Friday, 2026-04-10

opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: OSSA-2026-006 Errata 1  https://review.opendev.org/c/openstack/ossa/+/98398308:28
opendevreviewMerged openstack/ossa master: OSSA-2026-006 Errata 1  https://review.opendev.org/c/openstack/ossa/+/98398313:39
fungiwow... https://www.openwall.com/lists/oss-security/2026/04/10/113:41
fungitalk about trying to put the cat back in the bag13:41
fungibeans back in the can13:41
fungimaybe there's more to the story there13:41
fungiinteresting to see the reporter's maximum embargo roughly corresponds with ours, but i guess upstream there didn't like the idea that a reporter could disclose a vulnerability they discovered13:43
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-007 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/98412920:55
gouthamrfungi: interesting, but, wouldn't the upstream policies govern this?20:58
gouthamrdeleting the bug is weird, but, we have language that a reasonable fix must be identified within two weeks to justify the embargo21:02
fungiupstream policies can't govern a bug reporter, though sure the project is within their rights to delete a bug report in their defect tracker of course21:04
fungibut ignores that the reporter can still publish their own advisory with all the same details, so there's not much point21:05
fungiit mainly just makes the project look bad when the only story out there is that the reporter notified them, waited 3.5 months, still no fix/advisory, opened a public bug and then it got deleted21:06
fungiour policy in openstack is to switch the bug to public within 3 months regardless of whether a fix is ready, so within the expectations of that reporter, but i guess systemd is used to taking longer to fix things sometimes21:08
fungia lot of our reporting policy and intake process is designed to placate reporters so that they won't feel like they need to give up on us and go publish something on their own, understanding that we can't stop them if they do and so we're effectively at their mercy21:09
fungihence stating a maximum embargo window up front and making sure we do everything possible to credit them in our publications21:11
gouthamrack fungi, that's good learning21:19
gouthamrJayF: fungi: are you around to check on an OSSA, or wait until Monday?21:20
fungii'm around21:20
fungifor as long as you need21:21
gouthamrthis might be quick :) https://review.opendev.org/c/openstack/ossa/+/984129 21:21
fungibut also if you want an excuse to be done for the week and enjoy your weekend, i'm happy to give it to you ;)21:21
gouthamrhaha, no.. i've a few more hours. i noticed responses on the bug a bit late or would've done this earlier in the day21:21
fungiaha, thanks i missed that one21:21
fungigouthamr: lgtm, though i commented recommending tuesday instead at this point. it's not like a few more days are going to make it easier for someone to exploit anyway21:34
gouthamrfungi: ah ty, makes sense, i can update the date and W-1 and wait21:34
fungialso don't forget to add closes-bug trailers for both the bugs listed in the advisory and add an ossa bugtask to the one that doesn't have it yet21:34
fungiand set them both to public security instead of just public21:35
gouthamryes the other one has no mention of any of this!21:36
fungiand many thanks for working on this one!21:37

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!