| tkajinam | https://review.opendev.org/c/openstack/releases/+/1001599 | 02:27 |
|---|---|---|
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add yamllint for advisories https://review.opendev.org/c/openstack/ossa/+/1001584 | 05:34 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add yamllint for advisories https://review.opendev.org/c/openstack/ossa/+/1001584 | 05:46 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: OSSA-2026-036 Errata 1 https://review.opendev.org/c/openstack/ossa/+/1001610 | 06:12 |
| gouthamr | o/ need some reviews on this errata: https://review.opendev.org/c/openstack/ossa/+/1001610 | 15:06 |
| JayF | gouthamr: I thought we kept those notes around? | 15:23 |
| JayF | gouthamr: I know for all the Ironic ones I've errata'd a CVE onto, I left the documentation in place as to when we originally requested it | 15:23 |
| JayF | -1 for ^ that | 15:24 |
| gouthamr | we've been inconsistent JayF.. | 15:32 |
| gouthamr | https://review.opendev.org/c/openstack/ossa/+/1001028/2/ossa/OSSA-2026-035.yaml | 15:32 |
| JayF | and of course I didn't notice on that one | 15:32 |
| JayF | I'll remove my vote; but I still think it's the wrong thing to do | 15:33 |
| gouthamr | yeah and rosmaita said that | 15:33 |
| gouthamr | too* | 15:33 |
| JayF | especially when we've had to wait weeks or months | 15:33 |
| gouthamr | :P but what is the use of that kind of info? | 15:33 |
| gouthamr | its on the LP, and git history.. but, why retain it in the advisory? | 15:33 |
| JayF | It's not about use or note | 15:33 |
| JayF | *not | 15:33 |
| JayF | an OSSA is an incident report | 15:34 |
| JayF | you don't remove information from an incident report | 15:34 |
| JayF | when we remove "requested CVE on $date", we remove an item from the timeline | 15:34 |
| rosmaita | i agree with JayF | 15:35 |
| gouthamr | don't feel too strongly about this, but want to do whatever consistently :) fungi, wdyt? | 16:19 |
| fungi | i usually remove the note about the cve request when the cve id is added, the notes to me should present the present state of things not serve as a historical record (the errata list is for that) | 16:42 |
| opendevreview | Sofia Sarhiri proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline https://review.opendev.org/c/openstack/security-doc/+/1000155 | 16:57 |
| gouthamr | i've been thinking retaining "notes" a little bit, and looked at the OSSAs we've published so far. This problem is new and was rare before 2026. i still think request->assignment gap isn't really part of the "incident" we're trying to report and advisory. It is process metadata. keeping it in our advisory will turn into a scorecard for how long MITRE takes on CVE assignments.. | 18:10 |
| gouthamr | we've edited notes before too, looking at git history.. | 18:11 |
| gouthamr | so its not really like a ledger | 18:11 |
| gouthamr | but errata history is a ledger | 18:14 |
| JayF | I can't tell if you think this is a good or a bad thing lol --> keeping it in our advisory will turn into a scorecard for how long MITRE takes on CVE assignments | 19:23 |
| fungi | yeah, i'm not against shaming mitre, i'm just not sure our security advisories are the place to do it | 19:31 |
| JayF | While it'd be a bonus to demonstrate that clearly we can operate security advisories without an external ID (CVE), I was thinking more that it helps indicate *we* asked for the CVE. | 19:36 |
| JayF | either way, if we come down on "remove the note", it's in git, I don't have it as a strongly held opinion | 19:37 |
| JayF | just wanted to be sure we all have a consistent answer to it moving forward | 19:37 |
| fungi | my main reason for removing those notes has been brevity, not presenting the reader with more information than they need | 19:42 |
| fungi | every extra word is a tax on our downstream distributors and users | 19:42 |
| opendevreview | Goutham Pacha Ravi proposed openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph https://review.opendev.org/c/openstack/security-doc/+/1001738 | 20:26 |
| gouthamr | fungi: JayF: so do you think i can still push that errata today? :) | 20:37 |
| gouthamr | fungi JayF rosmaita: sorry to throw you another one, could you please bless this OSSN if you're around and are able.. no pressure; i just wanted to try and avoid sending it out tomorrow (friday), but then, this isn't an OpenStack bug - its guidance to deal with Ceph bugs | 20:47 |
| * gouthamr makes minor formatting changes | 20:48 | |
| opendevreview | Goutham Pacha Ravi proposed openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph https://review.opendev.org/c/openstack/security-doc/+/1001738 | 20:48 |
| rosmaita | gouthamr: looking | 20:50 |
| gouthamr | rosmaita++ ty | 20:52 |
| fungi | gouthamr: sure, i'll take a quick look | 20:54 |
| gouthamr | ty fungi! | 20:54 |
| fungi | this has been a... i dunno... two-year journey for us? so i'm thrilled to finally delete it from my inbox | 20:55 |
| rosmaita | gouthamr: lgtm, fungi can merge it if he doesn't find any issues | 21:04 |
| gouthamr | \o/ | 21:07 |
| gouthamr | thanks rosmaita | 21:07 |
| fungi | i've approved it. i trust other reviewers' input on the technical details since this one's pretty involved | 21:22 |
| gouthamr | \o/ thanks fungi, JayF.. will go live with the wiki and prep email | 21:23 |
| fungi | i'll do what i can to spread the word once it's announced | 21:23 |
| opendevreview | Merged openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph https://review.opendev.org/c/openstack/security-doc/+/1001738 | 21:29 |
| gouthamr | i sent emails to openstack lists | 21:35 |
| gouthamr | for oss-security, i'll just tweak the subject slightly | 21:36 |
| gouthamr | "Multiple authentication vulnerabilities in Ceph affecting OpenStack" | 21:36 |
| fungi | yeah, it's not an openstack-specific vulnerability so some titular acrobatics are warranted | 21:38 |
| gouthamr | ++ Done | 21:39 |
| gouthamr | i can haz yas/no for https://review.opendev.org/c/openstack/ossa/+/1001610 ? :) | 21:40 |
| fungi | approved | 21:45 |
| fungi | we don't have time to slow down, unfortunately | 21:45 |
| opendevreview | Merged openstack/ossa master: OSSA-2026-036 Errata 1 https://review.opendev.org/c/openstack/ossa/+/1001610 | 21:53 |
| gouthamr | ty, emails sent! :) | 22:12 |
| fungi | accepted the openstack-announce copy | 22:18 |
| fungi | https://bugs.launchpad.net/mistral/+bug/2164561 is now public | 22:38 |
| *** mrunge_ is now known as mrunge | 23:28 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!