Tuesday, 2026-09-22

opendevreviewGrzegorz Grasza proposed openstack/security-doc master: Add OSSN-0111: Keystone MFA enforcement gaps and replay weaknesses  https://review.opendev.org/c/openstack/security-doc/+/100674214:37
JayFOpenStack, like many other open source projects, has had an influx of contribution from security researchers. We have had a record number of security advisories and notes this year: 40 OpenStack Security Advisories (OSSAs) issued this year along with 13 OpenStack Security Notes (OSSNs).21:12
JayFThank you to all OpenStack contributors who assisted with resolving these security issues and we hope that our work on security and reliability will pay off in OpenStack clouds around the world.21:12
JayFfungi: gouthamr: ^ that's my draft blurb for Alison, WDYT21:12
JayFhttps://bugs.launchpad.net/ironic/+bug/2166505 is now public21:19
JayF(for context: 35 of those 40, and 13/13 of them were after 2026.1 release, so I don't think using the full year numbers are misleading)21:24
fungiJayF: i would say "this year *so far*" or to date or whatever, as the year is clearly not over yet and we expect number-go-up21:24
gouthamro/ JayF: i used gazpacho RC1 day as my cut-off earlier.. 21:24
gouthamryeah, i think we'll easily beat the highest ever (think it was 201421:25
gouthamrif you're interested in CVEs: it's 53 CVEs21:25
gouthamrthat's higher than 201421:25
gouthamrotherwise, note looks good to me.. 21:26
gouthamrwow, timing :P 21:26
JayF2014 was 4121:27
JayFi'm claiming the record based on an assumption that we have 2 or more coming in the next 3 months21:27
JayFwhich seems like the easiest assumption in the universe to make lol21:27
gouthamr:| yeah21:27
fungiyeah, the exact time range i used for release stats was 2026-03-13 00:00 utc to 2026-09-11 00:00 utc (start of friday gazpacho rc1 to end of thursday hibiscus rc1)21:27
gouthamr++ ^ i copied that approach21:28
fungibut for the security stuff i don't think we have to be so precise21:28
JayFI was using 4/1 -> (now) for counting OSSAs in/out of the cycle21:28
fungiclose enough, nobody's going to question this21:28
fungibig number, lots work, much sweat21:28
gouthamri suspect you'll respond to allison, JayF 21:29
JayFhave responded :D 21:31
gouthamr++21:35
aprice[m]hello - JayF, gouthamf and fungi - figured coming here to sync on a few things may be helpful21:38
JayFo/21:38
fungicertainly faster for turn-around ;)21:38
aprice[m]thank you for sending over the blurb, JayF. I wanted to proactively flag an edit and explain to see if yall had pushback before we do reviews21:38
JayFI'm already offended you imply my copy was not perfect21:38
JayF:D21:39
aprice[m]for both the press release and the landing page, I want to avoid "a record number of security advisories and notes" because it gives the opportunity to spin the narrative into "OpenStack is not secure"21:39
aprice[m]ha! 21:39
fungii second that concern21:39
JayFI feel more or less the exact opposite, but as I said during a meeting today: I don't usually give input to marketing because I'm a weirdo lol21:39
JayFany attempt to equivocate or use anything but data to talk about security makes me suspicious of the security policy21:40
aprice[m]haha 21:40
aprice[m]well you're a weirdo whose opinion I value greatly21:40
JayFI find it difficult to imagine we could say anything other then the unequivocal truth without it backfiring21:40
fungisecurity relies in our responsiveness and attention to detail, so focusing on that could help21:40
JayFmeaning: if this is a real concern; don't put a blurb in at all21:40
fungiwe can absolutely show how the workload has increased21:41
aprice[m]well i think that putting the data in and how the community has responded is an important part of the story. Because it's not just that they exist, it's that the community is coming together to address them in an open and transparent way21:41
JayFThe truth is: we do have a lot of OSSAs this cycle. We've had a lot of CVEs. The entire OSS community has. Maybe a sentence about how we are in the same tsunami wave everyone else is21:41
fungiyes, i think that makes sense21:41
aprice[m]and yeah, we can talk about the increase, it's just the "record number" that writes the headline we dont want 21:41
aprice[m]right - i liked the part where it was "OpenStack like other OSS projects..." 21:41
JayFlike starting it with: "This year has radically increased reported security vulnerabilities across all open source software; OpenStack is not immune to this trend. [existing blurb with minor edits]"21:41
aprice[m]becuase then other OSS projects can learn from what we are doing. which is important. 21:41
aprice[m]right 21:42
aprice[m]i think that works great21:42
JayFThen maybe replace the platitude at the end with:21:42
aprice[m]no need to get in the Guinness book on this one21:42
JayF"As always, the OpenStack Vulnerability Management team ensures that security issues are handled punctually and discretely. We thank all contributors for assisting in making OpenStack more secure."21:43
JayFif you wanna highlight how professional we are 21:43
aprice[m]YES21:43
aprice[m]love that 21:43
JayFhell maybe even say21:43
aprice[m]haha21:43
aprice[m]i wont show the bar tabs21:43
JayF"Since 2013, the VMT has ensured..."21:43
JayFputting the date on it will anchor that we have been doing this forever21:43
JayFwhich is true, and is something very few other projects have the history to claim21:43
JayFmaybe better than "WE GOT SO MANY CVEs ISN'T IT AWESOME" ;) 21:43
aprice[m]that's perfect because we actually have a callback like that in thierry's quote. so it can show it's not a new, reactive endeavor 21:43
aprice[m]it's something that's been around that is established21:44
aprice[m]OpenStack, like many other open source projects, has had an influx of contribution from security researchers: 40 OpenStack Security Advisories (OSSAs) issued so far this year along with 13 OpenStack Security Notes (OSSNs). As always, the OpenStack Vulnerability Management team ensures that security issues are handled punctually and discretely. We thank all contributors for assisting in making OpenStack more secure.21:44
fungilgtm21:45
JayF+121:48
JayFaprice[m]: you already accepted my talk for OIF NA, and I *will* be gunning for the Guiness book there ;) 21:48
aprice[m]ok great - thanks yall! 21:48
JayFlol21:48
aprice[m]hehe I can't stop you there! 21:48
fungihe's unstoppable21:50
JayFyou may have inspired a "mistake" slide where I put "we've created 67 CVEs this year already" [next slide] [created is struck out and replaced with advisoried]21:51
JayFlol21:51
JayFwe're SO GOOD at making CVEs21:51
fungiyeah, to be totally fair, we created most of the vulnerabilities a very, very long time ago ;)21:53
funginow we're finally fixing them!21:53
JayFwe had the anniversary (10 year!) of the founding of insight softmax (the consulting company whose name is actually on my check)21:53
JayFand one of our folks, David Leadbetter (dgl of https://dgl.cx/) was joked to have resolved more CVEs in his career than created21:54
JayFme, on the other hand: I know better than to count. I know at least 2 where I wrote the broken code, found the security bug, fixed the security bug, and issued the advisory lol21:54
JayFjob security 🪄21:55
fungii do spend rather a lot of time shaking my head at my past self21:55
JayFI always in tech think about it this way: if I look back and don't find things I shake my head at21:55
JayFthat's dangerous; it means I'm not learning or growing21:55
fungiwhat's worse is when i'm going through code and find comments i left for future me about bugs i expected to encounter21:56
fungiand i don't remember writing those comments21:56
fungiso of course i've wasted time debugging some problem only to eventually realize i predicted it years before21:57
* gouthamr ty for jumping in right here aprice[m]! welcome to #openstack-security.. 22:00
aprice[m]woohoo! 22:00
aprice[m]is this where all the fun happens?22:01
fungionly some of the fun22:01
JayFno, that's #openstack-insecurity22:01
gouthamrthis became the most active IRC channel 22:01
JayFbut therapy is only on Thursdays22:01
fungiwe try to spread our fun around22:01
gouthamras a consequence of all the things we've said too22:01
aprice[m]ill be back thursday. never miss community therapy22:04
JayFyeah, we discuss literary topics in #openstack-ironic on Saturdays, too22:04
JayFI forget when the space meeting is in #openstack-nova22:04
JayF(ok I'm done)22:04
-opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline momentarily while we upgrade to a new patch release, but should return within a few minutes23:02
*** mrunge_ is now known as mrunge23:57

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!