Tuesday, 2020-08-11

fungi  ohai15:21
sean-k-mooneyhi i have a public bug that potentially has security impacts, at this point there is no point in moving it to security since its been public since 2020-06-2915:21
sean-k-mooneyshould i mark it as public security or what the best way to approch it15:21
fungiwhat's the bug number? i'll take a look and add an ossa bugtask et cetera15:21
openstackLaunchpad bug 1885558 in OpenStack Compute (nova) "sriov: instance with macvtap vnic_type live migration failed" [High,In progress] - Assigned to renminmin (rmm0811)15:22
fungihttps://security.openstack.org/vmt-process.html also talks about how we handle issues reported in public vs in private15:22
sean-k-mooneyah good ill take a look at that. the bug as described is not intially obviously a security issue but there are other failure modes that kind of are15:23
sean-k-mooneyanyway ill read that now15:23
fungiyeah, you could open a separate private security bug for nova detailing the non-obvious risks it poses, and then we can mark them as duplicates when the second bug is made public15:24
fungithough unless the impact is really severe, handling it in public is probably better anyway15:25
sean-k-mooneysure i can do that. am i can pm you a short description too i would prefer not to say it on the open channel15:25
fungiyeah, no problem15:27
