Thursday, 2026-07-09

opendevreviewGoutham Pacha Ravi proposed openstack/security-doc master: OSSN-0101: Nova console proxy Origin poisoning  https://review.opendev.org/c/openstack/security-doc/+/99618716:41
gouthamrfungi: JayF rosmaita: ^ can i have your review on this?17:24
fungigouthamr: i was just about done reading through it, so... yes! ;)17:24
JayFWhy is that an OSSN, not an OSSA?17:25
JayFThere's no operator action required other than applying patches, afaict17:25
gouthamrbecause of the classification, this was discussed here.. it wasn't treated as a class A vulnerability because the exploit requires other exploits17:25
JayFack; I think it's confusing that we use that as part of the line but it's technically correct17:26
fungiyeah, that was my main question too, i had to revisit the bug report to confirm17:26
JayFIt's 100% a decoder ring to operators already what OSSN v OSSA means17:26
fungiit was considered a hardening opportunity17:26
JayFand not having "OSSN means you need to do more than apply patches" as the only differentiator makes it harder17:26
fungia hardening opportunity that got fixes backported and a publication about it, but no cve assignment requested17:27
gouthamr+117:27
funginot directly exploitable to a malicious end, but could be chained with other bugs potentially17:27
fungidefinitely a grey area for us17:28
JayFI'm not saying we should have a CVE or anything like that17:28
JayFjust that this is 1000% a area so grey it makes it nearly-impossible for people outside of our sphere to understand OSSA vs N17:28
fungimade more grey by the fact that ossa and ossn were handled by entirely separate groups of people once upon a time, which was the real reason for the distinction17:28
fungibut then the people who handled the ossn process vanished, dumping it in the vmt's lap17:29
JayFMaybe I'll propose a change to make it where "any advisory with only patches, regardless of severity -> OSSA" "any advisory with action needed beyond application of patches, regardless of severity -> OSSN"17:29
JayF"regardless of severity" not meaning we file them in all cases; but instead that "more severe things are OSSAs" would not be true17:29
fungii would be okay with that if we expect to continue having the vmt oversee the ossn process anyway. the reason for the separation before was to offload low-risk concerns to someone other than the vmt17:30
JayFcoordination cost would be greater than the value I suspect17:30
rosmaitawe have also had situations where we did both OSSA and OSSN17:30
fungimaybe explaining it differently: the vmt issued security advisories for things we deemed warranted them. some security practitioners in the community also wanted publications about things the vmt rejected from the advisory process so they came up with their own publication series about those17:32
fungiin reality, when those people then left the community, the ossn publication process would have ended, but the vmt had by that point baked ossn hand-off to the ossg into the vmt process, which we were too few/busy to amend to remove those references17:33
fungithough when it was just me, we basically stopped issuing ossn publications unless someone in the broader community wanted to write one, and then the vmt (me) essentially rubber-stamped them17:35
fungithough not really in the guise of the vmt, i was rubber-stamping them as a security-doc core reviewer/security sig chair17:36
fungii was still not treating it as a responsibility of the vmt members17:36
fungiit's possible that nuanced distinction didn't confer17:37
fungiit was more a result of me wearing too many hats at once17:38
* fungi became a hat tree17:38
opendevreviewMerged openstack/security-doc master: OSSN-0101: Nova console proxy Origin poisoning  https://review.opendev.org/c/openstack/security-doc/+/99618717:56
gouthamrtyty, will react to this discussion in a bit, got into a meeting17:56
gouthamrugh, i messed up the version string18:31
opendevreviewGoutham Pacha Ravi proposed openstack/security-doc master: OSSN-0101: Fix affected version string  https://review.opendev.org/c/openstack/security-doc/+/99670018:32
gouthamrsorry :(18:32
gouthamrhttps://wiki.openstack.org/wiki/OSSN/OSSN-0101 is live ; i'll edit this there too if you folks can approve18:32
gouthamron the process, i agree.. since the VMT seems to now own the thing, and there's an overlap with the security-sig, we can define some rules18:50
gouthamrif the goal is that OSSNs will have some sort of operator intervention beyond applying patches, it'll be a good clarification; i agree that I've been using this as the VMT's classification was not enough to trigger an OSSA.. but, operator notification is still important to suggest an upgrade, so here's an OSSN18:51
gouthamrso if you propose the rules, i'll be +1, JayF 18:52
* gouthamr is a smaller hat tree, still growing some limbs18:53
fungilgtm, rubber-stamped ;)18:56
gouthamrhaha :) 18:56
gouthamrtyty, sending emails18:56
fungiyeah, the various ossn mentions in our taxonomy were essentially a compromise with the ossg back in the day, to indicate the sorts of non-ossa bugs they sometimes would issue an ossn about, though ossn can also be used for more than just vmt cast-off bugs18:57
gouthamryes! external software/systems18:58
fungiaccepted openstack-announce post, version string was certainly correct there!18:58
gouthamrneat :) 18:59
gouthamrwon't bug you anymore, hopefully for today18:59
fungihah, it's the whole reason i come here tho!19:03
gouthamrbugs? :D19:04
opendevreviewMerged openstack/security-doc master: OSSN-0101: Fix affected version string  https://review.opendev.org/c/openstack/security-doc/+/99670019:04
-Guest12850- NOTICE: The Gerrit service on review.opendev.org will be offline briefly one hour from now, at 21:00 UTC, while we rename a project.20:02
-Guest12850- NOTICE: The Gerrit service on review.opendev.org is going offline momentarily at 21:00 UTC while we rename a project, but will return within a few minutes.21:00

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!