Thursday, 2022-10-06

fungithis bug report was just brought to my attention: https://bugzilla.redhat.com/show_bug.cgi?id=210541911:33
fungilooks like red hat assigned a cve for it, but never reported it upstream to keystone11:33
*** blarnath is now known as d34dh0r5312:27
fungireminder that we're holding our monthly meeting in roughly 10 minutes14:49
fungi#startmeeting security15:01
opendevmeetMeeting started Thu Oct  6 15:01:11 2022 UTC and is due to finish in 60 minutes.  The chair is fungi. Information about MeetBot at http://wiki.debian.org/MeetBot.15:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:01
opendevmeetThe meeting name has been set to 'security'15:01
fungiapologies, i'll be a bit slow chairing since i'm quite unprepared. it's been a busy week!15:01
fungi#link https://etherpad.opendev.org/p/security-agenda Meeting Agenda15:03
fungii'll add a section there real fast ;)15:03
fungi#topic Prior Actions15:04
fungi#link https://meetings.opendev.org/meetings/security/2022/security.2022-09-01-15.02.html (previous minutes)15:05
fungifungi propose xstatic discussion topic on horizon ptg agenda15:05
fungii haven't done that, though at this point i'm unsure what the interest is from the horizon side, but i'll do that real fast15:06
fungithough it doesn't appear they've made an etherpad for proposed discussion topics15:08
fungiso maybe i'll follow up with them first15:08
fungi#action fungi propose xstatic discussion topic on horizon ptg agenda15:09
fungireadded for now15:09
fungifungi add new volunteers to embargo-notice ml15:09
fungii've done that15:09
fungifungi update ossn/security-doc members in gerrit and launchpad15:09
fungii've started on that but not finished yet, noting that some of those groups are waaaaaay out of date and need substantial cleanup of alumni who haven't been contributing actively for years. i'll readd the action for now15:10
fungi#action fungi update ossn/security-doc members in gerrit and launchpad15:10
fungifungi reach out to nova reviewers about 85000315:10
fungi#link https://review.opendev.org/850003 Gracefully ERROR in _init_instance if vnic_type changed15:11
fungiseems that has merged as of september 1015:12
fungifixed in zed, with backports proposed for all supported stable branches (so back as far as stable/wallaby)15:13
fungid34dh0r53: if you wanted to pick this back up, we could probably get a draft ossa proposed in gerrit with links to all the backports now and a (more final) list of affected versions15:14
fungiwe probably shouldn't move forward with publication until the backports merge, though we probably can as long as they seem to be getting positive reviews and passing tests15:14
fungiwe've never really set a strict policy on timing for ossa publication with regard to already public vulnerability reports, aside from being able to point to the available patches somewhere (even if they haven't merged)15:16
fungiit's more a judgement call in order to potentially save ourselves extra work with subsequent errata15:16
fungiand given those backports are all failing tests and have no code reviews yet, it's probably best we hold off a little longer still15:17
fungibut there was some activity on them as recently as last week, so i don't think we need any new action item coming out of the meeting for that15:18
fungifungi switch bug 1981813 to class b1 for now15:18
fungi#link https://launchpad.net/bugs/1981813 Compute service fails to restart if the vnic_type of a bound port changed from direct to macvtap (CVE-2022-37394)15:18
fungiwe can drop this, as it's apparent some attempt at backporting is underway15:19
fungifungi switch advisory tasks for old public security bugs to won't fix for now15:19
fungii haven't completely made an attempt at this yet, but i've punted it to our ptg topics (i'll cover that in a few minutes), so not readding the action item15:20
fungifungi schedule an hour at the ptg for the security sig15:20
fungii've done that, we're set for an hour starting at 15:00 utc on wednesday of the ptg15:21
fungi#topic Public Bug Reports15:22
fungi#link https://storyboard.openstack.org/#!/story/2010004 Remote code execution: Trove backup15:23
fungi#link https://launchpad.net/bugs/1989008 Lax rulesets leading to privilege escalation vulnerabilities15:24
fungi#link https://bugzilla.redhat.com/show_bug.cgi?id=2105419 Application credential token remains valid longer than expected15:25
fungithat last one doesn't seem to have a corresponding upstream bug report, even though red hat assigned it a cve15:26
gagehugoo/15:26
gagehugoapologies for being late15:26
fungino worries! we have logs ;)15:26
fungi#topic PTG Planning15:27
fungiso, as mentioned a few minutes ago, we have an hour (15:00 utc on wednesday)15:27
fungii can always add another one if that's a conflict for people who had things they want to cover15:28
fungii've started a list of proposed discussion topics and activities, though it's far from chiseled in stone:15:28
fungi#link https://etherpad.opendev.org/p/oct2022-ptg-openstack-security15:28
fungii figured if nothing else, we can debate some of the currently public security bugs and maybe close some out if we can determine they're no longer relevant (or at least close out our security advisory tasks if it looks like they're unneeded or unlikely to happen any time soon)15:29
fungialso we could work on getting some old ossg stuff moved off the wiki, or at least plan and divvy up tasks for that15:30
fungiif anybody has anything else to bring up, please add it15:31
fungi#topic Open Discussion15:32
fungia couple of things to note... first is that i did a quick cleanup of our sig's main page on the wiki15:33
fungi#link https://wiki.openstack.org/wiki/Security-SIG15:33
fungii took a hatchet to a lot of old ossg info, as well as anything which was redundant with what we've got on the current security.o.o site15:33
fungialso there's a security-related post to the openstack-discuss ml from today:15:34
fungi#link https://lists.openstack.org/pipermail/openstack-discuss/2022-October/030755.html Openstack Security Assessments15:35
fungii made an initial attempt to answer it, but in short, some security folks are looking at openstack security from the end-user guidance perspective, which i don't think we've really done any coordinated attempt at documenting15:35
fungias i note in my reply, most of our focus has been on fixing vulnerabilities in the software and discussing how to securely deploy and operate it15:36
fungibut not much i'm aware of telling users the dos and don'ts about using the services securely15:37
fungianyway, if anybody has more to add, please follow up to that ml thread15:37
fungianything else anyone wants to bring up before we close the meeting?15:38
gagehugonothing from me15:41
fungithanks gagehugo!15:45
fungi#endmeeting15:45
opendevmeetMeeting ended Thu Oct  6 15:45:34 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:45
opendevmeetMinutes:        https://meetings.opendev.org/meetings/security/2022/security.2022-10-06-15.01.html15:45
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/security/2022/security.2022-10-06-15.01.txt15:45
opendevmeetLog:            https://meetings.opendev.org/meetings/security/2022/security.2022-10-06-15.01.log.html15:45

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!