Thursday, 2026-08-27

cardoegouthamr: I'd like to bring up https://review.opendev.org/c/openstack/keystone/+/979789 and https://review.opendev.org/c/openstack/keystone/+/975342 these are the cause a reproducible crasher in keystone. I can denial of service keystone by just running skyline configured with federation. I've been asking to bring these up at meetings and IRC but there's been 0 traction.01:17
cardoeFor next week01:17
cardoehttps://bugs.launchpad.net/keystone/+bug/2139467 it's been a reported crasher for 7 months01:21
cardoeJust seems bad to ignore.01:21
gouthamrcardoe: ack, we might overload the agenda at this point though.. can we chat here? Artem and Dave Wilde are both afk for a bit - holidays.. but xek and dmendiza[m] should be around and can help figure out this specific issue06:41
gouthamrhave you asked in a keystone meeting?06:42
gouthamrtbf, xek is struggling to get reviews on fixes for OSSA-2026-03706:42
gouthamr2/4 active reviewers are out, and one of them wrote/shepherded the fix, so, we're in a pickle.. i don't know if knikolla works on keystone anymore.. the last comment on gerrit from him was from Jan 202506:43
gouthamrhttps://review.opendev.org/admin/groups/keystone-core,members06:44
opendevreviewIvan Anfimov proposed openstack/governance master: Update Zun release/security liaisons  https://review.opendev.org/c/openstack/governance/+/100250109:10
cardoegouthamr: kinda makes my ML post relevant about culling inactive cores12:10
cardoegouthamr: so I think the issue is more about a difference in opinion. some things can already be done and why federated users should be excluded from some operations13:19
TheJuliaInteresting you bring up culling because I had a discussion recently where it was raised to me that a lack of actively doing so in a project creates an inherent security risk because its functionally a violation of the concept of least privilege when a user has lingering rights not actively being exercised. On the human side I think its easy just to grant rights back to people if they ask at some point down the road.13:19
cardoeI absolutely agree. That person is also less likely to notice if their credentials get hacked because they are not active in that space.13:22
TheJuliayup13:22
fungiyes, the presence of unused accounts in a privileged group makes them especially attractive targets of compromise since their owners aren't around to notice activity which isn't actually theirs and others may simply be fooled into thinking they've come back13:47
cardoefungi: yep that's my concern14:25
sean-k-mooneyfor what its worth i am planing to simiarly triage the membership fo the cyrbog core team groups15:09
sean-k-mooneywhen doing this for watcher the intally approch we took was if you have not activly contibuted to the review or mantiance of any of the release corresponding to the  current stable brnach then you were a candiate for removal15:11
sean-k-mooneyi.e. if some one was last active in 2024.2 or older and has not done any review or other contibutions since then they woudl be condiered an inactive core15:12
gouthamryeah some "automatic" revocation norms would actually help maintainers set the expectations without fear or favor 15:12
sean-k-mooneyrevieiwing the membership is on my todo list after rc115:15
JayFcardoe: for the future, a reproducable DoS in Keystone is likely a security vulnerability. That issue should've gone through VMT process.15:16
JayFcardoe: and while I hate that the VMT ends up in this role, designating something a security issue and putting a deadline on it helps with prioritization15:16
JayFcardoe: I don't what this to be the openstack community, but it's the one we got15:16
cardoeWell I didn't realize you could DoS it at first. I thought it was just a functionality bug so I wrote a patch.15:17
cardoeUntil someone clicked the button in a dev env with like 2 keystone workers running as rapidly as they could and other stuff was bad.15:17
sean-k-mooneyi mean its not to late to treat it as a public security bug15:19
sean-k-mooneyand if requried issue an adveisory15:19
JayFwith it being a public bug now, I'll leave that to the general keystone contributor/community base15:20
JayFit's not likely to be a class a, which means OSSA (advisory) is unlikely, and OSSN (note) usually is a community choice15:20
opendevreviewMerged openstack/security-doc master: Migrate OSSN txt files to build pipeline  https://review.opendev.org/c/openstack/security-doc/+/100015515:22
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266115:58
fricklersean-k-mooney: 2024.2 is pretty generous IMO, I was thinking to apply the same criteria as for AC status. that would even be quite easy to check automatically, just match the list in gerrit with the roll generated from the election tooling. likely the shouldn't be a hard "drop them all" list, but rather a "take a close look" one16:20
sean-k-mooneyfrickler: well my intial tinking ws if non of the branche that are under stable mantacnes are ones you have help maintian then your inactive16:22
fricklerand if that check finds persons that the PTL or whoever checks this think still are active in some other way, that would also give a good motivation to add them as extra-ACs explicitly 16:22
sean-k-mooneybut that was more because fo not having any other better suggetion16:23
fricklersean-k-mooney: ah, so you were thinking fresh contributions to older stable branches? I'm not even sure whether the election tooling wouldn't consider those, need to check the code. or maybe fungi knows right away because he was dealing with the code recently?16:25
sean-k-mooneywell if your a core but dont review on master but have been reviing backprot then that still somewhat active16:26
sean-k-mooneyperhaps movign you to the stabel core group after a few release woudl refect reality better16:26
sean-k-mooneybut its not a 0 impact16:26
frickleryes, I agree, I'm just not sure how the tooling handles this16:26
sean-k-mooneyoh well we just looked in gerrit for reviews using before/after16:27
sean-k-mooneynothing fancy16:27
sean-k-mooneybut we also tried to let folkd know a cycle in advance 16:27
sean-k-mooneyi.e. after rc1 we cleaned up really old memeber and said to the folkd that were effectivly inactive for 18 months that we woudl remvoe them at the end of the cycle if they were not active16:28
fricklerotoh it would sound weird to me if someone actively said "I'll review only stable/2025.2 and older". it may happen by chance, yes, but why would someone actively decide for that?16:28
sean-k-mooneywell elodilles  mainly reviews older banches :)16:28
sean-k-mooneyand nwere one but there are folks that due to there jobs or use of openstack care more about stabel branches then new features16:29
sean-k-mooneybut i agree its the excpetion rather then the norm16:29
frickleryes, but all stable branches afaict, that would also stay within the "last two cycles" running windows16:29
sean-k-mooneyyep the (once it becomes unmaintined/) guidline was kind of arbiarty whiel we were reviving the project16:30
sean-k-mooneyas with cybrog i didnt want to just remvoe peopel as one fo the first things after being approinted to the core team16:31
sean-k-mooneyfor established and fucntionging teams i think refelctign on the memberhsip each cycle after rc1 is a good thing16:31
sean-k-mooneyits after the electiosn and ff rush16:31
fungifrickler: the election tooling does include stable branch contributions just like the master/main branch, doesn't differentiate, though *in addition* you can tell it to generate a list of people involved specifically in stable branch work because that used to be how we determined the electorate and ptl candidates for the stable branch management team (which hasn't existed for16:37
fungimany years now but it's never been cleaned up in the tools)16:37
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0109: EC2-derived tokens retain full privileges  https://review.opendev.org/c/openstack/security-doc/+/100239217:03
fricklerfungi: thanks for confirming. just for completeness: are other branches like unmaintained, ironic bugfix or possible feature branches counted as well or are those excluded?17:07
fungiactivity on all branches of official deliverables are aggregated to determine the electorate and ptl candidate qualification17:08
fungiincluding feature branches, backport branches, unmaintained branches, et cetera17:08
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0110: Self-service password change does not revoke generators  https://review.opendev.org/c/openstack/security-doc/+/100241017:22
fungifrickler: put another way, what the election tooling queries is the owners of changes that merged to an official deliverable repository within a set timeframe (and now anyone who left a cr+2 or w+1 on those same changes), it doesn't look at branch information at all, just the repository for each change17:28
fungithis is also why the definition for atc/ac has basically always talked about cycles and not releases. it's not changes that went into particular releases but changes that merged in certain cycles17:29
opendevreviewJay Faulkner proposed openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097  https://review.opendev.org/c/openstack/security-doc/+/100267217:30
fungieven the contributors we thank on the release marketing pages are a list of all people who contributed during the cycle, not only people whose work directly landed in that final release17:31
fungiso if you only had a stable/2026.1 backport merge during the 2026.2 hibiscus cycle, you're still a hibiscus contributor from that perspective17:32
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267317:34
frickleroh, interesting topic: that list still only includes "changes merged", but not "core reviews" or extra-acs? might be an opportunity to make at least 10 extra people happy if I remember the number correctly17:36
fungifor hibiscus it will include the core reviewers, because i just run the same tools the election officials use to generate the list (merely with different start/end dates)17:36
fungino actual changes needed on my end now that the election tooling has been updated17:37
fungiand it has always included the extra a(t)cs17:38
fungiand more recently, contributors to sig-owned and tc-owned repos17:38
fricklerok, cool17:40
opendevreviewMerged openstack/security-doc master: Minor cleanups for OSSN-0004, OSSN-0097  https://review.opendev.org/c/openstack/security-doc/+/100267217:45
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267317:48
*** bauzas1 is now known as bauzas18:07
gouthamrwhen do you pull this list, fungi 18:16
gouthamri want to suggest a follow up list to thank folks that worked on security issues during this release, and would like to coordinate it with tc/foundation staff/vmt.. 18:18
fungigouthamr: rc118:18
fungifrom a thanks perspective, the development cycle extends from the rnd of rc1 week for the prior release to the end of rc1 week of the current release18:19
*** Unknown123 is now known as Mike--18:19
fungibasically the point at which stable branches are created in cycle-with-rc model deliverables and further commits to master are targeting the 2027.1 release rather than the 2026.2 release18:20
gouthamrmakes sense; and i can work with that18:22
JayFgouthamr: solve a vuln, get a VMTee?18:25
JayFgouthamr: go tell your bosses we need t-shirt budget, go go go :D 18:25
JayFlol18:25
gouthamri wish :P 18:25
fungivmtee, love it18:26
gouthamr"VMTee" is awesome18:26
gouthamrVM+Tee :P i'm tripping18:26
fungithough chances are all we can afford is a cup of vmtea18:26
JayFHere's your VMTNFT, it's a goofy looking money who loves security! wow!18:30
JayFs/money/monkey/ 18:30
JayF(although on reflection, I think they were technically bored apes)18:30
TheJuliaCan we go for morale stile patches instead?18:39
TheJuliaerr, style18:39
fungionly if we can call them "security patches"18:42
JayFIf OpenStack is corporate OSS, and we do punk-style recognition patches, I think that officially makes us a Poseur ;) 18:43
fungii'll start wearing a fully-patched jacket18:43
clarkbthe extra fancy water bottle stickers (basically an evolution of the laptop sticker that handles water better) are all the rage right now. "Bug killing device" with an image of water drowning a mosquito or something18:44
JayF[I survived the 2026 LLMSecuroPacalypse]18:51
fungiaipocalypse18:54
* TheJulia has a silly idea to surface18:55
gouthamrya’ll are too optimistic, we have three more months 18:56
funginah, i think 2026 will stretch on for many years, much like the eternal september19:00
JayFgouthamr: I self-edited a (so far) outta that message lol19:00
TheJuliaWho has the fast forward button then?19:39
TheJulia(and if it is actually a relativistic drive, I'll be worried)19:40
*** Unknown123 is now known as Mike--19:43
gouthamrit's shaped like fast-forward on amazon prime video than the one on netflix19:48
TheJulia:(19:53
fungigouthamr: is that the button labeled "please show me another commercial"?20:07
opendevreviewJeremy Stanley proposed openstack/governance master: Propose SECURITY.rst goal  https://review.opendev.org/c/openstack/governance/+/100269220:44
JayFI don't have a fast forward button, but I am an expert in time travel.21:03
JayFBeen moving forward at a rate of 1 second per second for approximately 42 years ;) 21:03
opendevreviewMerged openstack/security-doc master: OSSN canonical URLs are in docs.openstack.org, now  https://review.opendev.org/c/openstack/security-doc/+/100267321:14
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:17
fungiJayF: i have a magic time travel bag that i can put over my head go forward in time at the speed of normal time21:31
fungiwhen i take the bag off my head i've been magically transported into the future that amount of time21:31
JayFI have one of those, but instead of a bag, I just position myself horizontally on it to zoom 8 hours into the future21:32
fungicomes in really handy for sleeping in airports21:32
JayFit even helps slow down aging if you do it regularly enough!21:32
clarkba few weeks ago I watched someone sleep in an airport across the armrests of those awful chairs that are built to prevent you from sleeping on them. I was very impressed. A real time traveler21:35
opendevreviewBrian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:36
opendevreviewBrian Rosmaita proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:38
opendevreviewJay Faulkner proposed openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266121:51
fungiclarkb: you have convinced me to take up the challenge!22:04
opendevreviewMerged openstack/security-doc master: Move OSSN process documentation into build  https://review.opendev.org/c/openstack/security-doc/+/100266122:09
opendevreviewJay Faulkner proposed openstack/security-doc master: Trivial: Migrate README.md -> README.rst  https://review.opendev.org/c/openstack/security-doc/+/100269822:12
opendevreviewJay Faulkner proposed openstack/security-doc master: Split out OSSN index page headers  https://review.opendev.org/c/openstack/security-doc/+/100269922:12
opendevreviewJay Faulkner proposed openstack/security-doc master: Trivial: Remove redundant OSSN txt, move others  https://review.opendev.org/c/openstack/security-doc/+/100270422:28
opendevreviewJay Faulkner proposed openstack/security-doc master: Backfill publication dates for OSSNs; publish them  https://review.opendev.org/c/openstack/security-doc/+/100270722:57

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!