| JayF | I have workflowed https://review.opendev.org/c/openstack/security-doc/+/1000155 and will begin the migration of OSSNs to build pipeline style now. | 15:08 |
|---|---|---|
| JayF | Please do not workflow any OSSNs without checking with me. | 15:08 |
| JayF | For the two pending ones, I'll push a YAML-migrated version as a new patchset when I've gotten far enough to do so | 15:09 |
| fungi | thanks!!! | 15:10 |
| fungi | this is very exciting | 15:10 |
| fungi | after sooooo many years | 15:10 |
| gouthamr | ++ | 15:11 |
| gouthamr | xek: ^ | 15:11 |
| gouthamr | great stuff, JayF! | 15:11 |
| JayF | point that at sarhiri :) | 15:11 |
| opendevreview | Merged openstack/security-doc master: Migrate OSSN txt files to build pipeline https://review.opendev.org/c/openstack/security-doc/+/1000155 | 15:22 |
| JayF | fungi: uh, I'm having trouble finding a working public URL for ^ | 15:27 |
| JayF | is there AFS delay in play? | 15:27 |
| * JayF has tried https://security.openstack.org/security-notes/index.html + https://security.openstack.org/docs/security-notes/index.html | 15:27 | |
| JayF | https://docs.openstack.org/security-notes/index.html bingo | 15:30 |
| gouthamr | \o/ | 15:34 |
| JayF | I'm adding some docs on creating OSSNs and linkbacks from the VMT guide to OSSN as the next step, while that's under review I'll work on getting yaml drafts up for the keystone pending OSSNs and start on wiki link updating | 15:42 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 15:58 |
| JayF | One thing I will do if I get time today: add some kinda "last updated" date to the OSSN index, since those aren't really timebound at all | 16:02 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs https://review.opendev.org/c/openstack/ossa/+/1002662 | 16:03 |
| JayF | fungi: gouthamr: rosmaita: ^ I'd appreciate a quick review if you have the time to spare. I have dedicated the whole day to completing this migration so the more stuff I can get done, the more polish I can put on the floor :D | 16:04 |
| rosmaita | JayF: will take a look after lunch | 16:05 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs https://review.opendev.org/c/openstack/ossa/+/1002662 | 16:17 |
| fungi | i have always thought including an initial publication date and maybe revision history summary (like we do with ossa/errata) would be helpful in the ossn context | 16:41 |
| JayF | fungi: I have robots pointed at mediawiki to help me do the data migration there, let me know if there's any performance impact and I need to throttle back | 16:52 |
| fungi | noted, as long as they don't look like browsers or llm training crawlers per their agent strings i think they'll directly bypass anubis | 16:59 |
| JayF | I mean, I'm having claude write a script, then I'll review and run it | 16:59 |
| fungi | though it does associate a behavior score with clients by ip address as well, so it's possible that over time if the process takes a lot of requests its score may increase | 16:59 |
| JayF | claude already did some digging on the wiki and didn't appear restricted (sorry if that makes me the bearer of bad news? IDK if you wanna restrict human-backed agents...) | 16:59 |
| fungi | the protections we have in place aren't designed to block llm agents, it's to keep abusive crawlers in check | 17:00 |
| fungi | so if your script is targeted and knows what it wants to retrieve it's unlikely to hit the tripwire, the problem we have is with automation that wants to download ~everything and doesn't even know how to tell when links on pages go to other similar views of mostly the same content they're just fetching redundantly thousands of different ways | 17:01 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: OSSN-0109: EC2-derived tokens retain full privileges https://review.opendev.org/c/openstack/security-doc/+/1002392 | 17:03 |
| JayF | that matches my personal thoughts on these kinda tools, too | 17:03 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: OSSN-0110: Self-service password change does not revoke generators https://review.opendev.org/c/openstack/security-doc/+/1002410 | 17:22 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097 https://review.opendev.org/c/openstack/security-doc/+/1002672 | 17:30 |
| JayF | As discussed in VMT meeting, I'm going to self-land 1002672 as it's an obvious cleanup. Post-facto review always appreciated :) | 17:30 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now https://review.opendev.org/c/openstack/security-doc/+/1002673 | 17:34 |
| JayF | https://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) are the things needing active review for my migration to move forward in git | 17:36 |
| JayF | I'll be executing on the wiki-editing-script here in a few minutes | 17:36 |
| opendevreview | Merged openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097 https://review.opendev.org/c/openstack/security-doc/+/1002672 | 17:45 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now https://review.opendev.org/c/openstack/security-doc/+/1002673 | 17:48 |
| JayF | RFR https://wiki.openstack.org/wiki/OSSN/OSSN-0085 -- this is an example of the edit made by the script I'm about to run across *all OSSNs* in the wiki. Someone please take a look and make sure I didn't misspell "wiki" or something similarly stupid because it'll be a *lot* harder to write a script to edit exiting than to inject a header lol | 17:53 |
| JayF | **edit existing | 17:53 |
| * JayF -> lunch, if folks could make a comment about that wiki page and review https://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) I'd appreciate it | 18:02 | |
| fungi | JayF: wiki admonition lgtm! | 18:04 |
| *** bauzas1 is now known as bauzas | 18:07 | |
| * JayF kicks off the bulk edit | 18:09 | |
| JayF | fungi: https://wiki.openstack.org/wiki/OSSN/OSSN-0093 is "protected" and I appear to have no rights to edit it | 18:17 |
| JayF | other than that, edits complete | 18:17 |
| JayF | if you mark it unprotected, I can point my script at it, or you can manually use your wiki admin to add the note, either way is OK with me | 18:20 |
| fungi | JayF: done, please try again | 18:21 |
| JayF | saved OSSN/OSSN-0093 OSSN-0093 rev 188095 | 18:22 |
| JayF | bingo | 18:22 |
| JayF | I manually did a warning on Security_Notes page | 18:22 |
| JayF | now basically I want the docs updates merged into git before I announce on the ML, if possible. | 18:22 |
| fungi | no idea why, but the page history says that i set it to protected indefinitely in 2024-03-06 for "safety precautions" | 18:22 |
| fungi | i've already forgotten what happened | 18:22 |
| JayF | Well, it's not the canonical copy now | 18:23 |
| JayF | fungi: you have any use for this bulk edit thing claude coughed up? I was going to dispose of it | 18:23 |
| fungi | not really | 18:23 |
| JayF | yeah code quality on it is brual | 18:24 |
| JayF | *brutal | 18:24 |
| JayF | not super reusable | 18:24 |
| JayF | gouthamr: please re-review from base to PS 2 on 1002662 | 18:44 |
| JayF | gouthamr: you are commenting on a fix I made from PS1->PS2 :) | 18:44 |
| JayF | oh, I didn't realize that was a review from before PS2 :D | 18:45 |
| JayF | we saw and fixed the same things indepedently | 18:45 |
| * JayF has more plates spinning currently than usual | 18:45 | |
| fungi | i'll check them out once plates are done spinning | 18:55 |
| * JayF (actually this time) -> lunch, please look at https://review.opendev.org/q/hashtag:%22ossn-migration%22+(status:open) when you can | 19:41 | |
| opendevreview | Brian Rosmaita proposed openstack/ossa master: Add link to process doc on the landing page https://review.opendev.org/c/openstack/ossa/+/1002690 | 20:19 |
| fungi | straw man: https://review.opendev.org/c/openstack/governance/+/1002692 Propose SECURITY.rst goal | 20:45 |
| opendevreview | Merged openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now https://review.opendev.org/c/openstack/security-doc/+/1002673 | 21:14 |
| opendevreview | Jay Faulkner proposed openstack/ossa master: Add linkbacks to new OSSN docs https://review.opendev.org/c/openstack/ossa/+/1002662 | 21:15 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 21:17 |
| JayF | I removed the depends-on which caused zuul to dislike 1002662; please just make sure 1002661 lands first, or else we've committed dead links :D | 21:17 |
| JayF | rosmaita: fungi: ^ updated for comments | 21:17 |
| * JayF is gonna send the announcement to the list in 30-60 minutes, would like to have the process doc landed by then if possible but 🤷♂️ | 21:23 | |
| fungi | build-tox-manuals-publishdocs is angry at 1002661 | 21:33 |
| rosmaita | JayF: want me to fix? | 21:33 |
| JayF | I'm here, I can do it real quick | 21:33 |
| rosmaita | ok, will leave notes, gimme a sec | 21:33 |
| JayF | rosmaita: maybe I do want you to? /home/zuul/src/opendev.org/openstack/security-doc/security-notes/source/index.rst:5: WARNING: toctree contains reference to nonexisting document ':doc:`ossn-process`' [toc.not_readable] | 21:34 |
| rosmaita | sure, it will be faster | 21:34 |
| JayF | ooh, or home/zuul/src/opendev.org/openstack/security-doc/security-notes/source/ossn-process.rst:2: WARNING: Field list ends without a blank line; unexpected unindent. [docutils] | 21:34 |
| JayF | is that causing ossn-process to not be in toctree | 21:34 |
| JayF | which casuses the above error | 21:34 |
| JayF | that one newline fixes the ossn-process error, but not the toctree stuff | 21:36 |
| JayF | if you know that by heart, please go take it rosmaita | 21:36 |
| opendevreview | Brian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 21:36 |
| JayF | OH | 21:37 |
| rosmaita | oops, need one more go at this | 21:37 |
| JayF | thank you, a diff is worth a thousand characters | 21:37 |
| JayF | gratitude retracted ;) | 21:37 |
| opendevreview | Brian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 21:38 |
| rosmaita | should be ok now | 21:38 |
| JayF | that doesn't render great at all locally | 21:39 |
| JayF | https://usercontent.irccloud-cdn.com/file/78kQvjtk/image.png | 21:39 |
| rosmaita | oh ... that's exactly what i was going for | 21:39 |
| rosmaita | you could put the "creating" link after the toctree, but then no one would ever see it | 21:40 |
| JayF | Yeah, I mainly want it to not be lost in the sea of OSSN-* | 21:40 |
| rosmaita | right, and my thought was that it looked weird as the first ossn in the list | 21:41 |
| JayF | yeah, I think both of those were bad in different ways | 21:41 |
| JayF | I'm trying to think of some third way | 21:41 |
| JayF | that doesn't involve moving half of the first para of ossn-process to the list | 21:41 |
| rosmaita | Well, you could have a short intro paragraph with the link to ossn-process | 21:42 |
| rosmaita | but that could be a followup | 21:42 |
| JayF | this is the landing page I'm going to link to in my announcement, I'm trying to get it cleaned up. This kinda is the followup alerady? if that makes sense | 21:45 |
| JayF | rosmaita: WDYT https://usercontent.irccloud-cdn.com/file/rxmv4sJn/image.png | 21:50 |
| JayF | I think that threads the needle nicely, and as a bonus has a link back to the OSSA page. | 21:50 |
| rosmaita | Yes, LGTM | 21:51 |
| rosmaita | print it! | 21:51 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 21:51 |
| JayF | please just +2A it? I think it's had enough review to carryover | 21:51 |
| rosmaita | i wonder if pep8 is going to barf on that long line in ossn.py | 21:52 |
| JayF | neo, you just have to remember the truth: there is no pep8 | 21:53 |
| rosmaita | if only that were true | 21:53 |
| JayF | (the only linters on that repo are doc8) | 21:53 |
| JayF | `tox -elinters` is passing locally on 1002661 | 21:53 |
| rosmaita | probably won't matter then | 21:53 |
| JayF | and frankly it'd make it 10x uglier to split the line | 21:53 |
| JayF | if anything, I should put that in a .txt file and include it... but KISS + a working thing >>>>> | 21:54 |
| rosmaita | yes, putting into an include file could be a followup | 21:54 |
| fungi | lgtm, belated +2. as long as it merges we can always fix it up later | 21:54 |
| JayF | I mean, my intention was to spend one day on this | 21:55 |
| JayF | then leave it untouched for another decade | 21:55 |
| rosmaita | ok, i workflowed it, hopefully zuul won't have an issue | 21:55 |
| JayF | https://review.opendev.org/c/openstack/ossa/+/1002690/1 is a treat, too | 21:56 |
| JayF | thanks for that Brian (so I don't ping you even more lol) | 21:56 |
| rosmaita | is https://review.opendev.org/c/openstack/ossa/+/1002662 ready now? | 22:05 |
| JayF | yeah, it'll race with the one you just approved | 22:05 |
| JayF | but it'll be fine | 22:05 |
| JayF | oh no! we might have a link pointing to a place that doesn't exist for a minute! The horror! | 22:06 |
| JayF | :d | 22:06 |
| opendevreview | Brian Rosmaita proposed openstack/ossa master: Add link to process doc on the landing page https://review.opendev.org/c/openstack/ossa/+/1002690 | 22:07 |
| rosmaita | JayF: good luck (i am headed out to walk the dog, then dinner) | 22:07 |
| opendevreview | Merged openstack/security-doc master: Move OSSN process documentation into build https://review.opendev.org/c/openstack/security-doc/+/1002661 | 22:09 |
| opendevreview | Merged openstack/ossa master: Add linkbacks to new OSSN docs https://review.opendev.org/c/openstack/ossa/+/1002662 | 22:09 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Trivial: Migrate README.md -> README.rst https://review.opendev.org/c/openstack/security-doc/+/1002698 | 22:12 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Split out OSSN index page headers https://review.opendev.org/c/openstack/security-doc/+/1002699 | 22:12 |
| opendevreview | Merged openstack/ossa master: Add link to process doc on the landing page https://review.opendev.org/c/openstack/ossa/+/1002690 | 22:14 |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Trivial: Remove redundant OSSN txt, move others https://review.opendev.org/c/openstack/security-doc/+/1002704 | 22:28 |
| * JayF is trying to help claude bang out a publication date backfill before EOD | 22:38 | |
| opendevreview | Jay Faulkner proposed openstack/security-doc master: Backfill publication dates for OSSNs; publish them https://review.opendev.org/c/openstack/security-doc/+/1002707 | 22:57 |
| JayF | fungi: no urgency whatsoever, but if you have any historical insight to https://review.opendev.org/c/openstack/security-doc/+/1002707/1/security-notes/OSSN-0032.yaml#8 please let me know :) | 23:01 |
| JayF | Not asking you to do the research, just if you remember a thing please point at it :D | 23:02 |
| *** mrunge_ is now known as mrunge | 23:22 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!