Thursday, 2026-08-20

tkajinamhttps://review.opendev.org/c/openstack/releases/+/100159902:27
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add yamllint for advisories  https://review.opendev.org/c/openstack/ossa/+/100158405:34
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add yamllint for advisories  https://review.opendev.org/c/openstack/ossa/+/100158405:46
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: OSSA-2026-036 Errata 1  https://review.opendev.org/c/openstack/ossa/+/100161006:12
gouthamro/ need some reviews on this errata: https://review.opendev.org/c/openstack/ossa/+/100161015:06
JayFgouthamr: I thought we kept those notes around?15:23
JayFgouthamr: I know for all the Ironic ones I've errata'd a CVE onto, I left the documentation in place as to when we originally requested it15:23
JayF-1 for ^ that15:24
gouthamrwe've been inconsistent JayF.. 15:32
gouthamrhttps://review.opendev.org/c/openstack/ossa/+/1001028/2/ossa/OSSA-2026-035.yaml15:32
JayFand of course I didn't notice on that one15:32
JayFI'll remove my vote; but I still think it's the wrong thing to do15:33
gouthamryeah and rosmaita said that15:33
gouthamrtoo*15:33
JayFespecially when we've had to wait weeks or months 15:33
gouthamr:P but what is the use of that kind of info? 15:33
gouthamrits on the LP, and git history.. but, why retain it in the advisory?15:33
JayFIt's not about use or note15:33
JayF*not15:33
JayFan OSSA is an incident report15:34
JayFyou don't remove information from an incident report15:34
JayFwhen we remove "requested CVE on $date", we remove an item from the timeline15:34
rosmaitai agree with JayF15:35
gouthamrdon't feel too strongly about this, but want to do whatever consistently :) fungi, wdyt?16:19
fungii usually remove the note about the cve request when the cve id is added, the notes to me should present the present state of things not serve as a historical record (the errata list is for that)16:42
opendevreviewSofia Sarhiri proposed openstack/security-doc master: Migrate OSSN txt files to build pipeline  https://review.opendev.org/c/openstack/security-doc/+/100015516:57
gouthamri've been thinking retaining "notes" a little bit, and looked at the OSSAs we've published so far. This problem is new and was rare before 2026. i still think request->assignment gap isn't really part of the "incident" we're trying to report and advisory. It is process metadata. keeping it in our advisory will turn into a scorecard for how long MITRE takes on CVE assignments.. 18:10
gouthamrwe've edited notes before too, looking at git history.. 18:11
gouthamrso its not really like a ledger 18:11
gouthamrbut errata history is a ledger18:14
JayFI can't tell if you think this is a good or a bad thing lol --> keeping it in our advisory will turn into a scorecard for how long MITRE takes on CVE assignments19:23
fungiyeah, i'm not against shaming mitre, i'm just not sure our security advisories are the place to do it19:31
JayFWhile it'd be a bonus to demonstrate that clearly we can operate security advisories without an external ID (CVE), I was thinking more that it helps indicate *we* asked for the CVE.19:36
JayFeither way, if we come down on "remove the note", it's in git, I don't have it as a strongly held opinion19:37
JayFjust wanted to be sure we all have a consistent answer to it moving forward19:37
fungimy main reason for removing those notes has been brevity, not presenting the reader with more information than they need19:42
fungievery extra word is a tax on our downstream distributors and users19:42
opendevreviewGoutham Pacha Ravi proposed openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph  https://review.opendev.org/c/openstack/security-doc/+/100173820:26
gouthamrfungi: JayF: so do you think i can still push that errata today? :) 20:37
gouthamrfungi JayF rosmaita: sorry to throw you another one, could you please bless this OSSN if you're around and are able.. no pressure; i just wanted to try and avoid sending it out tomorrow (friday), but then, this isn't an OpenStack bug - its guidance to deal with Ceph bugs20:47
* gouthamr makes minor formatting changes20:48
opendevreviewGoutham Pacha Ravi proposed openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph  https://review.opendev.org/c/openstack/security-doc/+/100173820:48
rosmaitagouthamr: looking20:50
gouthamrrosmaita++ ty20:52
fungigouthamr: sure, i'll take a quick look20:54
gouthamrty fungi!20:54
fungithis has been a... i dunno... two-year journey for us? so i'm thrilled to finally delete it from my inbox20:55
rosmaitagouthamr: lgtm, fungi can merge it if he doesn't find any issues21:04
gouthamr\o/21:07
gouthamrthanks rosmaita 21:07
fungii've approved it. i trust other reviewers' input on the technical details since this one's pretty involved21:22
gouthamr\o/ thanks fungi, JayF.. will go live with the wiki and prep email21:23
fungii'll do what i can to spread the word once it's announced21:23
opendevreviewMerged openstack/security-doc master: OSSN-0108: Multiple authentication vulnerabilities in Ceph  https://review.opendev.org/c/openstack/security-doc/+/100173821:29
gouthamri sent emails to openstack lists21:35
gouthamrfor oss-security, i'll just tweak the subject slightly21:36
gouthamr"Multiple authentication vulnerabilities in Ceph affecting OpenStack"21:36
fungiyeah, it's not an openstack-specific vulnerability so some titular acrobatics are warranted21:38
gouthamr++ Done21:39
gouthamri can haz yas/no for https://review.opendev.org/c/openstack/ossa/+/1001610 ? :)21:40
fungiapproved21:45
fungiwe don't have time to slow down, unfortunately21:45
opendevreviewMerged openstack/ossa master: OSSA-2026-036 Errata 1  https://review.opendev.org/c/openstack/ossa/+/100161021:53
gouthamrty, emails sent! :)22:12
fungiaccepted the openstack-announce copy22:18
fungihttps://bugs.launchpad.net/mistral/+bug/2164561 is now public22:38
*** mrunge_ is now known as mrunge23:28

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!