*** chas has quit IRC | 00:02 | |
*** aastha has quit IRC | 00:17 | |
*** dikonoor has joined #openstack-security | 00:31 | |
*** salv-orlando has joined #openstack-security | 00:46 | |
*** salv-orlando has quit IRC | 00:51 | |
*** dave-mccowan has quit IRC | 01:06 | |
*** dikonoor has quit IRC | 01:15 | |
*** dave-mccowan has joined #openstack-security | 01:29 | |
*** jamielennox is now known as jamielennox|away | 01:50 | |
*** salv-orlando has joined #openstack-security | 01:53 | |
*** jamielennox|away is now known as jamielennox | 02:00 | |
*** salv-orlando has quit IRC | 02:04 | |
*** diazjf has joined #openstack-security | 02:07 | |
*** sdake_ has joined #openstack-security | 02:08 | |
*** sdake has quit IRC | 02:12 | |
*** austin987 has joined #openstack-security | 02:12 | |
*** chas has joined #openstack-security | 02:14 | |
*** sdake_ has quit IRC | 02:17 | |
*** chas has quit IRC | 02:18 | |
*** sdake has joined #openstack-security | 02:19 | |
*** sdake has quit IRC | 02:23 | |
*** sdake has joined #openstack-security | 02:29 | |
*** bigdogstl has joined #openstack-security | 02:46 | |
*** bigdogstl has quit IRC | 02:51 | |
*** bigdogstl has joined #openstack-security | 02:56 | |
*** jamielennox is now known as jamielennox|away | 02:56 | |
*** diazjf has quit IRC | 02:58 | |
*** bigdogstl has quit IRC | 03:01 | |
*** salv-orlando has joined #openstack-security | 03:03 | |
*** salv-orlando has quit IRC | 03:06 | |
*** jamielennox|away is now known as jamielennox | 03:10 | |
*** sdake has quit IRC | 03:12 | |
*** sdake has joined #openstack-security | 03:13 | |
openstackgerrit | Vinay Potluri proposed openstack/security-doc: Updated OSSN-0069 https://review.openstack.org/356712 | 03:24 |
---|---|---|
*** dikonoor has joined #openstack-security | 03:46 | |
*** sdake has quit IRC | 03:56 | |
*** austin987 has quit IRC | 04:00 | |
*** salv-orlando has joined #openstack-security | 04:07 | |
*** dave-mccowan has quit IRC | 04:09 | |
*** salv-orlando has quit IRC | 04:14 | |
*** chas has joined #openstack-security | 04:15 | |
*** chas has quit IRC | 04:20 | |
*** sdake has joined #openstack-security | 04:22 | |
*** chas has joined #openstack-security | 04:46 | |
*** chas has quit IRC | 04:50 | |
*** austin987 has joined #openstack-security | 04:59 | |
*** terri has quit IRC | 04:59 | |
*** austin987 has quit IRC | 05:11 | |
*** salv-orlando has joined #openstack-security | 05:17 | |
*** salv-orlando has quit IRC | 05:20 | |
*** salv-orlando has joined #openstack-security | 05:25 | |
*** salv-orlando has quit IRC | 05:25 | |
*** salv-orlando has joined #openstack-security | 05:26 | |
*** austin987 has joined #openstack-security | 05:27 | |
*** austin987 has quit IRC | 05:52 | |
*** chas has joined #openstack-security | 06:12 | |
*** rcernin has joined #openstack-security | 06:26 | |
*** salv-orlando has quit IRC | 06:31 | |
*** tesseract- has joined #openstack-security | 06:44 | |
*** salv-orlando has joined #openstack-security | 06:45 | |
*** salv-orlando has quit IRC | 07:16 | |
*** jass93 has quit IRC | 07:39 | |
*** jass93 has joined #openstack-security | 07:39 | |
*** B_Smith has quit IRC | 07:54 | |
*** B_Smith has joined #openstack-security | 07:54 | |
*** salv-orlando has joined #openstack-security | 07:54 | |
*** sdake has quit IRC | 08:05 | |
*** sdake has joined #openstack-security | 08:05 | |
*** openstackgerrit has quit IRC | 08:18 | |
*** openstackgerrit has joined #openstack-security | 08:18 | |
*** terri has joined #openstack-security | 08:30 | |
*** sdake has quit IRC | 08:48 | |
*** vinaypotluri has quit IRC | 09:01 | |
*** salv-orl_ has joined #openstack-security | 09:17 | |
*** salv-orlando has quit IRC | 09:20 | |
*** tkelsey has joined #openstack-security | 09:32 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/361038 | 09:34 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/361038 | 09:49 |
*** chas_ has joined #openstack-security | 10:40 | |
*** chas has quit IRC | 10:42 | |
*** salv-orl_ has quit IRC | 11:27 | |
*** shohel has joined #openstack-security | 11:35 | |
*** chas_ has quit IRC | 11:51 | |
*** woodster_ has joined #openstack-security | 12:34 | |
*** nkinder has joined #openstack-security | 12:37 | |
*** jass93 has quit IRC | 12:49 | |
*** _elmiko is now known as elmiko | 12:56 | |
*** salv-orlando has joined #openstack-security | 13:03 | |
*** mvaldes has joined #openstack-security | 13:06 | |
*** zul has joined #openstack-security | 13:07 | |
*** dave-mccowan has joined #openstack-security | 13:12 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-analysis: Update requirements https://review.openstack.org/361167 | 13:13 |
openstackgerrit | Andreas Jaeger proposed openstack/security-analysis: Report sphinx errors https://review.openstack.org/361168 | 13:13 |
*** sdake has joined #openstack-security | 13:14 | |
*** sdake_ has joined #openstack-security | 13:15 | |
*** sdake has quit IRC | 13:19 | |
*** sdake_ has quit IRC | 13:37 | |
*** dikonoor has quit IRC | 13:38 | |
*** sdake has joined #openstack-security | 13:40 | |
*** salv-orlando has quit IRC | 13:40 | |
*** shohel has quit IRC | 13:44 | |
*** knangia has quit IRC | 13:51 | |
*** mvaldes has quit IRC | 14:22 | |
*** singlethink has joined #openstack-security | 14:24 | |
*** ccneill-phone has quit IRC | 14:25 | |
*** mvaldes has joined #openstack-security | 14:27 | |
lhinds | who are the core reviewers on openstack/security-doc ? | 14:31 |
*** cleong has joined #openstack-security | 14:35 | |
*** zul has quit IRC | 14:42 | |
*** vinaypotluri has joined #openstack-security | 14:47 | |
*** hockeynut has joined #openstack-security | 15:03 | |
*** rcernin has quit IRC | 15:04 | |
*** sdake_ has joined #openstack-security | 15:11 | |
*** sdake has quit IRC | 15:15 | |
*** knangia has joined #openstack-security | 15:18 | |
*** browne has joined #openstack-security | 15:20 | |
*** aastha has joined #openstack-security | 15:26 | |
*** ccneill has joined #openstack-security | 15:28 | |
*** pcaruana has quit IRC | 15:33 | |
*** tesseract- has quit IRC | 15:38 | |
*** zul has joined #openstack-security | 15:42 | |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: Buffer Overflow data file dependency is removed https://review.openstack.org/360558 | 15:52 |
*** zul has quit IRC | 15:56 | |
*** mdong has joined #openstack-security | 16:08 | |
*** edtubill has joined #openstack-security | 16:08 | |
*** nkinder has quit IRC | 16:15 | |
*** salv-orlando has joined #openstack-security | 16:18 | |
*** diazjf has joined #openstack-security | 16:20 | |
*** mdong_ has joined #openstack-security | 16:25 | |
*** hockeynut has quit IRC | 16:28 | |
*** mdong has quit IRC | 16:28 | |
*** mdong_ is now known as mdong | 16:28 | |
*** zul has joined #openstack-security | 16:30 | |
*** tkelsey has quit IRC | 16:39 | |
*** rcernin has joined #openstack-security | 16:44 | |
*** nkinder has joined #openstack-security | 16:46 | |
ccneill | vinaypotluri / unrahul : can one of you review this and +2 if you're good with it? | 16:46 |
unrahul | which one ccneill ? | 16:47 |
ccneill | https://review.openstack.org/#/c/358870/ | 16:47 |
vinaypotluri | sure charles | 16:47 |
ccneill | sorry, forgot to paste lol | 16:47 |
ccneill | thanks! | 16:47 |
unrahul | :D | 16:48 |
unrahul | done! | 16:48 |
unrahul | ccneill: can u pls check this https://review.openstack.org/#/c/360127/, sanitize logs cr and comment | 16:49 |
ccneill | yep, taking a look now | 16:49 |
unrahul | I was thinking of modifying it and making it mandatory that auth req creds are masked and giving option to the user to extend the functionality using a logging option to other stuff if req.. | 16:50 |
*** mdong has quit IRC | 16:56 | |
*** mdong_ has joined #openstack-security | 16:56 | |
*** dikonoor has joined #openstack-security | 16:58 | |
ccneill | trying to decide what terminology makes the most sense... | 17:00 |
openstackgerrit | Merged openstack/syntribos: Memoized extension functions https://review.openstack.org/358870 | 17:00 |
ccneill | unrahul: maybe we make it a stropt with choices, like "all", "auth", and "none" | 17:03 |
ccneill | all == we filter x-auth tokens and identity passwords | 17:04 |
ccneill | maybe "auth_password" == we only filter the password used to request the token | 17:04 |
*** nkinder has quit IRC | 17:04 | |
ccneill | none == no filtering | 17:04 |
ccneill | I guess we could make them individual logger options.. | 17:05 |
ccneill | mask_passwords, mask_tokens, mask_* | 17:05 |
unrahul | hmm.. I think oslo utils only sanitize passwords, not tokens.. will have to overwrite the method.. dont think it would be a big deal though.. | 17:06 |
unrahul | so are we giving the option to mask/unmask auth req secrets?? | 17:06 |
*** diazjf has quit IRC | 17:06 | |
ccneill | hmm I haven't really worked with oslo.util | 17:06 |
ccneill | let me look | 17:06 |
unrahul | because.. I was thinking.. if we give an option to unmask auth req secrets.. and some leaves it open.. on a gate job.. everyone will get to know the login details to the cluster... :/ | 17:07 |
ccneill | right.. I guess if they want to debug the password sent to identity they can look at it through a proxy | 17:08 |
ccneill | I was thinking of leaving it configurable, but there's no reason to leave the option to shoot yourself in the foot if it's not really that useful in the first place | 17:08 |
unrahul | yeah.. :D.. it would be epic.. | 17:09 |
ccneill | looks like oslo.util doesn't do x-auth-token headers.. | 17:10 |
unrahul | so.. may be we can give options for rest of req.. but not for keystone auth.. and anyone want to build similar auth plugins/extenstions.. we could say in the doc to ensure that secrets are sanitized.. | 17:10 |
ccneill | +1 | 17:10 |
unrahul | yeah .. I can checkout the code and think it would be a simple as adding one more option to the list.. (hopefully) and overide the method.. | 17:11 |
ccneill | hmm.. x-auth-tokens are gonna be tricky | 17:11 |
ccneill | because we fuzz that header.. | 17:11 |
unrahul | or should we roll our own..? | 17:11 |
ccneill | we might want to roll our own | 17:11 |
unrahul | we fuzz passwords too ryt..? | 17:11 |
ccneill | mmm yes we might, but not in the actual identity request | 17:11 |
unrahul | oh.. yeah | 17:11 |
ccneill | (get_token_v2/etc.) | 17:11 |
ccneill | that's the reason for the filter_secrets thing on RequestObject | 17:12 |
ccneill | but we can't do that for fuzzing x-auth-token unless we build some logic into the fuzzer to specifically add it whenever the variable being fuzzed is NOT x-auth-token | 17:12 |
unrahul | I think we can request a token for a few mintues.. or something | 17:13 |
unrahul | and do our stuff.. | 17:13 |
unrahul | ? | 17:13 |
ccneill | hmmm.. I don't think we want to tie it to that, then we have a race condition whenever a syntribos job runs | 17:14 |
ccneill | and we have to predict how long a run will last | 17:14 |
ccneill | >< | 17:14 |
unrahul | I shall mod the patch I guess.. somehow :o.. .. I was working on rolling our own and browne told me about this awesome package (oslo.utils) .. so I was like, cool will use that instead | 17:14 |
unrahul | so what are our assumptions.. and logging options u think is req.. ? | 17:14 |
ccneill | I'll comment on the CR in a sec | 17:15 |
unrahul | +1 | 17:15 |
*** diazjf has joined #openstack-security | 17:16 | |
*** rcernin has quit IRC | 17:22 | |
*** blackdiaamond has quit IRC | 17:49 | |
*** sdake_ has quit IRC | 18:02 | |
*** diazjf has quit IRC | 18:03 | |
mdong_ | ccneill: I know this is all super nitpicky stuff | 18:04 |
mdong_ | but if I change payload_dir and exclude_results to payload-dir and exclude-results | 18:05 |
mdong_ | then those options in the config options will be inconsistent with the rest of the config file | 18:05 |
mdong_ | so under [syntribos] we’ll have payload-dir, but under [logger], we’ll have log_dir | 18:06 |
mdong_ | so basically it’s a straight choice between being inconsistent with the rest of the config file and being inconsistent with the rest of our CLI options | 18:06 |
*** mdong_ is now known as mdong | 18:07 | |
*** tkelsey has joined #openstack-security | 18:36 | |
*** aastha has quit IRC | 18:37 | |
*** tkelsey has quit IRC | 18:41 | |
*** knangia has quit IRC | 18:51 | |
*** zul has quit IRC | 18:51 | |
*** dikonoor has quit IRC | 18:56 | |
*** markvoelker has quit IRC | 18:57 | |
ccneill | mdong: >< yeah, I realized that.. I just think it will be annoying to remember which ones are which | 18:58 |
ccneill | but it's not a big deal - we can leave it alone for now | 18:59 |
ccneill | to avoid the trouble of having to re-do the docs/configs/etc. | 18:59 |
*** markvoelker has joined #openstack-security | 19:00 | |
*** browne has quit IRC | 19:09 | |
*** salv-orlando has quit IRC | 19:10 | |
*** knangia has joined #openstack-security | 19:10 | |
mdong | cool, so I’ve also been thinking about the other comment you had about counting excluded tests | 19:19 |
mdong | so basically counting the number of issues that were skipped is pretty trivial, but there can of course be many duplicate issues | 19:19 |
mdong | hence why the formatter creates an entirely new data structure just to count the issues, to remove duplicates | 19:20 |
mdong | so we could have another separate data structure to remove duplicates from the count of excluded issues as well | 19:22 |
mdong | which is fine, but that’s just wasted work for data that’s basically just thrown away | 19:22 |
ccneill | agreed.. | 19:22 |
ccneill | :/ | 19:22 |
mdong | so I was thinking, we could just not test for the issues we exclude | 19:23 |
ccneill | mmm that could get tricky | 19:23 |
ccneill | unfortunately we have to start testing on Monday and I don't think we'll have much time for big changes like this for a little while at least | 19:23 |
mdong | if we don’t care about reporting them, why do we care about running them? of course this is a more involved change | 19:23 |
mdong | yeah | 19:23 |
ccneill | right, I agree | 19:24 |
ccneill | I think we have some work to do around convenience methods for running checks | 19:24 |
ccneill | we were also planning on removing "500_errors" as a distinct type of issue | 19:24 |
ccneill | or at least were discussing that possibility | 19:24 |
ccneill | since we want to push the checks to the tests themselves instead of having a "check_default_issues" method in base_fuzz | 19:25 |
mdong | so for this change at least, what did you wanna do? We could just leaving the counting as is and then come back later to skip checks from being run | 19:25 |
ccneill | yep ^ | 19:26 |
ccneill | I think we'll revisit in the future | 19:26 |
mdong | sounds good | 19:26 |
ccneill | we'll see what we get from our testing starting on Monday | 19:26 |
ccneill | and if it turns out that we reeeeeeeally need this, we'll try to make time for it | 19:26 |
mdong | I don’t think I need to have another patch up for that CR then | 19:26 |
ccneill | nope, I'll +1 | 19:26 |
mdong | sounds good, I’ll put that as a backlog card | 19:29 |
*** browne has joined #openstack-security | 19:31 | |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: Buffer Overflow data file dependency is removed https://review.openstack.org/360558 | 19:31 |
*** aastha has joined #openstack-security | 19:33 | |
ccneill | mdong: good call | 19:36 |
*** ISBEL has joined #openstack-security | 19:54 | |
*** jraim has quit IRC | 20:02 | |
*** singlethink has quit IRC | 20:02 | |
*** aimeeu has quit IRC | 20:04 | |
*** serverascode has quit IRC | 20:04 | |
*** singlethink has joined #openstack-security | 20:05 | |
ISBEL | hola dime tu nombre real | 20:26 |
*** jraim has joined #openstack-security | 20:35 | |
*** ISBEL has quit IRC | 20:36 | |
*** serverascode has joined #openstack-security | 20:42 | |
*** gmurphy has quit IRC | 20:43 | |
*** edtubill has quit IRC | 20:50 | |
*** sdake has joined #openstack-security | 21:02 | |
*** salv-orlando has joined #openstack-security | 21:03 | |
*** cleong has quit IRC | 21:07 | |
*** aimeeu has joined #openstack-security | 21:09 | |
*** salv-orl_ has joined #openstack-security | 21:18 | |
*** salv-orlando has quit IRC | 21:20 | |
*** gmurphy has joined #openstack-security | 21:25 | |
*** gmurphy has quit IRC | 21:32 | |
*** gmurphy has joined #openstack-security | 21:33 | |
*** mvaldes has quit IRC | 21:56 | |
*** sdake_ has joined #openstack-security | 22:01 | |
*** sdake has quit IRC | 22:03 | |
*** mdong has quit IRC | 22:05 | |
*** mdong_ has joined #openstack-security | 22:05 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: patch to sanitize debug log https://review.openstack.org/360127 | 22:24 |
*** austin987 has joined #openstack-security | 22:26 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: patch to sanitize debug log https://review.openstack.org/360127 | 22:28 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Revamped results schema https://review.openstack.org/361507 | 22:30 |
*** austin987 has quit IRC | 22:32 | |
unrahul | ccneill: u there? | 22:33 |
*** austin987 has joined #openstack-security | 22:36 | |
ccneill | yep, sup | 22:43 |
unrahul | i have uploaded the patch | 22:44 |
*** edmondsw has quit IRC | 22:44 | |
unrahul | but still we are not sure on what do for tokens | 22:44 |
unrahul | ryt | 22:44 |
*** elmiko is now known as _elmiko | 22:44 | |
unrahul | should we sanitize the token.. or..not.? | 22:44 |
unrahul | as we would be fuzzing the token as well.. | 22:44 |
ccneill | right | 22:45 |
ccneill | let's not worry about it right now | 22:45 |
ccneill | we want to be ready for Monday, and I think we want to at least be filtering out Keystone passwords by then | 22:45 |
ccneill | but we'll figure out x-auth-tokens when we have time | 22:45 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Revamped results schema https://review.openstack.org/361507 | 22:46 |
ccneill | looks like Jenkins -1'd for a pep8 thing in a docstring http://logs.openstack.org/27/360127/7/check/gate-syntribos-pep8-ubuntu-xenial/ab5e1db/console.html#_2016-08-26_22_32_23_776922 | 22:46 |
*** singlethink has quit IRC | 22:46 | |
unrahul | ah crap. let me check | 22:47 |
*** austin987 has quit IRC | 22:50 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: patch to sanitize debug log https://review.openstack.org/360127 | 22:51 |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: Buffer Overflow data file dependency is removed https://review.openstack.org/360558 | 22:56 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: patch to sanitize debug log https://review.openstack.org/360127 | 22:57 |
*** salv-orl_ has quit IRC | 23:00 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Revamped results schema https://review.openstack.org/361507 | 23:00 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added config file improvements https://review.openstack.org/358856 | 23:00 |
*** serverascode has quit IRC | 23:01 | |
*** aimeeu has quit IRC | 23:01 | |
*** jraim has quit IRC | 23:09 | |
*** serverascode has joined #openstack-security | 23:20 | |
unrahul | hey ccneill jenkins gave a +1 phew .. | 23:22 |
ccneill | nice | 23:23 |
ccneill | looking it over now | 23:24 |
ccneill | about to pack up for the weekend | 23:24 |
unrahul | yeah.. tired.. need to hit some place.. have some food..haa Friday.. | 23:26 |
ccneill | yep yep | 23:27 |
*** aimeeu has joined #openstack-security | 23:32 | |
ccneill | made some comments.. don't worry about them right now if you're about to head out - we'll revisit on Monday | 23:32 |
unrahul | yup.. just saw those ccneill , i shall upload a patch later.. then.. see u guys on monday.. | 23:33 |
ccneill | o/ have a good weekend! | 23:34 |
unrahul | yup u too! | 23:35 |
*** amit213 has quit IRC | 23:37 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Revamped results schema https://review.openstack.org/361507 | 23:38 |
*** amit213 has joined #openstack-security | 23:40 | |
*** mdong_ has quit IRC | 23:43 | |
*** aimeeu has quit IRC | 23:46 | |
*** serverascode has quit IRC | 23:46 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!