*** markvoelker has joined #openstack-security | 01:39 | |
*** markvoelker has quit IRC | 01:44 | |
*** tmcpeak has quit IRC | 02:01 | |
*** alejandrito has joined #openstack-security | 02:08 | |
*** alejandrito has quit IRC | 02:37 | |
*** austin_laptop has joined #openstack-security | 02:52 | |
*** dwyde has joined #openstack-security | 02:55 | |
*** dwyde has quit IRC | 02:56 | |
*** markvoelker has joined #openstack-security | 03:40 | |
*** markvoelker has quit IRC | 03:45 | |
*** sdake has quit IRC | 05:01 | |
*** salv-orlando has joined #openstack-security | 05:41 | |
*** markvoelker has joined #openstack-security | 05:41 | |
*** markvoelker has quit IRC | 05:46 | |
*** salv-orlando has quit IRC | 05:48 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Stop mixing IPs and domains https://review.openstack.org/209867 | 05:52 |
---|---|---|
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Integrate PyASN1 for certificate operations https://review.openstack.org/204368 | 05:52 |
*** salv-orlando has joined #openstack-security | 06:01 | |
*** shohel has joined #openstack-security | 06:06 | |
*** tjt263 has quit IRC | 06:15 | |
*** tmoreira has joined #openstack-security | 07:02 | |
*** tmoreira is now known as tmvieira | 07:25 | |
*** tmvieira is now known as tmoreira | 07:26 | |
*** tmoreira is now known as tmoreira|afk | 07:32 | |
*** Anne-On-A-Moose has joined #openstack-security | 07:35 | |
*** elo has joined #openstack-security | 07:38 | |
*** markvoelker has joined #openstack-security | 07:42 | |
*** markvoelker has quit IRC | 07:46 | |
Anne-On-A-Moose | Hi, was wondering if any of you have experience of bad bios? | 07:52 |
*** salv-orlando has quit IRC | 07:54 | |
*** tmoreira|afk is now known as tmoreira | 07:56 | |
*** shohel has quit IRC | 08:31 | |
*** shohel1 has joined #openstack-security | 08:31 | |
*** elo has quit IRC | 08:59 | |
*** shohel1 has quit IRC | 09:06 | |
*** shohel has joined #openstack-security | 09:06 | |
*** tkelsey has joined #openstack-security | 09:12 | |
*** salv-orlando has joined #openstack-security | 09:29 | |
*** tmoreira has quit IRC | 09:42 | |
*** markvoelker has joined #openstack-security | 09:43 | |
*** markvoelker has quit IRC | 09:49 | |
*** tmoreira has joined #openstack-security | 09:53 | |
*** salv-orlando has quit IRC | 09:58 | |
*** salv-orlando has joined #openstack-security | 09:58 | |
*** alex_klimov has joined #openstack-security | 10:11 | |
*** salv-orl_ has joined #openstack-security | 10:28 | |
*** salv-orlando has quit IRC | 10:30 | |
*** salv-o___ has joined #openstack-security | 11:11 | |
*** salv-orl_ has quit IRC | 11:11 | |
*** sdake has joined #openstack-security | 11:28 | |
*** jmckind has joined #openstack-security | 11:29 | |
*** markvoelker has joined #openstack-security | 11:29 | |
*** jmckind has quit IRC | 11:30 | |
*** jmckind has joined #openstack-security | 11:32 | |
*** sdake_ has joined #openstack-security | 11:32 | |
*** markvoelker has quit IRC | 11:34 | |
*** sdake has quit IRC | 11:36 | |
*** jmckind has quit IRC | 11:36 | |
*** jmckind has joined #openstack-security | 11:38 | |
*** sdake has joined #openstack-security | 11:49 | |
*** sdake_ has quit IRC | 11:52 | |
*** Anne-On-A-Moose has quit IRC | 11:59 | |
*** dave-mccowan has joined #openstack-security | 12:01 | |
*** tmoreira has quit IRC | 12:03 | |
*** markvoelker has joined #openstack-security | 12:08 | |
*** tmoreira has joined #openstack-security | 12:08 | |
*** Anne-On-A-Moose has joined #openstack-security | 12:10 | |
*** tmoreira has quit IRC | 12:17 | |
*** jmckind has quit IRC | 12:19 | |
*** salv-o___ has quit IRC | 12:26 | |
*** salv-orlando has joined #openstack-security | 12:26 | |
*** edmondsw has joined #openstack-security | 12:38 | |
*** yaya has joined #openstack-security | 12:56 | |
*** tjt263 has joined #openstack-security | 13:01 | |
*** elmiko has joined #openstack-security | 13:03 | |
*** tmoreira has joined #openstack-security | 13:05 | |
*** yaya has quit IRC | 13:14 | |
*** nkinder has joined #openstack-security | 13:16 | |
*** singlethink has joined #openstack-security | 13:27 | |
*** salv-orl_ has joined #openstack-security | 13:28 | |
*** salv-orlando has quit IRC | 13:31 | |
*** singlethink has quit IRC | 13:32 | |
*** tmcpeak has joined #openstack-security | 13:35 | |
*** salv-orl_ has quit IRC | 13:59 | |
*** tjt263 has quit IRC | 14:03 | |
*** tkelsey has quit IRC | 14:08 | |
*** tkelsey has joined #openstack-security | 14:09 | |
*** yaya has joined #openstack-security | 14:12 | |
*** voodookid has joined #openstack-security | 14:18 | |
*** sdake_ has joined #openstack-security | 14:23 | |
*** sdake has quit IRC | 14:27 | |
*** sdake has joined #openstack-security | 14:34 | |
*** yaya has quit IRC | 14:36 | |
*** sdake_ has quit IRC | 14:37 | |
*** yaya has joined #openstack-security | 14:46 | |
*** dave-mcc_ has joined #openstack-security | 15:00 | |
*** shohel has quit IRC | 15:00 | |
*** salv-orlando has joined #openstack-security | 15:01 | |
*** dave-mccowan has quit IRC | 15:04 | |
*** dave-mccowan has joined #openstack-security | 15:07 | |
*** dave-mcc_ has quit IRC | 15:09 | |
*** jmckind has joined #openstack-security | 15:11 | |
*** dwyde has joined #openstack-security | 15:14 | |
*** timkennedy has quit IRC | 15:26 | |
*** shakamunyi has joined #openstack-security | 15:27 | |
*** bpokorny has joined #openstack-security | 15:28 | |
*** singlethink has joined #openstack-security | 15:32 | |
*** jmckind has quit IRC | 15:40 | |
*** tmoreira has quit IRC | 15:41 | |
*** singlethink has quit IRC | 15:44 | |
*** singlethink has joined #openstack-security | 15:47 | |
*** Dorfen has joined #openstack-security | 15:50 | |
*** bknudson has joined #openstack-security | 15:54 | |
*** elo has joined #openstack-security | 15:56 | |
*** timkennedy has joined #openstack-security | 15:57 | |
*** browne has joined #openstack-security | 16:05 | |
*** alex_klimov has quit IRC | 16:06 | |
*** singlethink has quit IRC | 16:08 | |
*** singlethink has joined #openstack-security | 16:13 | |
*** yaya has quit IRC | 16:28 | |
*** singleth_ has joined #openstack-security | 16:30 | |
*** yaya has joined #openstack-security | 16:31 | |
*** singlethink has quit IRC | 16:33 | |
*** dwyde has quit IRC | 16:34 | |
openstackgerrit | Merged openstack/security-doc: Add missing a white space https://review.openstack.org/210317 | 16:42 |
openstackgerrit | Merged openstack/security-doc: Update links that point to other documentation guides https://review.openstack.org/208076 | 16:43 |
openstackgerrit | Merged openstack/security-doc: Fix list-tables in Object Storage https://review.openstack.org/209638 | 16:43 |
*** gmurphy has joined #openstack-security | 16:51 | |
*** pdesai has joined #openstack-security | 16:56 | |
*** singlethink has joined #openstack-security | 16:58 | |
elmiko | hey sec-doc folks =) | 16:59 |
pdesai | hi elmiko | 17:00 |
elmiko | Daviey, you around? | 17:00 |
elmiko | hi pdesai , nice work on catching those few extra bugs =) | 17:00 |
Daviey | hiya | 17:00 |
pdesai | sure :) | 17:01 |
*** singleth_ has quit IRC | 17:01 | |
elmiko | hey Daviey | 17:01 |
elmiko | ok, so let's get rolling | 17:01 |
Daviey | elmiko: o/ | 17:01 |
elmiko | looks like all the medium bugs have been addressed and merged | 17:01 |
pdesai | there is one on block storage i guess | 17:01 |
elmiko | we've also had a few other bugs fixed which were deployed into rst and xml | 17:01 |
elmiko | pdesai, line# ? | 17:01 |
pdesai | Empty (original has 2 paragarphs and a note) (medium) - I see data in the file, so waiting for the below to run checkbuild to validate | 17:02 |
pdesai | 370 | 17:02 |
pdesai | i am not sure what the status is | 17:02 |
elmiko | oh, good call. (missed that one) | 17:02 |
elmiko | hmm, i'm not familiar with this one. | 17:02 |
pdesai | me neither | 17:03 |
elmiko | should the 2 paras from the original be ported to the rst? | 17:03 |
pdesai | i see the two paras from original in rst | 17:04 |
elmiko | ah, ok | 17:04 |
pdesai | http://docs.openstack.org/draft/security-guide-rst/block-storage.html | 17:04 |
*** sdake_ has joined #openstack-security | 17:04 | |
elmiko | this might be a sicarie question then | 17:04 |
pdesai | http://docs.openstack.org/security-guide/content/block-storage.html | 17:04 |
pdesai | may be, but looks like there is no outstanding bugs left then | 17:05 |
elmiko | ok, yea | 17:05 |
*** Anne-On-A-Moose has quit IRC | 17:05 | |
elmiko | the next question will be, should we move out of freeze on the rst and are we in a position to freeze out new work on the docbook? | 17:05 |
elmiko | Daviey, did the sidebar changes get merged yet? | 17:06 |
Daviey | elmiko: yes | 17:06 |
pdesai | what is the chage request? | 17:06 |
pdesai | oh nice | 17:06 |
elmiko | cool | 17:06 |
Daviey | elmiko: just waiting for the theme to cut a release | 17:07 |
Daviey | i will chase this tonorrow | 17:07 |
elmiko | ah ok, still waiting on that then. cool, thanks! | 17:07 |
elmiko | it sounds like we will be on track to switch over when sicarie gets back | 17:07 |
*** sdake has quit IRC | 17:07 | |
Daviey | great | 17:08 |
elmiko | i suppose we could take a few more of the smaller bugs in the etherpad just to fill things out while awaiting our fearless leader's return | 17:08 |
elmiko | other than that, i'm not aware of other issues. | 17:08 |
elmiko | (although there are some old bugs that need addressing) | 17:09 |
elmiko | either of you have any issues to bring up? | 17:09 |
pdesai | and we need to address two things, after we lift a freeze, (1) getting rid of warning on rst (2) | 17:09 |
Daviey | do we have a hit list? | 17:10 |
pdesai | (2) moving away from draft on docs site | 17:10 |
elmiko | the etherpad has a bunch of low-level stuff that we agreed didn't need to be done before the switch over | 17:10 |
elmiko | pdesai, maybe we should focus on hunting warnings this next week then? | 17:11 |
pdesai | yup sounds good | 17:11 |
*** jamielennox is now known as jamielennox|away | 17:11 | |
*** dwyde has joined #openstack-security | 17:11 | |
elmiko | Daviey, not really a hit list, more a low prio trashcan fire list lol | 17:11 |
pdesai | :) | 17:12 |
Daviey | hah | 17:12 |
elmiko | but i guess, if folks have time, take a look at the warnings generated from the rst build and put up some patches to fix them =) | 17:12 |
elmiko | maybe we can dump all the warnings into the etherpad just to help coordinate on fixing them? | 17:12 |
pdesai | yup that would help | 17:13 |
Daviey | yeah | 17:13 |
elmiko | of course, now that i say that i'm not getting any lol | 17:13 |
Daviey | Considering how many times i have built RST locally.. you'd think i'd have noticed we had SOME warnings.. but i don't remember seeing any! | 17:13 |
pdesai | elmiko, lets talk more then :) | 17:14 |
*** sdake_ is now known as sdake | 17:14 | |
elmiko | pdesai, are these warnings coming out of the niceness checks? | 17:14 |
pdesai | i havent seen any warnings | 17:15 |
pdesai | i generally run tox -e docs | 17:15 |
pdesai | :) | 17:15 |
elmiko | ok, until we find warnings, let's focus on getting more of the low/very low bugs out of the way | 17:15 |
Daviey | pdesai: Ah, same here.. might explain why we have been excused the warnings | 17:16 |
elmiko | just grab some out of the etherpad and post links to reviews, i'll go through and keep them updated | 17:16 |
*** salv-orlando has quit IRC | 17:16 | |
pdesai | yup sounds good | 17:16 |
elmiko | i just re-ran tox against a fresh build and didn't see any warnings, so let's just move on till we find them =) | 17:16 |
elmiko | sounds good then | 17:17 |
pdesai | i checked one of the latest review request and did nto find any warnings, niceness or deletions | 17:17 |
elmiko | great | 17:17 |
elmiko | i don't have any other topics | 17:18 |
Daviey | shall we go home? | 17:18 |
elmiko | i think so | 17:18 |
elmiko | unless pdesai has something? | 17:18 |
pdesai | nope nothing from myside, waiting for the freeze lift :) | 17:18 |
Daviey | Hmm... | 17:19 |
Daviey | pdesai: I don't think you need to wait on content for the freeze lift... | 17:19 |
*** Anne-On-A-Moose has joined #openstack-security | 17:19 | |
Daviey | I *think* we agreed that landing stuff soley in RST was acceptable now.. just not expecting it in prod yet | 17:19 |
elmiko | +1 | 17:20 |
pdesai | oh awesome, didnt catch that | 17:20 |
elmiko | i don't have an issue accepting reviews for new material to rst only | 17:20 |
Daviey | Great! | 17:20 |
elmiko | we are close enough that i imagine the switch over will happen next week when sicarie is back | 17:20 |
elmiko | so, makes sense imo to start reviewing new content | 17:20 |
pdesai | cool | 17:21 |
elmiko | i can confirm with the docs team though just to make sure before we start merging | 17:21 |
Daviey | elmiko: What needs confirming? | 17:21 |
elmiko | Daviey, i just want to make sure we're not missing some detail that i'm not aware of | 17:22 |
Daviey | Ah | 17:22 |
elmiko | mainly because sicarie has been more involved with the rst conversion efforts upstream | 17:22 |
*** Anne-On-A-Moose has left #openstack-security | 17:22 | |
elmiko | otherwise i'd say we could probably switch over to rst =) | 17:23 |
Daviey | Well.. i just checked, and the release notes have now been merged for openstacksdocstheme.. so it really is just blocked on someone cutting a release of the theme | 17:24 |
Daviey | So i'm guessing that will happen today/tomorrow | 17:24 |
elmiko | awesome | 17:24 |
elmiko | Daviey, where to check for when that is released? | 17:24 |
Daviey | elmiko: i guess pypi or the openstack-docs ML | 17:25 |
elmiko | ack, thanks | 17:26 |
Daviey | https://pypi.python.org/pypi/openstackdocstheme | 17:26 |
*** dave-mccowan has quit IRC | 17:26 | |
elmiko | cool | 17:26 |
Daviey | elmiko: Worth looking at https://review.openstack.org/#/c/199393/ ? | 17:26 |
Daviey | It renames sections.. but does it in the old and new world | 17:26 |
*** yaya has quit IRC | 17:26 | |
elmiko | hmm, looks like andreas gave it +A | 17:27 |
elmiko | i also gave some +A to older changes that fixed rst and xml | 17:27 |
elmiko | but going forward i think we can start to work on just rst | 17:27 |
elmiko | i don't think it's a big issue to fix the xml stuff along with the rst stuff, but we should stop doing it soon(TM) | 17:28 |
elmiko | once the theme stuff lands we will be in a good position to really cut over and stop accepting xml changes | 17:29 |
elmiko | again though, i'd like to sync up with the doc team just make sure we're not moving too fast or over-stepping some boundary i'm not aware of | 17:30 |
elmiko | does that make sense? | 17:30 |
Daviey | DD"Move fast and break stuff" -- somefoo | 17:30 |
Daviey | somefool* | 17:30 |
elmiko | hehe | 17:31 |
elmiko | ok, then, we're over time. thanks pdesai and Daviey | 17:31 |
*** sdake_ has joined #openstack-security | 17:32 | |
Daviey | thanks elmiko | 17:32 |
tmcpeak | Daviey: thanks for taking over that change | 17:32 |
tmcpeak | looks good | 17:32 |
pdesai | thanks guys | 17:32 |
openstackgerrit | Merged openstack/security-doc: Renamed Future section and added domain information https://review.openstack.org/199393 | 17:32 |
*** yaya has joined #openstack-security | 17:35 | |
*** sdake has quit IRC | 17:35 | |
Daviey | elmiko: Actually, this change triggers a release when it is merged - https://review.openstack.org/#/c/211131/ | 17:37 |
elmiko | Daviey, oh, very nice! | 17:37 |
tmcpeak | bknudson: nice!! | 17:43 |
tmcpeak | (on your testing stuff) | 17:43 |
*** austin_laptop has quit IRC | 17:48 | |
*** dave-mccowan has joined #openstack-security | 17:56 | |
*** pdesai has quit IRC | 17:58 | |
*** dave-mcc_ has joined #openstack-security | 17:58 | |
*** dave-mccowan has quit IRC | 18:01 | |
*** salv-orlando has joined #openstack-security | 18:10 | |
*** salv-orlando has quit IRC | 18:22 | |
*** salv-orlando has joined #openstack-security | 18:31 | |
*** yaya has quit IRC | 18:32 | |
*** sdake_ is now known as sdake | 18:35 | |
*** yaya has joined #openstack-security | 18:40 | |
*** yaya_ has joined #openstack-security | 18:42 | |
*** yaya has quit IRC | 18:44 | |
*** yaya_ is now known as yaya | 18:44 | |
*** dave-mcc_ has quit IRC | 18:55 | |
*** austin_laptop has joined #openstack-security | 19:06 | |
*** dave-mccowan has joined #openstack-security | 19:07 | |
*** austin_laptop has quit IRC | 19:07 | |
*** browne has quit IRC | 19:18 | |
*** austin_laptop has joined #openstack-security | 19:23 | |
*** sdake_ has joined #openstack-security | 19:29 | |
*** sdake has quit IRC | 19:33 | |
*** dwyde has quit IRC | 19:34 | |
*** JAHoagie has joined #openstack-security | 19:35 | |
*** sdake has joined #openstack-security | 19:35 | |
*** dwyde has joined #openstack-security | 19:37 | |
*** sdake_ has quit IRC | 19:38 | |
*** jhfeng has joined #openstack-security | 19:50 | |
*** yaya has quit IRC | 19:56 | |
*** salv-orlando has quit IRC | 19:57 | |
*** bpokorny has quit IRC | 20:01 | |
*** salv-orlando has joined #openstack-security | 20:02 | |
*** yaya has joined #openstack-security | 20:02 | |
*** yaya has quit IRC | 20:04 | |
*** b10n1k has joined #openstack-security | 20:07 | |
*** yaya has joined #openstack-security | 20:08 | |
*** browne has joined #openstack-security | 20:14 | |
*** tkelsey has quit IRC | 20:19 | |
*** alex_klimov has joined #openstack-security | 20:26 | |
*** elo1 has joined #openstack-security | 20:27 | |
*** elo has quit IRC | 20:29 | |
*** elo1 has quit IRC | 20:35 | |
*** singleth_ has joined #openstack-security | 20:55 | |
*** singlethink has quit IRC | 20:57 | |
*** wverdugo500 has joined #openstack-security | 20:58 | |
austin_laptop | bandit is warning for chmod 755; this is for a python project that packs system images into a tarball, its pretty common to need to chmod 755, is this warning really necessary (or really a medium severity?) | 20:59 |
austin_laptop | https://paste.debian.net/291110/ | 20:59 |
*** yaya has quit IRC | 21:00 | |
*** elo has joined #openstack-security | 21:01 | |
*** tkelsey has joined #openstack-security | 21:12 | |
*** b10n1k has quit IRC | 21:15 | |
*** tkelsey has quit IRC | 21:16 | |
*** b10n1k has joined #openstack-security | 21:18 | |
*** JAHoagie has quit IRC | 21:21 | |
*** elo has quit IRC | 21:23 | |
tmcpeak | austin_laptop: the reason it's warning is because it's world readable | 21:31 |
tmcpeak | that's generally a bad idea | 21:31 |
tmcpeak | if it's really not an issue in this case we have the "#nosec" tag which indicates a human has looked at it and deemed that it isn't a security risk that you are creating that file world readable | 21:32 |
austin_laptop | tmcpeak, okay, thanks | 21:36 |
*** JAHoagie has joined #openstack-security | 21:36 | |
tmcpeak | austin_laptop: sure | 21:37 |
*** b10n1k has quit IRC | 21:39 | |
*** yaya has joined #openstack-security | 21:43 | |
*** yaya has quit IRC | 22:00 | |
*** nkinder has quit IRC | 22:01 | |
*** sdake has quit IRC | 22:01 | |
*** nkinder has joined #openstack-security | 22:04 | |
*** nkinder has quit IRC | 22:09 | |
*** nkinder has joined #openstack-security | 22:11 | |
*** austin_laptop has quit IRC | 22:21 | |
*** austin_laptop has joined #openstack-security | 22:22 | |
*** edmondsw has quit IRC | 22:25 | |
*** dwyde has quit IRC | 22:27 | |
*** salv-orl_ has joined #openstack-security | 22:31 | |
*** salv-orlando has quit IRC | 22:33 | |
Daviey | austin_laptop: Sure you need *7*55? | 22:36 |
Daviey | austin_laptop: Wouldn't 644 be more suitable? | 22:36 |
Daviey | (and this is what the bandit check does.. make you think about it :) | 22:37 |
austin_laptop | Daviey, for something like /dev, no | 22:37 |
austin_laptop | Daviey, sure :) | 22:37 |
Daviey | Ah, i see | 22:37 |
austin_laptop | I had missed the #nosec when I originally read the README | 22:38 |
*** jamielennox|away is now known as jamielennox | 22:38 | |
austin_laptop | so solved now, thanks for the quick replies :) | 22:38 |
Daviey | austin_laptop: You can create a profile excluding this test.. but it is pretty cheap to add #nosec IMO | 22:38 |
austin_laptop | Daviey, yeah, I passed that along to the maintainer of that codebase. It's a small enough issue that it's easier to annotate than blindly disable all | 22:39 |
Daviey | And by adding #nosec to git, you are adding an audit log of your analysis :) | 22:39 |
austin_laptop | Daviey, though I was curious of the format for doing that | 22:39 |
austin_laptop | I could only find the default bandit.yaml, wasn't sure how to blacklist that call (for testing) | 22:39 |
Daviey | In the latest release the sample bandit.yaml contains a Profile for ALL.. which you can use as a reference | 22:40 |
*** singleth_ has quit IRC | 22:42 | |
Daviey | afk | 22:44 |
*** alex_klimov has quit IRC | 22:54 | |
*** yaya has joined #openstack-security | 23:00 | |
*** yaya has quit IRC | 23:07 | |
*** voodookid has quit IRC | 23:18 | |
*** sdake has joined #openstack-security | 23:31 | |
*** jhfeng has quit IRC | 23:33 | |
*** sdake has quit IRC | 23:53 | |
*** sdake has joined #openstack-security | 23:56 | |
*** viraptor has joined #openstack-security | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!