Tuesday, 2026-06-16

gouthamrhttps://bugs.launchpad.net/glance/+bug/2152110 is now public05:15
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-022 (CVE-2026-46448)  https://review.opendev.org/c/openstack/ossa/+/99360614:11
gouthamrhttps://bugs.launchpad.net/nova/+bug/2151252 is now public14:12
zigoThanks, pushing fixes to osbpo.debian.net14:19
gouthamrzigo++14:19
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-024]: IPA Binary Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/ossa/+/98685014:29
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346514:29
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346514:29
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-024]: IPA Binary Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/ossa/+/98685014:29
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346514:40
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-024]: IPA Binary Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/ossa/+/98685014:40
fungigouthamr: since we've got a backlog for test resources in zuul (there were problems with ovh regions over the past day), i went ahead and confirmed the docs build for 993606 locally and then manually enqueued it into the gate pipeline to get things moving sooner14:43
gouthamrthought that was you14:43
gouthamri was staring at the zuul console :) ty fungi 14:44
gouthamri have a local render copied, will send the email as soon as this merges14:44
fungisounds great, thanks!14:44
fungirax-dfw is finally building the node for the request14:55
fungioh, actually zuul moved the request to raxflex-dfw3 after giving up waiting on rax-dfw14:55
fungiyay! running14:56
gouthamr\o/14:57
opendevreviewMerged openstack/ossa master: Add OSSA-2026-022 (CVE-2026-46448)  https://review.opendev.org/c/openstack/ossa/+/99360614:58
* gouthamr sends emails14:58
fungiapproved the openstack-announce copy now14:59
gouthamrthanks fungi!14:59
sean-k-mooneyso https://bugs.launchpad.net/nova/+bug/2151252 is now public but i not cat while it was embargo the poc was publicly aviable on https://gist.github.com/ so does that mean the embargo was breahced by the very fact this was posted to an external tool/trakcer outside of launchpad18:24
sean-k-mooneyyes you needed ot know the exact url because it marked as secret18:25
sean-k-mooneybut under our vmt proces my understaing is we shoudl not have any external docs or tracker even if they are prviate via obscurity like that18:25
fungiwe should avoid doing things like that, yes, but the vmt makes pragmatic determinations on a case-by-case basis18:27
fungiif it's unlikely that someone could come across the url anywhere or find it through simple scanning/crawling, then we tend to act as if it's effectively still private18:28
fungibut we'd prefer not to have to do that at all, of course18:29
sean-k-mooneyya its secuirty though obsquitiy a least the rnadom assiment looks liek its maybe a uuid without the -18:30
sean-k-mooneyso its not eially guessabel18:30
fungiso in summary, don't do that, but if it happens anyway we have a hard decision to make and it's not necessarily assumed that the embargo is officially broken and ended18:33
sean-k-mooneywell it migh be beter ot move the artifact if it can be removed to an attachment nad update teh description18:34
sean-k-mooneybut ya ill just review the backprot18:34
sean-k-mooneywith that said we need to get beter at making sure we dont skip release notes with secuirt fixes...18:35
fungithe vmt doesn't have any policy mandating it (we don't really have that level of control over project maintainer decisions to begin with), but yes better consistency around that is always helpful to operators/users18:35
sean-k-mooneyright but we woudl normlaly expect one at the project level18:36
sean-k-mooneyif this wasnt a secuirty backport i was ask for it to be added ot follow our normal process18:36
fungiwe could add it as guidance in https://security.openstack.org/#security-information-for-openstack-developers18:36
fungieitehr in the "How to propose and review a security patch" section or "Secure development guidelines" or maybe some new section entirely18:37
sean-k-mooneyhttps://github.com/openstack/reno/blob/master/reno/defaults.py#L58-L7118:38
sean-k-mooneywe have cirtical/secuirt section in the default reno template18:38
sean-k-mooneypresices for this type of bug18:38
sean-k-mooneyit more imporant to fix the issue18:39
sean-k-mooneybut its very little addtional work to also docuemnt it so operator can knwo what is incldued in a given release18:39
opendevreviewJeremy Stanley proposed openstack/ossa master: Retitle and clarify embargoed patch guidelines  https://review.opendev.org/c/openstack/ossa/+/99365418:47
JayFCan I get reviews on https://review.opendev.org/c/openstack/ossa/+/993465 ? I can get OSSA-2026-023 out once it lands19:33
JayFI'll note -024 is changing to an OSSN, so I abandoned that PR19:33
JayFfungi: ^ /me playing channel-hopscotch :D 19:35
* gouthamr looks19:35
gouthamris this for tomorrow?19:36
JayFfor right-now if you approve it19:37
JayF:)19:37
gouthamroh, fix date then :) 19:37
fungilooking19:37
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346519:38
fungii'm good with getting it out today, reviewing now19:38
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366819:39
fungiand then i'll review the ossn next19:39
JayFOSSN is getting W-1 from me, I'm still waiting on some of the backports to get posted19:40
gouthamrposted some comments JayF 19:42
JayFgouthamr: I avoid use of the term "master" when possible in technical contexts in lieu of more inclusive language, like "development". It also mirrors our release language.19:43
fungias did i19:44
gouthamrack19:44
opendevreviewJay Faulkner proposed openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346519:46
JayFgouthamr: fungi: Comments addressed, except the one noted above and the nitpick about short form urls19:48
gouthamrty JayF 19:48
fungithanks! i haven't tested the urls yet to make sure they go to the right changes, but will do that momentarily19:49
* gouthamr loves hashtags and started putting the CVE as one to link everything.. 19:52
fungiconvenient!19:52
JayFI am too busy with these things to provide bells and whistles :)19:52
JayFalthough I encourage the folks writing the fixes to do that19:52
gouthamr:P let me, i've the OCD19:52
JayFrunning OSS*s basically run my executive function to zero19:53
JayFand that would be pulling more from that pool19:53
opendevreviewMerged openstack/ossa master: [OSSA-2026-023] Ironic: Volume props unredacted (CVE-2026-54421)  https://review.opendev.org/c/openstack/ossa/+/99346519:59
fungiJayF: announce at will20:00
fungiit's also live on the security site as of ~20.05 utc20:07
fungiapproved through the openstack-announce moderator queue just now too20:08
JayFthank you20:09
JayFhopefully OSSN-0100 can get out today as well, Clif is working on the backports20:09
fungimy avilability will be spotty coming up while i cook/eat dinner, but i'll try to be around to review and approve that as well20:10
JayFI'll poke gouthamr for reviews, he's in my TZ 20:11
fungithat'll likely be more timely but i'm still happy to serve as a less responsive fallback option this evening just in case20:12
JayFI'll say this as clearly as possible: I never ever want your attention or code review on something not-urgent outside of your normal working hours and/or when you are at dinner/family/whatever-else-not-work time :D 20:13
JayFIf we can't take a whole month off like Curl, we sure as hell can take 16 hours off a day :)20:14
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:21
gouthamr++ what he said20:21
fungiappreciated! though i'm also around odd hours and take breaks, so i don't feel bad keeping an eye on things sometimes anyway20:27
fungibut yes, the curl summer sure is tempting20:27
* fungi makes terrible bananarama/karate kid reference20:28
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:32
JayFgouthamr: ^ that should be the final edition20:32
gouthamrah20:32
gouthamri was just reviewing that20:32
gouthamrcan you look at my comments on the prior PS, still a concern20:33
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:33
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:35
JayFgouthamr: ^ okay, nice catch20:35
opendevreviewJay Faulkner proposed openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:36
JayF(just removed another trailing space :C)20:36
gouthamrgood stuff20:37
fungiso ironic 37.0.0 included the patch?20:37
JayFyes it did20:37
JayFClif found it, when I couldn't, when he tried to backport it 20:38
JayFso ironic and ipa latest bugfix branches have the fix already20:38
fungigot it20:39
gouthamrlgtm20:39
fungilgtm, but holding in case ironic reviewers want to do a last pass20:39
JayFLand it, clif looked at it and Julia's plate is super full20:40
JayFget'r'done20:40
* gouthamr celebrates one hundred security notes20:40
JayFgouthamr: https://www.youtube.com/watch?v=CQeezCdF4mk20:41
fungiapproved in that case20:41
gouthamr:P20:41
JayFIs there a trick for the conversion to wiki format?20:42
JayFOr is it just manual? I did it by hand in -009920:42
gouthamrwe can script this; i did this manually too.. basically "#" becomes "=" for mediawiki.. 20:43
fungii think we've often done it the other way around, just copy the wiki markup view directly into the file in the security-doc repo20:43
JayFYeah, I am always going git first :)20:44
JayFsounds like # -> = and fixing up the lists by hand is all that's needed, that's all I did in the past20:44
JayFhttps://wiki.openstack.org/wiki/OSSN/OSSN-0100 published20:45
* JayF fixing footer layout20:45
gouthamr++20:45
opendevreviewMerged openstack/security-doc master: [OSSN-0100] IPA Command Injection (CVE-2026-43003)  https://review.opendev.org/c/openstack/security-doc/+/99366820:53
gouthamrwould anyone complain if we wrote OSSNs in rst, like OSSAs?20:54
gouthamrpseudo markdown is painful to read :P 20:54
JayFsarhiri is working on a change right now (while also onboarding generally to GR-OSS) to make OSSN/security-notes behave more similarly to OSSAs20:54
gouthamrw00t, you found someone!20:55
fungigouthamr: more preferably yaml, but yes just like ossas20:55
gouthamr++ yes20:56
JayFyeah, she's a full timer at GR-OSS working on developer relations, and stuff like the security-note migration is in scope for the work20:56
JayF(and getting more listeners to my podcast :D)20:56
gouthamrthat's great! 20:56
JayFsome tasks are more achievable than others lol20:56
fungi(yaml with the possibility for embedded rst, which is then converted to an rst doc on the fly)20:56
JayFmy instruction to sarhiri was more or less "make it like OSSA"20:57
JayFwith the note that almost anything in a docs build would be better than what we have now lol20:57
fungiyes, precisely. thanks for finding someone!20:57

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!