*** sdake_ has joined #openstack-security | 00:07 | |
*** sdake has quit IRC | 00:11 | |
*** markvoelker has joined #openstack-security | 00:21 | |
*** markvoelker has quit IRC | 00:25 | |
*** bpokorny has joined #openstack-security | 00:34 | |
*** salv-orlando has joined #openstack-security | 00:47 | |
*** salv-orlando has quit IRC | 00:50 | |
*** salv-orlando has joined #openstack-security | 01:05 | |
*** salv-orlando has quit IRC | 01:12 | |
*** markvoelker has joined #openstack-security | 01:21 | |
*** sdake has joined #openstack-security | 01:24 | |
*** sdake_ has quit IRC | 01:26 | |
*** markvoelker has quit IRC | 01:26 | |
*** sdake_ has joined #openstack-security | 01:27 | |
*** sdake has quit IRC | 01:30 | |
*** markvoelker has joined #openstack-security | 02:22 | |
*** markvoelker has quit IRC | 02:27 | |
*** sdake_ is now known as sdake | 02:44 | |
*** salv-orlando has joined #openstack-security | 02:56 | |
*** salv-orlando has quit IRC | 03:01 | |
*** salv-orlando has joined #openstack-security | 03:14 | |
*** salv-orlando has quit IRC | 03:19 | |
*** markvoelker has joined #openstack-security | 03:23 | |
*** markvoelker has quit IRC | 03:27 | |
*** bpokorny has quit IRC | 03:51 | |
openstackgerrit | Michael Simo proposed openstack/security-doc: Reworded sentence in chapter 7 of security-guide https://review.openstack.org/178021 | 03:56 |
---|---|---|
*** markvoelker has joined #openstack-security | 04:24 | |
*** markvoelker has quit IRC | 04:28 | |
*** markvoelker has joined #openstack-security | 05:24 | |
*** markvoelker has quit IRC | 05:29 | |
*** salv-orlando has joined #openstack-security | 05:53 | |
*** salv-orlando has quit IRC | 05:56 | |
*** salv-orlando has joined #openstack-security | 05:59 | |
*** salv-orlando has quit IRC | 05:59 | |
openstackgerrit | Anthony Chow proposed openstack/security-doc: Bug fix for 1447655. Modify paragraph for better grammer and clarity as requested by the ticket. https://review.openstack.org/179701 | 06:03 |
*** salv-orlando has joined #openstack-security | 06:11 | |
*** salv-orlando has quit IRC | 06:15 | |
*** sdake_ has joined #openstack-security | 06:22 | |
*** sdake has quit IRC | 06:25 | |
*** sdake_ is now known as sdake | 06:35 | |
*** salv-orl_ has joined #openstack-security | 06:45 | |
*** sdake has quit IRC | 07:21 | |
*** markvoelker has joined #openstack-security | 07:26 | |
*** markvoelker has quit IRC | 07:30 | |
*** aswadr has joined #openstack-security | 07:50 | |
*** markvoelker has joined #openstack-security | 08:27 | |
*** markvoelker has quit IRC | 08:31 | |
*** asrangne has joined #openstack-security | 09:11 | |
*** salv-orlando has joined #openstack-security | 09:13 | |
*** salv-orl_ has quit IRC | 09:13 | |
*** aswadr has quit IRC | 09:13 | |
*** markvoelker has joined #openstack-security | 09:27 | |
*** markvoelker has quit IRC | 09:32 | |
*** salv-orlando has quit IRC | 09:43 | |
*** salv-orl_ has joined #openstack-security | 09:46 | |
*** salv-orlando has joined #openstack-security | 09:50 | |
*** salv-orl_ has quit IRC | 09:53 | |
*** salv-orl_ has joined #openstack-security | 10:31 | |
*** salv-orlando has quit IRC | 10:34 | |
*** asrangne has quit IRC | 10:43 | |
*** salv-orl_ has quit IRC | 10:46 | |
*** salv-orlando has joined #openstack-security | 10:47 | |
*** salv-orlando has quit IRC | 11:23 | |
*** tmcpeak has joined #openstack-security | 11:48 | |
*** markvoelker has joined #openstack-security | 11:50 | |
*** dave-mccowan has joined #openstack-security | 12:10 | |
*** salv-orlando has joined #openstack-security | 12:24 | |
*** salv-orlando has quit IRC | 12:37 | |
*** sdake has joined #openstack-security | 12:57 | |
*** bknudson has quit IRC | 13:01 | |
*** _elmiko is now known as elmiko | 13:07 | |
*** elmiko has joined #openstack-security | 13:08 | |
*** nkinder has quit IRC | 13:15 | |
*** sdake_ has joined #openstack-security | 13:31 | |
*** singlethink has joined #openstack-security | 13:32 | |
*** bknudson has joined #openstack-security | 13:33 | |
*** sdake has quit IRC | 13:34 | |
*** L0aD1nG has joined #openstack-security | 13:41 | |
L0aD1nG | hello what is this channel about? | 13:41 |
elmiko | for discussions about openstack security related topics | 13:43 |
*** edmondsw has joined #openstack-security | 13:49 | |
*** singleth_ has joined #openstack-security | 13:49 | |
L0aD1nG | what is the definition of "openstack security" then?? | 13:49 |
*** singlethink has quit IRC | 13:53 | |
elmiko | not sure what you mean | 13:58 |
elmiko | L0aD1nG: http://security.openstack.org/ maybe that helps | 13:59 |
L0aD1nG | elmiko: so openstack is a cloud service | 13:59 |
L0aD1nG | ? | 13:59 |
L0aD1nG | and here is the security related discussions about it? | 14:00 |
elmiko | you might want to start here, http://docs.openstack.org/ | 14:00 |
elmiko | it's a collection of opensource services used for creating cloud infrastructures | 14:00 |
L0aD1nG | ohh | 14:01 |
elmiko | (and in this sense services==applications) | 14:01 |
L0aD1nG | yea | 14:01 |
L0aD1nG | thanks a lot | 14:01 |
elmiko | np | 14:01 |
*** dave-mccowan has quit IRC | 14:03 | |
*** zz_naotok has quit IRC | 14:04 | |
*** zz_naotok has joined #openstack-security | 14:06 | |
*** nkinder has joined #openstack-security | 14:07 | |
L0aD1nG | cya around elmiko | 14:09 |
*** L0aD1nG has left #openstack-security | 14:09 | |
elmiko | tmcpeak: you may find this interesting | 14:14 |
elmiko | tmcpeak: https://bugzilla.redhat.com/show_bug.cgi?id=1217857 | 14:14 |
openstack | bugzilla.redhat.com bug 1217857 in Package Review "Review Request: bandit - A framework for performing security analysis of Python source code" [Medium,New] - Assigned to nobody | 14:14 |
elmiko | a coworker proposed bandit for inclusion in fedora | 14:15 |
*** dave-mccowan has joined #openstack-security | 14:15 | |
tmcpeak | elmiko: checking | 14:16 |
*** salv-orlando has joined #openstack-security | 14:16 | |
tmcpeak | elmiko: awesome!! | 14:16 |
elmiko | tmcpeak: yea, i thought you'd find that amusing =) | 14:18 |
elmiko | i guess he's been running it against of system level stuff he's using too | 14:19 |
tmcpeak | the more the merrier :) we love to see people using it | 14:19 |
*** salv-orlando has quit IRC | 14:32 | |
*** voodookid has joined #openstack-security | 14:37 | |
*** dwyde has joined #openstack-security | 14:37 | |
openstackgerrit | Victor Howard proposed openstack/security-doc: Dashboard in Security Guide Bad Sentence https://review.openstack.org/179802 | 14:55 |
*** sdake has joined #openstack-security | 15:01 | |
*** dwyde has quit IRC | 15:01 | |
*** sdake__ has joined #openstack-security | 15:03 | |
*** sdake_ has quit IRC | 15:03 | |
*** sdake has quit IRC | 15:07 | |
openstackgerrit | Victor Howard proposed openstack/security-doc: Added detail to the allowed hosts section https://review.openstack.org/179810 | 15:11 |
*** bpokorny has joined #openstack-security | 15:15 | |
*** singleth_ has quit IRC | 15:36 | |
*** salv-orlando has joined #openstack-security | 15:41 | |
*** salv-orlando has quit IRC | 16:12 | |
*** singlethink has joined #openstack-security | 16:13 | |
*** yeison has joined #openstack-security | 16:22 | |
*** yeison has left #openstack-security | 16:22 | |
*** yeison has joined #openstack-security | 16:27 | |
*** yeison has left #openstack-security | 16:27 | |
*** sdake__ is now known as sdake | 16:58 | |
*** salv-orlando has joined #openstack-security | 17:30 | |
*** singleth_ has joined #openstack-security | 17:30 | |
*** singlethink has quit IRC | 17:34 | |
*** salv-orlando has quit IRC | 17:39 | |
*** singlethink has joined #openstack-security | 17:58 | |
*** singleth_ has quit IRC | 18:02 | |
*** sdake_ has joined #openstack-security | 18:30 | |
*** sdake has quit IRC | 18:34 | |
*** sdake_ is now known as sdake | 18:34 | |
*** voodookid has quit IRC | 18:39 | |
*** dwyde has joined #openstack-security | 18:45 | |
*** subscope_ has joined #openstack-security | 18:49 | |
*** sdake_ has joined #openstack-security | 19:09 | |
*** sdake has quit IRC | 19:13 | |
*** salv-orlando has joined #openstack-security | 19:22 | |
*** salv-orlando has quit IRC | 19:33 | |
*** singlethink has quit IRC | 19:35 | |
*** singlethink has joined #openstack-security | 19:37 | |
openstackgerrit | Travis McPeak proposed stackforge/bandit: Adding /usr/local/etc/bandit/ to paths for Bandit config checking https://review.openstack.org/179894 | 19:38 |
*** dlitz has quit IRC | 19:49 | |
*** singleth_ has joined #openstack-security | 20:00 | |
*** bpokorny_ has joined #openstack-security | 20:02 | |
*** singlethink has quit IRC | 20:03 | |
*** bpokorny has quit IRC | 20:04 | |
*** dwyde_ has joined #openstack-security | 20:07 | |
*** subscope_ has quit IRC | 20:08 | |
*** dwyde has quit IRC | 20:09 | |
*** dwyde_ is now known as dwyde | 20:09 | |
tmcpeak | dstufft: you around? | 20:22 |
dstufft | tmcpeak: hi | 20:28 |
*** jraim has quit IRC | 20:30 | |
*** jraim has joined #openstack-security | 20:33 | |
*** sdake has joined #openstack-security | 20:45 | |
tmcpeak | dstufft: hi, still there? | 20:48 |
tmcpeak | had some questions about how to properly package a config file | 20:48 |
tmcpeak | for Bandit | 20:48 |
dstufft | sure | 20:48 |
dstufft | the answer might not be very good though :) | 20:48 |
tmcpeak | lol | 20:48 |
tmcpeak | that's what I've seen so far | 20:49 |
*** singlethink has joined #openstack-security | 20:49 | |
tmcpeak | I mean not from you but packaging in general | 20:49 |
tmcpeak | so Bandit requires a config file to run | 20:49 |
*** sdake_ has quit IRC | 20:49 | |
tmcpeak | we do some checks in the local directory, and the user's directory to allow them to override | 20:49 |
tmcpeak | but we're somewhat confused about where it will be installed when we do pip install | 20:50 |
tmcpeak | if it is in a virtual environment it goes to the virtualenv etc directory, which works fine | 20:50 |
tmcpeak | if it isn't in a virtual environment it seems to *sometimes* go to /usr/local/etc/bandit and sometimes not | 20:50 |
tmcpeak | is it system dependent? | 20:50 |
*** sdake_ has joined #openstack-security | 20:52 | |
*** singleth_ has quit IRC | 20:52 | |
*** browne has joined #openstack-security | 20:53 | |
browne | tmcpeak: In bandit.yaml, where is the wordlist/default-passwords file? Is this something each exploiter of bandit should create? | 20:55 |
*** salv-orlando has joined #openstack-security | 20:55 | |
tmcpeak | browne: no… that's probably another thing we haven't packaged correctly | 20:55 |
tmcpeak | it's supposed to come with Bandit, although I'm sure the binary install isn't setting that up | 20:55 |
*** sdake has quit IRC | 20:56 | |
browne | oh, i don't see it in the bandit source tree either | 20:56 |
tmcpeak | hmm, really? | 20:56 |
browne | oh, wait, yes, i did find, sorry | 20:56 |
tmcpeak | cool | 20:56 |
browne | ok, so I think it'll try to load that file using the relative path in bandit.yaml, which will fail for most other projects | 20:58 |
browne | guess i'll open a bug | 20:58 |
tmcpeak | browne: cool, please do | 20:59 |
tmcpeak | dstufft: if you have any pointer on the above, I'll greatly appreciate it | 21:03 |
dstufft | tmcpeak: oh you're using data files? | 21:03 |
tmcpeak | dstufft: we currently have this, https://github.com/stackforge/bandit/blob/master/setup.cfg#L26 | 21:03 |
tmcpeak | which doesn't seem to fulfill all of our hopes and dreams | 21:04 |
dstufft | yea... | 21:04 |
dstufft | data files don't really work in the general case | 21:04 |
dstufft | I mean | 21:04 |
dstufft | it works in that we'll put the file somewhere | 21:04 |
dstufft | that somewhere might not be where you expect | 21:04 |
tmcpeak | dstufft: yeah, I've kind of seen taht | 21:04 |
tmcpeak | what's best practice? | 21:04 |
dstufft | generally I recommend using package_data where possible | 21:04 |
dstufft | at least until we make data files work sanely | 21:05 |
tmcpeak | dstufft: something like this: http://stackoverflow.com/questions/13288188/how-to-properly-define-package-data-in-setup-py ? | 21:05 |
dstufft | tmcpeak: yea that looks right, not sure how to translate that to pbr exactly, but something like that | 21:06 |
dstufft | it'll be *inside* the bandit package then | 21:06 |
tmcpeak | ok cool, I think that's what we want | 21:06 |
tmcpeak | dstufft: awesome, thank you. I'll give that a shot | 21:06 |
dstufft | so you'll do something like os.path.join(os.path.dirname(__file__), "default.yml") to get it | 21:06 |
dstufft | or if you want to support zip stuff, you can use pkgutil.get_data | 21:06 |
tmcpeak | dstufft: perfect | 21:06 |
tmcpeak | dstufft: also, welcome to the dark side :P | 21:07 |
dstufft | which dark side is this | 21:07 |
tmcpeak | HP | 21:07 |
dstufft | there are many dark sides, and I'm in more than one | 21:07 |
dstufft | oh! | 21:07 |
dstufft | yes :D | 21:07 |
tmcpeak | which office you in? | 21:08 |
dstufft | my living room | 21:08 |
tmcpeak | excellent :) | 21:08 |
dstufft | I mean, there's the king of prussia office like 5-10 minutes away, and the wayne office like 20 minutes away | 21:08 |
dstufft | but I have no intention of spending time there once I get my I9 form done | 21:09 |
tmcpeak | haha, that's an above industry average commute ;) | 21:09 |
dstufft | who wants to wear pants while they're working anyways | 21:09 |
tmcpeak | +1 | 21:10 |
tmcpeak | dstufft: thanks for the pointer! | 21:10 |
dstufft | At least, I assume HP frowns on not wearing pants if you're in the office | 21:10 |
dstufft | tmcpeak: no problem! | 21:10 |
*** bpokorny has joined #openstack-security | 21:11 | |
*** bpokorny_ has quit IRC | 21:15 | |
*** dave-mccowan has quit IRC | 21:51 | |
*** dwyde has quit IRC | 22:24 | |
*** dlitz has joined #openstack-security | 22:27 | |
*** elmiko is now known as _elmiko | 22:28 | |
*** nkinder has quit IRC | 22:35 | |
*** singlethink has quit IRC | 22:42 | |
*** bknudson has quit IRC | 22:44 | |
*** sdake has joined #openstack-security | 23:04 | |
*** sdake_ has quit IRC | 23:08 | |
*** tmcpeak has quit IRC | 23:17 | |
*** dave-mccowan has joined #openstack-security | 23:56 | |
*** nkinder has joined #openstack-security | 23:58 | |
*** sdake_ has joined #openstack-security | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!