*** nkinder has joined #openstack-security | 00:05 | |
*** shohel02 has joined #openstack-security | 00:41 | |
*** shohel02 has quit IRC | 00:46 | |
*** tmcpeak has quit IRC | 01:02 | |
*** salv-orlando has quit IRC | 01:04 | |
*** tmcpeak has joined #openstack-security | 01:33 | |
*** tmcpeak has quit IRC | 01:35 | |
*** shohel02 has joined #openstack-security | 01:41 | |
*** dave-mccowan has joined #openstack-security | 01:41 | |
*** shohel02 has quit IRC | 01:46 | |
*** bpokorny has joined #openstack-security | 01:51 | |
*** bpokorny has quit IRC | 02:17 | |
*** dave-mccowan has quit IRC | 02:40 | |
*** dave-mccowan has joined #openstack-security | 02:40 | |
*** shohel02 has joined #openstack-security | 02:41 | |
*** hyakuhei has quit IRC | 02:45 | |
*** shohel02 has quit IRC | 02:46 | |
*** bpokorny has joined #openstack-security | 03:23 | |
*** shohel02 has joined #openstack-security | 03:41 | |
*** shohel02 has quit IRC | 03:46 | |
*** dave-mccowan has quit IRC | 04:12 | |
*** hyakuhei has joined #openstack-security | 04:29 | |
*** _et has joined #openstack-security | 04:36 | |
*** _et has left #openstack-security | 04:37 | |
*** _et has joined #openstack-security | 04:37 | |
chair6 | just noticed some weirdness in the online version of the security guide | 04:39 |
---|---|---|
chair6 | links in the ToC on the left, and urls associated with each page, do not map to chapter number / title | 04:39 |
chair6 | for example, in the ToC the text '29. Message queuing architecture' points to URL http://docs.openstack.org/security-guide/content/ch037_risks.html | 04:40 |
chair6 | then the content at http://docs.openstack.org/security-guide/content/ch037_risks.html has heading 'Chapter 29. Message queuing architecure' | 04:40 |
chair6 | something funky going on.. | 04:41 |
*** shohel02 has joined #openstack-security | 04:41 | |
chair6 | looks like google has indexed content with those mismatched URLs as well | 04:43 |
*** shohel02 has quit IRC | 04:46 | |
*** bpokorny has quit IRC | 04:47 | |
_et | chair6: file a bug? | 04:48 |
*** bpokorny has joined #openstack-security | 04:54 | |
*** subscope_ has joined #openstack-security | 04:55 | |
*** bpokorny has quit IRC | 04:56 | |
_et | https://bugs.launchpad.net/openstack-manuals/+bug/1395974 | 04:57 |
*** bpokorny has joined #openstack-security | 04:57 | |
_et | chair6: done. | 04:57 |
*** bpokorny has quit IRC | 05:01 | |
chair6 | thanks _et | 05:06 |
*** jamielennox has quit IRC | 05:11 | |
*** jamielennox has joined #openstack-security | 05:11 | |
*** _et has quit IRC | 05:14 | |
*** subscope_ has quit IRC | 05:25 | |
*** shohel02 has joined #openstack-security | 05:41 | |
*** shohel02 has quit IRC | 05:46 | |
*** shohel02 has joined #openstack-security | 06:41 | |
*** shohel02 has quit IRC | 06:46 | |
*** shohel02 has joined #openstack-security | 07:41 | |
openstackgerrit | Merged openstack/security-doc: Fix recommendations post-POODLE https://review.openstack.org/135844 | 07:45 |
*** shohel02 has quit IRC | 07:46 | |
*** jamielennox is now known as jamielennox|away | 07:49 | |
*** salv-orlando has joined #openstack-security | 08:08 | |
*** shohel02 has joined #openstack-security | 08:14 | |
*** salv-orlando has quit IRC | 10:00 | |
*** salv-orlando has joined #openstack-security | 10:02 | |
openstackgerrit | Abu Shohel Ahmed proposed openstack/security-doc: Adds OpenStack security threat analysis folder https://review.openstack.org/121034 | 10:14 |
*** salv-orlando has quit IRC | 10:57 | |
*** salv-orlando has joined #openstack-security | 11:02 | |
*** salv-orlando has quit IRC | 11:11 | |
*** salv-orlando has joined #openstack-security | 11:11 | |
*** shohel02 has quit IRC | 11:57 | |
*** shohel02 has joined #openstack-security | 12:02 | |
*** salv-orlando has quit IRC | 12:25 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 13:07 |
*** LinStatSDR has quit IRC | 13:18 | |
*** LinStatSDR has joined #openstack-security | 13:18 | |
*** shohel02 has quit IRC | 13:21 | |
*** dave-mccowan has joined #openstack-security | 13:35 | |
*** tmcpeak has joined #openstack-security | 13:40 | |
*** shohel02 has joined #openstack-security | 13:43 | |
*** salv-orlando has joined #openstack-security | 13:53 | |
*** shohel02 has quit IRC | 13:59 | |
*** shohel02 has joined #openstack-security | 14:06 | |
*** shohel02 has quit IRC | 14:12 | |
*** paulmo has joined #openstack-security | 14:13 | |
*** nkinder has quit IRC | 14:14 | |
*** shohel02 has joined #openstack-security | 14:19 | |
*** dave-mccowan_ has joined #openstack-security | 14:29 | |
*** dave-mccowan has quit IRC | 14:32 | |
*** dave-mccowan_ is now known as dave-mccowan | 14:32 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 14:44 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 14:46 |
*** dave-mccowan has quit IRC | 14:47 | |
*** dave-mccowan has joined #openstack-security | 15:01 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:02 |
*** nkinder has joined #openstack-security | 15:06 | |
*** LinStatSDR has quit IRC | 15:14 | |
*** voodookid has joined #openstack-security | 15:23 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:27 |
*** shohel02 has quit IRC | 15:41 | |
*** sicarie has joined #openstack-security | 15:47 | |
openstackgerrit | Merged stackforge/bandit: Refactoring "checks_functions" to check function definitions https://review.openstack.org/137049 | 15:52 |
*** shohel02 has joined #openstack-security | 15:55 | |
*** bpokorny has joined #openstack-security | 15:56 | |
tmcpeak | nkinder: you around? | 16:04 |
*** tmcpeak has quit IRC | 16:58 | |
*** salv-orlando has quit IRC | 17:01 | |
*** LinStatSDR has joined #openstack-security | 17:03 | |
*** bpokorny has quit IRC | 17:06 | |
*** bpokorny has joined #openstack-security | 17:22 | |
bknudson | I tried running bandit using http://git.openstack.org/cgit/stackforge/bandit/tree/README.md#n39 but it fails with a bunch of errors | 17:25 |
bknudson | AttributeError: 'Name' object has no attribute 'value' | 17:25 |
bknudson | I tried running the tests and those all passed | 17:26 |
*** edmondsw has joined #openstack-security | 17:30 | |
*** tmcpeak has joined #openstack-security | 17:35 | |
*** shohel02 has quit IRC | 17:39 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Fixing an oversight when processing none-attr nodes. https://review.openstack.org/137153 | 17:40 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Fixing an oversight when processing none-attr nodes https://review.openstack.org/137153 | 17:44 |
openstackgerrit | Merged stackforge/bandit: Fixing an oversight when processing none-attr nodes https://review.openstack.org/137153 | 18:04 |
chair6 | thanks bknudson, that bug should be fixed | 18:05 |
bknudson | I'll try it. | 18:06 |
bknudson | that helped but getting a different error running against keystone | 18:08 |
bknudson | http://paste.openstack.org/show/138298/ | 18:08 |
*** jamielennox|away is now known as jamielennox | 18:11 | |
nkinder | tmcpeak: hey, what's up? | 18:11 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node. https://review.openstack.org/137165 | 18:25 |
tmcpeak | nkinder: was going to check about what I should do to make a nicely formatted ML post | 18:25 |
tmcpeak | but hyakuhei pointed me to the ML etiquette link | 18:26 |
nkinder | tmcpeak: ok, cool | 18:27 |
*** bpokorny_ has joined #openstack-security | 18:27 | |
*** bpokorny has quit IRC | 18:31 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node. https://review.openstack.org/137165 | 18:31 |
*** bpokorny has joined #openstack-security | 18:32 | |
*** salv-orlando has joined #openstack-security | 18:33 | |
*** bpokorn__ has joined #openstack-security | 18:33 | |
*** bpokorny_ has quit IRC | 18:35 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Graceful degradation when failing to full qualify an attr node https://review.openstack.org/137165 | 18:36 |
*** bpokorny has quit IRC | 18:37 | |
openstackgerrit | Merged stackforge/bandit: Graceful degradation when failing to full qualify an attr node https://review.openstack.org/137165 | 18:40 |
chair6 | bknudson: ^ that should do it, try again .. the joys of trying to get one last feature in before 'announcing' :( | 18:41 |
bknudson | chair6: how do I mark a line (use of random) as safe? | 18:42 |
bknudson | I need to get it to not look at test code | 18:42 |
chair6 | for an individual line, add a trailing # nosec | 18:43 |
tmcpeak | bknudson: do you think a formal way to exclude a directory would be more useful? | 18:45 |
*** bpokorny has joined #openstack-security | 18:45 | |
tmcpeak | I guess the same thing could be done with a find command, or by running Bandit on individual directories though… | 18:46 |
bknudson | tmcpeak: we'll need a way to run it for a project (e.g., keystone) and the project should be able to say what directories to exclude | 18:46 |
tmcpeak | bknudson: yeah, totally | 18:46 |
bknudson | the the directory is keystone/test and we want to exclude just that directory. | 18:46 |
tmcpeak | do you think running Bandit through find like this: find ~/openstack-repo/keystone -name '*.py' | xargs bandit -n 1 and then using some find magic to exclude that directory would be a good solution, or do you think we should build it into Bandit itself? | 18:47 |
bknudson | I think it should be built into bandit... you'll need a config file anyways | 18:48 |
*** bpokorn__ has quit IRC | 18:49 | |
tmcpeak | bknudson: cool, should be easy enough to add | 18:49 |
tmcpeak | config file already there, just need to add that | 18:49 |
tmcpeak | bknudson: I'll add that to the queue | 18:50 |
*** jimhoagland has joined #openstack-security | 19:40 | |
*** gabriela has joined #openstack-security | 20:33 | |
*** gabriela has left #openstack-security | 20:36 | |
*** jimhoagland has quit IRC | 20:46 | |
*** gabriela has joined #openstack-security | 21:02 | |
gabriela | hola | 21:08 |
*** gabriela has left #openstack-security | 21:19 | |
*** sicarie_ has joined #openstack-security | 21:21 | |
*** jamielennox is now known as jamielennox|away | 21:23 | |
*** LinStatSDR has quit IRC | 21:25 | |
*** jamielennox|away is now known as jamielennox | 21:28 | |
*** paulmo has quit IRC | 21:45 | |
*** dave-mccowan has quit IRC | 21:51 | |
*** tmcpeak has quit IRC | 22:13 | |
*** tmcpeak has joined #openstack-security | 22:14 | |
*** tmcpeak has quit IRC | 23:09 | |
*** edmondsw has quit IRC | 23:12 | |
*** tmcpeak has joined #openstack-security | 23:15 | |
*** nkinder has quit IRC | 23:18 | |
*** sicarie_ has quit IRC | 23:29 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!