*** rf0lc0 has quit IRC | 00:22 | |
*** gyee has quit IRC | 00:31 | |
*** ykatabam has quit IRC | 00:34 | |
*** whoami-rajat___ has joined #openstack-meeting | 00:37 | |
*** ianychoi__ is now known as ianychoi | 00:44 | |
*** rcernin has quit IRC | 00:48 | |
*** rcernin has joined #openstack-meeting | 00:55 | |
*** rcernin has quit IRC | 01:08 | |
*** rcernin has joined #openstack-meeting | 01:26 | |
*** rcernin has quit IRC | 01:39 | |
*** ricolin_ has joined #openstack-meeting | 01:45 | |
*** rcernin has joined #openstack-meeting | 02:13 | |
*** ykatabam has joined #openstack-meeting | 02:28 | |
*** macz_ has joined #openstack-meeting | 02:41 | |
*** macz_ has quit IRC | 02:46 | |
*** armax has quit IRC | 03:26 | |
*** ykatabam has quit IRC | 03:29 | |
*** yasufum_ has quit IRC | 03:55 | |
*** armstrong has quit IRC | 04:05 | |
*** ociuhandu has joined #openstack-meeting | 04:08 | |
*** ociuhandu has quit IRC | 04:12 | |
*** psahoo has joined #openstack-meeting | 04:16 | |
*** manpreet has joined #openstack-meeting | 04:21 | |
*** yasufum has joined #openstack-meeting | 04:25 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-meeting | 04:33 | |
*** psahoo has quit IRC | 05:07 | |
*** psahoo has joined #openstack-meeting | 05:07 | |
*** dsariel has left #openstack-meeting | 05:12 | |
*** yasufum_ has joined #openstack-meeting | 05:31 | |
*** yasufum has quit IRC | 05:32 | |
*** yasufum_ is now known as yasufum | 05:32 | |
*** bbowen_ has joined #openstack-meeting | 05:37 | |
*** bbowen has quit IRC | 05:39 | |
*** macz_ has joined #openstack-meeting | 06:18 | |
*** macz_ has quit IRC | 06:22 | |
*** psachin has joined #openstack-meeting | 06:29 | |
*** ralonsoh has joined #openstack-meeting | 06:37 | |
*** vishalmanchanda has joined #openstack-meeting | 06:54 | |
*** slaweq has joined #openstack-meeting | 07:01 | |
*** ociuhandu has joined #openstack-meeting | 07:02 | |
*** rpittau|afk is now known as rpittau | 07:27 | |
*** manpreet has quit IRC | 07:33 | |
*** whoami-rajat___ has quit IRC | 07:33 | |
*** ttx has quit IRC | 07:33 | |
*** moguimar has quit IRC | 07:33 | |
*** jamesdenton has quit IRC | 07:33 | |
*** patrickeast has quit IRC | 07:33 | |
*** mattoliverau has quit IRC | 07:33 | |
*** freefood has quit IRC | 07:33 | |
*** manpreet has joined #openstack-meeting | 07:33 | |
*** moguimar has joined #openstack-meeting | 07:38 | |
*** jamesdenton has joined #openstack-meeting | 07:38 | |
*** patrickeast has joined #openstack-meeting | 07:38 | |
*** mattoliverau has joined #openstack-meeting | 07:38 | |
*** freefood has joined #openstack-meeting | 07:38 | |
*** yasufum has quit IRC | 07:38 | |
*** tosky has joined #openstack-meeting | 07:54 | |
*** rcernin has quit IRC | 07:57 | |
*** e0ne has joined #openstack-meeting | 08:01 | |
*** ttx has joined #openstack-meeting | 08:02 | |
*** yasufum has joined #openstack-meeting | 08:06 | |
*** johnsom has quit IRC | 09:25 | |
*** johnsom has joined #openstack-meeting | 09:25 | |
*** walshh_ has quit IRC | 09:25 | |
*** walshh_ has joined #openstack-meeting | 09:26 | |
*** dalvarez has quit IRC | 09:45 | |
*** armax has joined #openstack-meeting | 09:54 | |
*** macz_ has joined #openstack-meeting | 09:55 | |
*** macz_ has quit IRC | 09:59 | |
*** rcernin has joined #openstack-meeting | 10:29 | |
*** rcernin has quit IRC | 10:31 | |
*** rh-jlabarre has quit IRC | 10:49 | |
*** psachin has quit IRC | 10:53 | |
*** psachin has joined #openstack-meeting | 11:03 | |
*** bcm has quit IRC | 11:05 | |
*** yasufum has quit IRC | 11:08 | |
*** lpetrut has joined #openstack-meeting | 11:25 | |
*** macz_ has joined #openstack-meeting | 11:43 | |
*** macz_ has quit IRC | 11:48 | |
*** rledisez has quit IRC | 11:58 | |
*** alecuyer has quit IRC | 11:58 | |
*** rledisez has joined #openstack-meeting | 11:59 | |
*** raildo has joined #openstack-meeting | 12:00 | |
*** armstrong has joined #openstack-meeting | 12:08 | |
*** rf0lc0 has joined #openstack-meeting | 12:22 | |
*** njohnston has joined #openstack-meeting | 12:24 | |
*** _erlon_ has joined #openstack-meeting | 12:25 | |
*** TrevorV has joined #openstack-meeting | 13:05 | |
*** macz_ has joined #openstack-meeting | 13:31 | |
*** macz_ has quit IRC | 13:36 | |
*** Luzi has joined #openstack-meeting | 13:44 | |
*** eharney_ has joined #openstack-meeting | 14:00 | |
*** jokke has joined #openstack-meeting | 14:00 | |
jokke | #startmeeting glance | 14:01 |
---|---|---|
openstack | Meeting started Thu Oct 8 14:01:03 2020 UTC and is due to finish in 60 minutes. The chair is jokke. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: glance)" | 14:01 | |
openstack | The meeting name has been set to 'glance' | 14:01 |
jokke | #topic roll-call | 14:01 |
*** openstack changes topic to "roll-call (Meeting topic: glance)" | 14:01 | |
jokke | o/ | 14:01 |
*** eharney has quit IRC | 14:01 | |
jokke | Today's Agenda is subject to a change https://etherpad.opendev.org/p/glance-team-meeting-agenda | 14:01 |
Steap | o/ | 14:02 |
jokke | hey | 14:02 |
jokke | giving minute or two to see if we get anyone else joining us | 14:03 |
jokke | ok, so Abhishek had a loss in the family, he is absent today | 14:05 |
jokke | #topic updates | 14:05 |
*** openstack changes topic to "updates (Meeting topic: glance)" | 14:05 | |
jokke | #link https://etherpad.opendev.org/p/Glance-Wallaby-PTG-planning | 14:05 |
jokke | Summit and PG are approaching quick | 14:06 |
jokke | Please give your input in the etherpad linked | 14:06 |
jokke | We tagged RC2, it just contains API version bump otherwise looks like we're good to go for the release | 14:06 |
jokke | Periodic jobs are running green for a change | 14:07 |
jokke | #topic Multi-store tests | 14:07 |
*** openstack changes topic to "Multi-store tests (Meeting topic: glance)" | 14:07 | |
jokke | There is bunch of patches linked in the agenda, I'm not going to repeat them all here. Please feel free to have a look | 14:08 |
jokke | I'm not sure if there was anything else in plans for this tpic that bring awareness | 14:08 |
jokke | #topic Open Discussion | 14:09 |
*** openstack changes topic to "Open Discussion (Meeting topic: glance)" | 14:09 | |
jokke | Steap: did you have something? | 14:09 |
Steap | honestly, not really, except for https://review.opendev.org/749091, but it is more of a downstream thing :) | 14:10 |
jokke | Cool, thanks for bringing that up, rosmaita &smcginnis if you're around at some point ^^ could do with second. ;) | 14:12 |
smcginnis | Will take a look. | 14:13 |
Steap | Thanks :) | 14:13 |
jokke | cheers | 14:13 |
jokke | that's all from my side anything else? | 14:13 |
jokke | ok going 1st | 14:15 |
jokke | going twice | 14:15 |
jokke | Sold! Thanks all! this was quick one. o/~ | 14:16 |
jokke | #endmeeting | 14:16 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 14:16 | |
openstack | Meeting ended Thu Oct 8 14:16:43 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:16 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-10-08-14.01.html | 14:16 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-10-08-14.01.txt | 14:16 |
openstack | Log: http://eavesdrop.openstack.org/meetings/glance/2020/glance.2020-10-08-14.01.log.html | 14:16 |
smcginnis | Probably good the meeting was mostly uneventful at this point in the cycle. ;) | 14:17 |
jokke | ++ | 14:19 |
*** lpetrut has quit IRC | 14:21 | |
*** slaweq has quit IRC | 14:38 | |
*** slaweq has joined #openstack-meeting | 14:42 | |
*** andrebeltrami has joined #openstack-meeting | 14:55 | |
*** priteau has joined #openstack-meeting | 14:59 | |
*** psahoo has quit IRC | 14:59 | |
gagehugo | #startmeeting security | 15:01 |
openstack | Meeting started Thu Oct 8 15:01:43 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. | 15:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 15:01 |
*** openstack changes topic to " (Meeting topic: security)" | 15:01 | |
openstack | The meeting name has been set to 'security' | 15:01 |
gagehugo | #link https://etherpad.opendev.org/p/security-agenda agenda | 15:02 |
gagehugo | o/ | 15:03 |
*** mlavalle has joined #openstack-meeting | 15:03 | |
fungi | hey there | 15:04 |
gagehugo | fungi: hey o/ | 15:05 |
fungi | #link https://launchpad.net/bugs/1895688 Authenticated RCE in blazar-dashboard | 15:05 |
openstack | Launchpad bug 1895688 in Blazar "Authenticated RCE in blazar-dashboard via python expression in POST parameters" [Critical,Fix released] - Assigned to Pierre Riteau (priteau) | 15:05 |
priteau | Hi o/ | 15:06 |
fungi | er, sorry, was prepping an entry and had a stray newline in there :/ | 15:06 |
fungi | didn't mean to jump into the topic early | 15:06 |
gagehugo | no worries haha | 15:07 |
gagehugo | #topic Authenticated RCE in blazar-dashboard via python expression in POST parameters | 15:07 |
*** openstack changes topic to "Authenticated RCE in blazar-dashboard via python expression in POST parameters (Meeting topic: security)" | 15:07 | |
gagehugo | #link https://bugs.launchpad.net/blazar/+bug/1895688 | 15:07 |
openstack | Launchpad bug 1895688 in Blazar "Authenticated RCE in blazar-dashboard via python expression in POST parameters" [Critical,Fix released] - Assigned to Pierre Riteau (priteau) | 15:07 |
fungi | priteau took care of that very quickly once he got access to blazar's private bugs | 15:08 |
priteau | That was the hard part :-) | 15:08 |
gagehugo | nice | 15:08 |
priteau | To be fair, credit goes to the discover of the issue who shared a patch | 15:08 |
priteau | The patch was backported to victoria, ussuri, train, stein | 15:10 |
priteau | New releases produced for ussuri, train, stein | 15:10 |
gagehugo | ok cool | 15:11 |
priteau | I wanted to ask what is the next step, should we produce an OSSA? | 15:11 |
priteau | As I mentioned to fungi in private discussions, there is quite likely very few users of this software | 15:11 |
fungi | it's probably a good idea, though if you're not in a hurry you could file a request for a cve assignment via mitre's web form first | 15:12 |
fungi | but really it's up to you. if you feel like the impact is extremely limited then it may not be worth the trouble | 15:12 |
priteau | I would like to do things properly, it can be useful to know | 15:13 |
fungi | sure. in that case we have instructions... lemme get the link | 15:14 |
gagehugo | https://security.openstack.org/vmt-process.html#send-cve-request | 15:14 |
gagehugo | priteau ^ | 15:14 |
fungi | #link https://security.openstack.org/vmt-process.html#send-cve-request cve request instructions | 15:15 |
fungi | yep | 15:15 |
gagehugo | :) | 15:15 |
fungi | and then after, or in parallel, you can start working on a yaml file addition to the ossa repo: | 15:15 |
fungi | #link https://security.openstack.org/vmt-process.html#openstack-security-advisories-ossa template for ossa metadata | 15:16 |
fungi | stuff like $DESCRIPTION_CONTENT and $AFFECTED_VERSIONS are part of the impact description, which there's also a template for in that document | 15:17 |
fungi | but feel free to ask in #openstack-security if you have questions and we're happy to guide you | 15:17 |
priteau | In the cve form, do I need to list each affected version as a separate entry? | 15:18 |
priteau | or just comma-separate them? | 15:19 |
*** macz_ has joined #openstack-meeting | 15:19 | |
fungi | we usually comma-separate version ranges | 15:20 |
gagehugo | I believe I just comma separated them last time I submitted one | 15:20 |
fungi | i'll get you an example | 15:20 |
fungi | #link https://security.openstack.org/ossa/OSSA-2020-006.html#affects example affected version ranges list | 15:21 |
priteau | Thanks | 15:21 |
priteau | "<1.3.1, ==2.0.0, ==3.0.0" | 15:22 |
fungi | yeah, assuming 1.3.1, 2.0.1 and 3.0.1 are the fixed releases | 15:23 |
priteau | They are | 15:23 |
fungi | then that looks entirely correct | 15:24 |
*** macz_ has quit IRC | 15:24 | |
priteau | I think I've got enough information to request the CVE. I'll do it a bit later today. | 15:26 |
gagehugo | sounds good! | 15:27 |
fungi | they usually get back to you by e-mail with the cve number they've assigned within a day or two | 15:27 |
gagehugo | "usually" | 15:27 |
fungi | but yeah, don't get worried if you don't hear from them until monday or tuesday | 15:27 |
fungi | you'll generally get a confirmation e-mail for the submission itself straight away though | 15:28 |
*** macz_ has joined #openstack-meeting | 15:29 | |
gagehugo | fungi priteau: anything else for this topic? | 15:29 |
priteau | Not for now, I'll ask in the security channel if I run into problems | 15:30 |
fungi | we're all happy to help | 15:30 |
gagehugo | ^^ | 15:30 |
gagehugo | #topic horizon bug | 15:30 |
*** openstack changes topic to "horizon bug (Meeting topic: security)" | 15:30 | |
gagehugo | #link https://bugs.launchpad.net/horizon/+bug/1898465 | 15:30 |
openstack | Launchpad bug 1898465 in OpenStack Dashboard (Horizon) "In Openstack Horizon component it was observed that the application is taking input from URL and reflecting it into the webpage" [Undecided,New] | 15:30 |
gagehugo | This was made public | 15:30 |
fungi | yeah, i marked it as a security hardening opportunity for now | 15:31 |
fungi | there's another public horizon bug for an open redirect which will likely get an ossa soon | 15:32 |
fungi | the stable/ussuri backport for it merged today, but older stable branches still need backports i think | 15:33 |
gagehugo | thanks fungi | 15:36 |
gagehugo | #topic open discussion | 15:36 |
*** openstack changes topic to "open discussion (Meeting topic: security)" | 15:36 | |
gagehugo | Anything else for this week? | 15:36 |
fungi | it might be nice to get some renewed movement on the memcached socket pileup | 15:37 |
gagehugo | agreed | 15:38 |
gagehugo | #link https://bugs.launchpad.net/keystonemiddleware/+bug/1892852 | 15:38 |
openstack | Launchpad bug 1892852 in OpenStack Security Advisory "memcached socket not released upon lbaas API request " [Undecided,Incomplete] | 15:38 |
gagehugo | that's the duplicate one | 15:38 |
gagehugo | #link https://bugs.launchpad.net/keystonemiddleware/+bug/1883659 | 15:38 |
openstack | Launchpad bug 1883659 in oslo.cache "keystonemiddleware connections to memcached from neutron-server grow beyond configured values" [Undecided,Confirmed] | 15:38 |
fungi | there's a theoretical fix for oslo.cache but it's not seen any updates for a month or two | 15:38 |
fungi | it's probably also a duplicate of 1888394 | 15:39 |
fungi | which was opened in july | 15:39 |
gagehugo | heh | 15:41 |
fungi | looks like that's the only one referred to by the fix change, so i'll add some comments in it about being a duplicate as well | 15:41 |
fungi | and let the devs sort it out | 15:42 |
fungi | right now reviewers arriving at https://review.opendev.org/742193 don't have any clear indication that there are outstanding security bugs for it | 15:42 |
gagehugo | hmm | 15:44 |
gagehugo | that might poke them along | 15:44 |
gagehugo | fungi priteau: thanks! I need to run, have a good rest of the week! | 15:45 |
gagehugo | #endmeeting | 15:45 |
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/" | 15:45 | |
openstack | Meeting ended Thu Oct 8 15:45:26 2020 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:45 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-10-08-15.01.html | 15:45 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/security/2020/security.2020-10-08-15.01.txt | 15:45 |
openstack | Log: http://eavesdrop.openstack.org/meetings/security/2020/security.2020-10-08-15.01.log.html | 15:45 |
*** Luzi has quit IRC | 15:46 | |
fungi | thanks gagehugo! | 15:46 |
*** e0ne has quit IRC | 15:55 | |
*** gyee has joined #openstack-meeting | 16:00 | |
*** rpittau is now known as rpittau|afk | 16:01 | |
*** yoctozepto has quit IRC | 16:16 | |
*** yoctozepto has joined #openstack-meeting | 16:16 | |
*** ricolin_ has quit IRC | 16:29 | |
*** vishalmanchanda has quit IRC | 16:34 | |
*** psachin has quit IRC | 16:57 | |
*** ociuhandu_ has joined #openstack-meeting | 17:03 | |
*** ociuhandu has quit IRC | 17:06 | |
*** ociuhandu_ has quit IRC | 17:07 | |
*** mlavalle has quit IRC | 17:08 | |
*** mlavalle has joined #openstack-meeting | 17:09 | |
*** eharney_ is now known as eharney | 17:39 | |
*** ociuhandu has joined #openstack-meeting | 17:47 | |
*** ociuhandu has quit IRC | 17:52 | |
*** lbragstad_ has joined #openstack-meeting | 18:35 | |
*** lbragstad has quit IRC | 18:37 | |
*** yasufum has joined #openstack-meeting | 19:05 | |
*** yasufum has quit IRC | 19:10 | |
*** yasufum has joined #openstack-meeting | 19:10 | |
*** priteau has quit IRC | 19:31 | |
*** ralonsoh has quit IRC | 19:50 | |
*** yasufum has quit IRC | 20:23 | |
*** slaweq has quit IRC | 20:26 | |
*** TrevorV has quit IRC | 20:30 | |
*** yasufum has joined #openstack-meeting | 21:20 | |
*** rf0lc0 has quit IRC | 21:30 | |
*** yasufum has quit IRC | 21:38 | |
*** jmasud has quit IRC | 21:48 | |
*** manpreet has quit IRC | 21:49 | |
*** yasufum has joined #openstack-meeting | 21:56 | |
*** _erlon_ has quit IRC | 22:22 | |
*** yasufum has quit IRC | 22:27 | |
*** yasufum has joined #openstack-meeting | 22:44 | |
*** rcernin has joined #openstack-meeting | 22:47 | |
*** bbowen_ has quit IRC | 22:52 | |
*** bbowen_ has joined #openstack-meeting | 22:52 | |
*** mlavalle has quit IRC | 22:54 | |
*** tosky has quit IRC | 22:59 | |
*** yasufum has quit IRC | 22:59 | |
*** yasufum has joined #openstack-meeting | 23:17 | |
*** yasufum has quit IRC | 23:30 | |
*** macz_ has quit IRC | 23:32 | |
*** jmasud has joined #openstack-meeting | 23:35 | |
*** rfolco has joined #openstack-meeting | 23:38 | |
*** rfolco has quit IRC | 23:40 | |
*** rfolco has joined #openstack-meeting | 23:41 | |
*** rfolco has quit IRC | 23:45 | |
*** gyee has quit IRC | 23:50 | |
*** armax has quit IRC | 23:59 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!