Wednesday, 2016-09-07

johnsomYeah, it works manually for me too00:00
tmcpeakpep8 runtests: commands[2] | git stash00:00
tmcpeakWARNING:test command found but not installed in testenv00:00
tmcpeak  cmd: /usr/bin/git00:00
tmcpeak  env: /Users/travismcpeak/Documents/projects/openstack/octavia/.tox/pep800:00
tmcpeakMaybe you forgot to specify a dependency? See also the whitelist_externals envconfig setting.00:00
tmcpeakI get that, but it otherwise works00:00
johnsomNo, I added that00:00
tmcpeakjohnsom: stash works for me, although I get a strange message about 'test' not being installed00:01
tmcpeakhttp://paste.openstack.org/show/567276/00:01
tmcpeakahh, I see what it's saying00:02
tmcpeakit's saying the environment uses git but it's not listed as a dependency00:02
johnsomYeah, I think it is skipping those lines without it in the00:02
johnsomwhitelist_externals =00:02
tmcpeakjohnsom: anyway, that works for me00:03
tmcpeakwrapping bandit-baseline in stash/unstash00:03
tmcpeakjohnsom: git is actually not listed in any of those whitelists00:05
tmcpeakI think it needs to be added separately00:05
tmcpeaknevermind, I'm not reading correctly00:05
johnsomI added it to that one00:05
tmcpeakahh ok00:05
tmcpeakhaving it work for me and not you is strange...00:06
openstackgerritVinay Potluri proposed openstack/syntribos: Added neutron templates  https://review.openstack.org/36641000:07
johnsomOk, let me play around with it.  It is odd behavior00:10
openstackgerritRahul U Nair proposed openstack/syntribos: Adding templates for neutron  https://review.openstack.org/36625700:12
*** ccneill has quit IRC00:35
*** browne has quit IRC01:22
*** zhihui has joined #openstack-security01:45
*** tmcpeak has quit IRC02:08
*** austin987 has joined #openstack-security02:11
*** salv-orlando has joined #openstack-security02:30
*** salv-orl_ has quit IRC02:33
*** dave-mccowan has quit IRC02:33
*** tmcpeak has joined #openstack-security03:00
openstackgerritchen.xing proposed openstack/security-doc: [sec-guide] Consistent the 'Nginx' term  https://review.openstack.org/36645703:16
*** sdake_ has joined #openstack-security03:32
*** sdake has quit IRC03:35
*** markvoelker has quit IRC03:54
*** diazjf has joined #openstack-security04:25
*** aleyvah40 has joined #openstack-security04:37
*** aleyvah40 has left #openstack-security04:41
*** diazjf has quit IRC04:44
*** markvoelker has joined #openstack-security04:55
*** markvoelker has quit IRC04:59
*** tmcpeak has quit IRC05:06
*** knangia has quit IRC05:11
*** openstackgerrit has quit IRC05:18
*** openstackgerrit has joined #openstack-security05:18
*** austin987 has quit IRC05:27
*** sdake_ is now known as sdake05:46
*** sdake has quit IRC06:18
*** austin987 has joined #openstack-security06:20
*** pcaruana has joined #openstack-security06:34
*** vinaypotluri has quit IRC06:52
*** markvoelker has joined #openstack-security06:56
*** markvoelker has quit IRC07:01
*** tesseract- has joined #openstack-security07:02
*** sdake has joined #openstack-security07:03
*** Bbyles has joined #openstack-security07:13
*** Bbyles has quit IRC07:17
*** trisq has joined #openstack-security07:23
*** woodster_ has quit IRC07:39
*** austin987 has quit IRC07:41
*** knangia has joined #openstack-security07:44
*** liverpooler has joined #openstack-security08:29
*** salv-orl_ has joined #openstack-security08:29
*** salv-orlando has quit IRC08:32
*** openstackgerrit has quit IRC08:34
*** openstackgerrit has joined #openstack-security08:34
*** markvoelker has joined #openstack-security08:57
*** B_Smith has joined #openstack-security09:00
*** markvoelker has quit IRC09:01
openstackgerritMerged openstack/anchor: Add __ne__ built-in function  https://review.openstack.org/36537709:11
*** sdake has quit IRC09:47
*** markvoelker has joined #openstack-security09:57
*** markvoelker has quit IRC10:02
*** knangia has quit IRC10:21
*** trisq has quit IRC10:44
*** dikonoor has joined #openstack-security10:55
*** dikonoor has quit IRC11:05
*** dikonoor has joined #openstack-security11:15
*** dave-mccowan has joined #openstack-security11:41
*** dave-mccowan has quit IRC11:46
*** salv-orl_ has quit IRC11:52
*** salv-orlando has joined #openstack-security11:52
*** markvoelker has joined #openstack-security11:58
*** markvoelker has quit IRC12:03
openstackgerritLuke Hinds proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671212:05
*** dasm has joined #openstack-security12:07
dasmlhinds: o/12:07
dasmlhinds: i'd like to ask about: https://review.openstack.org/#/c/356712/1812:07
dasmlhinds: could you elaborate a little bit more, what's the purpose of note?12:07
lhindshio dasm12:08
dasmlhinds: if i understand it correctly, kilo and liberty no longer have problems with ipv612:08
dasmlhinds: so there is no danger in re-enabling it.12:08
lhindsIPv6 was being enabled in the default namespace, meaning it could bypass security group rules.12:08
lhindsnow its disabled as you say12:08
lhindsso the note is to make operators aware that re-enabling this, means a tenant can get direct access to the Host12:09
dasmlhinds: ok, stupid me. i just read what's inside bugfix.12:09
dasmit's not about "we permanently solved an issue"12:09
lhindsso if they change ipv6 using systctl and flag it as enabled again, they are allowing tenants to again break isolation (and undo the work of the patch)12:10
dasmbut just "we disabled ipv6 so bug is bypassed"12:10
dasmlhinds: yeah. now i get it.12:10
lhindsdasm: yep, you got it!12:10
lhindsno worries, it took me a while to get my head round it too12:10
dasmlhinds: \o/12:10
lhinds:)12:10
dasmlhinds: thanks for explaining this to me.12:11
lhindsthanks for the review btw! its good to have eyes on to make sure we don't put out the wrong info12:11
lhindsas these notes are consumed by a lot (we hope at least)12:11
dasmlhinds: i like this last part "we hope" :)12:11
dasmlhinds: yeah, vinay was pretty convincing to look into this note.12:12
lhindsI am hoping to get to see what I can learn more from the summit , on ops making use of these notes12:12
lhindsah yeah, vinay did some good work on the note12:13
*** liverpooler has quit IRC12:28
*** edmondsw has joined #openstack-security12:31
*** markvoelker has joined #openstack-security12:32
*** trisq has joined #openstack-security12:34
*** woodster_ has joined #openstack-security12:42
*** jkf has joined #openstack-security12:57
*** singlethink has joined #openstack-security13:38
*** mvaldes has joined #openstack-security13:47
*** tmcpeak has joined #openstack-security13:48
*** rcernin has joined #openstack-security13:57
*** jmckind has joined #openstack-security14:03
*** ayoung has quit IRC14:03
*** liverpooler has joined #openstack-security14:04
*** zul_ has joined #openstack-security14:05
*** knangia has joined #openstack-security14:17
*** zul_ has quit IRC14:20
*** salv-orlando has quit IRC14:20
*** lhinds has quit IRC14:20
*** webhat has quit IRC14:20
*** salv-orlando has joined #openstack-security14:30
*** woodburn has quit IRC14:34
*** dikonoor has quit IRC14:35
*** salv-orlando has quit IRC14:40
*** zul_ has joined #openstack-security14:42
*** lhinds has joined #openstack-security14:42
*** webhat has joined #openstack-security14:42
*** woodburn has joined #openstack-security14:43
*** ayoung has joined #openstack-security14:48
*** vinaypotluri has joined #openstack-security14:52
openstackgerritVinay Potluri proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671215:12
openstackgerritRahul U Nair proposed openstack/syntribos: Refactoring debug_logger  https://review.openstack.org/36536815:14
*** sdake has joined #openstack-security15:24
openstackgerritLuke Hinds proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671215:29
dasmlhinds: vinaypotluri hey guys. jenkins failed for ^ because of too long lines.15:33
lhindsI think thats the ubuntu check? note the gate-security-doc-tox-doc-publish-checkbuild?15:34
lhindsI see those lines just on the edge from what I recall15:34
dasmlhinds: checkniceness15:34
vinaypotlurilet me let me quickly correct it15:35
openstackgerritVinay Potluri proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671215:36
*** salv-orlando has joined #openstack-security15:41
openstackgerritchen.xing proposed openstack/security-doc: [sec-guide] Consistent the 'Nginx' term  https://review.openstack.org/36645715:46
*** mdong has joined #openstack-security15:47
*** salv-orlando has quit IRC15:48
openstackgerritVinay Potluri proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671215:51
*** ccneill has joined #openstack-security15:55
*** salv-orlando has joined #openstack-security15:57
*** pcaruana has quit IRC16:01
*** sicarie has joined #openstack-security16:02
openstackgerritchen.xing proposed openstack/security-doc: Add a glossary link to 'Nginx's  https://review.openstack.org/36684916:02
openstackgerritchen.xing proposed openstack/security-doc: Add a glossary link to 'Nginx's  https://review.openstack.org/36684916:08
*** tesseract- has quit IRC16:09
openstackgerritMerged openstack/syntribos: Refactoring debug_logger  https://review.openstack.org/36536816:13
ccneillall the template CRs have at least +1's, so if we can get a few +2's this morning we'll be ready to get hacking :)16:25
openstackgerritMerged openstack/syntribos: Unit tests for the identity client  https://review.openstack.org/36536516:35
*** ayoung has quit IRC16:35
*** ayoung has joined #openstack-security16:36
ccneillhere comes the merge train..16:39
*** sigmavirus is now known as irvirus16:40
*** irvirus is now known as sigmavirus16:40
mdongccneill, unrahul: can one of you send me the configs you’re using to test Neutron?16:40
ccneillmdong: shouldn't really be any different except the endpoint port, right?16:41
openstackgerritMerged openstack/syntribos: Neutron LBaaS and FWaaS templates  https://review.openstack.org/36635716:41
mdongI’m getting a “failed to authenticate"16:41
ccneillinteresting..16:42
ccneillfrom keystone or neutron?16:42
mdongfrom the identity extension16:42
openstackgerritMerged openstack/syntribos: Adding templates for neutron  https://review.openstack.org/36625716:42
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686116:42
openstackgerritVinay Potluri proposed openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671216:44
*** mvaldes has quit IRC16:48
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686116:50
unrahulhey mdong did u get the config??16:55
mdongyeah, got it now, thanks16:57
*** mdong_ has joined #openstack-security17:00
*** mdong has quit IRC17:04
*** mdong_ is now known as mdong17:04
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686117:07
openstackgerritMerged openstack/syntribos: Added neutron templates  https://review.openstack.org/36641017:09
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686117:10
*** mvaldes has joined #openstack-security17:14
*** sicarie has quit IRC17:15
*** sicarie has joined #openstack-security17:16
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686117:19
*** jmckind_ has joined #openstack-security17:24
*** ayoung has quit IRC17:27
*** jmckind has quit IRC17:27
openstackgerritKhanak Nangia proposed openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686117:28
ccneillis anyone else getting seemingly random 401s/404s vs 201s?17:34
*** trisq has quit IRC17:34
*** ndillon has joined #openstack-security17:35
*** sicarie has quit IRC17:35
*** ccneill_ has joined #openstack-security17:48
*** ccneill has quit IRC17:49
*** ccneill_ is now known as ccneill17:50
*** jkf has left #openstack-security17:53
unrahulEh some I guess when I ran the trial run,  thought it might be because it was trying to access some random resource18:01
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/36689818:23
openstackgerritMerged openstack/syntribos: Adding neutron templates for Syntribos  https://review.openstack.org/36686118:23
openstackgerritMerged openstack/security-doc: Updated OSSN-0069  https://review.openstack.org/35671218:25
lhindsyay!18:27
lhindsfinally18:27
*** zul has quit IRC18:27
lhindsping tmcpeak18:27
lhindsor hyakuhei18:28
lhindsFor the Neutron review, Brian Haley gave a soft -1 based on some nits, so its a given its ok with him (as the nits have been addressed)18:29
vinaypotluriYay... Finally !!! :)18:30
ccneillnice!18:31
*** ayoung has joined #openstack-security18:39
unrahul:D. finally vinaypotluri !18:44
*** ndillon has quit IRC18:49
knangia:D vinaypotluri  !!!18:51
*** zul_ has quit IRC18:55
*** diazjf has joined #openstack-security18:55
*** sdake has quit IRC19:02
*** salv-orlando has quit IRC19:02
*** sdake has joined #openstack-security19:10
*** zul has joined #openstack-security19:12
*** salv-orlando has joined #openstack-security19:13
*** rcernin has quit IRC19:21
*** tmcpeak has quit IRC19:24
*** ndillon has joined #openstack-security19:26
*** zul_ has joined #openstack-security19:31
mdongccneill: did the auth tests run when yall were testing Keystone?19:53
*** mvaldes1 has joined #openstack-security19:53
ccneillI think I had to make some edits to get it to work.. should've saved them :\19:54
mdongyeah…this line should be changed19:55
mdonghttps://github.com/openstack/syntribos/blob/master/syntribos/tests/auth/auth.py#L8519:55
*** mvaldes has quit IRC19:56
*** diazjf has quit IRC19:57
*** mvaldes1 has quit IRC19:58
unrahulhey ccneill mdong are any of the versions v2.0 uri returning anything other than 404?20:01
unrahulI am getting mostly 404 and once got a weird 503.20:01
unrahulwhen token was fuzzed20:01
ccneillmdong: yeah, that's right. it should be "if not _ and not _"20:01
ccneillunrahul: yeah, mostly 404.. :S20:02
ccneillwonder if we need to enable some extensions somehow?20:02
unrahulI am not sure.. though.. that why we are getting 404 :/20:02
ccneillalso, weirdly, I get 401s for lots of requests, and them seemingly randomly 404s sometimes20:03
unrahulI think the neutron I have setup in the cloud is v1 .. :|20:03
*** diazjf has joined #openstack-security20:03
unrahuli got a few 502 and one elusive 503 , not able to get it now though20:03
*** diazjf has quit IRC20:04
*** openstackgerrit has quit IRC20:04
*** openstackgerrit has joined #openstack-security20:04
ccneill{"versions": [{"status": "CURRENT", "id": "v2.0", "links": [{"href": "http://...:9696/v2.0", "rel": "self"}]}]}20:06
ccneilllooks like 2.0 is enabled20:06
unrahulits not showing up when I do a openstack catalog list.. may be it wont show up20:09
*** mwturvey has joined #openstack-security20:09
*** salv-orlando has quit IRC20:10
*** tmcpeak has joined #openstack-security20:12
*** diazjf has joined #openstack-security20:17
ccneillmdong: also, line 30 should be "setUp" not "setUpClass"20:18
*** mdong has quit IRC20:18
*** mdong has joined #openstack-security20:18
*** salv-orlando has joined #openstack-security20:18
ccneillotherwise it doesn't end up sending those requests20:18
*** mwturvey has quit IRC20:19
ccneillso.. I seem to get 401s with the admin account but more 200s with the regular user..20:22
*** rizze has joined #openstack-security20:22
rizzehello20:23
ccneillunrahul: uhhh.. got a 500 on GET /v2.0 lol :X20:25
*** rizze has quit IRC20:26
unrahulehh.. that is weird  :D20:27
unrahulwhats going on ccneill . . any idea..?20:27
*** ndillon has quit IRC20:29
unrahulat least networks are getting created..20:29
*** salv-orl_ has joined #openstack-security20:29
unrahulthere are a ton of networks created.. showing up when I use the command line..20:30
*** sicarie has joined #openstack-security20:30
ccneillhm.. I haven't been doing all the tests, just some of them, and I was using the admin user which was failing most of the time, but strangely not all of the time..20:32
*** salv-orlando has quit IRC20:33
unrahul:/20:34
*** sicarie has quit IRC20:35
*** sicarie has joined #openstack-security20:35
unrahulexit20:35
*** jmckind_ has quit IRC20:39
unrahulhey ccneill20:54
ccneillyo20:54
unrahulI think the because the neutron admin uri is a local one.. as ideally it should not be exposed20:55
unrahulthat we are getting these 40420:55
unrahulfor most..20:55
unrahulthat any admin functionality is essentially blocked20:55
*** mvaldes has joined #openstack-security20:56
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/36689820:56
ccneillah20:57
unrahulso.. what should we do..?20:57
unrahulrun syntribos inside the cluster.. or only test the publically available features. if the assumption is correct that is20:58
ccneilllet's just test what we can for now, and we can revisit the admin stuff if we have time21:00
*** dougwig has joined #openstack-security21:04
*** mdong has quit IRC21:07
*** mdong has joined #openstack-security21:08
*** edmondsw has quit IRC21:19
*** mvaldes has quit IRC21:28
dougwighiya, is anyone here familiar with the launchpad setup for cve bugs?  octavia's secret bugs aren't linked to the neutron-coresec group properly.21:32
*** mvaldes has joined #openstack-security21:32
*** singlethink has quit IRC21:59
*** singlethink has joined #openstack-security22:01
*** mvaldes has quit IRC22:02
*** jass93 has quit IRC22:02
*** jass93 has joined #openstack-security22:10
tmcpeakgmurphy: ^22:14
tmcpeakdougwig: gmurphy can help you :)22:15
gmurphydougwig: i think you'll need to contact one of the openstack admins to sort that out. - https://launchpad.net/~openstack-admins22:19
gmurphyJeremy Stanley is probably your best bet (fungi on irc)22:20
*** diazjf has quit IRC22:20
gmurphyhe's in vmt and also that admin group.22:20
*** singleth_ has joined #openstack-security22:23
*** sdake has quit IRC22:24
*** diazjf has joined #openstack-security22:25
*** diazjf has quit IRC22:25
*** mdong has quit IRC22:26
*** singlethink has quit IRC22:26
*** mdong has joined #openstack-security22:27
*** singleth_ is now known as singlethink22:32
*** singlethink has quit IRC22:40
dougwigtmcpeak, gmurphy: ty22:43
tmcpeakdougwig: sure man, let us know if we can help22:55
*** mdong has quit IRC22:56
*** mdong has joined #openstack-security22:56
*** mdong has quit IRC23:05
*** jass93 has quit IRC23:09
*** salv-orl_ has quit IRC23:16
*** salv-orlando has joined #openstack-security23:17
*** salv-orlando has quit IRC23:21
*** edmondsw has joined #openstack-security23:46
*** edmondsw has quit IRC23:49
unrahulhey ccneill  any luck?23:51
ccneillmmm maybe a few minor things23:51
ccneillgot a bunch of length_diff failures on the BOF tests, but as far as I can tell nothing interesting is happening in the response..23:52
ccneillsome potential second-order XSS maybe23:52
ccneillI don't know how hard it would be, but it would be cool to set up Horizon so we could test for XSS23:53
unrahulI shall try to set it up ccneill , shouldnt be that hard..23:54
unrahulI am trying to setup my devstack .. had shutdown the vm , so not working properly, may be will have a better chance with that..23:54
*** jass93 has joined #openstack-security23:54
ccneillyeah, that would let us do admin testing, and it might be faster too23:55
ccneillI was thinking I might set up devstack on my laptop too23:55
unrahulyeah.. that should help I guess.. as the cluster.. it is a lil diff ryt..23:55
ccneillI'm just thinking the network latency of testing locally vs. cluster might help our tests run faster23:57
ccneillit's kinda outside our scope to try to solve for every possible configuration, or at least if we want to do that we should spend more time per project23:57
unrahulyeah.. and creating nws and not deleting them.. all of the team doing that again and again on the cluster can easliy mess with our config.. or fill up the pool23:59
ccneillyep23:59
unrahulbut if its devstack, we can easily destroy it and start it back up23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!