| *** dikonoor has joined #openstack-security | 00:09 | |
| *** knangia has quit IRC | 00:12 | |
| *** vinaypotluri has quit IRC | 00:12 | |
| *** dikonoor has quit IRC | 00:18 | |
| *** markvoelker has joined #openstack-security | 00:22 | |
| *** markvoelker has quit IRC | 00:27 | |
| *** BR5C003Y_D00 has joined #openstack-security | 00:47 | |
| *** dave-mcc_ has joined #openstack-security | 00:54 | |
| *** zul has joined #openstack-security | 00:55 | |
| *** dave-mccowan has quit IRC | 00:55 | |
| *** BR5C003Y_D00 has quit IRC | 00:59 | |
| *** browne has quit IRC | 01:04 | |
| *** zul has quit IRC | 01:08 | |
| *** zul has joined #openstack-security | 01:12 | |
| *** encodingcollecto has joined #openstack-security | 01:22 | |
| *** jass93_ has joined #openstack-security | 01:25 | |
| *** dave-mccowan has joined #openstack-security | 01:27 | |
| *** dave-mcc_ has quit IRC | 01:29 | |
| *** encodingcollecto has quit IRC | 01:57 | |
| *** dave-mccowan has quit IRC | 02:01 | |
| *** gouthamr has quit IRC | 02:07 | |
| *** yuanying has quit IRC | 02:27 | |
| *** sdake has joined #openstack-security | 03:14 | |
| *** knangia has joined #openstack-security | 03:32 | |
| *** sdake_ has joined #openstack-security | 03:45 | |
| *** sdake has quit IRC | 03:47 | |
| *** yuanying has joined #openstack-security | 04:13 | |
| *** agireud has quit IRC | 04:16 | |
| *** diazjf has joined #openstack-security | 04:19 | |
| *** agireud has joined #openstack-security | 04:24 | |
| *** markvoelker has joined #openstack-security | 04:25 | |
| *** markvoelker has quit IRC | 04:30 | |
| *** salv-orlando has joined #openstack-security | 04:41 | |
| *** yuanying has quit IRC | 04:45 | |
| *** liverpooler has quit IRC | 04:45 | |
| *** salv-orlando has quit IRC | 04:46 | |
| *** yuanying has joined #openstack-security | 04:54 | |
| *** salv-orlando has joined #openstack-security | 05:07 | |
| *** diazjf has quit IRC | 05:09 | |
| *** markvoelker has joined #openstack-security | 05:26 | |
| *** markvoelker has quit IRC | 05:31 | |
| *** knangia has quit IRC | 05:52 | |
| *** liverpooler has joined #openstack-security | 06:02 | |
| *** yuanying has quit IRC | 06:02 | |
| *** liverpooler has quit IRC | 06:07 | |
| *** liverpooler has joined #openstack-security | 06:07 | |
| *** sdake_ has quit IRC | 06:11 | |
| *** rcernin has joined #openstack-security | 06:15 | |
| *** markvoelker has joined #openstack-security | 06:27 | |
| *** salv-orlando has quit IRC | 06:29 | |
| *** markvoelker has quit IRC | 06:32 | |
| *** salv-orlando has joined #openstack-security | 06:36 | |
| *** shohel has joined #openstack-security | 06:40 | |
| *** salv-orlando has quit IRC | 06:41 | |
| *** tesseract- has joined #openstack-security | 07:11 | |
| *** salv-orlando has joined #openstack-security | 07:14 | |
| *** yuanying has joined #openstack-security | 07:14 | |
| *** pcaruana has joined #openstack-security | 07:26 | |
| *** markvoelker has joined #openstack-security | 07:28 | |
| *** markvoelker has quit IRC | 07:32 | |
| *** salv-orl_ has joined #openstack-security | 07:56 | |
| *** salv-orlando has quit IRC | 07:58 | |
| *** jass93_ has quit IRC | 08:06 | |
| *** jass93_ has joined #openstack-security | 08:11 | |
| *** qwertyco_ has joined #openstack-security | 08:15 | |
| *** jass93_ has quit IRC | 08:18 | |
| *** jass93_ has joined #openstack-security | 08:19 | |
| *** qwertyco_ has quit IRC | 08:21 | |
| *** qwertyco has joined #openstack-security | 08:21 | |
| *** qwertyco is now known as qwertyco_ | 08:24 | |
| *** qwertyco_ has quit IRC | 08:26 | |
| *** qwertyco has joined #openstack-security | 08:26 | |
| *** lhinds is now known as lhinds|away | 08:47 | |
| *** qwertyco has quit IRC | 08:58 | |
| *** qwertyco has joined #openstack-security | 08:58 | |
| *** qwertyco has quit IRC | 08:58 | |
| *** qwertyco has joined #openstack-security | 08:59 | |
| *** qwertyco has quit IRC | 09:14 | |
| *** qwertyco has joined #openstack-security | 09:14 | |
| *** SlapChopGraty has joined #openstack-security | 09:18 | |
| *** SlapChopGraty has left #openstack-security | 09:20 | |
| *** qwertyco has quit IRC | 09:21 | |
| *** qwertyco has joined #openstack-security | 09:21 | |
| *** qwertyco has quit IRC | 09:37 | |
| *** qwertyco has joined #openstack-security | 09:37 | |
| *** salv-orl_ has quit IRC | 09:51 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 09:53 |
|---|---|---|
| *** woodster_ has quit IRC | 10:00 | |
| *** salv-orlando has joined #openstack-security | 10:23 | |
| openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 10:46 |
| openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 10:46 |
| hyakuhei- | Thanks sic | 10:55 |
| *** d0ugal has quit IRC | 11:05 | |
| *** d0ugal has joined #openstack-security | 11:06 | |
| *** kun_huang has quit IRC | 11:10 | |
| *** kun_huang has joined #openstack-security | 11:11 | |
| *** usuario has joined #openstack-security | 11:48 | |
| usuario | hello? | 11:48 |
| hyakuhei- | hi | 11:51 |
| *** hyakuhei- has quit IRC | 11:52 | |
| *** hyakuhei- has joined #openstack-security | 11:52 | |
| *** hyakuhei- has quit IRC | 11:52 | |
| *** hyakuhei- has joined #openstack-security | 11:52 | |
| *** hyakuhei- is now known as hyakuhei | 11:52 | |
| usuario | U know how I cant stop the /tree command? | 11:57 |
| usuario | he is reading the OS in sequency | 11:57 |
| usuario | And I cant stop it | 11:57 |
| *** usuario has quit IRC | 11:59 | |
| *** gouthamr has joined #openstack-security | 12:02 | |
| *** salv-orlando has quit IRC | 12:24 | |
| *** qwertyco has quit IRC | 12:24 | |
| *** qwertyco has joined #openstack-security | 12:24 | |
| *** lamt has quit IRC | 12:25 | |
| *** edmondsw has joined #openstack-security | 12:26 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 12:30 |
| *** markvoelker has joined #openstack-security | 12:31 | |
| openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 12:37 |
| *** liverpooler has quit IRC | 12:56 | |
| *** dave-mccowan has joined #openstack-security | 13:04 | |
| *** ayoung has joined #openstack-security | 13:04 | |
| *** agireud has quit IRC | 13:10 | |
| *** shohel has quit IRC | 13:11 | |
| *** agireud has joined #openstack-security | 13:18 | |
| *** zul has quit IRC | 13:30 | |
| *** zul has joined #openstack-security | 13:33 | |
| *** mvaldes has joined #openstack-security | 13:54 | |
| *** sdake has joined #openstack-security | 13:59 | |
| *** hongbin has joined #openstack-security | 14:06 | |
| *** sdake has quit IRC | 14:15 | |
| *** mvaldes1 has joined #openstack-security | 14:15 | |
| *** mvaldes has quit IRC | 14:17 | |
| *** liverpooler has joined #openstack-security | 14:23 | |
| *** gouthamr has quit IRC | 14:29 | |
| *** gouthamr has joined #openstack-security | 14:31 | |
| *** qwertyco has quit IRC | 14:41 | |
| *** diazjf has joined #openstack-security | 14:46 | |
| *** diazjf has quit IRC | 14:48 | |
| *** tmcpeak has joined #openstack-security | 14:50 | |
| *** capnoday has joined #openstack-security | 14:53 | |
| *** capnoday has quit IRC | 14:55 | |
| *** DuncanT has quit IRC | 14:55 | |
| *** woodrow has quit IRC | 14:55 | |
| *** capnoday has joined #openstack-security | 14:55 | |
| *** sweston has quit IRC | 14:55 | |
| *** dougwig has quit IRC | 14:55 | |
| *** ediardo has quit IRC | 14:55 | |
| *** fyxim has quit IRC | 14:55 | |
| *** diazjf has joined #openstack-security | 14:58 | |
| *** salv-orlando has joined #openstack-security | 14:59 | |
| *** diazjf has quit IRC | 15:01 | |
| *** mvaldes1 has quit IRC | 15:05 | |
| *** mvaldes has joined #openstack-security | 15:05 | |
| *** jass93_ has quit IRC | 15:08 | |
| *** fyxim has joined #openstack-security | 15:11 | |
| *** diazjf has joined #openstack-security | 15:15 | |
| *** dougwig has joined #openstack-security | 15:18 | |
| *** sweston has joined #openstack-security | 15:20 | |
| *** woodrow has joined #openstack-security | 15:25 | |
| *** DuncanT has joined #openstack-security | 15:36 | |
| *** vinaypotluri has joined #openstack-security | 15:42 | |
| *** ediardo has joined #openstack-security | 15:43 | |
| *** diazjf has quit IRC | 15:44 | |
| *** diazjf has joined #openstack-security | 15:45 | |
| *** knangia has joined #openstack-security | 15:46 | |
| *** unrahul has quit IRC | 15:52 | |
| *** unrahul has joined #openstack-security | 15:52 | |
| *** woodburn has joined #openstack-security | 15:54 | |
| *** rcernin has quit IRC | 16:01 | |
| *** ccneill has joined #openstack-security | 16:17 | |
| *** jass93_ has joined #openstack-security | 16:18 | |
| unrahul | Hey ccneill u thr? | 16:20 |
| unrahul | Hey michaelxin ccneill do we have a meeting now? | 16:20 |
| ccneill | unrahul: sorry, should've mentioned this earlier. we're having a security engineering hack day today | 16:23 |
| ccneill | probably won't be super active today on IRC (though I'll at least lurk in our OSSP meeting and chime in with syntribos updates) | 16:24 |
| tmcpeak | security engineering hack day sounds legit | 16:24 |
| unrahul | Hey ccneill sounds cool | 16:24 |
| ccneill | tmcpeak: been agitating for it for a long time.. :) | 16:25 |
| tmcpeak | good man :) | 16:26 |
| *** eoroot has joined #openstack-security | 16:28 | |
| *** eoroot has left #openstack-security | 16:28 | |
| *** tesseract- has quit IRC | 16:31 | |
| *** eoroot has joined #openstack-security | 16:31 | |
| eoroot | hello | 16:32 |
| *** eoroot has left #openstack-security | 16:32 | |
| *** mdong has joined #openstack-security | 16:34 | |
| *** diazjf has quit IRC | 16:42 | |
| *** tkelsey has joined #openstack-security | 16:45 | |
| *** mvaldes has quit IRC | 16:47 | |
| *** mvaldes has joined #openstack-security | 16:47 | |
| dave-mccowan | tmcpeak ping | 16:51 |
| tmcpeak | dave-mccowan: yo! how's it going? | 16:51 |
| dave-mccowan | hi travis. good. i ran into a bandit issue, and found there is already a bug open. | 16:52 |
| dave-mccowan | https://bugs.launchpad.net/bandit/+bug/1622615 | 16:52 |
| openstack | Launchpad bug 1622615 in Bandit "Bandit reports 'json.load' as 'yaml.load'" [Undecided,New] | 16:52 |
| dave-mccowan | bandit is mistaking json.load() with yaml.load() | 16:52 |
| dave-mccowan | do you already know about this? | 16:52 |
| tmcpeak | dave-mccowan: no, that sounds sub-optimal :D | 16:52 |
| tmcpeak | I'll check it out today, thanks! | 16:52 |
| dave-mccowan | looking at the code, it looks like anything.load() would also trigger the blacklist, as long as the yaml library is also imported. | 16:53 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/380554 | 16:53 |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/bandit: Updated from global requirements https://review.openstack.org/383105 | 16:53 |
| dave-mccowan | tmcpeak i'd be happy to help with the fix. i just wanted to check that it wasn't a known issue or limitation of the design. let me know if i can help. | 16:54 |
| tmcpeak | dave-mccowan: that's awesome, should be a simple fix, I think we just need to include the full qualname of the yaml.load | 16:54 |
| dave-mccowan | tmcpeak what would happen if i "import yaml as foo" and then called "foo.load()"? (not sure if that's a requirement...) | 16:55 |
| tmcpeak | tkelsey: ^ do you remember? | 16:56 |
| tmcpeak | I think this works as expected | 16:56 |
| tmcpeak | dave-mccowan: would love your help on the fix though | 16:59 |
| tkelsey | humm? | 17:00 |
| tmcpeak | if you alias an import | 17:00 |
| dave-mccowan | tmcpeak ok. i just assigned it to myself. | 17:00 |
| tmcpeak | dave-mccowan: thanks! | 17:00 |
| tkelsey | it should detect alias stuff fine | 17:00 |
| tkelsey | but it should not get it confused :-/ | 17:01 |
| *** sdake has joined #openstack-security | 17:01 | |
| *** jamielennox|away has quit IRC | 17:02 | |
| *** woodster_ has joined #openstack-security | 17:05 | |
| *** jamielennox|away has joined #openstack-security | 17:16 | |
| *** jamielennox|away is now known as jamielennox | 17:16 | |
| tmcpeak | dave-mccowan: an interesting design choice we made :P https://github.com/openstack/bandit/blob/master/bandit/plugins/yaml_load.py#L58 | 17:32 |
| dave-mccowan | tmcpeak yea, that code doesn't seem very smart. | 17:33 |
| tmcpeak | agreed :) | 17:33 |
| tmcpeak | especially since qualname is for that exact thing | 17:34 |
| dave-mccowan | tmcpeak should this code be removed, and the check added to blacklists/calls.py? | 17:36 |
| openstackgerrit | Merged openstack/bandit: Updated from global requirements https://review.openstack.org/383105 | 17:39 |
| dave-mccowan | tmcpeak nevermind. i see how to use qualname in this case. | 17:41 |
| tmcpeak | dave-mccowan: thanks! | 17:41 |
| dave-mccowan | tmcpeak quick question... i've forgotten how to run bandit out of my tree, instead of the version that is pip installed on my server. | 17:45 |
| tmcpeak | sigmavirus: ^ | 17:45 |
| tmcpeak | what was that magics you used for that? | 17:45 |
| tmcpeak | I think there's s —develop or something | 17:46 |
| tmcpeak | otherwise you can do 'pip install -e .' or something | 17:46 |
| sigmavirus | the -e. is the magic | 17:48 |
| dave-mccowan | sigmavirus any way to run the source directly from the tree? this would be handy to run bandit inside a debugger. | 17:49 |
| sigmavirus | dave-mccowan: that's it | 17:50 |
| sigmavirus | pip install -e. will install it from source and any modifications you make will get picked up | 17:50 |
| sigmavirus | because it does symlinks not a real install | 17:50 |
| sigmavirus | -e stands for editable | 17:50 |
| dave-mccowan | sigmavirus cool. thanks. | 17:51 |
| sigmavirus | tox -e venv does something similar too iirc | 17:51 |
| *** jass93__ has joined #openstack-security | 17:56 | |
| *** tkelsey has quit IRC | 17:56 | |
| *** jass93_ has quit IRC | 17:58 | |
| *** diazjf has joined #openstack-security | 18:23 | |
| openstackgerrit | Andreas Jaeger proposed openstack/bandit: Enable release notes translation https://review.openstack.org/383200 | 18:24 |
| openstackgerrit | Dave McCowan proposed openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 18:31 |
| *** mdong has quit IRC | 18:33 | |
| *** mdong has joined #openstack-security | 18:35 | |
| *** mvaldes has quit IRC | 18:35 | |
| *** mvaldes has joined #openstack-security | 18:35 | |
| openstackgerrit | Deepak proposed openstack/anchor: Changed the home-page link https://review.openstack.org/383314 | 18:41 |
| *** capnoday has quit IRC | 18:46 | |
| *** jamielennox has quit IRC | 19:03 | |
| openstackgerrit | Deepak proposed openstack/bandit: Changed the home-page url link https://review.openstack.org/383415 | 19:04 |
| *** jamielennox|away has joined #openstack-security | 19:05 | |
| *** jamielennox|away is now known as jamielennox | 19:06 | |
| *** salv-orlando has quit IRC | 19:13 | |
| *** nkinder has quit IRC | 19:15 | |
| *** nkinder has joined #openstack-security | 19:16 | |
| sigmavirus | tmcpeak: ^ Do we want to point to the developer docs instead of the wiki? | 19:18 |
| tmcpeak | sigmavirus: what's this? | 19:19 |
| sigmavirus | tmcpeak: https://review.openstack.org/383415 | 19:19 |
| tmcpeak | sigmavirus: no, I think we want to keep it at the wiki | 19:19 |
| tmcpeak | only developers would use the developer docs | 19:19 |
| sigmavirus | probably same for anchor then, eh? | 19:19 |
| sigmavirus | https://review.openstack.org/383314 | 19:19 |
| tmcpeak | sigmavirus: yep | 19:19 |
| tmcpeak | good call | 19:20 |
| *** Canaimero-e64b8 has joined #openstack-security | 19:20 | |
| *** agireud has quit IRC | 19:21 | |
| sigmavirus | tmcpeak: always be suspicious of reviews like that proposed in batches | 19:21 |
| tmcpeak | sigmavirus: yep yep | 19:21 |
| *** Canaimero-e64b8 has left #openstack-security | 19:22 | |
| *** agireud has joined #openstack-security | 19:29 | |
| *** agireud has quit IRC | 19:33 | |
| openstackgerrit | Merged openstack/bandit: Enable release notes translation https://review.openstack.org/383200 | 19:34 |
| *** agireud has joined #openstack-security | 19:43 | |
| *** jass93_ has joined #openstack-security | 19:46 | |
| *** jass93__ has quit IRC | 19:48 | |
| *** dave-mccowan has quit IRC | 19:49 | |
| *** dave-mccowan has joined #openstack-security | 19:58 | |
| *** dave-mcc_ has joined #openstack-security | 20:01 | |
| *** dave-mccowan has quit IRC | 20:04 | |
| *** agireud has quit IRC | 20:06 | |
| *** sdake has quit IRC | 20:09 | |
| openstackgerrit | Dave McCowan proposed openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 20:18 |
| *** salv-orlando has joined #openstack-security | 20:27 | |
| *** ludeatbest has joined #openstack-security | 20:31 | |
| *** ludeatbest has quit IRC | 20:33 | |
| *** mvaldes has quit IRC | 20:34 | |
| *** browne has joined #openstack-security | 20:40 | |
| *** dave-mcc_ has quit IRC | 20:41 | |
| *** mvaldes has joined #openstack-security | 21:00 | |
| *** zooey has joined #openstack-security | 21:01 | |
| *** dave-mccowan has joined #openstack-security | 21:01 | |
| *** ayoung has quit IRC | 21:02 | |
| *** zooey has quit IRC | 21:10 | |
| *** zooey has joined #openstack-security | 21:10 | |
| *** zooey has joined #openstack-security | 21:10 | |
| *** diazjf has quit IRC | 21:13 | |
| *** diazjf has joined #openstack-security | 21:25 | |
| *** gfhellma has joined #openstack-security | 21:26 | |
| tmcpeak | browne: yo | 21:27 |
| tmcpeak | sigmavirus: | 21:27 |
| tmcpeak | https://review.openstack.org/#/c/383245/ | 21:27 |
| tmcpeak | +A por favor? | 21:27 |
| *** gouthamr has quit IRC | 21:27 | |
| *** gouthamr has joined #openstack-security | 21:31 | |
| *** gouthamr has quit IRC | 21:32 | |
| *** gouthamr has joined #openstack-security | 21:35 | |
| *** gouthamr has quit IRC | 21:37 | |
| *** agireud has joined #openstack-security | 21:37 | |
| browne | tmcpeak: what's up | 21:42 |
| browne | oh, i'll review | 21:43 |
| tmcpeak | sweet, thanks | 21:43 |
| *** rcernin has joined #openstack-security | 21:47 | |
| *** diazjf has quit IRC | 21:51 | |
| openstackgerrit | Merged openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 21:51 |
| *** rcernin has quit IRC | 21:59 | |
| *** rcernin has joined #openstack-security | 21:59 | |
| *** sdake has joined #openstack-security | 22:13 | |
| *** mdong has quit IRC | 22:13 | |
| *** mdong has joined #openstack-security | 22:14 | |
| *** ayoung has joined #openstack-security | 22:21 | |
| *** mvaldes has quit IRC | 22:35 | |
| *** mdong has quit IRC | 22:37 | |
| *** tmcpeak has quit IRC | 22:59 | |
| *** salv-orlando has quit IRC | 23:01 | |
| *** gouthamr has joined #openstack-security | 23:01 | |
| *** ayoung has quit IRC | 23:05 | |
| *** hongbin has quit IRC | 23:08 | |
| *** ccneill_ has joined #openstack-security | 23:09 | |
| *** ccneill has quit IRC | 23:11 | |
| *** gfhellma has quit IRC | 23:14 | |
| *** jass93_ has quit IRC | 23:32 | |
| *** zooey has left #openstack-security | 23:34 | |
| *** rcernin has quit IRC | 23:36 | |
| *** ayoung has joined #openstack-security | 23:49 | |
| *** pcaruana has quit IRC | 23:55 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!