Wednesday, 2020-06-03

*** Jackneill has quit IRC00:15
*** Jackneill has joined #openstack-security00:28
*** gyee has quit IRC01:40
*** rcernin has quit IRC02:24
*** rcernin has joined #openstack-security02:31
*** rcernin has quit IRC03:23
*** rcernin has joined #openstack-security03:31
*** rcernin has quit IRC03:46
*** rcernin has joined #openstack-security04:23
*** rcernin has quit IRC04:28
*** rcernin has joined #openstack-security04:29
*** rcernin has quit IRC05:36
*** rcernin has joined #openstack-security05:37
*** rcernin has quit IRC05:51
*** rcernin has joined #openstack-security05:56
*** rcernin has quit IRC06:10
*** rcernin has joined #openstack-security06:14
*** rcernin has quit IRC06:28
*** jawad_axd has joined #openstack-security07:23
*** redrobot has quit IRC08:35
openstackgerritBrian Rosmaita proposed openstack/security-doc master: Add OSSN-0086  https://review.opendev.org/73311611:37
*** Guest27280 has joined #openstack-security13:22
*** Guest27280 is now known as redrobot13:25
*** jawad_axd has quit IRC15:20
*** gyee has joined #openstack-security15:42
*** trident has quit IRC16:09
*** trident has joined #openstack-security16:12
mnaserfungi: is there any reason why this was not released over embargo disclosure :(16:16
mnaserthis is a fun surprise in the middle of the ptg16:16
fungimnaser: it's not directly fixable16:17
fungii was trying to convince them to make it public sooner, but it's not an advisory, it's configuration guidance accompanied by some patches16:17
mnaserfungi: right, i just kinda saw patches and figured it's something we need to patch..16:18
fungionly if you're using scaleio/vxflexos storage driver16:18
fungiit was effectively ignored until we implemented a policy to limit embargo durations, and then right before the embargo was scheduled to expire and become public suddenly folks wanted to work on a solution for it16:20
fungiand asked to extend the embargo beyond its expiration16:21
fungii didn't feel like extending for two weeks was in everyone's best interests16:25
fungibetter that users of that driver know sooner what the security limitations are16:26
fungi(especially since one of the bits of guidance there is that it's unsafe in combination with bare metal instances, and there's no solution to that other than to stop using them together)16:27
openstackgerritMerged openstack/security-doc master: Add OSSN-0086  https://review.opendev.org/73311617:35
openstackgerritAndreas Jaeger proposed openstack/security-analysis master: Switch to newer openstackdocstheme version  https://review.opendev.org/73331618:54
openstackgerritAndreas Jaeger proposed openstack/security-specs master: Switch to newer openstackdocstheme version  https://review.opendev.org/73331718:55
openstackgerritAndreas Jaeger proposed openstack/security-analysis master: Switch to newer openstackdocstheme version  https://review.opendev.org/73331619:21
*** rcernin has joined #openstack-security23:14

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!