Thursday, 2026-08-27

JayFI have workflowed https://review.opendev.org/c/openstack/security-doc/+/1000155 and will begin the migration of OSSNs to build pipeline style now.15:08
JayFPlease do not workflow any OSSNs without checking with me.15:08
JayFFor the two pending ones, I'll push a YAML-migrated version as a new patchset when I've gotten far enough to do so15:09
fungithanks!!!15:10
fungithis is very exciting15:10
fungiafter sooooo many years15:10
gouthamr++ 15:11
gouthamrxek: ^15:11
gouthamrgreat stuff, JayF!15:11
JayFpoint that at sarhiri :)15:11
opendevreviewMerged openstack/security-doc master: Migrate OSSN txt files to build pipeline  https://review.opendev.org/c/openstack/security-doc/+/100015515:22
JayFfungi: uh, I'm having trouble finding a working public URL for ^15:27
JayFis there AFS delay in play?15:27
* JayF has tried https://security.openstack.org/security-notes/index.html + https://security.openstack.org/docs/security-notes/index.html15:27
JayFhttps://docs.openstack.org/security-notes/index.html bingo15:30
gouthamr\o/15:34
JayFI'm adding some docs on creating OSSNs and linkbacks from the VMT guide to OSSN as the next step, while that's under review I'll work on getting yaml drafts up for the keystone pending OSSNs and start on wiki link updating15:42
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266115:58
JayFOne thing I will do if I get time today: add some kinda "last updated" date to the OSSN index, since those aren't really timebound at all16:02
opendevreviewJay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs  https://review.opendev.org/c/openstack/ossa/+/100266216:03
JayFfungi: gouthamr: rosmaita: ^ I'd appreciate a quick review if you have the time to spare. I have dedicated the whole day to completing this migration so the more stuff I can get done, the more polish I can put on the floor :D 16:04
rosmaitaJayF: will take a look after lunch16:05
opendevreviewJay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs  https://review.opendev.org/c/openstack/ossa/+/100266216:17
fungii have always thought including an initial publication date and maybe revision history summary (like we do with ossa/errata) would be helpful in the ossn context16:41
JayFfungi: I have robots pointed at mediawiki to help me do the data migration there, let me know if there's any performance impact and I need to throttle back16:52
funginoted, as long as they don't look like browsers or llm training crawlers per their agent strings i think they'll directly bypass anubis16:59
JayFI mean, I'm having claude write a script, then I'll review and run it16:59
fungithough it does associate a behavior score with clients by ip address as well, so it's possible that over time if the process takes a lot of requests its score may increase16:59
JayFclaude already did some digging on the wiki and didn't appear restricted (sorry if that makes me the bearer of bad news? IDK if you wanna restrict human-backed agents...)16:59
fungithe protections we have in place aren't designed to block llm agents, it's to keep abusive crawlers in check17:00
fungiso if your script is targeted and knows what it wants to retrieve it's unlikely to hit the tripwire, the problem we have is with automation that wants to download ~everything and doesn't even know how to tell when links on pages go to other similar views of mostly the same content they're just fetching redundantly thousands of different ways17:01
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0109: EC2-derived tokens retain full privileges  https://review.opendev.org/c/openstack/security-doc/+/100239217:03
JayFthat matches my personal thoughts on these kinda tools, too17:03
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0110: Self-service password change does not revoke generators  https://review.opendev.org/c/openstack/security-doc/+/100241017:22
opendevreviewJay Faulkner proposed openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097  https://review.opendev.org/c/openstack/security-doc/+/100267217:30
JayFAs discussed in VMT meeting, I'm going to self-land 1002672 as it's an obvious cleanup. Post-facto review always appreciated :)17:30
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267317:34
JayFhttps://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) are the things needing active review for my migration to move forward in git17:36
JayFI'll be executing on the wiki-editing-script here in a few minutes17:36
opendevreviewMerged openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097  https://review.opendev.org/c/openstack/security-doc/+/100267217:45
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267317:48
JayFRFR https://wiki.openstack.org/wiki/OSSN/OSSN-0085 -- this is an example of the edit made by the script I'm about to run across *all OSSNs* in the wiki. Someone please take a look and make sure I didn't misspell "wiki" or something similarly stupid because it'll be a *lot* harder to write a script to edit exiting than to inject a header lol17:53
JayF**edit existing17:53
* JayF -> lunch, if folks could make a comment about that wiki page and review https://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) I'd appreciate it18:02
fungiJayF: wiki admonition lgtm!18:04
*** bauzas1 is now known as bauzas18:07
* JayF kicks off the bulk edit18:09
JayFfungi: https://wiki.openstack.org/wiki/OSSN/OSSN-0093 is "protected" and I appear to have no rights to edit it18:17
JayFother than that, edits complete18:17
JayFif you mark it unprotected, I can point my script at it, or you can manually use your wiki admin to add the note, either way is OK with me18:20
fungiJayF: done, please try again18:21
JayF  saved OSSN/OSSN-0093         OSSN-0093  rev 18809518:22
JayFbingo18:22
JayFI manually did a warning on Security_Notes page18:22
JayFnow basically I want the docs updates merged into git before I announce on the ML, if possible. 18:22
fungino idea why, but the page history says that i set it to protected indefinitely in 2024-03-06 for "safety precautions"18:22
fungii've already forgotten what happened18:22
JayFWell, it's not the canonical copy now18:23
JayFfungi: you have any use for this bulk edit thing claude coughed up? I was going to dispose of it18:23
funginot really18:23
JayFyeah code quality on it is brual18:24
JayF*brutal18:24
JayFnot super reusable18:24
JayFgouthamr: please re-review from base to PS 2 on 100266218:44
JayFgouthamr: you are commenting on a fix I made from PS1->PS2 :)18:44
JayFoh, I didn't realize that was a review from before PS2 :D 18:45
JayFwe saw and fixed the same things indepedently18:45
* JayF has more plates spinning currently than usual18:45
fungii'll check them out once plates are done spinning18:55
* JayF (actually this time) -> lunch, please look at https://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) when you can 19:41
opendevreviewBrian Rosmaita proposed openstack/ossa master: Add link to process doc on the landing page  https://review.opendev.org/c/openstack/ossa/+/100269020:19
fungistraw man: https://review.opendev.org/c/openstack/governance/+/1002692 Propose SECURITY.rst goal20:45
opendevreviewMerged openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267321:14
opendevreviewJay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs  https://review.opendev.org/c/openstack/ossa/+/100266221:15
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:17
JayFI removed the depends-on which caused zuul to dislike 1002662; please just make sure 1002661 lands first, or else we've committed dead links :D 21:17
JayFrosmaita: fungi: ^ updated for comments21:17
* JayF is gonna send the announcement to the list in 30-60 minutes, would like to have the process doc landed by then if possible but 🤷‍♂️21:23
fungibuild-tox-manuals-publishdocs is angry at 100266121:33
rosmaitaJayF: want me to fix?21:33
JayFI'm here, I can do it real quick21:33
rosmaitaok, will leave notes, gimme a sec21:33
JayFrosmaita: maybe I do want you to? /home/zuul/src/opendev.org/openstack/security-doc/security-notes/source/index.rst:5: WARNING: toctree contains reference to nonexisting document ':doc:`ossn-process`' [toc.not_readable]21:34
rosmaitasure, it will be faster21:34
JayFooh, or home/zuul/src/opendev.org/openstack/security-doc/security-notes/source/ossn-process.rst:2: WARNING: Field list ends without a blank line; unexpected unindent. [docutils]21:34
JayFis that causing ossn-process to not be in toctree21:34
JayFwhich casuses the above error21:34
JayFthat one newline fixes the ossn-process error, but not the toctree stuff21:36
JayFif you know that by heart, please go take it rosmaita 21:36
opendevreviewBrian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:36
JayFOH21:37
rosmaitaoops, need one more go at this21:37
JayFthank you, a diff is worth a thousand characters21:37
JayFgratitude retracted ;) 21:37
opendevreviewBrian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:38
rosmaitashould be ok now21:38
JayFthat doesn't render great at all locally21:39
JayFhttps://usercontent.irccloud-cdn.com/file/78kQvjtk/image.png21:39
rosmaitaoh ... that's exactly what i was going for21:39
rosmaitayou could put the "creating" link after the toctree, but then no one would ever see it21:40
JayFYeah, I mainly want it to not be lost in the sea of OSSN-*21:40
rosmaitaright, and my thought was that it looked weird as the first ossn in the list21:41
JayFyeah, I think both of those were bad in different ways21:41
JayFI'm trying to think of some third way21:41
JayFthat doesn't involve moving half of the first para of ossn-process to the list21:41
rosmaitaWell, you could have a short intro paragraph with the link to ossn-process21:42
rosmaitabut that could be a followup21:42
JayFthis is the landing page I'm going to link to in my announcement, I'm trying to get it cleaned up. This kinda is the followup alerady? if that makes sense 21:45
JayFrosmaita: WDYT https://usercontent.irccloud-cdn.com/file/rxmv4sJn/image.png21:50
JayFI think that threads the needle nicely, and as a bonus has a link back to the OSSA page.21:50
rosmaitaYes, LGTM21:51
rosmaitaprint it!21:51
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:51
JayFplease just +2A it? I think it's had enough review to carryover21:51
rosmaitai wonder if pep8 is going to barf on that long line in ossn.py21:52
JayFneo, you just have to remember the truth: there is no pep821:53
rosmaitaif only that were true21:53
JayF(the only linters on that repo are doc8)21:53
JayF`tox -elinters` is passing locally on 100266121:53
rosmaitaprobably won't matter then21:53
JayFand frankly it'd make it 10x uglier to split the line21:53
JayFif anything, I should put that in a .txt file and include it... but KISS + a working thing >>>>>21:54
rosmaitayes, putting into an include file could be a followup21:54
fungilgtm, belated +2. as long as it merges we can always fix it up later21:54
JayFI mean, my intention was to spend one day on this21:55
JayFthen leave it untouched for another decade21:55
rosmaitaok, i workflowed it, hopefully zuul won't have an issue21:55
JayFhttps://review.opendev.org/c/openstack/ossa/+/1002690/1 is a treat, too21:56
JayFthanks for that Brian (so I don't ping you even more lol)21:56
rosmaitais https://review.opendev.org/c/openstack/ossa/+/1002662 ready now?22:05
JayFyeah, it'll race with the one you just approved22:05
JayFbut it'll be fine22:05
JayFoh no! we might have a link pointing to a place that doesn't exist for a minute! The horror!22:06
JayF :d 22:06
opendevreviewBrian Rosmaita proposed openstack/ossa master: Add link to process doc on the landing page  https://review.opendev.org/c/openstack/ossa/+/100269022:07
rosmaitaJayF: good luck (i am headed out to walk the dog, then dinner)22:07
opendevreviewMerged openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266122:09
opendevreviewMerged openstack/ossa master: Add linkbacks to new OSSN docs  https://review.opendev.org/c/openstack/ossa/+/100266222:09
opendevreviewJay Faulkner proposed openstack/security-doc master: Trivial: Migrate README.md -> README.rst  https://review.opendev.org/c/openstack/security-doc/+/100269822:12
opendevreviewJay Faulkner proposed openstack/security-doc master: Split out OSSN index page headers  https://review.opendev.org/c/openstack/security-doc/+/100269922:12
opendevreviewMerged openstack/ossa master: Add link to process doc on the landing page  https://review.opendev.org/c/openstack/ossa/+/100269022:14
opendevreviewJay Faulkner proposed openstack/security-doc master: Trivial: Remove redundant OSSN txt, move others  https://review.opendev.org/c/openstack/security-doc/+/100270422:28
* JayF is trying to help claude bang out a publication date backfill before EOD22:38
opendevreviewJay Faulkner proposed openstack/security-doc master: Backfill publication dates for OSSNs; publish them  https://review.opendev.org/c/openstack/security-doc/+/100270722:57
JayFfungi: no urgency whatsoever, but if you have any historical insight to https://review.opendev.org/c/openstack/security-doc/+/1002707/1/security-notes/OSSN-0032.yaml#8 please let me know :)23:01
JayFNot asking you to do the research, just if you remember a thing please point at it :D23:02
*** mrunge_ is now known as mrunge23:22

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!