Thursday, 2026-08-13

opendevreviewJeremy Stanley proposed openstack/ossa master: Add OSSA-2026-035  https://review.opendev.org/c/openstack/ossa/+/100087516:59
fungigouthamr: JayF: rosmaita: ^ (public workflow advisory)17:00
* gouthamr looks17:05
rosmaitafungi: lgtm17:11
gouthamrfungi: asked a question17:13
gouthamrcan turnaround with a quick +2 if you see17:13
fungigouthamr: i'm missing sufficient context to understand the rather terse question you asked there17:15
rosmaitapretty sure it's the QOS policy that can't be deleted (based on the LP bug description)17:16
gouthamrsorry, maybe it was my misunderstanding of the bug17:16
rosmaitabut i don't know a lot about octavia17:16
JayFmy read on it == rosmaita 17:16
fungiyes, if you're asking what it prevents deletion of, it's that the owner of the qos policy can't delete it once it's associated with someone else's amphora17:16
gouthamrmy bad then, yes17:17
JayFattacker creates an amphora, attaches the victim's qos policy, victim can never delete policy until attacker unattaches17:17
fungi(or the operator unattaches it for them)17:17
gouthamrack; noted that clarification and approved17:18
gouthamrty!17:18
fungito be fair, i was on the fence about whether this needed an advisory at all. the way i would see it playing out in a public cloud is that someone discovers they can't delete their qos policy, they file a trouble ticket, an operator looks into it and fixes the invalid association, problem solved17:19
fungithe main impact is that it wastes operators' time until they realize that it's a malicious behavior and revokes the attacker's account17:19
opendevreviewMerged openstack/ossa master: Add OSSA-2026-035  https://review.opendev.org/c/openstack/ossa/+/100087517:21
gouthamrbut that's the way it is framed17:21
gouthamrbeyond such a nuisance, a different tenant shouldn't be able to use a qos policy meant for someone else17:21
fungias for temporarily including cve request ids in advisory notes, that allows an interested third party to nudge mitre on our behalf if they get tired of not having a cve assignment, because i personally find myself having a hard time caring about cve identifiers most of the time17:22
gouthamri didn't see anything about not sharing request IDs 17:23
JayFI've been putting the CAN IDs in the bugs17:23
fungiwell you mentioned can ids, which i guess is what the new form gives you instead of a request id17:23
JayFunless someone feels strongly, I'm not changing that behavior17:23
gouthamrthat's not public advisory JayF 17:23
gouthamr"This reaches the CNA-LR team, who will review as soon as possible. In the meantime, please do not use the CAN number as a public vulnerability ID."17:23
gouthamr^ and i think i saw something remind me about this somewhere else17:24
JayFYeah, we don't use it as an ID, but we do make them public17:24
JayFwhen the bugs are opened post-embargo17:24
gouthamryes17:24
fungiyeah, we don't use it as a vulnerability id, we use it as a tracking reference17:24
fungiwe say "we requested a cve id and don't have one yet, the request was made on x date and this was the tracking number for the request" basically17:24
fungibecause we don't have time to follow up pestering mitre to process the request, but maybe someone else does17:25
fungithe main annoyance is that launchpad seems to scrape can ids from bug comments and then automatically attach them as cves17:26
fungieven though they're not cves at all17:26
JayFyeah, I usually remove them 17:27
gouthamri'm unable to track whatever i read, maybe i'll find it later when i'm not actively looking :D 17:27
JayFwith the button 17:27
fungimaybe if we don't quote them in can format it would be avoided17:27
gouthamrput a space in it or something to beat their logic17:27
fungi"the request has a CAN ID of NNNNNN"17:28
JayFat some point I'd rather leave the text in proper formats for humans who come later rather than catering to the over-excitable platform :D 17:29
JayFpressing an additional button to remove the invalid one in LP... how long could it take? lolsob17:29
gouthamryeah, technically i think LP is at fault here.. and maybe they'll take a patch.. we shouldn't be the only ones running into this17:29
JayFI'm sure this would ZOOM to the top of their backlog /s :D 17:30
JayF#2 behind the task of "fix the entire internet since AI-bots are breaking it"17:30
gouthamri'll try "hear me, i'm important"17:30
fungi"don't you know who i think i am?!?"17:31
* gouthamr pictures an intense FOSS drama on broadway17:31
fungihah, i just realized i put the wrong date in the note, the cve request was made on 2026-07-27, oh well17:49
funginot all that important to correct17:49
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0107: IPA Container HWM Security Misimplmented  https://review.opendev.org/c/openstack/security-doc/+/100078419:54
JayFfungi: gouthamr: rosmaita: ^ I would like to release this advisory today; it's been revised for Ironic comments.19:55
* gouthamr is looking19:57
opendevreviewMerged openstack/security-doc master: OSSN-0107: IPA Container HWM Security Misimplmented  https://review.opendev.org/c/openstack/security-doc/+/100078420:32
fungisorry, stepped out for food, but lgtm20:56

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!