| fungi | https://bugs.launchpad.net/ironic/+bug/2166511 is now public (duplicate of 2150332) | 13:35 |
|---|---|---|
| JayF | Do we have a practice for when a bug is public security vs public? | 15:13 |
| JayF | Ironic has some class d things I'd like to get outta our "security meeting" dashboard as they aren't urgent | 15:13 |
| fungi | the practice, generally speaking, is we use public security for anything that got or is planned to get an ossa, and regular public (often coupled with the security bugtag) for everything else | 15:14 |
| fungi | ideally everything that's public security type has an ossa task that is either open or fixed, not other closed states | 15:15 |
| fungi | we can certainly revisit that practice, but it's (not-well-recorded) patterns we followed for most of the project's lifetime | 15:17 |
| JayF | https://bugs.launchpad.net/ironic/+bug/2166500 is now open | 15:20 |
| JayF | fungi: that's the answer I wanted | 15:20 |
| JayF | fungi: maybe with the exception of "leave it public sec if it might get an OSSN" in ironic cases :) | 15:21 |
| fungi | now that the vmt is overseeing ossn publication more, i can see maybe extending public security type to cover both ossa and ossn | 15:21 |
| fungi | i suppose the more we can treat those alike, the simpler it may make our lives | 15:22 |
| JayF | that is basically where my mind has been the whole time | 15:36 |
| JayF | hint: if OSSAs and OSSNs both have schemas now, that's step 1 down a path to them being /the same/ schema with a "advisory_type:" key | 15:37 |
| fungi | yes, that was my thought process as well | 15:42 |
| fungi | baby steps | 15:42 |
| gouthamr | > the practice, generally speaking, is we use public security for anything that got or is planned to get an ossa, and regular public (often coupled with the security bugtag) for everything else | 16:39 |
| gouthamr | i haven't followed this consistently | 16:39 |
| fungi | it was never a hard and fast rule, which is why it's not reflected in our process document | 16:39 |
| gouthamr | or never i think, if i think this is class E (not a security bug), yes, i switch to direct public and let the team triage.. but, if this has _some_ OSSA/OSSN potential, i was just keeping things in "Public Security" - causing us much cleanup debt | 16:40 |
| fungi | the goal of that was mainly to make it easier to query for things | 16:42 |
| JayF | gouthamr: fungi: My original question was centered around some Ironic Class D hardening stuff, which we would never advisory... and I just wanted it outta the dashboard | 16:44 |
| gouthamr | JayF: ack, would you want operators to still find that security issue easily? if yes, a tag could work.. I can get behind setting "public security" for OSSA worthy bugs alone | 16:46 |
| JayF | I am -1 to the assumption that all Class D hardening opportunities are stuff operators need to track | 16:47 |
| JayF | in Ironic cases, it often means just adding to the docs "you are accepting implied security risk A" to the docs | 16:47 |
| JayF | instead of just leaving the 2+2 = equation in the docs for someone to sum together themselves | 16:47 |
| JayF | AI security bots are not as good at devops as actual humans, who woulda thought | 16:47 |
| gouthamr | you've angered a potential civilization with that statement | 16:48 |
| JayF | Oh no! This ephemeral prebuilt ramdisk which you access via ssh doesn't have a well-known host_key! | 16:48 |
| fungi | the horror! | 16:48 |
| JayF | Normal devop: "Yeah. Ephemeral, reusable ramdisks don't have host keys". LLM: "SECURITY ALERT: HOST KEY CHECK MISS CWE-12345 YOU ARE INSECURE" | 16:49 |
| JayF | and I take the approach of yeah, we shouldn't assume folks have that context anymore because [gestures generally at the industry], so being more explicit in the docs is valuable | 16:49 |
| JayF | but those bugs? I don't want any operator thinking about them ever. They are not valuable except in the output of the improved docs. | 16:50 |
| gouthamr | ack makes sense.. switch to "public", and don't need a "security" tag either.. | 16:51 |
| *** mrunge_ is now known as mrunge | 23:12 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!