*** avarner_ has quit IRC | 00:00 | |
*** JAHoagie has quit IRC | 00:08 | |
*** edtubill has joined #openstack-security | 00:30 | |
*** bpokorny_ has joined #openstack-security | 00:43 | |
*** bpokorny has quit IRC | 00:46 | |
*** bpokorny_ has quit IRC | 00:47 | |
*** edmondsw has quit IRC | 00:52 | |
*** tmcpeak has joined #openstack-security | 01:01 | |
*** edtubill has quit IRC | 01:09 | |
*** browne has quit IRC | 01:12 | |
*** edtubill has joined #openstack-security | 01:14 | |
*** salv-orlando has joined #openstack-security | 01:16 | |
*** tmcpeak has joined #openstack-security | 01:17 | |
*** salv-orlando has quit IRC | 01:17 | |
*** salv-orlando has joined #openstack-security | 01:18 | |
*** salv-orl_ has quit IRC | 01:19 | |
*** salv-orlando has quit IRC | 01:22 | |
openstackgerrit | Brian Moss proposed openstack/security-doc: Adding section about selecting supporting software https://review.openstack.org/289160 | 01:22 |
---|---|---|
openstackgerrit | Merged openstack/security-doc: Correct the glossary markups with reference to new glossary terms https://review.openstack.org/290970 | 01:46 |
*** pdesai has joined #openstack-security | 01:51 | |
*** pdesai has quit IRC | 02:04 | |
*** browne has joined #openstack-security | 02:12 | |
*** edtubill has quit IRC | 02:16 | |
*** edtubill has joined #openstack-security | 02:16 | |
*** edtubill has quit IRC | 02:22 | |
*** edtubill has joined #openstack-security | 02:26 | |
*** edtubill has quit IRC | 02:35 | |
*** tmcpeak has quit IRC | 02:44 | |
*** markvoelker has joined #openstack-security | 02:55 | |
*** markvoelker has quit IRC | 03:01 | |
*** salv-orlando has joined #openstack-security | 03:56 | |
*** jass93 has joined #openstack-security | 04:02 | |
*** jass93_ has quit IRC | 04:04 | |
*** salv-orlando has quit IRC | 04:10 | |
*** dave-mccowan has quit IRC | 04:21 | |
*** markvoelker has joined #openstack-security | 04:47 | |
*** markvoelker has quit IRC | 04:51 | |
*** gmurphy has quit IRC | 04:54 | |
*** gmurphy has joined #openstack-security | 04:56 | |
*** salv-orlando has joined #openstack-security | 05:23 | |
*** salv-orlando has quit IRC | 05:34 | |
*** pcaruana has quit IRC | 06:18 | |
*** salv-orlando has joined #openstack-security | 06:33 | |
*** rcernin has joined #openstack-security | 06:37 | |
*** salv-orlando has quit IRC | 06:41 | |
*** markvoelker has joined #openstack-security | 06:48 | |
*** markvoelker has quit IRC | 06:52 | |
*** salv-orlando has joined #openstack-security | 07:14 | |
*** salv-orl_ has joined #openstack-security | 07:16 | |
*** salv-orlando has quit IRC | 07:19 | |
*** y_sawai has joined #openstack-security | 07:49 | |
*** pcaruana has joined #openstack-security | 07:57 | |
*** salv-orl_ has quit IRC | 08:03 | |
*** browne has quit IRC | 08:03 | |
*** tesseract has joined #openstack-security | 08:20 | |
*** tesseract is now known as Guest59954 | 08:21 | |
*** Guest59954 is now known as new | 08:25 | |
*** new has quit IRC | 08:26 | |
*** tesseract- has joined #openstack-security | 08:26 | |
*** tkelsey has joined #openstack-security | 08:56 | |
*** tkelsey has quit IRC | 09:00 | |
*** tkelsey has joined #openstack-security | 09:01 | |
*** JAHoagie has joined #openstack-security | 09:02 | |
*** JAHoagie has quit IRC | 09:06 | |
*** y_sawai has quit IRC | 09:22 | |
*** y_sawai has joined #openstack-security | 09:23 | |
*** salv-orlando has joined #openstack-security | 09:24 | |
ykotko | @tkelsey: https://bugs.launchpad.net/bandit/+bug/1554112 I have updated the bug | 09:46 |
openstack | Launchpad bug 1554112 in Bandit "After excluding plugin from the bandit.yaml it still was used during the scaning" [Critical,Confirmed] - Assigned to Tim Kelsey (tim-kelsey) | 09:46 |
tkelsey | ykotko: awesome! I'll take a look :) thanks | 09:47 |
tkelsey | ykotko: im just confirming now, but I think this is actually fixed in master now, so the problem should go away with the next release | 09:55 |
ykotko | can you backport the patch? | 09:56 |
ykotko | *cherry pick | 09:56 |
tkelsey | i'll have to find the patch that fixed it, since we didn't spot this bug ourselves I'm not sure when it was fixed, I think we need to push a new release soon (like today) will that be OK for you? | 09:57 |
*** JAHoagie has joined #openstack-security | 10:02 | |
*** agireud has quit IRC | 10:03 | |
*** agireud has joined #openstack-security | 10:05 | |
*** JAHoagie has quit IRC | 10:06 | |
ykotko | @tkelsey: thanks | 10:40 |
tkelsey | ykotko: your welcome, thanks for the bug report | 10:40 |
*** y_sawai has quit IRC | 10:56 | |
*** JAHoagie has joined #openstack-security | 11:03 | |
*** JAHoagie has quit IRC | 11:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/294526 | 11:22 |
*** Mainus has joined #openstack-security | 11:34 | |
*** Mainus has left #openstack-security | 11:35 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Breaking up blacklist import IDs https://review.openstack.org/294538 | 11:50 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Breaking up blacklist import IDs https://review.openstack.org/294538 | 11:51 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Breaking up blacklist import IDs https://review.openstack.org/294538 | 11:55 |
*** JAHoagie has joined #openstack-security | 12:02 | |
*** dave-mccowan has joined #openstack-security | 12:05 | |
*** JAHoagie has quit IRC | 12:07 | |
*** edmondsw has joined #openstack-security | 12:16 | |
*** markvoelker has joined #openstack-security | 12:32 | |
*** ninag has joined #openstack-security | 12:42 | |
*** openstackgerrit has quit IRC | 12:48 | |
*** openstackgerrit has joined #openstack-security | 12:48 | |
*** mvaldes has joined #openstack-security | 12:55 | |
*** alejandrito has joined #openstack-security | 12:56 | |
*** mvaldes1 has joined #openstack-security | 12:58 | |
*** tesseract- has quit IRC | 12:59 | |
*** mvaldes has quit IRC | 13:00 | |
*** JAHoagie has joined #openstack-security | 13:02 | |
*** salv-orlando has quit IRC | 13:06 | |
*** JAHoagie has quit IRC | 13:06 | |
*** tesseract has joined #openstack-security | 13:08 | |
*** tesseract is now known as Guest84688 | 13:08 | |
*** cjschaef has joined #openstack-security | 13:11 | |
*** JAHoagie has joined #openstack-security | 13:20 | |
*** JAHoagie has quit IRC | 13:25 | |
*** cleong has joined #openstack-security | 13:35 | |
*** ametts has joined #openstack-security | 13:37 | |
*** JAHoagie has joined #openstack-security | 13:38 | |
*** rcernin has quit IRC | 14:01 | |
*** avarner_ has joined #openstack-security | 14:02 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:12 | |
*** Trident has quit IRC | 14:13 | |
*** Trident has joined #openstack-security | 14:14 | |
*** edtubill has joined #openstack-security | 14:16 | |
*** JAHoagie has quit IRC | 14:19 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Improving config generator script https://review.openstack.org/294616 | 14:22 |
*** mvaldes has joined #openstack-security | 14:27 | |
*** mvaldes1 has quit IRC | 14:27 | |
*** pcaruana has quit IRC | 14:38 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Blacklists now check node types are valid https://review.openstack.org/281365 | 14:44 |
*** Guest84688 has quit IRC | 14:48 | |
*** ametts has quit IRC | 14:57 | |
*** tesseract has joined #openstack-security | 15:00 | |
*** tesseract is now known as Guest76883 | 15:00 | |
*** cleong has quit IRC | 15:01 | |
*** bpokorny has joined #openstack-security | 15:02 | |
*** salv-orlando has joined #openstack-security | 15:10 | |
elmiko | sigmavirus24: what do you think about reviewable.io, have you been liking it? | 15:11 |
sigmavirus24 | eh | 15:11 |
sigmavirus24 | it's a bit annoying | 15:11 |
sigmavirus24 | but it's okay | 15:11 |
elmiko | yea, i'm having trouble adjusting to it | 15:12 |
elmiko | maybe i'm too used to gerrit | 15:12 |
sigmavirus24 | it has too many b.s. animations | 15:14 |
sigmavirus24 | that's what irks me most | 15:14 |
elmiko | oh gawds, those butterflies | 15:15 |
*** salv-orlando has quit IRC | 15:24 | |
*** agireud has quit IRC | 15:42 | |
*** agireud has joined #openstack-security | 15:44 | |
*** mvaldes1 has joined #openstack-security | 15:57 | |
*** mvaldes has quit IRC | 15:57 | |
*** tmcpeak has joined #openstack-security | 16:01 | |
*** ccneill_ has joined #openstack-security | 16:01 | |
*** bpokorny has quit IRC | 16:02 | |
*** bpokorny has joined #openstack-security | 16:13 | |
*** mvaldes1 has quit IRC | 16:14 | |
*** tmcpeak has quit IRC | 16:18 | |
*** tmcpeak has joined #openstack-security | 16:20 | |
*** tmcpeak has quit IRC | 16:22 | |
*** tmcpeak has joined #openstack-security | 16:24 | |
*** avarner_ has quit IRC | 16:27 | |
*** browne has joined #openstack-security | 16:35 | |
*** salv-orlando has joined #openstack-security | 16:41 | |
*** browne has quit IRC | 16:41 | |
*** browne has joined #openstack-security | 16:43 | |
tkelsey | tmcpeak: ping? | 16:45 |
tmcpeak | yo | 16:46 |
tmcpeak | tkelsey: whatup | 16:46 |
tkelsey | hey man, so im thinking we need to push a bandit version | 16:46 |
tmcpeak | in the 17.x branch? | 16:46 |
tkelsey | nah, probs just do 0.18 | 16:47 |
tmcpeak | why? | 16:47 |
tmcpeak | we're close enough to 1.0 why not just wait? | 16:47 |
tmcpeak | we're just bugfixing at this pint | 16:47 |
tmcpeak | point | 16:47 |
tkelsey | there are some bugs in 17.3 that are not in master that people are asking about/reporting | 16:47 |
tmcpeak | also I don't think we're stable enough to release right now | 16:47 |
tmcpeak | ahhh | 16:47 |
*** pcaruana has joined #openstack-security | 16:48 | |
tkelsey | the one from ykotko for example | 16:48 |
tmcpeak | so I'm not opposed to releasing, but what will we release? | 16:48 |
tmcpeak | master is pretty flaky | 16:48 |
tkelsey | hummm, well whats flaky on your radar ? | 16:48 |
tkelsey | most of the stuff in LP has fix submitted | 16:48 |
tmcpeak | yeah good Q | 16:49 |
tmcpeak | actually I guess it's not so flaky anymore | 16:49 |
tmcpeak | if it doesn't break Keystone I'm happy | 16:49 |
tmcpeak | I guess we have integration tests to check for that anyway | 16:49 |
tkelsey | there is one thing I need to fix, but otherwise im happy to push master out.... yeah we should check that, the (fixed) integration tests look good for keystone as well | 16:50 |
tkelsey | browne: are you about? | 16:50 |
browne | yep | 16:50 |
tkelsey | hey, so I am thinking of pushing a new bandit release to address some of the 0.17.x bugs | 16:51 |
tkelsey | how the integration tests looking? you mentioned there was a patch that still needed to merge? | 16:51 |
*** salv-orlando has quit IRC | 16:51 | |
browne | yep, waiting on https://review.openstack.org/#/c/286506/ | 16:52 |
browne | but we could make another patch set update to it to hurry it along | 16:52 |
tkelsey | ah yeah that one | 16:52 |
browne | i really want the integration piece working | 16:52 |
tkelsey | yeah your right, its very important | 16:53 |
*** salv-orlando has joined #openstack-security | 16:53 | |
*** bpokorny_ has joined #openstack-security | 16:53 | |
tkelsey | well lets give gcb some time to update that patch I guess | 16:53 |
*** bpokorny_ has quit IRC | 16:54 | |
tkelsey | I can hold off till monday for the bandit release, its just that we are getting reports of bugs that are fixed in master showing up | 16:54 |
*** bpokorny_ has joined #openstack-security | 16:54 | |
browne | understood. i'll try to take some time today to work on gcb's patch and get approvals | 16:54 |
tkelsey | browne: excellent, thank you :) | 16:55 |
*** bpokorny has quit IRC | 16:56 | |
tkelsey | I'll hold off till monday evening (UK time, so morning US) and see what the state of things are for a release | 16:56 |
browne | sounds good | 16:56 |
tkelsey | ok, thanks guys :) | 16:56 |
*** avarner_ has joined #openstack-security | 16:58 | |
tkelsey | browne tmcpeak, if have free time can you also check out https://review.openstack.org/#/c/294538/ please, since it changes some of the IDs I would like it to merge/die before any new release | 17:03 |
tmcpeak | yep, looking at that | 17:05 |
browne | so will the ID change break existing exploiters | 17:05 |
tkelsey | yes, but since we didn't release anything with test IDs (did 0.17.3 have them ?) that should be OK. | 17:06 |
tmcpeak | yeah agreed, should be ok | 17:06 |
tkelsey | just checked, 0.17.3 didnt have them\ | 17:08 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Moving test summary to end of screen results https://review.openstack.org/294724 | 17:10 |
*** browne has quit IRC | 17:19 | |
*** browne has joined #openstack-security | 17:25 | |
browne | yes we didn't release anything with IDs but what about plugin names | 17:29 |
browne | before we had a blacklist_calls and blacklist_imports and then within that plugin you could choose which imports to raise issues on | 17:29 |
browne | so if someone only wanted to flag pickle in their bandit.yaml, i think their config might not work the same as today. | 17:30 |
browne | but maybe this is something we can live with. | 17:30 |
tkelsey | browne: i see your point, but I think its OK. The legacy blacklist data will override the new stuff completely if its there. The previous set of IDs would mean we cant filter blacklists as finely as we can with the old system, hence this patch | 17:54 |
browne | ok then. i'll +W | 17:54 |
tkelsey | awesome, thanks | 17:54 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Adding debug tox testenv for bandit https://review.openstack.org/294742 | 18:04 |
*** bpokorny_ has quit IRC | 18:07 | |
*** bpokorny has joined #openstack-security | 18:07 | |
openstackgerrit | Merged openstack/bandit: Breaking up blacklist import IDs https://review.openstack.org/294538 | 18:09 |
*** bpokorny has quit IRC | 18:11 | |
*** bpokorny has joined #openstack-security | 18:12 | |
*** ccneill_ has quit IRC | 18:14 | |
*** Guest76883 has quit IRC | 18:15 | |
*** ccneill_ has joined #openstack-security | 18:15 | |
*** mvaldes has joined #openstack-security | 18:41 | |
*** mvaldes1 has joined #openstack-security | 18:43 | |
*** mvaldes has quit IRC | 18:45 | |
*** bpokorny_ has joined #openstack-security | 18:53 | |
*** bpokorny_ has quit IRC | 18:54 | |
*** bpokorny has quit IRC | 18:57 | |
*** bpokorny has joined #openstack-security | 18:58 | |
*** ibravo has joined #openstack-security | 19:02 | |
*** ccneill_ is now known as ccneill | 19:27 | |
openstackgerrit | Merged openstack/bandit: Improving config generator script https://review.openstack.org/294616 | 19:31 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Moving test summary to end of screen results https://review.openstack.org/294724 | 19:36 |
*** tkelsey has quit IRC | 19:38 | |
*** bpokorny has quit IRC | 20:06 | |
*** bpokorny has joined #openstack-security | 20:24 | |
*** ninag has quit IRC | 20:28 | |
*** ccneill has quit IRC | 20:29 | |
*** alejandrito has quit IRC | 20:37 | |
*** avarner_ has quit IRC | 20:55 | |
*** ninag has joined #openstack-security | 21:02 | |
openstackgerrit | Merged openstack/bandit: Adding debug tox testenv for bandit https://review.openstack.org/294742 | 21:03 |
*** mvaldes1 has quit IRC | 21:06 | |
*** ninag has quit IRC | 21:07 | |
*** mvaldes has joined #openstack-security | 21:07 | |
*** Aftergl0w has joined #openstack-security | 21:24 | |
*** yarkot1 has joined #openstack-security | 21:24 | |
*** Afterglow has quit IRC | 21:25 | |
*** yarkot has quit IRC | 21:25 | |
*** Aftergl0w is now known as Afterglow | 21:25 | |
*** Afterglow has quit IRC | 21:25 | |
*** Afterglow has joined #openstack-security | 21:25 | |
*** edmondsw has quit IRC | 21:26 | |
*** dstufft has quit IRC | 21:26 | |
*** redrobot has quit IRC | 21:26 | |
*** dstufft has joined #openstack-security | 21:26 | |
*** edmondsw has joined #openstack-security | 21:26 | |
*** redrobot has joined #openstack-security | 21:29 | |
*** redrobot is now known as Guest98399 | 21:29 | |
*** Guest98399 is now known as redrobot | 21:37 | |
*** mvaldes has quit IRC | 21:54 | |
*** cjschaef has quit IRC | 21:59 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:00 | |
*** jass93_ has joined #openstack-security | 22:02 | |
*** jass93 has quit IRC | 22:02 | |
*** edmondsw has quit IRC | 22:11 | |
*** edtubill has quit IRC | 22:13 | |
*** salv-orl_ has joined #openstack-security | 22:28 | |
*** salv-orlando has quit IRC | 22:30 | |
*** tmcpeak has quit IRC | 22:41 | |
*** tmcpeak has joined #openstack-security | 22:51 | |
*** hyakuhei has joined #openstack-security | 23:04 | |
*** hyakuhei has quit IRC | 23:05 | |
*** tmcpeak has quit IRC | 23:35 | |
*** markvoelker has quit IRC | 23:44 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!