| mharley[m] | fungi: and JayF , I'm the current security liaison for Barbican and the PTL for the project. How can I start working on the CVEs for OpenStack? | 12:52 |
|---|---|---|
| mharley[m] | I mean, joining the VMT. | 12:53 |
| fungi | mharley[m]: beyond those for barbican? we could use help following up on the (currently 20) public ossa bugs that are open, to figure out if they meet the criteria for an advisory or get them closed out if not: https://bugs.launchpad.net/ossa | 13:07 |
| fungi | also there are a bunch of documentation changes in flight for clarifying our processes, if you have input: https://review.opendev.org/q/status:open+project:openstack/ossa | 13:09 |
| fungi | gouthamr and rosmaita may have some good starter suggestions too | 13:10 |
| fungi | when they're around | 13:11 |
| mharley[m] | I'd say not only for Barbican. | 13:25 |
| mharley[m] | I'll check the links you share and will wait for gouthamr's and rosmalta's inputs. Thank you, fungi. | 13:28 |
| gouthamr | https://bugs.launchpad.net/ironic/+bug/2155826 is now public | 14:02 |
| gouthamr | https://bugs.launchpad.net/ironic-python-agent/+bug/2160050 is now public | 14:03 |
| gouthamr | (first link should be: https://bugs.launchpad.net/ironic-python-agent/+bug/2155826) | 14:03 |
| gouthamr | hey mharley[m]; thank you for offering help! yes, like fungi said, stale issues definitely need some attention.. in addition, we have the "ossn" project as well on launchpad: https://bugs.launchpad.net/ossn. Open issues here get very slow love from the vmt that's stretched thin.. it is a project benefitting operators and concerns notes for operators and users on less easily exploitable issues, or, hardening instructions | 14:07 |
| gouthamr | these are great places to start! | 14:08 |
| gouthamr | TheJulia: quick question, https://review.opendev.org/c/openstack/ironic-python-agent/+/998494 wasn't in JayF's original plans i think? i'll roll it in.. but just wanted to make sure the affected versions string is still correct? | 14:16 |
| gouthamr | '>=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1' | 14:16 |
| TheJulia | yes, I believe that is still correct | 14:18 |
| gouthamr | ah, this is #TIL on ironic/ipa branches.. "11.3" is in | 14:18 |
| gouthamr | ty | 14:19 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-027 (CVE-2026-pending) and OSSA-2026-028 (CVE-2026-54422) https://review.opendev.org/c/openstack/ossa/+/998498 | 14:21 |
| gouthamr | TheJulia ^ would appreciate your review | 14:22 |
| TheJulia | LGTM | 14:25 |
| gouthamr | thank you, TheJulia .. | 14:27 |
| gouthamr | fungi looks like this is ready.. ^ | 14:27 |
| fungi | thanks, yes i have the draft render up now double-checking all the urls | 14:28 |
| TheJulia | yup, just double checked the patch numbers | 14:28 |
| fungi | the cve reference on https://bugs.launchpad.net/ironic-python-agent/+bug/2160050 is weird/misleading, i'll remove it unless there's a reason for it | 14:31 |
| gouthamr | the CVE-2026-pending thingy? | 14:31 |
| fungi | no, 2026-2033690 | 14:32 |
| fungi | which doesn | 14:32 |
| fungi | 't seem to be a valid identifier | 14:32 |
| fungi | not sure how it got inserted/detected there | 14:32 |
| gouthamr | weird | 14:32 |
| gouthamr | i was able to unlink it | 14:33 |
| fungi | yeah, i assumed it was possible | 14:33 |
| gouthamr | oh wait, it could be the CAN - JayF may have added it to keep track.. it's still in Activity and i'll comment | 14:33 |
| gouthamr | i've stopped bothering with launchpad's CVE tracker addition :( their database is very old.. trailing by months | 14:34 |
| fungi | https://bugs.launchpad.net/ironic-python-agent/+bug/2155826 has one too | 14:35 |
| fungi | yeah, i mostly worry that (especially in the case of the one without any assignment yet) some downstream will see that on the bug and assume that's a real cve assignment even when we say there's none assigned yet | 14:35 |
| fungi | okay, yeah https://bugs.launchpad.net/ironic-python-agent/+bug/2160050/+activity shows that 2026-07-14 21:57:13 JayF linked cve-2026-2033690 so i agree that was probably the can id | 14:37 |
| opendevreview | Merged openstack/ossa master: Add OSSA-2026-027 (CVE-2026-pending) and OSSA-2026-028 (CVE-2026-54422) https://review.opendev.org/c/openstack/ossa/+/998498 | 14:50 |
| fungi | promote succeeded at 14:51:53 so should be published to the site just after the 14:55 vos release | 14:53 |
| fungi | and they're up! | 14:55 |
| fungi | gouthamr: ^ | 14:55 |
| gouthamr | ty fungi; emails going out in a couple | 14:57 |
| fungi | i'm on hand to approve through openstack-announce moderation | 14:57 |
| fungi | https://bugs.launchpad.net/ironic-python-agent/+bug/2161610 is now public (dupe of 2160050) | 14:58 |
| gouthamr | sent :) | 14:59 |
| fungi | approved both | 15:00 |
| gouthamr | ty! | 15:01 |
| mharley[m] | Thank you for the instructions, gouthamr. Will take a look at them all tomorrow. | 16:51 |
| gouthamr | mharley[m]: take your time. Since this is sensitive work, we bring folks in based on their demonstrated understanding of the processes and the quality of their contributions. There's no formal VMT onboarding path yet, but joining this security-sig and working through the open OSSA and OSSN bugs is exactly how you build that trust. We appreciate the help! | 17:15 |
| mharley[m] | \o/ | 17:27 |
| gouthamr | tkajinam: fungi was asking if you need help with releases? backports? | 17:27 |
| fungi | there's already some discussion on the zaqar release request in the #openstack-releases channel, yes | 17:28 |
| tkajinam | backports are all merged and settled. releases are remaining. | 17:28 |
| tkajinam | I can probably leave it to Hao for one day and will check the status tomorrow, but I was discussion potential impact of that bug with gouthamr in background and it might require us to accelerate the release. | 17:29 |
| tkajinam | I was discussing * | 17:29 |
| gouthamr | i think the patches and an OSSA might be more helpful | 17:30 |
| gouthamr | i can work on this right away | 17:30 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998550 | 18:16 |
| gouthamr | ^ fungi (cc tkajinam) ready for your perusal | 18:34 |
| fungi | thanks! | 18:35 |
| gouthamr | i'm having a better-than-i-expected response on https://review.opendev.org/c/openstack/governance/+/996563 so far :) | 18:35 |
| gouthamr | but at some point, i want to call it done and have the VMT/security-sig use that info rather than it sitting on gerrit | 18:36 |
| gouthamr | would appreciate thoughts from you folks | 18:36 |
| gouthamr | then will whip tc votes | 18:36 |
| fungi | gouthamr: i spotted one inaccuracy on 2026-029 | 18:39 |
| fungi | also not mentioned, but it seems to lack the usual "all deployments of zaqar are affected" or whatever from our usual impact description template | 18:40 |
| fungi | could argue that's implied, i wouldn't block on that | 18:40 |
| gouthamr | ah! yes, fixing both | 18:40 |
| fungi | if you already fed that version list to mitre you might want to update them with the correction once this merges | 18:41 |
| gouthamr | yes | 18:42 |
| opendevreview | Goutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998550 | 18:44 |
| gouthamr | fungi: wdyt we should do with ^, publish now, or wait for acks and send the email tomorrow? (friday though) | 19:18 |
| fungi | gouthamr: i went ahead and approved it, tkajinam can always follow up with corrections later if there's something else we missed | 19:34 |
| gouthamr | w00t, will line up emails | 19:34 |
| opendevreview | Merged openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending) https://review.opendev.org/c/openstack/ossa/+/998550 | 19:37 |
| fungi | gouthamr: and it's already live at https://security.openstack.org/ossa/OSSA-2026-029.html | 19:40 |
| gouthamr | ack, emailing now | 19:41 |
| gouthamr | emails sent; i fixed the username in the description in the email directly, but will address that in the errata update when the CVE assignment comes in too | 19:45 |
| fungi | good catch, i missed that | 19:49 |
| gouthamr | tkajinam: great legwork on this, thank you for pointing out the issue, fixing it up and getting releases lined up | 19:49 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!