Wednesday, 2021-02-17

*** xarlos has quit IRC00:07
*** star_cloud has quit IRC00:15
*** macz_ has quit IRC00:34
*** macz_ has joined #openstack-security00:55
*** macz_ has quit IRC01:00
*** macz_ has joined #openstack-security01:16
*** macz_ has quit IRC01:20
*** macz_ has joined #openstack-security01:37
*** macz_ has quit IRC01:41
*** macz_ has joined #openstack-security01:58
*** macz_ has quit IRC02:02
*** Jackneill has quit IRC02:06
*** macz_ has joined #openstack-security02:18
*** Jackneill has joined #openstack-security02:19
*** macz_ has quit IRC02:23
*** rcernin has quit IRC02:27
*** star_cloud has joined #openstack-security02:32
*** macz_ has joined #openstack-security02:58
*** macz_ has quit IRC03:02
*** rcernin has joined #openstack-security03:07
*** macz_ has joined #openstack-security04:17
*** macz_ has quit IRC04:22
*** macz_ has joined #openstack-security04:38
*** macz_ has quit IRC04:42
*** macz_ has joined #openstack-security04:58
*** gyee has quit IRC05:01
*** macz_ has quit IRC05:03
*** mnaser has quit IRC06:32
*** mnaser has joined #openstack-security06:34
*** heikkine has joined #openstack-security07:44
*** rcernin has quit IRC07:47
*** macz_ has joined #openstack-security08:10
*** rcernin has joined #openstack-security08:12
*** macz_ has quit IRC08:15
*** rcernin has quit IRC08:19
*** rcernin has joined #openstack-security08:26
*** rcernin has quit IRC08:31
*** rcernin has joined #openstack-security08:37
*** xarlos has joined #openstack-security08:43
*** rcernin has quit IRC08:51
*** rcernin has joined #openstack-security08:56
*** rcernin has quit IRC09:02
*** rcernin has joined #openstack-security09:28
*** rcernin has quit IRC09:35
*** rcernin has joined #openstack-security09:59
*** rcernin has quit IRC10:31
*** rcernin has joined #openstack-security12:58
*** rcernin has quit IRC13:02
*** macz_ has joined #openstack-security13:41
*** macz_ has quit IRC13:45
*** xarlos has quit IRC14:10
*** macz_ has joined #openstack-security15:19
*** macz_ has quit IRC15:24
*** macz_ has joined #openstack-security15:58
*** macz_ has quit IRC15:59
*** macz_ has joined #openstack-security15:59
*** rcernin has joined #openstack-security16:58
*** rcernin has quit IRC17:02
*** gyee has joined #openstack-security17:43
*** star_cloud has quit IRC18:25
*** star_cloud has joined #openstack-security18:33
fungii've marked our ossa task for ancient bug 1561199 "won't fix"19:47
openstackbug 1561199 in Swift3 "Client-accessible headers are used to send authentication information to other middlewares" [Undecided,Fix released] https://launchpad.net/bugs/156119919:47
fungisame for bug 156217519:49
openstackbug 1562175 in OpenStack Object Storage (swift) "Pre-auth COPY in versioned_writes can result in a successful COPY that wouldn't have been authorized" [Undecided,Fix released] https://launchpad.net/bugs/156217519:49
fungiand bug 156641619:52
openstackbug 1566416 in OpenStack Identity (keystone) "Keystone does not validate that s3tokens requests came from s3_token middleware" [Undecided,Fix released] https://launchpad.net/bugs/156641619:52
*** Jackneill has quit IRC19:53
fungialso bug 170858020:01
openstackbug 1708580 in OpenStack Security Notes "ovsfw ignores port_ranges under some conditions" [Undecided,New] https://launchpad.net/bugs/170858020:01
fungibug 1714858 too20:03
openstackbug 1714858 in Cinder "Some APIs don't check the owner policy" [Critical,Fix released] https://launchpad.net/bugs/1714858 - Assigned to TommyLike (hu-husheng)20:03
fungibug 1721193 as well20:06
openstackbug 1721193 in OpenStack Dashboard (Horizon) "Outdated and vulnerable versions of Javascript libraries" [Undecided,Incomplete] https://launchpad.net/bugs/172119320:06
*** Jackneill has joined #openstack-security20:06
gagehugothanks fungi20:08
fungiyeah, cleaning house, we'll see how many i can get through today20:09
*** Jackneill has quit IRC20:11
fungisame for bug 179757520:17
openstackbug 1797575 in neutron "Security vulnerability with SR-IOV ports" [Undecided,New] https://launchpad.net/bugs/179757520:17
*** Jackneill has joined #openstack-security20:23
fungiand bug 186189320:23
openstackbug 1861893 in OpenStack Compute (nova) "os-assisted-volume-snapshots passes unsanitised file path to the libvirt driver" [Medium,Confirmed] https://launchpad.net/bugs/186189320:23
fungiand related trio: bug 1888394, bug 1883659, bug 189285220:40
openstackbug 1888394 in oslo.cache "Oslo.cache exponencially raising up connection to memcached" [Undecided,In progress] https://launchpad.net/bugs/188839420:40
openstackbug 1883659 in oslo.cache "keystonemiddleware connections to memcached from neutron-server grow beyond configured values" [Undecided,Confirmed] https://launchpad.net/bugs/188365920:40
openstackbug 1892852 in oslo.cache "memcached socket not released upon lbaas API request " [Undecided,New] https://launchpad.net/bugs/189285220:40
fungiand bug 190189120:50
openstackbug 1901891 in OpenStack Identity (keystone) "Issues regarding application credentials" [Undecided,New] https://launchpad.net/bugs/190189120:50
fungiokay, i've been through all of them. surveying the ones the vmt is still tracking, we've got this many per project team: glance(1), horizon(3), keystone(2), neutron(7), nova(2), oslo(1), swift(1)20:53
fungisome are the same bug across more than one project20:53
fungii'll try to work up individual help requests to each team with their team-specific sets of bugs20:54
*** rcernin has joined #openstack-security20:59
*** rcernin has quit IRC21:03
*** rcernin has joined #openstack-security21:22
*** rcernin has quit IRC21:53
*** rcernin has joined #openstack-security22:00
*** star_cloud has quit IRC23:06
*** star_cloud has joined #openstack-security23:07
*** star_cloud has quit IRC23:16
*** star_cloud has joined #openstack-security23:18
*** star_cloud has quit IRC23:28
*** star_cloud has joined #openstack-security23:28
*** star_cloud has quit IRC23:38
*** star_cloud has joined #openstack-security23:39

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!