Thursday, 2026-07-23

mharley[m]fungi: and JayF , I'm the current security liaison for Barbican and the PTL for the project.  How can I start working on the CVEs for OpenStack?12:52
mharley[m]I mean, joining the VMT.12:53
fungimharley[m]: beyond those for barbican? we could use help following up on the (currently 20) public ossa bugs that are open, to figure out if they meet the criteria for an advisory or get them closed out if not: https://bugs.launchpad.net/ossa13:07
fungialso there are a bunch of documentation changes in flight for clarifying our processes, if you have input: https://review.opendev.org/q/status:open+project:openstack/ossa13:09
fungigouthamr and rosmaita may have some good starter suggestions too13:10
fungiwhen they're around13:11
mharley[m]I'd say not only for Barbican.13:25
mharley[m]I'll  check the links you share and will wait for gouthamr's and rosmalta's inputs.  Thank you, fungi.13:28
gouthamrhttps://bugs.launchpad.net/ironic/+bug/2155826 is now public14:02
gouthamrhttps://bugs.launchpad.net/ironic-python-agent/+bug/2160050 is now public14:03
gouthamr(first link should be: https://bugs.launchpad.net/ironic-python-agent/+bug/2155826)14:03
gouthamrhey mharley[m]; thank you for offering help! yes, like fungi said, stale issues definitely need some attention.. in addition, we have the "ossn" project as well on launchpad: https://bugs.launchpad.net/ossn. Open issues here get very slow love from the vmt that's stretched thin.. it is a project benefitting operators and concerns notes for operators and users on less easily exploitable issues, or, hardening instructions14:07
gouthamrthese are great places to start!14:08
gouthamrTheJulia: quick question, https://review.opendev.org/c/openstack/ironic-python-agent/+/998494 wasn't in JayF's original plans i think? i'll roll it in.. but just wanted to make sure the affected versions string is still correct?14:16
gouthamr'>=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1'14:16
TheJuliayes, I believe that is still correct14:18
gouthamrah, this is #TIL on ironic/ipa branches.. "11.3" is in 14:18
gouthamrty14:19
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-027 (CVE-2026-pending) and OSSA-2026-028 (CVE-2026-54422)  https://review.opendev.org/c/openstack/ossa/+/99849814:21
gouthamrTheJulia ^ would appreciate your review14:22
TheJuliaLGTM14:25
gouthamrthank you, TheJulia .. 14:27
gouthamrfungi looks like this is ready.. ^ 14:27
fungithanks, yes i have the draft render up now double-checking all the urls14:28
TheJuliayup, just double checked the patch numbers14:28
fungithe cve reference on https://bugs.launchpad.net/ironic-python-agent/+bug/2160050 is weird/misleading, i'll remove it unless there's a reason for it14:31
gouthamrthe CVE-2026-pending thingy?14:31
fungino, 2026-203369014:32
fungiwhich doesn14:32
fungi't seem to be a valid identifier14:32
funginot sure how it got inserted/detected there14:32
gouthamrweird14:32
gouthamri was able to unlink it14:33
fungiyeah, i assumed it was possible14:33
gouthamroh wait, it could be the CAN - JayF may have added it to keep track.. it's still in Activity and i'll comment14:33
gouthamri've stopped bothering with launchpad's CVE tracker addition :( their database is very old.. trailing by months14:34
fungihttps://bugs.launchpad.net/ironic-python-agent/+bug/2155826 has one too14:35
fungiyeah, i mostly worry that (especially in the case of the one without any assignment yet) some downstream will see that on the bug and assume that's a real cve assignment even when we say there's none assigned yet14:35
fungiokay, yeah https://bugs.launchpad.net/ironic-python-agent/+bug/2160050/+activity shows that 2026-07-14 21:57:13 JayF linked cve-2026-2033690 so i agree that was probably the can id14:37
opendevreviewMerged openstack/ossa master: Add OSSA-2026-027 (CVE-2026-pending) and OSSA-2026-028 (CVE-2026-54422)  https://review.opendev.org/c/openstack/ossa/+/99849814:50
fungipromote succeeded at 14:51:53 so should be published to the site just after the 14:55 vos release14:53
fungiand they're up!14:55
fungigouthamr: ^14:55
gouthamrty fungi; emails going out in a couple14:57
fungii'm on hand to approve through openstack-announce moderation14:57
fungihttps://bugs.launchpad.net/ironic-python-agent/+bug/2161610 is now public (dupe of 2160050)14:58
gouthamrsent :) 14:59
fungiapproved both15:00
gouthamrty!15:01
mharley[m]Thank you for the instructions, gouthamr.  Will take a look at them all tomorrow.16:51
gouthamrmharley[m]: take your time. Since this is sensitive work, we bring folks in based on their demonstrated understanding of the processes and the quality of their contributions. There's no formal VMT onboarding path yet, but joining this security-sig and working through the open OSSA and OSSN bugs is exactly how you build that trust. We appreciate the help!17:15
mharley[m]\o/17:27
gouthamrtkajinam: fungi was asking if you need help with releases? backports? 17:27
fungithere's already some discussion on the zaqar release request in the #openstack-releases channel, yes17:28
tkajinambackports are all merged and settled. releases are remaining.17:28
tkajinamI can probably leave it to Hao for one day and will check the status tomorrow, but I was discussion potential impact of that bug with gouthamr in background and it might require us to accelerate the release.17:29
tkajinamI was discussing *17:29
gouthamri think the patches and an OSSA might be more helpful17:30
gouthamri can work on this right away17:30
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99855018:16
gouthamr^ fungi (cc tkajinam) ready for your perusal 18:34
fungithanks!18:35
gouthamri'm having a better-than-i-expected response on https://review.opendev.org/c/openstack/governance/+/996563 so far :) 18:35
gouthamrbut at some point, i want to call it done and have the VMT/security-sig use that info rather than it sitting on gerrit18:36
gouthamrwould appreciate thoughts from you folks18:36
gouthamrthen will whip tc votes18:36
fungigouthamr: i spotted one inaccuracy on 2026-02918:39
fungialso not mentioned, but it seems to lack the usual "all deployments of zaqar are affected" or whatever from our usual impact description template18:40
fungicould argue that's implied, i wouldn't block on that18:40
gouthamrah! yes, fixing both18:40
fungiif you already fed that version list to mitre you might want to update them with the correction once this merges18:41
gouthamryes18:42
opendevreviewGoutham Pacha Ravi proposed openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99855018:44
gouthamrfungi: wdyt we should do with ^, publish now, or wait for acks and send the email tomorrow? (friday though)19:18
fungigouthamr: i went ahead and approved it, tkajinam can always follow up with corrections later if there's something else we missed19:34
gouthamrw00t, will line up emails19:34
opendevreviewMerged openstack/ossa master: Add OSSA-2026-029 (CVE-2026-pending)  https://review.opendev.org/c/openstack/ossa/+/99855019:37
fungigouthamr: and it's already live at https://security.openstack.org/ossa/OSSA-2026-029.html19:40
gouthamrack, emailing now19:41
gouthamremails sent; i fixed the username in the description in the email directly, but will address that in the errata update when the CVE assignment comes in too19:45
fungigood catch, i missed that19:49
gouthamrtkajinam: great legwork on this, thank you for pointing out the issue, fixing it up and getting releases lined up19:49

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!