Thursday, 2026-06-04

mikalUmmm, I am silly and not entirely sure I followed https://security.openstack.org/vmt-process.html right. I am meant to file a private security bug in the affected project right? Not some shared "VMT project"?02:11
gouthamrfeel free to give me the bug in private02:12
gouthamrmikal:02:12
mikalWell, given its locked down I can just do it here can't I?02:12
mikalRegardless, I did thing.02:13
gouthamrthis one is a public channel, ty02:13
gouthamrI got your ping02:13
gouthamrmikal: security by obscurity i think :) launchpad URLs contain the project name.. and we (vmt) don't know for sure if project trackers are secured well enough..02:20
gouthamryou did the right thing btw, all good..02:21
mikalOk cool. I shall proceed to do nothing until someone talks at me.02:26
fungimikal: for reference, in case you only found our vmt process documentation, the instructions for reporting suspected vulnerabilities are much shorter and can be found at https://security.openstack.org/reporting.html (linked from the "How to report security issues to OpenStack" heading at the top of the main security.openstack.org page)13:38
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-021 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99151414:07
opendevreviewMerged openstack/ossa master: Add OSSA-2026-021 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99151414:38
fungigouthamr: https://security.openstack.org/ossa/OSSA-2026-021.html is live now, don't forget to update the bug title14:40
gouthamrthank you fungi 14:51
fungiof course. i'm also on hand to do openstack-announce moderation when you're ready14:52
fungigouthamr: looks like your OSSN-0098 was waiting in the openstack-announce queue so i went ahead and approved that14:54
gouthamrah ty! just sent the emails15:00
fungiapproved now too15:03
JayFhttps://bugs.launchpad.net/ironic/+bug/2154288 is now public18:26
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172919:46
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172919:47
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172919:50
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172919:56
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172920:02
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: OSSA-2026-021: Errata 1 - add CVE  https://review.opendev.org/c/openstack/ossa/+/99173720:24
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172920:41
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0099] Service DoS in Ironic  https://review.opendev.org/c/openstack/security-doc/+/99172921:05
opendevreviewMerged openstack/ossa master: OSSA-2026-021: Errata 1 - add CVE  https://review.opendev.org/c/openstack/ossa/+/99173721:45
gouthamrty fungi21:46
fungiof course21:46
fungii should be the one thanking you21:46
gouthamr:P crossing Ts dotting Is before I go away and leave you with the mess 21:47
fungibut instead i need to figure out dinner once i approve things through openstack-announce21:47
gouthamrmy bad on openstack-discuss, i was testing whether subject mangling will preserve threading21:56
gouthamri preserved the original subject on openstack-announce21:57
fungiapproved it22:01
fungiand yeah, threading in most mail clients is done by looking at the in-reply-to and references headers22:01
fungifor a reply, in-reply-to holds the message-id of the message it's a reply to, and references often has a list of several prior message-id values from the thread depending on the sender's composing client22:02
fungii think gmail may attempt to associate messages by subject header, which is nonstandard behavior22:03
gouthamrugh, pbkac actually, ty for explaining.. i was matching the in-reply-to and actually saw the mess up22:06
fungiif it's your own post you want to thread up to, going into your sent mail and replying to the copy there should work in theory (just make sure you set the address to the list rather than to yourself)22:10
gouthamr++ worked well for the two other lists22:16
fungiawesome22:16

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!