Tuesday, 2016-02-02

*** pdesai has quit IRC00:05
*** ninag has joined #openstack-security00:07
openstackgerritEric Brown proposed openstack/bandit: Add PyPi badges  https://review.openstack.org/27494300:08
*** salv-orl_ has quit IRC00:08
*** ninag has quit IRC00:08
*** ccneill has quit IRC00:22
*** dave-mcc_ has joined #openstack-security00:27
*** dave-mccowan has quit IRC00:28
*** jamielennox|away is now known as jamielennox00:55
*** markvoelker has joined #openstack-security01:15
*** markvoelker has quit IRC01:20
*** jamielennox is now known as jamielennox|away01:23
*** entPop has joined #openstack-security01:30
*** winterIsLeaving has quit IRC01:31
*** entPop has quit IRC01:37
*** winterIsLeaving has joined #openstack-security01:37
*** bpokorny has quit IRC01:55
*** dave-mcc_ has quit IRC02:09
*** dave-mccowan has joined #openstack-security02:10
*** markvoelker has joined #openstack-security02:16
*** jhfeng has joined #openstack-security02:19
*** jhfeng has quit IRC02:20
*** markvoelker has quit IRC02:20
*** jamielennox|away is now known as jamielennox02:44
*** browne has quit IRC02:58
*** yuanying_ has joined #openstack-security03:21
*** yuanying has quit IRC03:24
*** tmcpeak has quit IRC03:39
*** yuanying has joined #openstack-security03:41
*** yuanying_ has quit IRC03:44
*** pdesai has joined #openstack-security03:47
*** browne has joined #openstack-security03:54
*** kitex has joined #openstack-security03:59
*** yuanying has quit IRC04:05
*** yuanying has joined #openstack-security04:06
*** yuanying_ has joined #openstack-security04:07
*** yuanying has quit IRC04:07
*** jamielennox is now known as jamielennox|away04:10
openstackgerritEric Brown proposed openstack/bandit: Add PyPi badges  https://review.openstack.org/27494304:16
*** markvoelker has joined #openstack-security04:17
*** markvoelker has quit IRC04:21
*** jamielennox|away is now known as jamielennox04:39
*** ccneill has joined #openstack-security04:42
*** tmcpeak has joined #openstack-security04:49
*** pdesai has quit IRC05:09
*** dave-mccowan has quit IRC05:10
*** winterIsLeaving has quit IRC05:10
*** jamielennox is now known as jamielennox|away05:13
*** winterIsLeaving has joined #openstack-security05:18
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add a script for generating CMC requests on Windows  https://review.openstack.org/26944505:21
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add a script for generating CMC requests on Windows  https://review.openstack.org/26944505:22
openstackgerritStanislaw Pitucha proposed openstack/anchor: Copy key identifier from the available CA  https://review.openstack.org/27501205:24
*** ccneill has quit IRC05:24
openstackgerritStanislaw Pitucha proposed openstack/anchor: Copy key identifier from the available CA  https://review.openstack.org/27501205:40
*** delajenkins has joined #openstack-security06:03
openstackgerritMerged openstack/anchor: Convert docs from md to rst  https://review.openstack.org/27439506:16
*** markvoelker has joined #openstack-security06:18
kitexHello06:21
kitexI have setup openstack in my old server.06:21
kitexbut I have found that it is showing only small portion of disk06:21
*** rcernin has joined #openstack-security06:22
*** markvoelker has quit IRC06:22
*** delajenkins has quit IRC06:23
*** rcernin has quit IRC06:46
*** tmcpeak has quit IRC06:52
*** liverpooler has joined #openstack-security07:20
*** zul has joined #openstack-security07:29
*** zul has quit IRC07:41
*** agireud has quit IRC08:10
*** agireud has joined #openstack-security08:12
*** markvoelker has joined #openstack-security08:18
*** markvoelker has quit IRC08:22
*** winterIsLeaving has quit IRC08:27
*** browne has quit IRC08:47
*** zul has joined #openstack-security08:55
*** kitex_ has joined #openstack-security09:07
*** kitex has quit IRC09:07
*** kitex_101 has joined #openstack-security09:10
*** kitex_ has quit IRC09:12
*** markd_ has joined #openstack-security09:40
*** kitex_101 has quit IRC09:40
*** mdavidson has quit IRC09:41
*** kitex_101 has joined #openstack-security09:41
*** markd_ has quit IRC09:41
*** mdavidson has joined #openstack-security09:41
kitex_101does anybody has any idea?09:59
kitex_101how to get right with stat09:59
kitex_101nova stat09:59
*** openstackgerrit has quit IRC10:17
*** openstackgerrit has joined #openstack-security10:17
*** markvoelker has joined #openstack-security10:19
*** markvoelker has quit IRC10:23
*** dave-mccowan has joined #openstack-security10:59
*** dave-mccowan has quit IRC11:17
*** agireud has quit IRC11:27
*** agireud has joined #openstack-security11:29
*** kitex_ has joined #openstack-security12:01
*** kitex_101 has quit IRC12:05
*** markvoelker has joined #openstack-security12:20
*** markvoelker has quit IRC12:24
*** z has quit IRC12:36
*** z has joined #openstack-security12:38
*** markvoelker has joined #openstack-security13:21
*** kitex_ has quit IRC13:24
openstackgerritTim Kelsey proposed openstack/bandit: ld config compatibility  https://review.openstack.org/27262013:25
*** markvoelker has quit IRC13:26
*** markvoelker_ has joined #openstack-security13:26
*** edmondsw has joined #openstack-security13:37
*** zul has quit IRC13:45
*** zul has joined #openstack-security13:59
*** salv-orlando has joined #openstack-security14:01
*** dave-mccowan has joined #openstack-security14:15
*** edtubill has joined #openstack-security14:24
*** zul has quit IRC14:33
*** timkennedy has joined #openstack-security14:34
*** timkennedy1 has quit IRC14:37
*** ninag has joined #openstack-security14:40
*** zul has joined #openstack-security14:57
*** mdavidson has quit IRC14:59
*** jhfeng has joined #openstack-security15:00
*** zul has quit IRC15:10
*** sigmavirus24_awa is now known as sigmavirus2415:10
*** zul has joined #openstack-security15:11
*** zul has quit IRC15:18
*** cjschaef has joined #openstack-security15:25
*** tmcpeak has joined #openstack-security15:27
*** zul has joined #openstack-security15:30
*** zul has quit IRC15:36
*** ykotko has quit IRC15:41
*** localloop127 has joined #openstack-security15:58
openstackgerritMerged openstack/bandit: Add PyPi badges  https://review.openstack.org/27494316:12
*** ccneill has joined #openstack-security16:16
*** browne has joined #openstack-security16:23
*** edtubill has quit IRC16:32
*** agireud has quit IRC16:36
*** agireud has joined #openstack-security16:37
*** timkennedy1 has joined #openstack-security16:39
*** timkennedy has quit IRC16:42
*** mvaldes has joined #openstack-security16:43
*** bpokorny has joined #openstack-security16:43
*** bpokorny has quit IRC16:45
*** bpokorny has joined #openstack-security16:46
openstackgerritTim Kelsey proposed openstack/bandit: Test names are converted to IDs before ever getting this far  https://review.openstack.org/27396516:48
openstackgerritTim Kelsey proposed openstack/bandit: Old config compatibility  https://review.openstack.org/27262016:55
*** salv-orlando has quit IRC17:14
*** zul has joined #openstack-security17:18
*** salv-orlando has joined #openstack-security17:26
*** winterIsLeaving has joined #openstack-security17:30
*** ccneill_ has joined #openstack-security17:31
*** openstackgerrit has quit IRC17:32
*** openstackgerrit has joined #openstack-security17:32
*** ccneill has quit IRC17:34
*** browne has quit IRC17:46
*** salv-orl_ has joined #openstack-security17:50
*** avarner has joined #openstack-security17:54
*** salv-orlando has quit IRC17:54
*** edtubill has joined #openstack-security17:55
*** zul has quit IRC17:56
*** ccneill__ has joined #openstack-security17:57
*** ccneill_ has quit IRC18:00
*** pdesai has joined #openstack-security18:01
*** sigmavirus24 is now known as sigmavirus24_awa18:03
*** mvaldes has quit IRC18:12
*** salv-orl_ has quit IRC18:28
*** salv-orlando has joined #openstack-security18:28
*** browne has joined #openstack-security18:29
*** salv-orlando has quit IRC18:31
*** cjschaef has quit IRC18:32
*** salv-orlando has joined #openstack-security18:32
*** cjschaef has joined #openstack-security18:34
*** ccneill__ has quit IRC18:34
*** localloop127 has quit IRC18:38
*** salv-orlando has quit IRC18:43
*** zul has joined #openstack-security18:45
*** salv-orlando has joined #openstack-security18:45
*** mvaldes has joined #openstack-security18:52
*** ccneill__ has joined #openstack-security18:57
*** whydidyoustealmy has joined #openstack-security19:03
*** ccneill__ is now known as ccneill19:04
*** Fred_Li_ has joined #openstack-security19:05
*** localloop127 has joined #openstack-security19:05
openstackgerritPriti Desai proposed openstack/security-doc: Fixing broken link  https://review.openstack.org/27537819:05
*** webhat_ has joined #openstack-security19:06
*** jkf_ has joined #openstack-security19:08
*** bknudson_ has joined #openstack-security19:11
*** Fred_Li has quit IRC19:12
*** barra204 has quit IRC19:12
*** bknudson has quit IRC19:12
*** webhat has quit IRC19:12
*** jkf has quit IRC19:12
*** michaelxin has quit IRC19:12
*** jkf_ is now known as jkf19:12
*** Fred_Li_ is now known as Fred_Li19:12
*** yosbelis has joined #openstack-security19:16
*** salv-orlando has quit IRC19:25
openstackgerritChristopher J Schaefer proposed openstack/bandit: Improved unit test coverage for bandit.cli.main  https://review.openstack.org/27490419:27
*** pdesai has quit IRC19:30
openstackgerritMerged openstack/security-doc: Fixing broken link  https://review.openstack.org/27537819:38
*** entPop has joined #openstack-security19:49
*** yosbelis has quit IRC19:51
*** winterIsLeaving has quit IRC19:51
*** michaelxin has joined #openstack-security19:52
*** whydidyoustealmy is now known as barra20419:53
*** mvaldes has quit IRC20:04
*** mvaldes has joined #openstack-security20:05
cjschaefare we tracking the progress of bandit v1.0 somewhere?20:11
elmikotmcpeak: ^^20:17
tmcpeakcjschaef: I don't think formally20:17
tmcpeaktkelsey might have some crazy whiteboard drawing in his UK cave20:17
tmcpeak:P20:17
tmcpeakwe should though20:17
cjschaefok, I see the topics/tasks on the etherpad, but was just wondering if it was documented somewhere else20:19
tmcpeakcjschaef: do you have any suggestions for a good way to track?20:21
tmcpeakI haven't personally done something like this with upstream before20:21
tmcpeaketherpad seems ok I guess, but not great20:21
cjschaefwell, nothing I've used outside company based tools. not sure what other projects use outside blueprints to track features or enhancements20:26
*** salv-orlando has joined #openstack-security20:28
*** liverpoo1er has quit IRC20:43
*** liverpooler has quit IRC20:43
*** edtubill has quit IRC20:47
tmcpeakcjschaef: ahh ok, fair enough20:47
cjschaeftmcpeak: I was just trying to get a feel on a timeframe for v1.0, although I'd like to keep improving test coverage as much as possible20:52
tmcpeakcjschaef: I think we mostly need to implement the profile file, get Tim's in flight stuff merged, clean house and test heavily20:53
cjschaeftmcpeak: gotcha, thanks for the info21:00
tmcpeakcjschaef: thanks for all the awesome work on the unit test improvement21:00
*** salv-orl_ has joined #openstack-security21:04
*** salv-orlando has quit IRC21:04
*** salv-orl_ has quit IRC21:08
*** salv-orlando has joined #openstack-security21:08
cjschaeftmcpeak: np, great way to learn the code base. well, try to anyway :)21:09
tmcpeakyeah, the unit test stuff is awesome to have21:09
tmcpeakand a good way to familiarize21:09
*** zul has quit IRC21:35
*** pdesai has joined #openstack-security21:42
tmcpeakdstufft: I've got a strange problem, can you sanity check?21:44
tmcpeakhttps://pypi.python.org/pypi/mysql-connector-python/json21:44
tmcpeakpip install mysql-connector-python==2.0.4         — fails21:44
tmcpeakNo distributions at all found for mysql-connector-python==2.0.421:44
tmcpeakeven 'pip install mysql-connector-python' by itself fails, so just looks like it can't find the package somehow21:48
*** entPop has quit IRC22:00
*** winterIsLeaving has joined #openstack-security22:00
*** edmondsw has quit IRC22:05
brownetmcpeak:  cjschaef: we should probably track as blueprints since we can mark them towards milestones that way22:08
tmcpeakbrowne: yeah, that's a good idea22:08
brownei've been lazy about even opening specs/blueprints/bugs in bandit22:09
brownegotta do better22:09
tmcpeakyeah me too22:13
*** edtubill has joined #openstack-security22:14
*** localloop127 has quit IRC22:24
elmikoyou bandit folks are such slackers... ;P22:25
*** zul has joined #openstack-security22:29
tmcpeakstuff it elmiko :P22:30
elmikohehe22:31
*** jamielennox|away is now known as jamielennox22:41
dstuffttmcpeak: PEP uh, 47022:42
*** zul has quit IRC22:42
tmcpeakdstufft: ahhh22:43
dstuffttmcpeak: mysql-connector-python was hosted externally to PyPI and used th emechanisms removed by PEP 470 to have ``pip install`` work, PEP 470 hapepned end of Dec so now it no longer works.22:43
dstufftI think it was one of the ones that was affected by that wanyways22:43
tmcpeakdstufft: ok cool, seems reasonable22:43
dstufftprobably there is an URL you can pass to -f to make it work, or open issues with mysqlc-connector-python to tell them to setup their own index and/or upload to PyPI22:44
tmcpeakyeah I did notice the external hosting and was wondering about that22:44
tmcpeakdidn't know there was a PEP though22:44
tmcpeaklooks like Oracle owned, so… :P22:44
dstuffttmcpeak: it was one of the few things that was still relying on the security of MD5 (and then, only in a tiny number of cases.. like 50 of them, the rest of the affected didn't have any verification unless they happened to be hosted via HTTPS)22:44
tmcpeakoh cool, yay for finally killing MD522:45
elmiko+122:45
dstufftnow we've gotten it so that MD5 is only really used to prevent S3 (where the files are stored) from compromising us, and that'll switch to sha256 when we switch to warehouse (or maybe earlier if I get motivated to poke my fingers in the bees nest that is legacy pypi)22:46
*** mvaldes has quit IRC22:46
*** edtubill has quit IRC22:47
tmcpeakoh that's cool22:47
*** cjschaef has quit IRC22:47
dstufftthat'll narrow our trust down to uh, {Fastly,Heroku,Rackspace}22:49
dstufftoh, and me22:49
dstufftbut if I go bad you're probably already screwed22:49
dstufftsince i can just hijack CPython or pip :D22:50
tmcpeakdstufft: yeah, if you go bad Python is in trouble22:53
*** jamielennox is now known as jamielennox|away23:05
elmikolol!23:06
*** salv-orlando has quit IRC23:13
*** salv-orlando has joined #openstack-security23:13
*** jhfeng has quit IRC23:27
*** mvaldes has joined #openstack-security23:36
*** bpokorny_ has joined #openstack-security23:50
*** bpokorny has quit IRC23:53

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!