*** avarner_ has quit IRC | 00:02 | |
*** zul has quit IRC | 00:19 | |
*** browne has quit IRC | 01:01 | |
*** zul_ has joined #openstack-security | 01:08 | |
*** zul_ is now known as zul | 01:08 | |
*** tmcpeak has quit IRC | 01:16 | |
*** raginbajin has quit IRC | 01:30 | |
*** krotscheck_dcm has quit IRC | 01:31 | |
*** raginbajin has joined #openstack-security | 01:31 | |
*** krotscheck has joined #openstack-security | 01:33 | |
*** dave-mccowan has joined #openstack-security | 01:54 | |
*** salv-orl_ has joined #openstack-security | 01:55 | |
*** jass93 has quit IRC | 01:56 | |
*** salv-orl_ has quit IRC | 01:58 | |
*** salv-orl_ has joined #openstack-security | 01:58 | |
*** salv-orlando has quit IRC | 01:59 | |
*** jass93 has joined #openstack-security | 02:00 | |
*** salv-orl_ has quit IRC | 02:05 | |
*** jass93_ has joined #openstack-security | 02:08 | |
*** jass93 has quit IRC | 02:09 | |
*** bpokorny has quit IRC | 02:21 | |
*** austin987 has joined #openstack-security | 02:41 | |
*** bpokorny has joined #openstack-security | 03:14 | |
*** yuanying has quit IRC | 03:22 | |
*** bpokorny has quit IRC | 03:25 | |
*** jass93 has joined #openstack-security | 04:02 | |
*** jass93_ has quit IRC | 04:02 | |
*** dave-mccowan has quit IRC | 04:16 | |
*** yuanying has joined #openstack-security | 04:24 | |
*** markvoelker has joined #openstack-security | 04:36 | |
*** int3rceptor has joined #openstack-security | 04:37 | |
*** int3rceptor has left #openstack-security | 04:38 | |
*** liverpooler has joined #openstack-security | 05:57 | |
*** markvoelker has quit IRC | 06:10 | |
*** rcernin has joined #openstack-security | 06:26 | |
*** markvoelker has joined #openstack-security | 06:26 | |
*** salv-orlando has joined #openstack-security | 06:37 | |
*** markvoelker has quit IRC | 06:39 | |
*** tesseract has joined #openstack-security | 06:45 | |
*** tesseract is now known as Guest23157 | 06:46 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/299166 | 07:03 |
---|---|---|
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/299166 | 07:13 |
openstackgerrit | Bathri Ajay Raj proposed openstack/security-doc: [security-guide] For consistency, expanded kerberos https://review.openstack.org/299172 | 07:20 |
*** jmckind_ has quit IRC | 07:26 | |
*** elo has quit IRC | 07:38 | |
*** elo has joined #openstack-security | 07:38 | |
*** markvoelker has joined #openstack-security | 07:40 | |
*** hyakuhei has joined #openstack-security | 07:44 | |
*** markvoelker has quit IRC | 07:45 | |
*** hyakuhei has quit IRC | 07:45 | |
*** hyakuhei has joined #openstack-security | 07:46 | |
*** hyakuhei has quit IRC | 07:47 | |
*** salv-orlando has quit IRC | 07:58 | |
*** hyakuhei has joined #openstack-security | 08:00 | |
*** hyakuhei has quit IRC | 08:00 | |
*** salv-orlando has joined #openstack-security | 08:08 | |
*** chthon has joined #openstack-security | 08:17 | |
*** tkelsey has joined #openstack-security | 08:22 | |
*** tkelsey has quit IRC | 08:26 | |
*** tkelsey has joined #openstack-security | 08:35 | |
*** markvoelker has joined #openstack-security | 08:42 | |
*** markvoelker has quit IRC | 08:47 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Ensure error exit codes fail integrations https://review.openstack.org/281560 | 08:53 |
*** chthon has quit IRC | 09:05 | |
*** chthon has joined #openstack-security | 09:20 | |
*** markvoelker has joined #openstack-security | 09:44 | |
*** markvoelker has quit IRC | 09:49 | |
*** chthon has quit IRC | 10:27 | |
*** chthon has joined #openstack-security | 10:40 | |
*** ibravo has joined #openstack-security | 11:29 | |
*** ibravo has quit IRC | 11:34 | |
*** ibravo has joined #openstack-security | 11:37 | |
*** dave-mccowan has joined #openstack-security | 11:40 | |
*** markvoelker has joined #openstack-security | 11:46 | |
*** openstackgerrit has quit IRC | 11:47 | |
*** openstackgerrit has joined #openstack-security | 11:47 | |
*** markvoelker has quit IRC | 11:51 | |
*** ibravo has quit IRC | 11:55 | |
*** Guest15833 is now known as Vivek | 12:26 | |
*** Vivek has quit IRC | 12:26 | |
*** Vivek has joined #openstack-security | 12:26 | |
*** salv-orl_ has joined #openstack-security | 12:28 | |
*** salv-orlando has quit IRC | 12:31 | |
*** openstackgerrit has quit IRC | 12:33 | |
*** openstackgerrit has joined #openstack-security | 12:33 | |
openstackgerrit | Alexey Ovchinnikov proposed openstack/security-doc: Shared File Systems service security guide fixes https://review.openstack.org/298227 | 12:36 |
*** markvoelker has joined #openstack-security | 12:47 | |
*** markvoelker has quit IRC | 12:51 | |
*** edmondsw has joined #openstack-security | 12:52 | |
*** ninag has joined #openstack-security | 12:53 | |
*** edmondsw has quit IRC | 12:58 | |
openstackgerrit | Alexey Ovchinnikov proposed openstack/security-doc: Shared File Systems service security guide fixes https://review.openstack.org/298227 | 13:06 |
*** hyakuhei has joined #openstack-security | 13:08 | |
*** hyakuhei has quit IRC | 13:11 | |
*** hyakuhei has joined #openstack-security | 13:13 | |
*** hyakuhei has quit IRC | 13:14 | |
*** openstackgerrit has quit IRC | 13:18 | |
*** openstackgerrit has joined #openstack-security | 13:18 | |
*** ibravo has joined #openstack-security | 13:22 | |
*** hyakuhei has joined #openstack-security | 13:23 | |
*** evand has quit IRC | 13:23 | |
*** hyakuhei has quit IRC | 13:25 | |
*** evand has joined #openstack-security | 13:25 | |
*** hyakuhei has joined #openstack-security | 13:26 | |
openstackgerrit | Alexey Ovchinnikov proposed openstack/security-doc: Shared File Systems service security guide fixes https://review.openstack.org/298227 | 13:28 |
*** cleong has joined #openstack-security | 13:34 | |
*** liverpooler has quit IRC | 13:34 | |
*** edmondsw has joined #openstack-security | 13:34 | |
*** salv-orl_ has quit IRC | 13:34 | |
*** ninag has quit IRC | 13:39 | |
*** ninag has joined #openstack-security | 13:41 | |
*** ninag has quit IRC | 13:42 | |
*** cjschaef has joined #openstack-security | 13:47 | |
*** markvoelker has joined #openstack-security | 13:48 | |
*** jmckind has joined #openstack-security | 13:51 | |
*** markvoelker has quit IRC | 13:52 | |
*** ametts has joined #openstack-security | 13:57 | |
*** jmckind has quit IRC | 13:59 | |
*** jmckind has joined #openstack-security | 14:04 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:12 | |
*** mvaldes has joined #openstack-security | 14:14 | |
*** avarner has joined #openstack-security | 14:14 | |
*** markvoelker has joined #openstack-security | 14:16 | |
*** hyakuhei has quit IRC | 14:36 | |
*** hyakuhei has joined #openstack-security | 14:38 | |
*** markvoelker has quit IRC | 14:46 | |
*** mvaldes has quit IRC | 14:47 | |
*** ametts has quit IRC | 14:57 | |
*** ninag has joined #openstack-security | 14:58 | |
*** tkelsey has quit IRC | 15:03 | |
*** tmcpeak has joined #openstack-security | 15:05 | |
*** diazjf has joined #openstack-security | 15:14 | |
*** diazjf has quit IRC | 15:17 | |
*** Guest23157 has quit IRC | 15:21 | |
*** markvoelker has joined #openstack-security | 15:29 | |
*** diazjf has joined #openstack-security | 15:32 | |
*** diazjf has quit IRC | 15:33 | |
*** diazjf has joined #openstack-security | 15:35 | |
*** austin987 has quit IRC | 15:39 | |
*** tkelsey has joined #openstack-security | 15:49 | |
*** ametts has joined #openstack-security | 15:51 | |
*** cjschaef has quit IRC | 15:53 | |
*** austin987 has joined #openstack-security | 15:53 | |
*** tkelsey has quit IRC | 15:56 | |
*** salv-orlando has joined #openstack-security | 16:02 | |
*** cjschaef has joined #openstack-security | 16:04 | |
*** salv-orlando has quit IRC | 16:11 | |
*** openstack has joined #openstack-security | 17:04 | |
*** mvaldes has joined #openstack-security | 17:06 | |
*** hyakuhei has quit IRC | 17:14 | |
openstackgerrit | chen.xing proposed openstack/security-doc: [sec-guide]Update security guide for next release https://review.openstack.org/299544 | 17:20 |
*** salv-orlando has joined #openstack-security | 17:33 | |
*** salv-orlando has quit IRC | 17:40 | |
*** jmckind has quit IRC | 17:43 | |
*** mvaldes has quit IRC | 17:45 | |
*** browne has joined #openstack-security | 17:46 | |
*** zul has quit IRC | 17:50 | |
*** tmcpeak has quit IRC | 17:52 | |
*** tmcpeak has joined #openstack-security | 17:53 | |
browne | looks like we introduced more plugin testing in bandit which is breaking more integration tests again. we need to hold off on any new changes so we can get 1.0 out | 17:54 |
tmcpeak | browne: cool, fair enough | 17:55 |
browne | or rebase on https://review.openstack.org/#/c/281560/ | 17:55 |
browne | or we can revert so we can push out 1.0 | 17:56 |
tmcpeak | which plugin test are you talking about? | 17:56 |
browne | as it stands now, keystone, oslo.config, and sahara are breaking | 17:56 |
browne | looks like there are new failures for continue statement in an exception block | 17:57 |
tmcpeak | what introduced a Keystone break? | 17:57 |
browne | https://review.openstack.org/#/c/296065/ | 17:58 |
tmcpeak | oooh | 17:59 |
browne | might be better to revert because it'll be very hard to get patches merged in those other projects right now (so close to release of mitaka) | 17:59 |
tmcpeak | so Keystone's gates aren't broken because they're using a config that only includes certain plugins, right? | 17:59 |
browne | keystone's gate isn't broken because they don't have this version of bandit yet that's checking extra things | 18:00 |
tmcpeak | and the profile wouldn't run it anyway... | 18:00 |
browne | oh, we already have stable/mitaka so maybe not as hard to get patches in those projects | 18:00 |
tmcpeak | seems like a useful plugin though. Any better option than reverting? | 18:00 |
*** diazjf has quit IRC | 18:01 | |
*** jass93 has quit IRC | 18:01 | |
browne | yeah, its useful. only other alternative is to nosec in those projects | 18:02 |
*** ninag has quit IRC | 18:03 | |
*** hyakuhei has joined #openstack-security | 18:11 | |
*** zul has joined #openstack-security | 18:11 | |
*** diazjf has joined #openstack-security | 18:12 | |
tmcpeak | that should be a low severity finding which should be filtered out either by profiles or by bandit run mode though, right? | 18:13 |
openstackgerrit | Merged openstack/security-doc: [sec-guide]Update security guide for next release https://review.openstack.org/299544 | 18:15 |
*** hyakuhei has quit IRC | 18:18 | |
browne | tmcpeak: but most projects are no longer using profiles | 18:21 |
browne | and once 1.0 comes out, they'll just use the test IDs to filter | 18:22 |
*** diazjf has quit IRC | 18:22 | |
*** diazjf has joined #openstack-security | 18:22 | |
browne | but we don't want to immediately break those projects on a new release of bandit | 18:22 |
browne | better to fix prior to release | 18:23 |
tmcpeak | browne: yep, agreed | 18:23 |
tmcpeak | why we have the integration tests :) | 18:23 |
browne | ha, yep | 18:23 |
*** mvaldes has joined #openstack-security | 18:27 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 18:34 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:35 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Added payloads for keystone API https://review.openstack.org/299032 | 18:36 |
*** krotscheck is now known as krotscheck_dcm | 18:46 | |
*** ninag has joined #openstack-security | 18:53 | |
*** mdong has joined #openstack-security | 18:56 | |
*** diazjf has quit IRC | 18:57 | |
*** jmckind has joined #openstack-security | 19:02 | |
*** salv-orlando has joined #openstack-security | 19:03 | |
*** tmcpeak has quit IRC | 19:30 | |
*** tkelsey has joined #openstack-security | 19:39 | |
*** tkelsey has quit IRC | 19:47 | |
*** tkelsey has joined #openstack-security | 19:53 | |
*** tkelsey has quit IRC | 20:02 | |
*** mvaldes has quit IRC | 20:09 | |
*** jass93 has joined #openstack-security | 20:22 | |
*** diazjf has joined #openstack-security | 20:23 | |
*** cleong has quit IRC | 20:26 | |
*** ninag has quit IRC | 20:26 | |
*** tmcpeak has joined #openstack-security | 20:36 | |
*** openstackgerrit has quit IRC | 20:48 | |
*** openstackgerrit has joined #openstack-security | 20:48 | |
*** mdong_ has joined #openstack-security | 20:57 | |
*** mdong has quit IRC | 20:59 | |
*** mdong_ is now known as mdong | 20:59 | |
openstackgerrit | Yasmine proposed openstack/syntribos: Uploading command injection files https://review.openstack.org/299626 | 21:01 |
*** bpokorny has quit IRC | 21:04 | |
*** mvaldes has joined #openstack-security | 21:09 | |
*** i44093453 has joined #openstack-security | 21:17 | |
*** i44093453 has left #openstack-security | 21:18 | |
*** mvaldes has quit IRC | 21:21 | |
*** tkelsey has joined #openstack-security | 21:22 | |
*** tkelsey has quit IRC | 21:27 | |
*** cjschaef has quit IRC | 21:33 | |
*** hyakuhei has joined #openstack-security | 21:40 | |
*** bpokorny has joined #openstack-security | 21:43 | |
*** hyakuhei has quit IRC | 21:46 | |
avarner | Does anyone know if the Bandit configuration refactor is done? | 21:52 |
avarner | I thought the refactor was to eliminate the need for configuration files, so I could specify tests on the command line | 21:53 |
avarner | But, I'm getting an error message reading `bandit: error: unrecognized arguments: -s blacklist_calls | 21:53 |
avarner | ` | 21:53 |
tmcpeak | avarner: you should specify them by ID and also blacklist calls isn't a test anymore, we've broken it into a bunch of tests | 21:54 |
tmcpeak | avarner: actually I'm pretty sure you can specify by name too, but the second thing I mentioned is most likely what's hanging you up | 21:55 |
avarner | Do you know the minimum version needed to use the `-s` argument? | 21:55 |
avarner | I think I have 0.17.3, but it doesn't work | 21:55 |
tmcpeak | hmm, good q | 21:55 |
tmcpeak | give me one sec I'll find out | 21:55 |
tmcpeak | avarner: yeah 0.17.3 doesn't have it. It's part of our 1.0 stuff which hasn't been released on PyPI yet | 21:56 |
tmcpeak | we're looking at a release very soon though | 21:57 |
tmcpeak | stay tuned | 21:57 |
avarner | ok, thanks | 21:57 |
tmcpeak | sure | 21:58 |
*** tkelsey has joined #openstack-security | 22:02 | |
*** diazjf has quit IRC | 22:04 | |
*** jass93 has quit IRC | 22:05 | |
*** tkelsey has quit IRC | 22:07 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Added payloads for keystone API https://review.openstack.org/299032 | 22:19 |
*** markvoelker has joined #openstack-security | 22:24 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:27 | |
*** jmckind has quit IRC | 22:37 | |
*** Unterd0g has joined #openstack-security | 22:40 | |
*** mdong has quit IRC | 22:42 | |
*** guest12342543467 has joined #openstack-security | 22:42 | |
*** mdong has joined #openstack-security | 22:42 | |
*** guest12342543467 has quit IRC | 22:48 | |
*** edmondsw has quit IRC | 22:48 | |
*** markvoelker has quit IRC | 22:57 | |
*** ametts has quit IRC | 22:57 | |
*** mdong has quit IRC | 23:14 | |
*** nkinder has joined #openstack-security | 23:16 | |
*** salv-orl_ has joined #openstack-security | 23:24 | |
*** salv-orlando has quit IRC | 23:26 | |
*** nkinder has quit IRC | 23:32 | |
*** jass93 has joined #openstack-security | 23:40 | |
*** austin987 has quit IRC | 23:50 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Added payloads for keystone API https://review.openstack.org/299032 | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!