
*** alex_klimov has quit IRC22:28
*** tkelsey has joined #openstack-security22:28
*** hyakuhei has quit IRC22:31
*** hyakuhei has joined #openstack-security22:33
*** sicarie has quit IRC22:34
*** sicarie has joined #openstack-security22:36
openstackgerritEric Brown proposed openstack/bandit: Fix manager having no attribute '_init_logger'  https://review.openstack.org/22024122:41
*** hyakuhei has quit IRC22:44
*** hyakuhei has joined #openstack-security22:45
elmikotkelsey, https://github.com/Swordfish90/cool-retro-term22:48
*** hyakuhei has quit IRC22:49
*** quie has quit IRC22:49
*** hyakuhei has joined #openstack-security22:52
*** edmondsw has quit IRC22:53
elmikosicarie: i fixed up https://review.openstack.org/#/c/219939/22:53
sicarieelmiko: cool, i’ll take a look22:54
tmcpeakhttp://choosesecurity.myshopify.com/products/choose-security-brian-krebs-is-my-ids-shirt22:55
tmcpeak^22:55
*** hyakuhei has quit IRC22:57
*** sdake has quit IRC23:06
*** voodookid has quit IRC23:08
*** markvoelker has joined #openstack-security23:13
*** markvoelker has quit IRC23:17
*** markvoelker has joined #openstack-security23:25
*** y_sawai has joined #openstack-security23:32
*** hyakuhei has joined #openstack-security23:35
openstackgerritShellee Aragon proposed openstack/security-doc: OSSN - Cached Keystone Tokens  https://review.openstack.org/21992223:38
*** hyakuhei has quit IRC23:40
*** y_sawai has quit IRC23:41
*** sicarie has quit IRC23:41
*** hyakuhei has joined #openstack-security23:43
openstackgerritJamie Finnigan proposed openstack/bandit: Adding assert_used documentation  https://review.openstack.org/20710423:43
openstackgerritJamie Finnigan proposed openstack/bandit: Adding "hardcoded_password" documentation  https://review.openstack.org/20847923:49

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!