*** ccie6747 has quit IRC | 00:00 | |
*** salv-orl_ has quit IRC | 00:31 | |
*** salv-orlando has joined #openstack-security | 00:34 | |
*** _et_ has joined #openstack-security | 00:37 | |
*** salv-orlando has quit IRC | 00:45 | |
*** salv-orlando has joined #openstack-security | 00:46 | |
*** hyakuhei has joined #openstack-security | 00:48 | |
openstackgerrit | Merged openstack/security-doc: Adding link for SELinux policies https://review.openstack.org/266567 | 00:53 |
---|---|---|
*** edmondsw has quit IRC | 00:55 | |
*** bpokorny has quit IRC | 01:05 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Pretty up the plugin documentation https://review.openstack.org/267254 | 01:09 |
openstackgerrit | Eric Brown proposed openstack/bandit: Pretty up the plugin documentation https://review.openstack.org/267254 | 01:11 |
*** browne has quit IRC | 01:13 | |
*** elo has quit IRC | 01:21 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix rst markups https://review.openstack.org/258846 | 01:49 |
*** winterIsLeaving has quit IRC | 01:58 | |
*** elo has joined #openstack-security | 02:11 | |
*** browne has joined #openstack-security | 02:16 | |
*** jmckind has quit IRC | 02:33 | |
*** elo has quit IRC | 02:42 | |
*** hyakuhei has quit IRC | 02:51 | |
*** dstanek has quit IRC | 02:52 | |
*** dstanek has joined #openstack-security | 02:53 | |
*** Windir has quit IRC | 02:53 | |
*** Windir has joined #openstack-security | 02:54 | |
*** bpokorny has joined #openstack-security | 02:55 | |
*** bpokorny has quit IRC | 03:07 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix rst markups https://review.openstack.org/258846 | 03:23 |
*** sonuk has joined #openstack-security | 03:24 | |
*** yuanying_ has quit IRC | 03:34 | |
*** tjt263 has quit IRC | 03:34 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Update readme with latest changes https://review.openstack.org/267281 | 03:40 |
*** yuanying has joined #openstack-security | 03:46 | |
*** yuanying_ has joined #openstack-security | 03:56 | |
*** browne1 has joined #openstack-security | 03:57 | |
*** yuanying has quit IRC | 03:59 | |
*** browne has quit IRC | 04:00 | |
*** yuanying_ has quit IRC | 04:00 | |
*** winterIsLeaving has joined #openstack-security | 04:00 | |
*** yuanying has joined #openstack-security | 04:06 | |
*** yuanying has quit IRC | 04:07 | |
*** yuanying_ has joined #openstack-security | 04:07 | |
*** salv-orl_ has joined #openstack-security | 04:10 | |
*** entPop has joined #openstack-security | 04:10 | |
*** salv-orlando has quit IRC | 04:12 | |
*** winterIsLeaving has quit IRC | 04:13 | |
*** winterIsLeaving has joined #openstack-security | 04:22 | |
*** entPop has quit IRC | 04:23 | |
*** entPop has joined #openstack-security | 04:26 | |
*** winterIsLeaving has quit IRC | 04:28 | |
*** winterIsLeaving has joined #openstack-security | 04:32 | |
*** entPop has quit IRC | 04:35 | |
*** winterIsLeaving has quit IRC | 04:39 | |
*** bpokorny has joined #openstack-security | 04:41 | |
*** _et_ has quit IRC | 04:42 | |
*** winterIsLeaving has joined #openstack-security | 04:50 | |
*** bpokorny has quit IRC | 05:00 | |
*** winterIsLeaving has quit IRC | 05:07 | |
*** winterIsLeaving has joined #openstack-security | 05:10 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module. https://review.openstack.org/267312 | 05:54 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module. https://review.openstack.org/267312 | 06:05 |
*** winterIsLeaving has quit IRC | 06:11 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 06:11 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 06:24 |
*** markvoelker has quit IRC | 06:42 | |
*** browne1 has quit IRC | 06:52 | |
*** elo has joined #openstack-security | 07:09 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/267355 | 07:22 |
*** salv-orl_ has quit IRC | 07:53 | |
*** salv-orlando has joined #openstack-security | 07:53 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/267355 | 08:34 |
*** markvoelker has joined #openstack-security | 08:43 | |
*** markvoelker has quit IRC | 08:48 | |
*** salv-orlando has quit IRC | 08:57 | |
*** salv-orlando has joined #openstack-security | 08:58 | |
*** salv-orlando has quit IRC | 09:05 | |
*** salv-orlando has joined #openstack-security | 09:05 | |
*** ig0r_ has joined #openstack-security | 09:17 | |
*** jamielennox is now known as jamielennox|away | 09:18 | |
*** ig0r_ has quit IRC | 09:41 | |
*** markvoelker has joined #openstack-security | 09:44 | |
*** markvoelker has quit IRC | 09:49 | |
*** salv-orl_ has joined #openstack-security | 10:10 | |
*** salv-orlando has quit IRC | 10:12 | |
*** lexholden has joined #openstack-security | 10:56 | |
*** FlayvaFlayy has joined #openstack-security | 11:31 | |
*** d0ugal has quit IRC | 11:40 | |
*** markvoelker has joined #openstack-security | 11:45 | |
*** markvoelker has quit IRC | 11:49 | |
*** FlayvaFlayy has quit IRC | 11:54 | |
*** lexholden has quit IRC | 11:56 | |
*** d0ugal has joined #openstack-security | 11:58 | |
*** lexholden has joined #openstack-security | 12:01 | |
*** lexholden has quit IRC | 12:11 | |
*** markvoelker has joined #openstack-security | 12:45 | |
*** markvoelker has quit IRC | 12:50 | |
mhayden | thursday is my meeting day, so i might not be in the room too often today | 13:16 |
*** markvoelker has joined #openstack-security | 13:25 | |
*** browne has joined #openstack-security | 13:26 | |
*** _et_ has joined #openstack-security | 13:37 | |
*** edmondsw has joined #openstack-security | 13:39 | |
*** ninag has joined #openstack-security | 13:41 | |
*** avarner has joined #openstack-security | 13:47 | |
*** avarner has quit IRC | 13:47 | |
*** dslev has joined #openstack-security | 13:48 | |
*** browne has quit IRC | 13:48 | |
*** hyakuhei has joined #openstack-security | 13:52 | |
*** dslev_ has joined #openstack-security | 13:54 | |
*** dslev has quit IRC | 13:57 | |
*** hyakuhei has quit IRC | 13:59 | |
*** dslev_ has quit IRC | 14:00 | |
*** dslev has joined #openstack-security | 14:16 | |
*** avarner has joined #openstack-security | 14:31 | |
*** jmckind has joined #openstack-security | 14:32 | |
*** _et_ has quit IRC | 14:36 | |
*** tmcpeak has joined #openstack-security | 14:38 | |
*** hyakuhei has joined #openstack-security | 14:38 | |
*** browne has joined #openstack-security | 14:39 | |
*** jhfeng has joined #openstack-security | 14:40 | |
openstackgerrit | Robert Clark proposed openstack/anchor: Updated the Docker readme so that port 5016 is used for anchor https://review.openstack.org/267614 | 14:47 |
*** tkelsey has joined #openstack-security | 14:48 | |
hyakuhei | tkelsey: https://review.openstack.org/#/c/267614/ pleasy weasy | 14:51 |
hyakuhei | As it’s just a README change please consider a +w too | 14:51 |
*** avarner has quit IRC | 14:51 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: DUMMY COMMIT - DO NOT MERGE https://review.openstack.org/267624 | 14:54 |
*** jhfeng has quit IRC | 14:54 | |
*** dave-mccowan has joined #openstack-security | 14:58 | |
elmiko | hyakuhei: i dunno... sounds fishy | 15:00 |
hyakuhei | lulz | 15:00 |
*** dave-mcc_ has joined #openstack-security | 15:00 | |
elmiko | hyakuhei: have you checked out kubernetes much? | 15:01 |
hyakuhei | Not recently - I check out conference talks on it now and again - I’m down with the koolaid, I’ve just not drunk any yet. | 15:01 |
elmiko | i've been messing with it recently, very neat | 15:02 |
elmiko | looking at that dockerfile made me think about it | 15:02 |
*** dave-mccowan has quit IRC | 15:04 | |
*** _et_ has joined #openstack-security | 15:05 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:07 | |
dave-mcc_ | A Cinder reviewer asked for Security Project's guidance on backporting this fix to Nova and Cinder: https://review.openstack.org/#/c/266680/ | 15:08 |
*** cjschaef has joined #openstack-security | 15:09 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 15:10 |
elmiko | dave-mcc_: gorka has a good question on that review, it seems more like a performance backport than a security one | 15:15 |
dave-mcc_ | elmiko no, it's a security fix. the cache (which should only be used in the copy_key operation) is being used always. weird stuff can happen: expired credentials are cached and reused, a second user can use the first user's cached credentials, ... | 15:17 |
elmiko | ah, ok | 15:18 |
elmiko | dave-mcc_: thanks for the clarification =) | 15:18 |
michaelxin | qhttps://talkgadget.google.com/hangouts/_/gz43wqtwiit4lu7uupm55yd3oma?authuser=0&hl=en | 15:19 |
michaelxin | elmiko: morning | 15:19 |
michaelxin | https://talkgadget.google.com/hangouts/_/gz43wqtwiit4lu7uupm55yd3oma?authuser=0&hl=en | 15:19 |
michaelxin | We have a big crowd today. | 15:19 |
michaelxin | Some Baribican members joined up. | 15:19 |
elmiko | michaelxin: thanks! i have meetings all morning but i will join when i get free =) | 15:20 |
michaelxin | elmiko: Sure. | 15:20 |
*** hyakuhei has quit IRC | 15:32 | |
*** loinvspredator has joined #openstack-security | 15:34 | |
loinvspredator | :) | 15:34 |
*** hyakuhei has joined #openstack-security | 15:36 | |
*** loinvspredator has left #openstack-security | 15:39 | |
tmcpeak | tkelsey: https://review.openstack.org/#/c/267125/ | 15:39 |
hyakuhei | tkelsey: https://review.openstack.org/#/c/267614/ | 15:40 |
tmcpeak | tkelsey: https://review.openstack.org/#/c/267202/ | 15:40 |
*** jhfeng has joined #openstack-security | 15:44 | |
sigmavirus24 | http://undeadly.org/cgi?action=article&sid=20160114142733 for interested parties | 15:44 |
openstackgerrit | Merged openstack/bandit: Allow list of tests specified on command line https://review.openstack.org/267125 | 15:48 |
openstackgerrit | Merged openstack/bandit: Proper B5xx test numbering https://review.openstack.org/267202 | 15:48 |
*** tjt263 has joined #openstack-security | 15:50 | |
*** hyakuhei has quit IRC | 15:53 | |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Remove unnecessary absolute_import logic https://review.openstack.org/267192 | 15:56 |
*** jhfeng has quit IRC | 15:57 | |
*** jhfeng has joined #openstack-security | 15:59 | |
*** jhfeng has quit IRC | 16:00 | |
*** pdesai1 has joined #openstack-security | 16:00 | |
*** dg_ has joined #openstack-security | 16:01 | |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Remove unnecessary absolute_import logic from modules https://review.openstack.org/267192 | 16:02 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Move cli modules into their own submodule https://review.openstack.org/267190 | 16:02 |
*** jhfeng has joined #openstack-security | 16:03 | |
*** salv-orlando has joined #openstack-security | 16:09 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Enable pep8 testing on tests https://review.openstack.org/267671 | 16:10 |
*** mvaldes has joined #openstack-security | 16:10 | |
*** jhfeng has quit IRC | 16:12 | |
*** salv-orl_ has quit IRC | 16:13 | |
sigmavirus24 | mvaldes: examples/yaml_load.py | 16:20 |
sigmavirus24 | https://bugs.launchpad.net/bandit/+bug/1508490 | 16:20 |
openstack | Launchpad bug 1508490 in Bandit "False positive when yaml.load is used with "Loader=yaml.SafeLoader"" [Medium,Confirmed] - Assigned to Tim Kelsey (tim-kelsey) | 16:20 |
*** diazjf has joined #openstack-security | 16:20 | |
diazjf | BYOK etherpad: https://etherpad.openstack.org/p/cEA79A5fG1 | 16:20 |
*** hyakuhei has joined #openstack-security | 16:24 | |
*** jhfeng has joined #openstack-security | 16:24 | |
diazjf | https://etherpad.openstack.org/p/cEA79A5fG1 | 16:24 |
michaelxin | https://etherpad.openstack.org/p/cEA79A5fG1 | 16:24 |
*** edtubill has joined #openstack-security | 16:27 | |
michaelxin | sigmavirus24: Ian, are you still working on Glance project? | 16:28 |
sigmavirus24 | Yes, I am | 16:28 |
michaelxin | sigmavirus24: Do you happen to know whether Glance is using any encryption? | 16:29 |
michaelxin | https://wiki.openstack.org/wiki/EncryptionInOpenstack#Glance | 16:29 |
michaelxin | It says that Glance is not doing any encryption. | 16:29 |
sigmavirus24 | michaelxin: we're working on image signing but otherwise, not really | 16:29 |
michaelxin | Is it still accurate? | 16:29 |
michaelxin | Just signing? | 16:30 |
sigmavirus24 | https://specs.openstack.org/openstack/glance-specs/specs/liberty/image-signing-and-verification-support.html Is the only thing i know of | 16:30 |
hyakuhei | I put a ? by glance because it probably makes the least sense to encrypt out of all the basic IaaS services. | 16:31 |
michaelxin | sigmavirus24: Thanks. | 16:32 |
michaelxin | hyakuhei: +1 | 16:32 |
sigmavirus24 | michaelxin: that's been updated | 16:32 |
michaelxin | sigmavirus24: Thanks. You are the man! :-) | 16:34 |
*** sonuk has quit IRC | 16:34 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Pretty up the plugin documentation https://review.openstack.org/267254 | 16:34 |
openstackgerrit | Merged openstack/anchor: Updated the Docker readme so that port 5016 is used for anchor https://review.openstack.org/267614 | 16:36 |
*** dg_ has quit IRC | 16:36 | |
browne | https://www.youtube.com/watch?v=wf-BqAjZb8M | 16:38 |
michaelxin | http://undeadly.org/cgi?action=article&sid=20160114142733&mode=expanded | 16:42 |
hyakuhei | rofl. Just yesterday tmcpeak was saying how there hasn’t been a serious SSH vulnerability for a long time…. | 16:44 |
hyakuhei | Until you are able to patch affected systems, the recommended workaround is to use | 16:44 |
hyakuhei | # echo 'UseRoaming no' >> /etc/ssh/ssh_config | 16:44 |
hyakuhei | ^ That could be an excellent example use case for the ansible work later today | 16:45 |
tmcpeak | hyakuhei: wowwww | 16:45 |
*** hyakuhei has quit IRC | 16:50 | |
*** hyakuhei has joined #openstack-security | 16:51 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding a test for test id on test plugins https://review.openstack.org/267700 | 16:53 |
tmcpeak | hyakuhei: got us set up for 5:30, they'd like me to call with a definite count later in the day | 16:53 |
tkelsey | sigmavirus24 browne https://review.openstack.org/#/c/267700/ | 16:54 |
hyakuhei | I don’t think we can get there for 5:30 unless we leave early | 16:54 |
michaelxin | The image sharing is using md5 by default for Glance. | 16:54 |
michaelxin | Glance already supports computing checksums of images when an image is uploaded, and this checksum is stored with the image. This same hash (which by default is MD5) will be used for the signature verification. | 16:55 |
michaelxin | This is sad. | 16:55 |
tmcpeak | hyakuhei: it says 15 mins without traffic, when I call I can tell them we might be more like 5:45 | 16:55 |
michaelxin | tmcpeak: Have fun. | 16:56 |
tmcpeak | :| | 16:56 |
michaelxin | I wish that I could go | 16:56 |
hyakuhei | tmcpeak: cool | 16:56 |
hyakuhei | michaelxin: your kids will understand man. | 16:57 |
tmcpeak | +1 | 16:57 |
michaelxin | hyakuhei: Thanks. | 16:57 |
michaelxin | Do try the chinese liquor | 16:57 |
michaelxin | :-) | 16:57 |
michaelxin | It is for brave men. | 16:57 |
tmcpeak | tkelsey is enthusiastic about it | 16:58 |
*** salv-orlando has quit IRC | 16:58 | |
tkelsey | damn right! | 16:58 |
tkelsey | :D | 16:58 |
*** salv-orlando has joined #openstack-security | 16:58 | |
*** dslev has quit IRC | 16:58 | |
michaelxin | +3 | 16:59 |
*** hyakuhei has quit IRC | 16:59 | |
*** tkelsey has quit IRC | 16:59 | |
*** tkelsey has joined #openstack-security | 17:01 | |
tkelsey | tmcpeak: https://review.openstack.org/#/c/267700/ | 17:01 |
*** hyakuhei has joined #openstack-security | 17:02 | |
*** salv-orlando has quit IRC | 17:03 | |
*** salv-orlando has joined #openstack-security | 17:04 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding a test for test id on test plugins https://review.openstack.org/267700 | 17:05 |
*** dslev has joined #openstack-security | 17:06 | |
*** dslev has quit IRC | 17:09 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Enable pep8 testing on tests https://review.openstack.org/267671 | 17:09 |
elmiko | hyakuhei: i think we may have not sent a clear enough message about the ossp meeting being cancelled today | 17:11 |
hyakuhei | oh poop | 17:11 |
elmiko | yea, couple folks showed up. i think it's all good now though, we are meeting next week right? | 17:11 |
hyakuhei | welp. I guess it’s a bit late to fix things now. | 17:11 |
hyakuhei | Yeah next week as normal | 17:12 |
elmiko | yea, i tolkd them what was up | 17:12 |
elmiko | ok, great | 17:12 |
hyakuhei | Cheers buddy, you’re a hero | 17:12 |
elmiko | hehe, right back at ya ;) | 17:12 |
michaelxin | elmiko: Thanks. | 17:14 |
michaelxin | We are break into two groups. | 17:15 |
michaelxin | One group is hacking bandit. | 17:15 |
michaelxin | Another group is working on bring your own key. | 17:15 |
openstackgerrit | Dave McCowan proposed openstack/bandit: Allow list of tests to skip to be specified on command line https://review.openstack.org/267713 | 17:15 |
michaelxin | You can find details at https://etherpad.openstack.org/p/cEA79A5fG1 | 17:15 |
*** pdesai1 has quit IRC | 17:16 | |
elmiko | michaelxin: cool, thanks! | 17:16 |
elmiko | michaelxin: i think we can skip the hangout for this afternoon (at least for me), my schedule is kinda crazy today :/ | 17:17 |
michaelxin | elmiko: sure. | 17:17 |
michaelxin | feel free to jum on the hangout now. | 17:17 |
michaelxin | disscussion just started. | 17:17 |
michaelxin | https://talkgadget.google.com/hangouts/_/gz43wqtwiit4lu7uupm55yd3oma?authuser=0&hl=en | 17:18 |
elmiko | nice whiteboards at rackspace ;) | 17:19 |
elmiko | michaelxin: angle back up a little | 17:19 |
tmcpeak | tkelsey: https://review.openstack.org/#/c/267179/ | 17:25 |
*** salv-orlando has quit IRC | 17:29 | |
*** salv-orlando has joined #openstack-security | 17:29 | |
elmiko | michaelxin: i got dropped... | 17:33 |
michaelxin | elmiko: can you try again? | 17:36 |
elmiko | trying now | 17:36 |
michaelxin | I can restart it. | 17:36 |
michaelxin | let me do that | 17:36 |
michaelxin | restarted. | 17:37 |
michaelxin | elmiko: Would you please try again | 17:37 |
*** jhfeng has quit IRC | 17:39 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 17:42 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 17:45 |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 17:46 |
*** diazjf has quit IRC | 17:50 | |
*** jhfeng has joined #openstack-security | 17:50 | |
*** jhfeng has quit IRC | 17:51 | |
tmcpeak | all: https://en.wikipedia.org/wiki/Shang_Tsung | 17:54 |
tmcpeak | elmiko = https://en.wikipedia.org/wiki/Shang_Tsung | 17:54 |
sigmavirus24 | tmcpeak: elmiko http://www.thesilmarillionmovie.com/wp-content/uploads/2014/02/thorin_silmarillion_movie56.jpg | 17:55 |
*** edtubill has quit IRC | 17:56 | |
*** edtubill has joined #openstack-security | 17:57 | |
elmiko | tmcpeak, sigmavirus24, lol | 17:58 |
*** jmckind has quit IRC | 18:00 | |
*** jhfeng has joined #openstack-security | 18:02 | |
*** jhfeng has quit IRC | 18:02 | |
*** ccie6747 has joined #openstack-security | 18:10 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 18:15 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:19 | |
mhayden | sigmavirus24: finally finished up with meetings -- someone said something about ansible stuff? | 18:20 |
*** diazjf has joined #openstack-security | 18:21 | |
*** edtubill has quit IRC | 18:21 | |
mhayden | michaelxin: hah, just saw your email | 18:22 |
* mhayden is wandering down to the room | 18:23 | |
browne | Cannot resolve file path for module sys | 18:28 |
sigmavirus24 | https://hydra.nixos.org/build/27120534/nixlog/1/raw | 18:30 |
sigmavirus24 | browne: ^ | 18:30 |
elmiko | hyakuhei: when are you guys starting the threat analysis conversation? | 18:30 |
*** jhfeng has joined #openstack-security | 18:30 | |
hyakuhei | I’m hoping to do that in the AM tomorrow so that Doug Chivers can join us | 18:31 |
elmiko | ok, awesome. i left a bunch of comments for him | 18:31 |
*** bpokorny has joined #openstack-security | 18:32 | |
elmiko | michaelxin: gonna go afk for a few, i'll try to stay connected to the hangout and just rejoin when i get back | 18:32 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding a test for test id on test plugins https://review.openstack.org/267700 | 18:34 |
hyakuhei | hey mhayden I updated cathead to actually work with recent versions of anchor https://review.openstack.org/267762 | 18:40 |
hyakuhei | Cathead is obviously not production ready but it’s simple enough to iterate on if you wanted to and can be configured to perform various actions when it grabs a fresh certificate etc | 18:41 |
mhayden | ORLY | 18:41 |
mhayden | is that "cat-head" or "ca-thead"? | 18:41 |
tmcpeak | it's cath-eee-ahd | 18:42 |
mhayden | fancy | 18:42 |
chair6 | https://en.wikipedia.org/wiki/Cathead | 18:42 |
chair6 | tmcpeak might be fancy, but according to google, it's "cat-head" | 18:43 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Add script to test bandit against projects at gate https://review.openstack.org/267029 | 18:43 |
mhayden | hyakuhei / tmcpeak: i found a good logo for it -> https://cdn.shopify.com/s/files/1/0224/1915/products/realistic-tabby-kitty-cat-head-shaped-vinyl-animal-photo-print-clutch-bag-dotoly_1024x1024.jpg?v=1398691200 | 18:43 |
tmcpeak | welp, that's considerably less fun | 18:43 |
chair6 | https://www.google.com/search?q=cathead&tbm=isch | 18:43 |
tmcpeak | mhayden: ship it! | 18:43 |
mhayden | just needs a green rectangle ;) | 18:44 |
tmcpeak | this'll do: http://www.thisiswhyimbroke.com/images/realistic-cat-head-mask.jpg | 18:44 |
* hyakuhei shudders. | 18:44 | |
mhayden | NOPE | 18:45 |
mhayden | NOPE | 18:45 |
mhayden | can't sleep now | 18:45 |
mhayden | thanks | 18:45 |
*** diazjf has quit IRC | 18:47 | |
*** bpokorny_ has joined #openstack-security | 18:49 | |
*** bpokorny_ has quit IRC | 18:50 | |
*** bpokorny_ has joined #openstack-security | 18:51 | |
sigmavirus24 | http://www.openwall.com/lists/oss-security/2016/01/14/7 > tmcpeak | 18:52 |
sigmavirus24 | mhayden: http://www.openwall.com/lists/oss-security/2016/01/14/7 | 18:52 |
*** bpokorny has quit IRC | 18:53 | |
mhayden | sigmavirus24: thank goodness i use telnet | 18:53 |
*** bpokorny_ has quit IRC | 18:55 | |
openstackgerrit | Merged openstack/bandit: Adding a test for test id on test plugins https://review.openstack.org/267700 | 18:55 |
*** bpokorny has joined #openstack-security | 18:56 | |
*** hyakuhei has quit IRC | 18:57 | |
*** bpokorny has quit IRC | 19:01 | |
*** diazjf has joined #openstack-security | 19:03 | |
*** jmckind has joined #openstack-security | 19:05 | |
elmiko | given that we have anchor and cathead, the next ship themed project name needs to Jibboom, imo. https://en.wikipedia.org/wiki/Jibboom | 19:06 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Add script to test bandit against projects at gate https://review.openstack.org/267029 | 19:06 |
*** hyakuhei has joined #openstack-security | 19:10 | |
*** jmckind_ has joined #openstack-security | 19:13 | |
sigmavirus24 | tkelsey: so... if some of the projects we're adding to our gate are already failing, can we make them non-voting until they start passing? | 19:13 |
sigmavirus24 | tkelsey: specifically I think sahara is failing /cc elmiko | 19:13 |
tkelsey | sigmavirus24: humm, seems like a good way to do it | 19:13 |
elmiko | sigmavirus24: +1, sahara probably won't be passing till close to mitaka final release (hopefully) | 19:14 |
tkelsey | yeah, makes sense, then we can turn them green as we go | 19:14 |
elmiko | i have a little more research to do about our usage of pickle and telnet | 19:14 |
*** jmckind has quit IRC | 19:16 | |
hyakuhei | Any thoughts on the best place to host a security blog? | 19:19 |
elmiko | can we have, blog.security.openstack.org? | 19:20 |
elmiko | or security.openstack.org/blog | 19:20 |
elmiko | probably though, we should talk with the doc folks about the best places | 19:20 |
elmiko | and for the styling as well | 19:20 |
sigmavirus24 | review of https://review.openstack.org/267066 would be helpful | 19:21 |
elmiko | sigmavirus24: done | 19:21 |
sigmavirus24 | Thanks elmiko | 19:21 |
elmiko | thanks to you as well sir =) | 19:22 |
sigmavirus24 | Now to get infra to look at that and review it | 19:22 |
hyakuhei | The openstack people don’t want to host a security blog elmiko | 19:24 |
hyakuhei | I was pondering something like this: http://jekyllbootstrap.com/ | 19:25 |
elmiko | yea, jekyll is nice and easy. i'm curious should be steer away from using the official openstack theme though? | 19:25 |
*** jhfeng has quit IRC | 19:26 | |
elmiko | we could certainly make a project with rst docs for the blog posts and go that route | 19:26 |
sigmavirus24 | hyakuhei: jekyll would be easy | 19:26 |
sigmavirus24 | elmiko: we could do a blog ins phinx too | 19:26 |
elmiko | hyakuhei: or, are you saying we should host at jekyllbootstrap.com? | 19:26 |
sigmavirus24 | *sphinx | 19:27 |
sigmavirus24 | elmiko: I don't think they host blogs there | 19:27 |
sigmavirus24 | it would be something.github.io potentially | 19:27 |
hyakuhei | We have an openstack-security org in github I think | 19:27 |
elmiko | sigmavirus24: my reasoning for staying to rst/sphinx is that we can reuse the openstacktheme | 19:27 |
hyakuhei | yeh https://github.com/openstack-security | 19:27 |
sigmavirus24 | elmiko: I get that. I don't know if we want to | 19:27 |
sigmavirus24 | Or if we would be allowed to | 19:27 |
elmiko | so, openstack-security.github.io then? | 19:27 |
hyakuhei | So hopefully a openstack-security.hgithub.com | 19:27 |
elmiko | sigmavirus24: ah, ok | 19:27 |
hyakuhei | yeh | 19:27 |
sigmavirus24 | So https://github.com/openstack-security/openstack-security.github.io powers openstack-security.github.io | 19:28 |
elmiko | i don't have an objection to that | 19:28 |
elmiko | yea, i have a github pages blog =) | 19:28 |
hyakuhei | We have some content there at the moment that is now replicated elsewhere | 19:28 |
hyakuhei | excellent | 19:28 |
elmiko | hyakuhei: do you envision us using the github review process for submissions? | 19:28 |
sigmavirus24 | Yeah no objection from me either | 19:28 |
hyakuhei | elmiko: that or reviewable yeah | 19:28 |
sigmavirus24 | elmiko: possibly reviewable.io I think hyakuhei said | 19:28 |
hyakuhei | ^ | 19:29 |
elmiko | ah, cool | 19:29 |
elmiko | sounds good to me, ship it! | 19:29 |
sigmavirus24 | there's also gerrithub.io but I think reviewable.io is nicer | 19:29 |
sigmavirus24 | We can also have Travis CI build stuff to make sure there are no build errors | 19:29 |
hyakuhei | Ok, so I’ll try the bootstrap and see if I can JFDI | 19:29 |
elmiko | i've used gerrithub, have not tried reviewable | 19:29 |
hyakuhei | meanwhile, let me know what your github ID’s are. | 19:29 |
elmiko | elmiko >.< | 19:29 |
sigmavirus24 | hyakuhei: same as irc nick | 19:29 |
sigmavirus24 | mvaldes: also http://logs.openstack.org/47/267747/1/check/gate-bandit-linters/c65d34e/console.html#_2016-01-14_18_26_08_934 | 19:32 |
*** jhfeng has joined #openstack-security | 19:39 | |
sigmavirus24 | ┐('~`)┌ | 19:39 |
sigmavirus24 | http://docs.openstack.org/developer/openstack-ansible-security/ | 19:40 |
browne | ¯\_(ツ)_/¯ | 19:40 |
hyakuhei | http://openstack-security.github.io/ | 19:41 |
hyakuhei | whoo | 19:41 |
*** mvaldes has quit IRC | 19:42 | |
sigmavirus24 | (☞゚ヮ゚)☞ | 19:43 |
elmiko | haha, awesome | 19:46 |
elmiko | hyakuhei: sweet, _1 | 19:46 |
elmiko | er +1 even | 19:46 |
hyakuhei | Ok, so reviewable is plugged into it too | 19:48 |
*** jhfeng has quit IRC | 19:50 | |
*** ccie6747 has quit IRC | 19:51 | |
*** jmckind has joined #openstack-security | 19:56 | |
*** jhfeng has joined #openstack-security | 19:57 | |
sigmavirus24 | elmiko: seriously, did you like gerrithub? | 19:58 |
*** jmckind_ has quit IRC | 19:59 | |
elmiko | sigmavirus24: i haven't used it enough to have a strong opinion. it was passable. | 19:59 |
sigmavirus24 | mhm | 19:59 |
elmiko | looking at reviewable.io, i've got some learning to do ;) | 19:59 |
openstackgerrit | Merged openstack/bandit: Changing config generator to display options https://review.openstack.org/267179 | 20:00 |
sigmavirus24 | elmiko: it's a lot like gerrit but made for the modern web | 20:00 |
elmiko | sigmavirus24: cool, first thing i need to do is figure out how to see openstack-security.gh.io ... lol | 20:00 |
elmiko | is there a layover for reviewable that can be seen from within github? | 20:01 |
* elmiko claps | 20:02 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: modified SQL tests https://review.openstack.org/267795 | 20:02 |
openstackgerrit | Eric Brown proposed openstack/bandit: Enable pep8 testing on tests https://review.openstack.org/267671 | 20:06 |
*** Ryan_Lane has joined #openstack-security | 20:06 | |
Ryan_Lane | with bandit is it possible to return more than one issue per check? | 20:07 |
elmiko | Ryan_Lane: do you mean, per test that is run, or for each overall run? | 20:07 |
Ryan_Lane | I'm iterating over a list of args and would like to return an issue on each arg that has an issue | 20:07 |
elmiko | ah, that may be question for tkelsey, tmcpeak, sigmavirus24, browne ^^ | 20:08 |
tkelsey | hey Ryan_Lane sorry we don't support that just yet :( it would be handy to have though | 20:09 |
Ryan_Lane | I guess I could iterate over the args and combine them into a single issue, but I was hoping to just return a list of issues | 20:09 |
Ryan_Lane | L'( | 20:09 |
Ryan_Lane | err :'( | 20:09 |
elmiko | i smell a bandit feature... ;) | 20:09 |
tkelsey | heh yeah, its would be nice to have. We can put it on our backlog though :) | 20:09 |
Ryan_Lane | I'm writing a plugin right now ;) | 20:09 |
tkelsey | elmiko: +1 | 20:09 |
tkelsey | Ryan_Lane: awesome | 20:10 |
elmiko | \o/ Ryan_Lane++ | 20:10 |
Ryan_Lane | it's a check for hardcoded passwords | 20:10 |
Ryan_Lane | I know there's already a plugin for this... but this one does different things | 20:10 |
elmiko | ah, cool | 20:10 |
sigmavirus24 | Ryan_Lane: what kind of different things? | 20:10 |
Ryan_Lane | it doesn't just look at targets and report back possible bad strings | 20:11 |
*** jmckind_ has joined #openstack-security | 20:11 | |
Ryan_Lane | it checks every string | 20:11 |
Ryan_Lane | and looks at its entropy | 20:11 |
Ryan_Lane | then bumps confidence and severity different directions based on different conditions | 20:11 |
tkelsey | Ryan_Lane: so we had some tests that looked at every string, but they were really noisy ... so would be interesting to see how yours turns out | 20:12 |
Ryan_Lane | so if the targets have things like "key, password, secret, etc" in it, it gets a +1 to confidence. if the caller is considered a safe source, it gets a -1 to confidence | 20:12 |
Ryan_Lane | if it's a flagged string (like re.compile('^AKIA')), it gets a 3/3 for confidence/severity | 20:13 |
Ryan_Lane | or "BEGIN RSA PRIVATE KEY" | 20:13 |
*** jmckind has quit IRC | 20:13 | |
Ryan_Lane | I'm fighting the noise with large numbers of regexes that match common things like imports, filenames, etc. | 20:13 |
openstackgerrit | Dave McCowan proposed openstack/security-doc: Add OSSN-0063 https://review.openstack.org/267800 | 20:20 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 20:21 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Move cli modules into their own submodule https://review.openstack.org/267190 | 20:21 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Remove unnecessary absolute_import logic from modules https://review.openstack.org/267192 | 20:21 |
sigmavirus24 | Let's approve https://review.openstack.org/#/c/267190/5 so we can stop rebasing that entire dependency chain tmcpeak :P | 20:22 |
tmcpeak | sigmavirus24: sounds good | 20:22 |
sigmavirus24 | cjschaef: I took care of your patch in that chain too | 20:22 |
cjschaef | awesome, I was just working to figure that out | 20:22 |
tmcpeak | tkelsey: https://review.openstack.org/#/c/267190/5 | 20:23 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/255546 | 20:30 |
sigmavirus24 | browne: https://github.com/ansible/ansible/issues/13873 | 20:33 |
*** jhfeng has quit IRC | 20:34 | |
openstackgerrit | Dave McCowan proposed openstack/bandit: Allow list of tests to skip to be specified on command line https://review.openstack.org/267713 | 20:38 |
*** jhfeng has joined #openstack-security | 20:39 | |
openstackgerrit | Merged openstack/bandit: Move cli modules into their own submodule https://review.openstack.org/267190 | 20:43 |
openstackgerrit | Merged openstack/bandit: Improved unit test coverage for baseline module https://review.openstack.org/267312 | 20:43 |
openstackgerrit | Merged openstack/bandit: Remove unnecessary absolute_import logic from modules https://review.openstack.org/267192 | 20:43 |
*** timkennedy1 has joined #openstack-security | 20:43 | |
elmiko | have fun tonight gang, i'm signing out. see ya in the morning =) | 20:44 |
sigmavirus24 | Later elmiko | 20:45 |
sigmavirus24 | Enjoy your evening | 20:45 |
elmiko | likewise sigmavirus24! | 20:45 |
*** timkennedy has quit IRC | 20:47 | |
sigmavirus24 | https://twitter.com/jcpoulard/status/305084997386252288 | 20:50 |
openstackgerrit | Dave McCowan proposed openstack/security-doc: Add OSSN-0063 https://review.openstack.org/267800 | 20:50 |
sigmavirus24 | tmcpeak: " Merge "Remove unnecessary absolute_import logic from modules"" | 20:51 |
openstackgerrit | Michael Dong proposed openstack/syntribos: modified SQL tests https://review.openstack.org/267795 | 20:51 |
sigmavirus24 | tmcpeak: "git reset --hard origin/master" | 20:53 |
sigmavirus24 | browne: git clean -Xf | 20:54 |
openstackgerrit | Eric Brown proposed openstack/bandit: Enable pep8 testing on tests https://review.openstack.org/267671 | 20:56 |
openstackgerrit | Matt Valdes proposed openstack/bandit: Split yaml blacklist check into its own file https://review.openstack.org/267747 | 20:58 |
tmcpeak | sigmavirus24: https://review.openstack.org/#/c/267671/4 | 20:59 |
*** mvaldes has joined #openstack-security | 21:00 | |
*** ccneill has joined #openstack-security | 21:00 | |
sigmavirus24 | tkelsey: python -m testtools.run TestId | 21:00 |
ccneill | o/ is there still a google hangout going on? | 21:01 |
ccneill | my voice is still shot, but I can at least listen along.. | 21:01 |
sigmavirus24 | ccneill: mvaldes said he'd be happy to let you do a hang out with us | 21:02 |
sigmavirus24 | we're all being very quiet | 21:02 |
ccneill | cool, well if anyone has a second to catch me up on all that I've missed, I just started a hangout: https://hangouts.google.com/call/or4zlquyu32nqycra4ruzz4qvya | 21:05 |
*** bpokorny has joined #openstack-security | 21:05 | |
sigmavirus24 | hyakuhei: where did you put the twitter theme? | 21:08 |
sigmavirus24 | into assets or _theme_packages? | 21:08 |
mvaldes | ccneill: there are minimal session notes in the etherpad | 21:08 |
sigmavirus24 | ccneill: mute :P | 21:08 |
ccneill | haha will do | 21:08 |
mvaldes | to catch up a bit | 21:09 |
mvaldes | mcdong is going over syntribos atm | 21:09 |
sigmavirus24 | hyakuhei: found the docs | 21:09 |
ccneill | cool cool. link to the etherpad? I'm on my personal laptop right now | 21:09 |
mvaldes | https://etherpad.openstack.org/p/security-mitaka-midcycle | 21:10 |
ccneill | <3 | 21:10 |
*** timkennedy has joined #openstack-security | 21:11 | |
*** timkennedy1 has quit IRC | 21:15 | |
sigmavirus24 | hyakuhei: https://github.com/openstack-security/openstack-security.github.io/tree/master/_theme_packages looks a bit ... odd | 21:17 |
sigmavirus24 | but it built locally just fine for me | 21:17 |
*** jhfeng has quit IRC | 21:17 | |
hyakuhei | Yeah, it works locally for me too but not upstream | 21:18 |
openstackgerrit | Merged openstack/bandit: Enable pep8 testing on tests https://review.openstack.org/267671 | 21:18 |
hyakuhei | I get an error from github in my email that points to https://help.github.com/articles/page-build-failed-missing-submodule/ | 21:18 |
Ryan_Lane | is anchor going to be usable outside of the openstack ecosystem? | 21:22 |
ccneill | mvaldes: is there current/planned support for xunit? | 21:24 |
ccneill | can't remember if the cafe runner supports it out of the box | 21:25 |
*** jhfeng has joined #openstack-security | 21:25 | |
hyakuhei | Ryan_Lane: Yup | 21:26 |
Ryan_Lane | how does it compare to lemur? | 21:26 |
*** jhfeng has quit IRC | 21:26 | |
hyakuhei | It plays nice with OpenStack (oslo logging, keystone tokens) but it’s not tightly coupled | 21:26 |
hyakuhei | No idea | 21:26 |
hyakuhei | Ah yeah, Lemur and Anchor are completely different projects, Lemur is really about managing certs. | 21:26 |
Ryan_Lane | hm. what's anchor's main purpose? | 21:26 |
Ryan_Lane | maintaining internal PKI infrastructure? | 21:27 |
hyakuhei | To issue short life certificates in an automated way. | 21:27 |
Ryan_Lane | gotcha | 21:27 |
elmiko | sigmavirus24, hyakuhei, how are you guys building ghpages stuff locally, because iirc, they have a different version of jekyll running at gh than what is available in the ruby gem stuff | 21:27 |
*** jhfeng has joined #openstack-security | 21:27 | |
hyakuhei | jekyll serve | 21:27 |
sigmavirus24 | elmiko: oh that might be the problem | 21:27 |
elmiko | did you get jekyll from the gems? | 21:27 |
sigmavirus24 | elmiko: yes | 21:27 |
elmiko | (it's probably too new) | 21:27 |
Ryan_Lane | @hyakuhei does it have the ability to also rotate the CA often? | 21:27 |
Ryan_Lane | like ephemeral overlapping CAs? | 21:27 |
elmiko | 1sec, i have a container project that build ghpages stuff. i'll grab the link | 21:27 |
Ryan_Lane | slack is ruining me. I use @ in irc now :( | 21:27 |
hyakuhei | It’s very light weight so you could do that pretty trivially yeah. | 21:27 |
mvaldes | ccneill: there can be :) | 21:27 |
hyakuhei | It supports running multiple roots | 21:27 |
ccneill | mvaldes: haha somehow I knew you'd say that.. | 21:27 |
browne | Ryan_Lane: Slack is the best | 21:27 |
sigmavirus24 | tkelsey: python -m testtools.discover [--list-tests maybe?] | 21:27 |
Ryan_Lane | :D | 21:27 |
elmiko | sigmavirus24, hyakuhei, check this project out https://github.com/Starefossen/docker-github-pages | 21:28 |
hyakuhei | lemur might make more sense as a anchor client | 21:29 |
*** sonuk has joined #openstack-security | 21:30 | |
Ryan_Lane | hyakuhei: hm. so you specify a ca and how long it's valid for? | 21:31 |
Ryan_Lane | so I could specify two CAs with 24 hour vailidity and it'll re-generate each CA every 24 hours? | 21:32 |
Ryan_Lane | then clients request certs from the service? | 21:32 |
ccneill | mvaldes: would you tell jgibbs I like the bandit+syntribos idea a lot? O:-) | 21:32 |
hyakuhei | Generally speaking it’s the ceritficates it provides that are ephemeral rather than the CA | 21:32 |
hyakuhei | because swapping out the root on every box in your infra is going to get messy | 21:32 |
Ryan_Lane | well, that's the idea of having multiple overlapping CAs | 21:33 |
ccneill | mvaldes: not super interesting for ints/floats in python maybe, but regexes might be fun :) | 21:33 |
Ryan_Lane | ensure you always have the current and new CAs, then when your cert is about to expire, request a new cert from the new CA | 21:33 |
tkelsey | sigmavirus24: FYI "python -m testtools.run discover --list" | 21:33 |
Ryan_Lane | hyakuhei: the basic idea is that I don't trust any node and want CAs to be short lived, like certs | 21:34 |
Ryan_Lane | so if anyone that had access to the CA leaves, it doesn't matter. it's going to expire soon anyway | 21:34 |
hyakuhei | So you could rotate CAs within within Anchor easily enough | 21:34 |
hyakuhei | and as it supports multiple CAs you can have overlap | 21:35 |
hyakuhei | which you’ll need | 21:35 |
*** timkennedy1 has joined #openstack-security | 21:35 | |
Ryan_Lane | cool. would I need to make a new backend, or just do occasionally restarts? | 21:35 |
Ryan_Lane | restarts would be non-fun :) | 21:35 |
Ryan_Lane | another fun use of this is ssh-ca | 21:36 |
Ryan_Lane | have an electron client that lives on your clients that connects to a web service protected by SSO. when it's launched, it goes through the sso flow and downloads a short-lived cert | 21:37 |
*** timkennedy has quit IRC | 21:37 | |
hyakuhei | So the blog theme works now, it required the addition of a .gitmodules file. | 21:38 |
sigmavirus24 | hyakuhei: that was going to be my guess | 21:39 |
hyakuhei | Easy to say after the fact ;) | 21:39 |
*** shakamunyi has quit IRC | 21:40 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Update readme with latest changes https://review.openstack.org/267281 | 21:40 |
elmiko | hyakuhei: nice! | 21:41 |
hyakuhei | If anyone has good photos from this week could you send them over to me please? | 21:45 |
*** diazjf has quit IRC | 21:45 | |
*** jhfeng has quit IRC | 21:45 | |
openstackgerrit | Matt Valdes proposed openstack/bandit: Split yaml blacklist check into its own file https://review.openstack.org/267747 | 21:46 |
*** jamielennox|away is now known as jamielennox | 21:49 | |
openstackgerrit | Merged openstack/bandit: Split yaml blacklist check into its own file https://review.openstack.org/267747 | 21:58 |
*** winterIsLeaving has joined #openstack-security | 21:59 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Update readme with latest changes https://review.openstack.org/267281 | 22:00 |
openstackgerrit | Merged openstack/bandit: Pretty up the plugin documentation https://review.openstack.org/267254 | 22:02 |
elmiko | sigmavirus24, hyakuhei, so is the site building locally for you guys? | 22:04 |
hyakuhei | yup, seems to be building on Github too | 22:05 |
elmiko | yea, saw that gh was working | 22:06 |
elmiko | cool | 22:06 |
sigmavirus24 | elmiko: it is | 22:07 |
sigmavirus24 | elmiko: 'gem install github-pages' | 22:07 |
elmiko | sigmavirus24: i'll try that again, i had huge issues getting my personal site to work with that stuff | 22:07 |
elmiko | hence, why i went with the docker solution | 22:07 |
openstackgerrit | Dave McCowan proposed openstack/bandit: Allow list of tests to skip to be specified on command line https://review.openstack.org/267713 | 22:07 |
elmiko | sigmavirus24: do you know if ruby has something like python virtualenvs? | 22:08 |
sigmavirus24 | elmiko: rvm, chruby, ruby-env | 22:08 |
sigmavirus24 | *rbenv | 22:08 |
elmiko | is there a "winner" amongst those? (ruby noob here) | 22:09 |
*** salv-orl_ has joined #openstack-security | 22:09 | |
dave-mcc_ | hyakuhei rob, will you please chime in on this review: https://review.openstack.org/#/c/266680/ there's some debate on if this should be backported. | 22:09 |
sigmavirus24 | elmiko: depends on who you ask | 22:10 |
hyakuhei | sure | 22:10 |
elmiko | sigmavirus24: gotcha, i'll mess around then ;) | 22:10 |
sigmavirus24 | elmiko: I prefer rvm but it's a bunch of bash hacks that fubar your path | 22:11 |
sigmavirus24 | rbenv is the parent of pyenv (if you've ever used that) | 22:11 |
elmiko | hmm, that sounds undesirable | 22:11 |
sigmavirus24 | never buggered with chruby | 22:11 |
openstackgerrit | Eric Brown proposed openstack/bandit: Add missing automodule doc for yaml_load https://review.openstack.org/267839 | 22:11 |
*** salv-orlando has quit IRC | 22:12 | |
hyakuhei | tmcpeak: https://github.com/openstack-security/openstack-security.github.io | 22:13 |
*** timkennedy has joined #openstack-security | 22:15 | |
sigmavirus24 | https://github.com/blog#continued-worktree-improvements | 22:18 |
*** timkennedy1 has quit IRC | 22:18 | |
hyakuhei | dave-mcc_: done. | 22:19 |
sigmavirus24 | https://review.openstack.org/267713 tkelsey | 22:24 |
*** dave-mcc_ has quit IRC | 22:25 | |
openstackgerrit | Merged openstack/bandit: Allow list of tests to skip to be specified on command line https://review.openstack.org/267713 | 22:26 |
*** ccneill has quit IRC | 22:26 | |
openstackgerrit | Eric Brown proposed openstack/bandit: Update readme with latest changes https://review.openstack.org/267281 | 22:31 |
hyakuhei | elmiko: Can you attempt to get a post up on the blog please? Doesn’t have to be any more than a hello world. I’m having local issues. | 22:31 |
elmiko | hyakuhei: ack, mtg currently, but i'll give it a shot in about 20mn | 22:36 |
hyakuhei | Danke | 22:36 |
Daviey | hyakuhei: a summary of the week would be really interesting aswell :) | 22:44 |
hyakuhei | We’ve already cut an internal one (HP propaganda) so we’ll share something similar more widely tomorrow :) | 22:45 |
Daviey | hyakuhei: well hopefully content heavy, not marketing heavy. :) | 22:45 |
hyakuhei | They’re not the same thing? | 22:46 |
Daviey | Oh You. | 22:46 |
*** ninag has quit IRC | 22:53 | |
elmiko | hyakuhei: https://openstack-security.github.io/test/2016/01/14/security-is-fun/ | 22:53 |
*** ninag has joined #openstack-security | 22:54 | |
*** jmckind_ has quit IRC | 22:54 | |
hyakuhei | elmiko: oh cool. What did you do to make the theme work? | 22:54 |
hyakuhei | When I try to create a page it doesn’t set the theme correctly. | 22:55 |
elmiko | weird.. | 22:56 |
elmiko | did you set the layout to post? | 22:56 |
hyakuhei | Yeah I think so, I’m just going to copy yours from now on anyway :D | 22:56 |
elmiko | haha, fair | 22:56 |
sigmavirus24 | https://github.com/heiswayi/the-plain | 22:57 |
*** ninag has quit IRC | 22:58 | |
*** hyakuhei has quit IRC | 22:58 | |
*** tmcpeak has quit IRC | 22:59 | |
*** browne has quit IRC | 22:59 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:59 | |
*** cjschaef has quit IRC | 22:59 | |
*** tkelsey has quit IRC | 23:02 | |
*** mvaldes has quit IRC | 23:04 | |
*** sonuk has quit IRC | 23:05 | |
*** bpokorny_ has joined #openstack-security | 23:17 | |
*** bpokorny has quit IRC | 23:20 | |
*** ccneill has joined #openstack-security | 23:24 | |
Ryan_Lane | is it possible to disable a specific bandit check on a line of code? I see a lot of the tests have test numbers associated with them | 23:25 |
*** Mainus has joined #openstack-security | 23:26 | |
*** ninag has joined #openstack-security | 23:28 | |
*** ccneill has quit IRC | 23:28 | |
Daviey | Ryan_Lane: Add #nosec to the line | 23:30 |
*** Mainus has quit IRC | 23:30 | |
*** ninag has quit IRC | 23:32 | |
Ryan_Lane | Daviey: that disables all bandit checks | 23:32 |
Ryan_Lane | I'd like to disable only one particular check | 23:33 |
Daviey | Ryan_Lane: Ah, i don't think you can do that.... jut disable the entire test for everything, or the entire line for each test. | 23:34 |
Ryan_Lane | for instance, something like #no-b103 | 23:34 |
Ryan_Lane | or #nosec-b103 | 23:34 |
Ryan_Lane | or something along those lines | 23:34 |
elmiko | i like that Ryan_Lane has come up with 2 features already =) | 23:46 |
Ryan_Lane | well, I'm at a point where I have some false-positives that look like they would actually be real secrets and would like to mark them as not secrets :) | 23:48 |
Ryan_Lane | but I don't want to disable other checks, because maybe it has some other security flaw | 23:49 |
elmiko | yea, makes sense | 23:49 |
Ryan_Lane | really liking bandit for the most part so far, though :) | 23:51 |
elmiko | \o/ | 23:51 |
Ryan_Lane | basically just an easy way to walk through an AST | 23:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!