Monday, 2016-07-11

*** sdake has joined #openstack-security00:09
*** dave-mccowan has joined #openstack-security00:11
*** sdake_ has quit IRC00:11
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/34018500:24
*** sdake_ has joined #openstack-security00:26
*** sdake has quit IRC00:29
*** zul has quit IRC00:38
*** dave-mccowan has quit IRC00:44
*** dave-mccowan has joined #openstack-security00:44
*** deblike has quit IRC01:42
*** M00nr41n has joined #openstack-security01:47
*** dave-mccowan has quit IRC01:48
*** ozialien10 has quit IRC01:49
*** ozialien10 has joined #openstack-security01:49
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/34018501:58
*** dave-mccowan has joined #openstack-security02:07
*** dave-mccowan has quit IRC02:26
*** sdake_ is now known as sdake02:35
*** dave-mccowan has joined #openstack-security02:44
*** el has joined #openstack-security03:32
elhola03:33
elcomo ansa03:33
elandan03:33
*** el has quit IRC03:34
openstackgerritRahul U Nair proposed openstack/syntribos: Adding header checks and unit tests  https://review.openstack.org/34021103:50
openstackgerritRahul U Nair proposed openstack/syntribos: Adding header checks and unit tests  https://review.openstack.org/34021103:57
*** M00nr41n has quit IRC03:59
*** dave-mccowan has quit IRC04:01
*** zul has joined #openstack-security04:15
*** sdake has quit IRC04:43
*** M00nr41n has joined #openstack-security04:51
*** pcaruana has quit IRC05:17
*** sdake has joined #openstack-security05:31
*** sdake has quit IRC05:33
*** jamielennox is now known as jamielennox|away05:34
*** sam_yan has joined #openstack-security05:49
*** jamielennox|away is now known as jamielennox05:50
sam_yanhow to understand ima ?06:09
*** rcernin has joined #openstack-security06:22
*** pcaruana has joined #openstack-security06:51
*** unrahul has quit IRC07:02
*** tesseract- has joined #openstack-security07:08
*** sam_yan has quit IRC07:21
*** liverpooler has joined #openstack-security07:25
*** aurelien__ has joined #openstack-security09:53
*** StudentTrstenice has joined #openstack-security10:44
*** StudentTrstenice has quit IRC10:46
openstackgerritRobert Clark proposed openstack/security-doc: Added Authors to Security Notes  https://review.openstack.org/33762710:51
*** sigmavirus_away is now known as sigmavirus11:14
*** sdake has joined #openstack-security11:19
*** dave-mccowan has joined #openstack-security11:46
*** sdake has quit IRC11:48
*** zul has quit IRC11:48
*** zul has joined #openstack-security11:55
*** deblike has joined #openstack-security12:00
*** dc3_ has joined #openstack-security12:15
*** dc3_ has left #openstack-security12:15
*** zul has quit IRC12:19
*** zul has joined #openstack-security12:24
*** deblike has quit IRC12:38
*** deblike has joined #openstack-security12:41
*** _elmiko is now known as elmiko13:00
*** markvoelker has joined #openstack-security13:08
*** cleong has joined #openstack-security13:19
*** M00nr41n has quit IRC13:23
*** markvoelker has quit IRC13:27
*** singlethink has joined #openstack-security13:38
*** sdake has joined #openstack-security13:48
*** sdake_ has joined #openstack-security13:49
*** sdake has quit IRC13:49
*** yeison has joined #openstack-security14:00
*** yeison has left #openstack-security14:01
*** markvoelker has joined #openstack-security14:02
*** markvoelker has quit IRC14:07
*** liverpooler has quit IRC14:08
*** dave-mccowan has quit IRC14:10
*** markvoelker has joined #openstack-security14:17
*** markvoelker has quit IRC14:23
*** dave-mccowan has joined #openstack-security14:30
*** nkinder has joined #openstack-security14:37
*** jmckind has joined #openstack-security14:42
*** unrahul has joined #openstack-security14:47
*** sdake_ has quit IRC14:47
*** markvoelker has joined #openstack-security14:48
*** nkinder has quit IRC14:53
*** vinaypotluri has joined #openstack-security15:10
*** pcaruana has quit IRC15:15
*** yaya has joined #openstack-security15:15
*** mvaldes has joined #openstack-security15:20
*** diazjf has joined #openstack-security15:23
*** aastha has joined #openstack-security15:29
*** mdong has joined #openstack-security15:52
*** browne has joined #openstack-security15:55
*** thehornet has joined #openstack-security16:00
*** thehornet has quit IRC16:01
*** yaya has quit IRC16:07
openstackgerritRahul U Nair proposed openstack/syntribos: Adding missing checks  https://review.openstack.org/34046016:11
*** aurelien__ has quit IRC16:12
*** M00nr41n has joined #openstack-security16:20
*** ccneill has joined #openstack-security16:26
*** jmckind_ has joined #openstack-security16:29
*** jmckind_ has quit IRC16:32
*** jmckind has quit IRC16:32
*** jmckind has joined #openstack-security16:33
*** woodburn has joined #openstack-security16:44
*** tesseract- has quit IRC16:49
*** rcernin has quit IRC16:51
openstackgerritRahul U Nair proposed openstack/syntribos: Adding missing checks  https://review.openstack.org/34047316:52
openstackgerritCharles Neill proposed openstack/syntribos: Converting to oslo.config for configuration  https://review.openstack.org/33793816:53
*** diazjf has quit IRC16:53
elmikoccneill: nicely done on the config stuff! i just happened to see your commit, so i left a drive-by review ;)17:04
ccneillelmiko: thank you, sir!17:04
ccneillI pulled the thread a little bit, and CAFE exploded, so I kinda had to just do it all at once lol17:04
elmikoooph17:04
elmikomake sense though, iirc you had the old config stuff woven in everywhere X_17:05
elmikoX)17:05
*** M00nr41n has quit IRC17:07
openstackgerritMichael Dong proposed openstack/syntribos: Refactored Auth test  https://review.openstack.org/34047717:07
ccneillyep yep17:09
ccneilland environment variables17:09
ccneillx_x17:09
*** yaya has joined #openstack-security17:10
*** yaya_ has joined #openstack-security17:13
unrahulccneill: mdong guys when is our debug log meeting, I some how dont have it on my calendar17:13
ccneill3:30-4:15 today17:13
*** M00nr41n has joined #openstack-security17:14
*** yaya has quit IRC17:14
*** yaya_ is now known as yaya17:14
unrahulthanks ccneill !17:15
ccneillnp!17:15
*** M00nr41n has quit IRC17:17
ccneillvinaypotluri: oops! I just sent out an email saying "need more team outing ideas" before I saw yours haha17:19
ccneillI like all of those ideas. haven't been rafting since I was a kid, that could be real fun17:20
vinaypotluriawesome then...17:22
vinaypotluri:)17:22
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/34048317:23
*** mvaldes has quit IRC17:29
*** pcaruana has joined #openstack-security17:39
ccneillunrahul: might have to hit the "rebase" button before rechecking your CR17:43
*** nkinder has joined #openstack-security17:52
*** diazjf has joined #openstack-security18:07
*** mvaldes has joined #openstack-security18:08
*** yaya has quit IRC18:22
*** ccneill has quit IRC18:23
*** yaya has joined #openstack-security18:40
*** yaya has quit IRC18:41
*** elo has joined #openstack-security18:42
unrahulyup!... was trying to do a manual rebase.. and git started behaving like git :/18:47
openstackgerritRahul U Nair proposed openstack/syntribos: Adding oslo logging  https://review.openstack.org/34018218:47
*** ccneill has joined #openstack-security18:47
openstackgerritRahul U Nair proposed openstack/syntribos: Adding missing checks  https://review.openstack.org/34047318:48
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/34048318:49
*** mvaldes has quit IRC18:57
*** B_Smith has quit IRC18:58
*** mvaldes has joined #openstack-security19:00
*** mvaldes1 has joined #openstack-security19:01
*** yaya has joined #openstack-security19:04
*** mvaldes has quit IRC19:04
*** deblike has quit IRC19:23
*** deblike has joined #openstack-security19:25
*** sdake has joined #openstack-security19:26
*** sdake has quit IRC19:26
*** nkinder has quit IRC19:31
*** rcernin has joined #openstack-security19:31
*** mvaldes1 has quit IRC19:44
*** mvaldes has joined #openstack-security19:47
ccneillhey folks, anyone got time for a +workflow on this CR? https://review.openstack.org/#/c/337938/19:49
ccneillI'd give you a rare Pokémon if I could O:-)19:52
*** B_Smith has joined #openstack-security19:55
*** yaya has quit IRC19:58
*** elo has quit IRC20:00
*** B_Smith has quit IRC20:02
*** davidjd-gh has joined #openstack-security20:02
*** jmckind has quit IRC20:03
*** B_Smith has joined #openstack-security20:04
*** davidjd-gh has quit IRC20:06
*** zul_ has joined #openstack-security20:10
unrahulworkflowed :D, will cash on that, once i get into the game, i think I am the last one :D20:11
*** chair6 has quit IRC20:13
ccneillsigh20:14
ccneilljust read this20:14
Ryan_Laneit would be awesome if the bandit docs were kept up to date20:14
ccneillhttps://techcrunch.com/2016/07/11/pokemon-go-shouldnt-have-full-access-to-your-gmail-docs-and-google-account-but-it-does20:14
ccneill>_<20:14
Ryan_Laneand if backwards incompatible changes didn't keep cropping in20:14
Ryan_Lanemaybe I'm the only one maintaining a plugin that's not inside of the repo, but it's slowly driving me insane20:15
Ryan_Lanethe latest one seems to be requiring a gen_config function?20:15
Ryan_Laneit looks like the docs on writing tests haven't been updated in a _really_ long time20:16
Ryan_Laneit doesn't even mention that bandit requires test numbers20:16
*** chair6 has joined #openstack-security20:16
*** pcaruana has quit IRC20:17
Ryan_Lanethere's no docs on what gen_config is supposed to do :(20:18
Ryan_Lanealso looks like openstack-specific data is creeping into core, which is a bit sad20:19
unrahulccneill:  oh f***k I have tried apps that require insane access, but none of them did use it, wonder why mails were accessed.20:19
unrahulccneill:  thats really creepy20:19
unrahulccneill:  now thinking if i should install it or not.. :/20:19
ccneillunrahul: <_> agreed. I just checked my account and it seems not to have gotten  "uber access". you can sign up with a "trainer" account instead of using your Google account20:20
unrahulRyan_Lane: :/ as always docs is something, that we have to collectively do something,  may be make the automatic doc updates more robust..20:20
openstackgerritMerged openstack/syntribos: Converting to oslo.config for configuration  https://review.openstack.org/33793820:20
*** ian_ott has joined #openstack-security20:21
unrahulRyan_Lane: we are always falling short of keeping docs up to date, partly because of the fact that there are so many updates and less number of experts to do the updates,,20:21
ccneillRyan_Lane: that sounds fun :( it would be cool if we had dedicated help from OpenStack docs group(s) to tackle stuff like that. I think all of us are pretty low on time for docs atm :/20:21
Ryan_Laneprojects shouldn't accept gerrit changes that don't include docs20:21
unrahulccneill: yup.. need to do that.. yeah, its been a while since i updated uber.. !, after their all powerful access update notification..20:22
Ryan_Lanethen you don't need to keep up with docs.20:22
unrahulccneill: sometimes, i wonder if they are trying to match drivers with users having common interest by datamining both inboxes..20:22
Ryan_Laneas a third party user, though, it makes things insanely difficult20:23
Ryan_Lanepushing docs off onto the docs team isn't a good practice, though. it ensures docs will always be poor20:23
Ryan_Laneespecially developer docs20:23
unrahulRyan_Lane: mm.. that is an interesting idea.. but sometimes, the changes are far and wide, that by the time it is realized some doc has to be changed... its too late.20:24
Ryan_Lanecan anyone tell me the behavior expected for the gen_config function?20:24
Ryan_Lane@unrahul a change that has that much in it should also likely be rejected20:24
Ryan_Lanebecause if it's too difficult to document because there's too many changes, then it's also likely not going to be reviewed properly either20:25
ccneillelmiko? hyakuhei? browne? sigmavirus? any thoughts for Ryan_Lane?20:25
unrahulRyan_Lane: mm.. ccneill is trying to summon the overlords to figure this out..20:26
Ryan_Lanethanks :)20:26
*** dave-mccowan has quit IRC20:26
Ryan_Lanedon't mean to bitch too much. I'm still a huge fan of bandit20:27
Ryan_Lanebut support's been a pain :)20:27
* elmiko pokes head in20:27
* elmiko reading back20:27
*** diazjf has quit IRC20:28
ccneillRyan_Lane: I agree with ya about keeping docs up to date via CRs, but we definitely haven't had a perfect track record of it in the project I'm working on (syntribos). usually ends up being one of the first sacrifices we make for speed of change (rightfully or not)20:28
unrahulRyan_Lane: yup, the tool is really cool.. let's try to resolve this..20:28
*** diazjf has joined #openstack-security20:28
unrahulccneill: +1 :D20:28
elmikoi agree that the docs should be kept updated and perhaps we need more options for advising internal api changes.20:29
ccneillwonder if there would be a reasonable way to introduce a "docs check" into tox?20:29
ccneilli.e. "I see 400 lines of code changes and 0 lines of changes to .rst docs. wtf"20:29
sigmavirusRyan_Lane: which gen_config function?20:29
elmikomy best advice, Ryan_Lane, would be to email the openstack-dev list with a subject containing "[bandit]", raise these issues again, and make sure to directly ping tkelsey (Tim Kelsey), browne (Eric Browne), and tmcpeak (Travis McPeak). those guys have been the most involved with bandit and its releases.20:30
elmikothat's more about the doc changes and rigor in general though20:30
Ryan_Lane@sigmavirus the ones in plugins20:31
elmikounfortunately, i don't have much involvement with the day-to-day for bandit20:31
Ryan_Lane(I maintain a plugin)20:31
Ryan_Lanehttps://github.com/lyft/bandit-high-entropy-string20:31
Ryan_Lanethe functions take config, but apparently now you need a gen_config function in the plugin for it to work20:31
*** mvaldes has quit IRC20:32
Ryan_LaneI ask because: https://github.com/lyft/bandit-high-entropy-string/issues/520:36
Ryan_Laneit's weird, because it seems that bandit checks to see if the function exists....20:37
Ryan_LaneI'm guessing gen_config is the defaults?20:42
*** yaya has joined #openstack-security20:42
*** mvaldes has joined #openstack-security20:43
*** dave-mccowan has joined #openstack-security20:47
*** mdong has quit IRC20:47
Ryan_Laneso if there's no config in the provided config, then it'll get it from gen_config?20:48
*** tmcpeak has joined #openstack-security20:49
tmcpeako/20:49
gmurphyRyan_Lane: tmcpeak should be able to help with your plugin issue20:50
tmcpeakRyan_Lane: wassup20:50
tmcpeakRyan_Lane: read backscroll20:52
tmcpeakyou were developing for pre 1.0 I assume?20:52
tmcpeakRyan_Lane: anyway, yeah our docs suck, agreed20:55
tmcpeakI'll file a bug on Bandit so we can track updating them20:55
Ryan_Lanetmcpeak: yeah, but not I support 1.0+20:55
Ryan_Lane*now20:55
tmcpeakok we've revamped the way we do config so that plugins define their own settings rather than having one awful config file that everybody had to ship around20:56
tmcpeakplugins will use the default setting unless you specifically override that20:56
tmcpeakanyway here's an example of how it should be done: https://github.com/openstack/bandit/blob/master/bandit/plugins/try_except_continue.py#L9020:57
tmcpeaksorry docs haven't caught up yet, I'll file a bug now20:57
openstackgerritTravis McPeak proposed openstack/bandit: Adding missing section to documentation about gen_config  https://review.openstack.org/34057421:14
tmcpeakRyan_Lane: ^21:14
*** yaya has quit IRC21:20
*** mvaldes has quit IRC21:21
*** cleong has quit IRC21:22
*** jmckind has joined #openstack-security21:23
*** mvaldes has joined #openstack-security21:25
*** mvaldes has quit IRC21:37
*** ian_ott has quit IRC21:40
*** anahy has joined #openstack-security21:40
*** yaya has joined #openstack-security21:54
Ryan_Lane@tmcpeak did this change in a point release?22:19
*** diazjf has quit IRC22:19
tmcpeakRyan_Lane: no, it changed in 1.0: https://github.com/openstack/bandit/releases/tag/1.022:21
Ryan_LaneI guess mostly my issue is that I didn't add the function, and only tested with config set22:24
tmcpeakwe kept the old functionality in 1.0 so to try not to break anybody that still wants to use config22:25
tmcpeakyou should be able to just add gen_config and everything will be great22:25
tmcpeakworks on 0.17.x and 1.0.x22:25
tmcpeakwe waited until 1.0 to do this specifically because we knew it could be a breaking change for plugin devs22:26
*** yaya has quit IRC22:26
*** anahy has quit IRC22:28
Ryan_Laneok. cool :)22:30
openstackgerritRahul U Nair proposed openstack/syntribos: Modifying checks to use test objects  https://review.openstack.org/34060222:33
*** singlethink has quit IRC22:35
*** jmckind has quit IRC22:52
unrahulHey ccneill  , not sure from where I got the idea that the oslo logs are called from init23:04
unrahulccneill:  somewhere I had seen it, but now its like as you pointed out none does so.23:05
unrahul:/23:05
ccneillunrahul: no worries, I'm trying to find something more definitive about it..23:05
ccneillunrahul: it seems most people reference doing it in the app's main()23:05
ccneillwe don't have a main(), but the closest thing is run(), which is where we're currently doing config setup too23:05
ccneillwe definitely need to split run() into smaller methods that are easier to understand23:06
ccneillsicne it's just sort of like "yeah, everything happens here. hope it makes sense" right now23:06
unrahulyup I agree on splitting up run() , its getting too big, already is .. i guess,,23:07
unrahulwas checking bandit and it seems they are using oslo_logging..23:07
ccneillyeah, I think oslo.log may actually be the best approach for us, since it integrates with oslo.config's conf file/CLI option parsing23:07
unrahulyup +1.23:08
ccneilllooking around for "logging best practices", I see people dealing with like logging.config.dictConfig23:08
ccneilland it also uses a fairly sane formatter that we don't have to make ourselves23:09
ccneillhmmm... digging through nose's code, I don't see anything that immediately stands out to me to explain the weird behavior I was seeing the other day23:11
ccneill¯\_(ツ)_/¯23:11
ccneillwe should be fine all around if we do it in run() though23:11
*** aastha has quit IRC23:19
*** zul_ has quit IRC23:21
*** rcernin has quit IRC23:43
*** markvoelker has quit IRC23:49
unrahul:/ .. yeah cool behavior though..23:59
unrahulyup , moving the run, would be the best..23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!