*** JAHoagie has quit IRC | 00:08 | |
*** jass93 has joined #openstack-security | 00:40 | |
*** vinaypotluri has quit IRC | 01:02 | |
*** ccneill has quit IRC | 01:07 | |
*** vinaypotluri has joined #openstack-security | 01:20 | |
*** mdong has joined #openstack-security | 01:22 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 01:28 |
---|---|---|
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 01:29 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 01:32 |
*** mdong has quit IRC | 01:44 | |
*** austin987 has joined #openstack-security | 01:49 | |
*** zhihui has joined #openstack-security | 01:54 | |
*** yeison has joined #openstack-security | 02:04 | |
*** yeison has quit IRC | 02:05 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 02:20 |
*** salv-orl_ has joined #openstack-security | 02:30 | |
*** gfhellma has joined #openstack-security | 02:33 | |
*** salv-orlando has quit IRC | 02:33 | |
*** gfhellma has quit IRC | 03:04 | |
*** markvoelker has quit IRC | 03:30 | |
*** sdake has joined #openstack-security | 03:31 | |
*** dikonoor has joined #openstack-security | 03:45 | |
*** jamielennox is now known as jamielennox|away | 04:05 | |
*** jamielennox|away is now known as jamielennox | 04:08 | |
*** jamielennox is now known as jamielennox|away | 04:41 | |
*** jamielennox|away is now known as jamielennox | 04:46 | |
*** salv-orl_ has quit IRC | 04:52 | |
*** salv-orlando has joined #openstack-security | 04:53 | |
*** sdake_ has joined #openstack-security | 05:10 | |
*** sdake has quit IRC | 05:12 | |
*** amitkqed has quit IRC | 05:16 | |
*** amitkqed has joined #openstack-security | 05:16 | |
*** knangia has quit IRC | 05:21 | |
*** zhihui has quit IRC | 05:29 | |
*** markvoelker has joined #openstack-security | 05:30 | |
*** markvoelker has quit IRC | 05:35 | |
openstackgerrit | chen.xing proposed openstack/security-doc: Update endpoint create command https://review.openstack.org/368314 | 05:37 |
*** jamielennox is now known as jamielennox|away | 05:53 | |
*** jamielennox|away is now known as jamielennox | 06:00 | |
*** jamielennox is now known as jamielennox|away | 06:13 | |
*** salv-orl_ has joined #openstack-security | 06:15 | |
*** salv-orlando has quit IRC | 06:18 | |
*** rcernin has joined #openstack-security | 06:19 | |
*** JAHoagie has joined #openstack-security | 06:19 | |
*** salv-orl_ has quit IRC | 06:19 | |
*** jamielennox|away is now known as jamielennox | 06:30 | |
*** liverpooler has joined #openstack-security | 06:32 | |
*** shohel has joined #openstack-security | 06:50 | |
*** woodster_ has quit IRC | 06:59 | |
*** pcaruana has joined #openstack-security | 07:02 | |
*** tesseract- has joined #openstack-security | 07:08 | |
*** yarkot has quit IRC | 07:11 | |
*** zhihui has joined #openstack-security | 07:17 | |
*** sdake has joined #openstack-security | 07:19 | |
*** sdake_ has quit IRC | 07:20 | |
*** salv-orlando has joined #openstack-security | 07:23 | |
*** markvoelker has joined #openstack-security | 07:31 | |
*** markvoelker has quit IRC | 07:36 | |
*** openstackgerrit has quit IRC | 07:48 | |
*** openstackgerrit has joined #openstack-security | 07:49 | |
*** JAHoagie has quit IRC | 07:54 | |
*** zhihui has quit IRC | 08:04 | |
*** sdake has quit IRC | 08:10 | |
*** tkelsey has joined #openstack-security | 08:17 | |
*** zhihui has joined #openstack-security | 08:17 | |
*** lmiccini_ has joined #openstack-security | 08:19 | |
*** cgross has quit IRC | 08:19 | |
*** lmiccini has quit IRC | 08:20 | |
*** cgross has joined #openstack-security | 08:21 | |
*** vinaypotluri has quit IRC | 08:22 | |
*** lmiccini_ is now known as lmiccini | 08:25 | |
*** zigo_ is now known as zigo | 08:34 | |
*** austin987 has quit IRC | 08:35 | |
*** markvoelker has joined #openstack-security | 09:25 | |
*** markvoelker has quit IRC | 09:29 | |
*** shohel1 has joined #openstack-security | 10:04 | |
*** shohel has quit IRC | 10:05 | |
*** shohel has joined #openstack-security | 10:09 | |
*** shohel1 has quit IRC | 10:11 | |
*** shohel has quit IRC | 10:15 | |
*** lmiccini has quit IRC | 10:25 | |
*** cgross has quit IRC | 10:25 | |
*** ayoung has quit IRC | 10:25 | |
*** shohel has joined #openstack-security | 10:28 | |
*** ayoung has joined #openstack-security | 10:37 | |
*** dikonoor has quit IRC | 10:49 | |
*** shohel1 has joined #openstack-security | 11:06 | |
*** shohel has quit IRC | 11:07 | |
*** shohel1 has quit IRC | 11:10 | |
*** markvoelker has joined #openstack-security | 11:25 | |
*** markvoelker has quit IRC | 11:30 | |
*** salv-orlando has quit IRC | 11:38 | |
*** zhihui has quit IRC | 12:09 | |
*** markvoelker has joined #openstack-security | 12:11 | |
*** edmondsw has joined #openstack-security | 12:24 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369416 | 12:26 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369416 | 12:34 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369425 | 12:40 |
*** zhihui has joined #openstack-security | 12:41 | |
*** salv-orlando has joined #openstack-security | 12:44 | |
*** dikonoor has joined #openstack-security | 12:45 | |
*** salv-orlando has quit IRC | 12:50 | |
*** sdake_ has joined #openstack-security | 13:04 | |
*** sdake_ is now known as sdake | 13:10 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369425 | 13:11 |
*** cleong has joined #openstack-security | 13:11 | |
*** woodster_ has joined #openstack-security | 13:18 | |
*** salv-orlando has joined #openstack-security | 13:40 | |
*** singlethink has joined #openstack-security | 13:56 | |
*** sdake has quit IRC | 13:58 | |
*** gfhellma has joined #openstack-security | 13:58 | |
*** JAHoagie has joined #openstack-security | 14:00 | |
*** zhihui has quit IRC | 14:06 | |
*** sdake has joined #openstack-security | 14:12 | |
*** gfhellma has quit IRC | 14:17 | |
*** mvaldes has joined #openstack-security | 14:19 | |
*** JAHoagie has quit IRC | 14:21 | |
*** jmckind has joined #openstack-security | 14:25 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369425 | 14:25 |
openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 14:39 |
*** dave-mccowan has joined #openstack-security | 14:41 | |
*** knangia has joined #openstack-security | 14:58 | |
*** austin987 has joined #openstack-security | 15:01 | |
*** mvaldes1 has joined #openstack-security | 15:05 | |
*** _elmiko is now known as elmiko | 15:07 | |
*** mvaldes has quit IRC | 15:08 | |
*** edtubill has joined #openstack-security | 15:08 | |
*** sigmavirus|awa has quit IRC | 15:11 | |
*** purp has quit IRC | 15:11 | |
*** _sigmavirus24 has joined #openstack-security | 15:14 | |
*** purp has joined #openstack-security | 15:15 | |
openstackgerrit | Allen proposed openstack/security-doc: Use hyperlink markup for the link title https://review.openstack.org/369525 | 15:21 |
tmcpeak | dstufft: waddup | 15:24 |
*** dave-mccowan has quit IRC | 15:32 | |
*** dave-mccowan has joined #openstack-security | 15:37 | |
*** diazjf has joined #openstack-security | 15:40 | |
*** mdong has joined #openstack-security | 15:50 | |
*** zul has joined #openstack-security | 15:52 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 15:59 |
*** jmckind_ has joined #openstack-security | 16:00 | |
*** jmckind has quit IRC | 16:01 | |
*** vinaypotluri has joined #openstack-security | 16:02 | |
openstackgerrit | Merged openstack/security-doc: Use hyperlink markup for the link title https://review.openstack.org/369525 | 16:03 |
*** JAHoagie has joined #openstack-security | 16:07 | |
*** mvaldes1 has quit IRC | 16:09 | |
*** ccneill has joined #openstack-security | 16:11 | |
ccneill | sigh.. vidyo is being buggy, will be there soon (hopefully).. | 16:16 |
*** mvaldes has joined #openstack-security | 16:30 | |
ccneill | unrahul, vinaypotluri, knangia, mdong : let's track the template generation in that google doc we started for neutron templates | 16:34 |
ccneill | everyone have the link? | 16:34 |
mdong | yep, though I think we should make a seperate sheet for Glance | 16:34 |
mdong | just so we don’t have to scroll down 200 lines to see the Glance templates | 16:35 |
vinaypotluri | yup | 16:35 |
vinaypotluri | https://docs.google.com/spreadsheets/d/1Utng17QJRW3aBIrDxu2B5oBq5jNVKewb8apj-Ztfe0s/edit | 16:35 |
ccneill | 25, not bad | 16:41 |
*** markvoelker has quit IRC | 16:44 | |
*** tesseract- has quit IRC | 16:46 | |
mdong | so one thing I noticed in our neutron templates is that the template names are inconsistent | 16:48 |
mdong | dunno if this is something yall already addressed | 16:48 |
ccneill | >_< | 16:49 |
ccneill | we haven't addressed it yet | 16:50 |
ccneill | but I noticed that during testing | 16:50 |
mdong | for example, the lbaas templates have the HTTP verbs first while the others have them last | 16:50 |
*** liverpooler has quit IRC | 16:50 | |
ccneill | yep | 16:50 |
ccneill | I don't think we've ever agreed on a naming convention | 16:50 |
ccneill | and I figured we'd just try the different approaches and see what we like | 16:51 |
ccneill | I don't think either is objectively "better" | 16:51 |
ccneill | depends on what you care about | 16:51 |
mdong | yeah, fair enough | 16:51 |
mdong | and it doesnt materially impact our testing either I suppose | 16:51 |
ccneill | ¯\_(ツ)_/¯ | 16:51 |
ccneill | using the method as the prefix makes it a little easier (imo) to find the template you're looking for when you're looking at the template dir | 16:53 |
ccneill | but prefixing with the resource name makes it easier to group based on the resource type | 16:53 |
mdong | and most of our other templates have the verb last | 16:53 |
ccneill | yeah, the leading method stuff was my doing | 16:54 |
mdong | but then again, splitting them into folders kinda already gets us the grouping benefit | 16:54 |
mdong | ¯\_(ツ)_/¯ | 16:54 |
ccneill | ¯\_(ツ)_/¯ | 16:54 |
*** mvaldes has quit IRC | 16:55 | |
ccneill | maybe we'll revisit later if we find reasons to be opinionated about it | 16:55 |
ccneill | during testing | 16:55 |
mdong | also, we have a folder called floatingips and a folder called metering_labels, one with an underscore and one without | 16:55 |
ccneill | I also love that different services use "v2.0" vs. "v2" | 16:55 |
*** diazjf has quit IRC | 16:56 | |
mdong | is there ever a service with a “v2.1”? like why the sig fig? | 16:56 |
ccneill | I think glance has a v1.1 | 16:56 |
ccneill | ¯\_(ツ)_/¯ | 16:56 |
ccneill | lots of shrugs today lol | 16:56 |
mdong | lol | 16:56 |
vinaypotluri | so we are testing against only V2 / V2.0 ? | 16:57 |
ccneill | yep | 16:58 |
*** pcaruana has quit IRC | 16:59 | |
*** gfhellma has joined #openstack-security | 16:59 | |
ccneill | hmm.. how should we handle this endpoint | 17:02 |
ccneill | http://developer.openstack.org/api-ref/image/v2/index.html?expanded=show-images-detail#show-images | 17:02 |
ccneill | lots of query strings, all conflicting to some extent | 17:03 |
*** rcernin has quit IRC | 17:03 | |
ccneill | lolwut. | 17:05 |
ccneill | CCYY-MM-DDThh:mm:ss±hh:mm | 17:05 |
ccneill | The ±hh:mm value, if included, is the time zone as an offset from UTC. | 17:05 |
ccneill | using a unicode character like that for a query param? O_o | 17:05 |
mdong | hah what | 17:07 |
mdong | I think it’s saying that it could be a + or a - | 17:07 |
mdong | not a literal ± | 17:07 |
mdong | and to handle conflicting query strings, we could be thorough and create seperate templates for mutually exclusive sets of query strings, but I dont think too many of those actually conflict? | 17:10 |
ccneill | ¯\_(ツ)_/¯ | 17:10 |
ccneill | maybe I'll make one with "all" | 17:10 |
ccneill | and a few others with more sane defaults | 17:11 |
ccneill | e.g. (size_min=0&size_max=100000) | 17:11 |
openstackgerrit | Michael Dong proposed openstack/syntribos: added glance templates https://review.openstack.org/369597 | 17:13 |
*** yarkot has joined #openstack-security | 17:14 | |
*** yarkot has quit IRC | 17:14 | |
ccneill | so this looks fun: http://specs.openstack.org/openstack/glance-specs/specs/api/v2/http-patch-image-api-v2.html | 17:19 |
*** tkelsey has quit IRC | 17:22 | |
*** browne has joined #openstack-security | 17:25 | |
*** dikonoor has quit IRC | 17:29 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 17:30 |
openstackgerrit | Vinay Potluri proposed openstack/syntribos: Added glance templates https://review.openstack.org/369609 | 17:35 |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding glance templates https://review.openstack.org/369611 | 17:44 |
*** jass93 has quit IRC | 17:44 | |
*** diazjf has joined #openstack-security | 17:47 | |
ccneill | hmmm.. looks like we might not be able to support this weird PATCH syntax with a list instead of a dict in its body... | 17:56 |
*** yarkot has joined #openstack-security | 17:56 | |
ccneill | argh | 17:58 |
ccneill | this might be a painful change.. | 17:58 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Glance Images Templates https://review.openstack.org/369616 | 18:04 |
*** rcernin has joined #openstack-security | 18:12 | |
*** mvaldes has joined #openstack-security | 18:17 | |
*** diazjf has quit IRC | 18:18 | |
*** diazjf has joined #openstack-security | 18:22 | |
*** jass93 has joined #openstack-security | 18:23 | |
vinaypotluri | ccneill: i was referring to the wrong link http://docs.openstack.org/developer/glance/glanceapi.html | 18:33 |
ccneill | ah, yeah I think the page I linked to is the up-to-date documentation for v2 | 18:34 |
mdong | for future reference, let’s not have multiple “added glance templates” CR’s >< | 18:34 |
mdong | I’ll be more specific with my commit messages | 18:35 |
ccneill | yeah.. shouldn't matter too much, but it'll be confusing if we ever need to go through the git history.. | 18:36 |
*** pcaruana has joined #openstack-security | 18:36 | |
ccneill | lol and all the branches are called "glance_templates" | 18:37 |
ccneill | at least we're consistent :P | 18:37 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Glance Images Templates https://review.openstack.org/369616 | 18:38 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Glance image tags and image schema templates https://review.openstack.org/369597 | 18:38 |
mdong | we’ve accidentally used topic branches exactly as intended lol | 18:39 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Glance image tags and image schema templates https://review.openstack.org/369597 | 18:41 |
ccneill | lol yeah | 18:41 |
vinaypotluri | ccneill: for image data do we need to create a file and set the path here ? http://developer.openstack.org/api-ref/image/v2/index.html?expanded=upload-binary-image-data-detail#upload-binary-image-data | 18:43 |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding glance templates https://review.openstack.org/369611 | 18:43 |
ccneill | hmmmm | 18:44 |
*** yarkot has quit IRC | 18:44 | |
ccneill | vinaypotluri: I don't think we want to include an entire image in our templates, so maybe just put some garbage in there lol | 18:45 |
ccneill | ¯\_(ツ)_/¯ | 18:45 |
ccneill | also, be sure to set the content-type to application/octet-stream | 18:45 |
vinaypotluri | ok | 18:45 |
vinaypotluri | for curl i give -d "filename". How would i do the same for template ? | 18:46 |
ccneill | meh, I don't think we want a separate file | 18:46 |
ccneill | I would just have like variable1=test or something in the body | 18:46 |
vinaypotluri | okay | 18:47 |
ccneill | so that we send some kind of data and all the body fuzz strings | 18:47 |
ccneill | I wonder if we could get a super tiny image somehow.. | 18:47 |
vinaypotluri | yea... that would be nice | 18:48 |
ccneill | even CoreOS is 256MB | 18:49 |
ccneill | :\ | 18:49 |
vinaypotluri | huge | 18:49 |
ccneill | and I reeeally don't want to include that in the codebase lol | 18:49 |
ccneill | http://tinycorelinux.net/downloads.html | 18:49 |
ccneill | 11MB.. | 18:49 |
openstackgerrit | Merged openstack/syntribos: Glance image tags and image schema templates https://review.openstack.org/369597 | 18:49 |
openstackgerrit | Merged openstack/syntribos: Glance Images Templates https://review.openstack.org/369616 | 18:50 |
ccneill | boom boom | 18:50 |
unrahul | cirros is just 12 mb | 18:51 |
unrahul | we can use that.. or tinycore if they have a qcow2 format.. i guess | 18:52 |
*** gfhellma has quit IRC | 18:56 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding glance templates https://review.openstack.org/369611 | 18:56 |
mdong | 11mb is still a lot to put in a template | 19:03 |
vinaypotluri | will it work if i we can compile an image with very less code? | 19:08 |
mdong | whatever image you have is going to have be on the order of megabytes, which is just a lot, considering our templates are a few hundred bytes each | 19:09 |
mdong | I say just fill it with garbage binary data | 19:09 |
mdong | because I don’t think it matters from our perspective if it’s a valid image | 19:09 |
openstackgerrit | Merged openstack/syntribos: Adding glance templates https://review.openstack.org/369611 | 19:13 |
*** zul has quit IRC | 19:13 | |
*** prometheanfire has joined #openstack-security | 19:15 | |
prometheanfire | can bug le who ask "Why do you use linux?" in an interview or elsewhere? | 19:15 |
prometheanfire | bah | 19:15 |
prometheanfire | can bug 1593799 be unembargo'd now? | 19:16 |
*** JAHoagie has quit IRC | 19:16 | |
*** dave-mccowan has quit IRC | 19:16 | |
*** Daviey_ has quit IRC | 19:16 | |
*** mihero has quit IRC | 19:16 | |
*** nkinder has quit IRC | 19:16 | |
*** terri has quit IRC | 19:16 | |
*** johnsom has quit IRC | 19:16 | |
*** yarkot1 has quit IRC | 19:16 | |
*** amitkqed has quit IRC | 19:16 | |
*** woodburn has quit IRC | 19:16 | |
*** markd_ has quit IRC | 19:16 | |
*** agireud has quit IRC | 19:16 | |
*** prometheanfire has quit IRC | 19:16 | |
*** Afterglow has quit IRC | 19:16 | |
*** vinaypotluri has quit IRC | 19:17 | |
*** ayoung has quit IRC | 19:17 | |
*** ediardo has quit IRC | 19:17 | |
*** michaelxin has quit IRC | 19:17 | |
*** jamielennox has quit IRC | 19:17 | |
*** mhayden has quit IRC | 19:17 | |
*** Guest66666 has quit IRC | 19:17 | |
*** woodrow has quit IRC | 19:17 | |
*** edtubill has quit IRC | 19:17 | |
*** knangia has quit IRC | 19:17 | |
*** zigo has quit IRC | 19:17 | |
*** yuanying has quit IRC | 19:17 | |
*** serverascode has quit IRC | 19:17 | |
*** murphy_zhao has quit IRC | 19:17 | |
*** dstanek has quit IRC | 19:17 | |
*** dougwig has quit IRC | 19:17 | |
*** jass93 has quit IRC | 19:17 | |
*** singlethink has quit IRC | 19:17 | |
*** d0ugal has quit IRC | 19:17 | |
*** lhinds has quit IRC | 19:17 | |
*** webhat has quit IRC | 19:17 | |
*** hyakuhei has quit IRC | 19:17 | |
*** ChanServ has quit IRC | 19:17 | |
*** mvaldes has quit IRC | 19:17 | |
*** purp has quit IRC | 19:17 | |
*** _sigmavirus24 has quit IRC | 19:17 | |
*** salv-orlando has quit IRC | 19:17 | |
*** tmcpeak has quit IRC | 19:17 | |
*** dstufft has quit IRC | 19:17 | |
*** jraim has quit IRC | 19:17 | |
*** tsufiev has quit IRC | 19:17 | |
*** nikhil has quit IRC | 19:17 | |
*** abstractj has quit IRC | 19:17 | |
*** bknudson has quit IRC | 19:17 | |
*** Unterd0g has quit IRC | 19:17 | |
*** crdotson has quit IRC | 19:17 | |
*** v12aml has quit IRC | 19:17 | |
*** rcernin has quit IRC | 19:17 | |
*** woodster_ has quit IRC | 19:17 | |
*** AlexeyAbashkin has quit IRC | 19:17 | |
*** unrahul has quit IRC | 19:17 | |
*** amit213 has quit IRC | 19:17 | |
*** Ryan_Lane has quit IRC | 19:17 | |
*** sweston has quit IRC | 19:17 | |
*** kun_huang has quit IRC | 19:17 | |
*** cleong has quit IRC | 19:17 | |
*** browne has quit IRC | 19:18 | |
*** mdong has quit IRC | 19:18 | |
*** tristanC has quit IRC | 19:18 | |
*** B_Smith has quit IRC | 19:18 | |
*** jmckind_ has quit IRC | 19:18 | |
*** gmurphy has quit IRC | 19:18 | |
*** pcaruana has quit IRC | 19:18 | |
*** diazjf has quit IRC | 19:18 | |
*** ccneill has quit IRC | 19:18 | |
*** austin987 has quit IRC | 19:18 | |
*** edmondsw has quit IRC | 19:18 | |
*** LongyanG has quit IRC | 19:18 | |
*** DuncanT has quit IRC | 19:18 | |
*** evand has quit IRC | 19:18 | |
*** aimeeu has quit IRC | 19:18 | |
*** kragniz has quit IRC | 19:18 | |
*** fyxim has quit IRC | 19:18 | |
*** openstackgerrit has quit IRC | 19:18 | |
*** elmiko has quit IRC | 19:18 | |
*** julian1 has quit IRC | 19:18 | |
*** gopenshaw has quit IRC | 19:18 | |
*** freerunner has quit IRC | 19:18 | |
*** dasm has quit IRC | 19:18 | |
*** woodburn has joined #openstack-security | 19:19 | |
*** jmckind has joined #openstack-security | 19:23 | |
*** yarkot1 has joined #openstack-security | 19:23 | |
*** terri has joined #openstack-security | 19:23 | |
*** nkinder has joined #openstack-security | 19:23 | |
*** mihero has joined #openstack-security | 19:23 | |
*** johnsom has joined #openstack-security | 19:23 | |
*** Daviey_ has joined #openstack-security | 19:23 | |
*** dave-mccowan has joined #openstack-security | 19:23 | |
*** JAHoagie has joined #openstack-security | 19:23 | |
*** browne has joined #openstack-security | 19:23 | |
*** markd_ has joined #openstack-security | 19:23 | |
*** pcaruana has joined #openstack-security | 19:23 | |
*** abstractj has joined #openstack-security | 19:23 | |
*** nikhil has joined #openstack-security | 19:23 | |
*** tsufiev has joined #openstack-security | 19:23 | |
*** dstufft has joined #openstack-security | 19:23 | |
*** tmcpeak has joined #openstack-security | 19:23 | |
*** salv-orlando has joined #openstack-security | 19:23 | |
*** _sigmavirus24 has joined #openstack-security | 19:23 | |
*** purp has joined #openstack-security | 19:23 | |
*** mvaldes has joined #openstack-security | 19:23 | |
*** yarkot has joined #openstack-security | 19:23 | |
*** kragniz has joined #openstack-security | 19:23 | |
*** kun_huang has joined #openstack-security | 19:23 | |
*** sweston has joined #openstack-security | 19:23 | |
*** Ryan_Lane has joined #openstack-security | 19:23 | |
*** AlexeyAbashkin has joined #openstack-security | 19:23 | |
*** rcernin has joined #openstack-security | 19:23 | |
*** ccneill has joined #openstack-security | 19:23 | |
*** ChanServ has joined #openstack-security | 19:23 | |
*** edtubill has joined #openstack-security | 19:23 | |
*** zigo has joined #openstack-security | 19:23 | |
*** yuanying has joined #openstack-security | 19:23 | |
*** murphy_zhao has joined #openstack-security | 19:23 | |
*** dstanek has joined #openstack-security | 19:23 | |
*** amitkqed has joined #openstack-security | 19:23 | |
*** Afterglow has joined #openstack-security | 19:23 | |
*** vinaypotluri has joined #openstack-security | 19:23 | |
*** michaelxin has joined #openstack-security | 19:23 | |
*** jamielennox has joined #openstack-security | 19:23 | |
*** mhayden has joined #openstack-security | 19:23 | |
*** Guest66666 has joined #openstack-security | 19:23 | |
*** woodrow has joined #openstack-security | 19:23 | |
*** hyakuhei has joined #openstack-security | 19:23 | |
*** orwell.freenode.net sets mode: +o ChanServ | 19:23 | |
*** openstackgerrit has joined #openstack-security | 19:23 | |
*** elmiko has joined #openstack-security | 19:23 | |
*** julian1 has joined #openstack-security | 19:23 | |
*** dasm has joined #openstack-security | 19:23 | |
*** gopenshaw has joined #openstack-security | 19:23 | |
*** freerunner has joined #openstack-security | 19:23 | |
*** gmurphy has joined #openstack-security | 19:23 | |
*** cleong has joined #openstack-security | 19:23 | |
*** austin987 has joined #openstack-security | 19:23 | |
*** edmondsw has joined #openstack-security | 19:23 | |
*** bknudson has joined #openstack-security | 19:23 | |
*** Unterd0g has joined #openstack-security | 19:23 | |
*** crdotson has joined #openstack-security | 19:23 | |
*** v12aml has joined #openstack-security | 19:23 | |
*** prometheanfire has joined #openstack-security | 19:23 | |
*** tristanC has joined #openstack-security | 19:23 | |
*** Long_yanG has joined #openstack-security | 19:23 | |
*** jass93 has joined #openstack-security | 19:23 | |
*** singlethink has joined #openstack-security | 19:23 | |
*** d0ugal has joined #openstack-security | 19:23 | |
*** lhinds has joined #openstack-security | 19:23 | |
*** webhat has joined #openstack-security | 19:23 | |
*** prometheanfire has quit IRC | 19:24 | |
*** prometheanfire has joined #openstack-security | 19:24 | |
*** sweston has quit IRC | 19:24 | |
*** B_Smith has joined #openstack-security | 19:24 | |
*** mdong has joined #openstack-security | 19:24 | |
*** agireud has joined #openstack-security | 19:24 | |
*** diazjf has joined #openstack-security | 19:24 | |
*** ayoung has joined #openstack-security | 19:26 | |
*** cleong has quit IRC | 19:26 | |
*** cleong has joined #openstack-security | 19:26 | |
*** aimeeu has joined #openstack-security | 19:28 | |
*** fyxim has joined #openstack-security | 19:33 | |
ccneill | mdong: I think syntribos' parser will fail if we don't give it valid XML/JSON/form data | 19:36 |
ccneill | we could make the parser more flexible to allow that though | 19:36 |
mdong | yeah, you’re right | 19:39 |
*** salv-orl_ has joined #openstack-security | 19:40 | |
*** diazjf has quit IRC | 19:40 | |
openstackgerrit | Merged openstack/syntribos: Added glance templates https://review.openstack.org/369609 | 19:41 |
*** salv-orlando has quit IRC | 19:43 | |
*** woodster_ has joined #openstack-security | 19:48 | |
ccneill | I guess it's kind of a weakness, but at the same time we can't really do binary fuzzing at this point to any meaningful degree, and the time spent sending off even a 1MB binary file would slow down test runs a lot probably | 19:48 |
ccneill | barbican's another one with a few application/octet-stream endpoints, but I don't know of any others | 19:50 |
*** zul has joined #openstack-security | 19:52 | |
mdong | I don’t think Syntribos should attempt to do binary fuzzing, but it shouldn’t crash on non json or xml content-types | 19:53 |
*** serverascode has joined #openstack-security | 19:53 | |
*** johnsom has quit IRC | 19:54 | |
*** potluri has joined #openstack-security | 19:55 | |
ccneill | yeah that's fair | 19:55 |
ccneill | we can just replace the whole body with our fuzz string I guess | 19:55 |
mdong | which still has value, right? like just incase they store the binary data in a SQL database? | 19:57 |
*** unrahul_ has joined #openstack-security | 19:58 | |
*** knangia has joined #openstack-security | 19:58 | |
*** evand has joined #openstack-security | 19:58 | |
unrahul_ | hey ccneill | 19:58 |
unrahul_ | you here? | 19:58 |
ccneill | mdong: yep, agreed | 19:59 |
ccneill | unrahul_: yep, sup | 19:59 |
*** DuncanT has joined #openstack-security | 19:59 | |
unrahul_ | my client is not working.. so logging from webchat. | 19:59 |
unrahul_ | could you review the extensions patch when u get time.? | 19:59 |
*** amit213 has joined #openstack-security | 19:59 | |
ccneill | yep, will take a look now | 19:59 |
unrahul_ | thanks ccneil | 19:59 |
*** unrahul has joined #openstack-security | 20:01 | |
*** unrahul__ has joined #openstack-security | 20:01 | |
*** jraim has joined #openstack-security | 20:02 | |
*** dougwig has joined #openstack-security | 20:03 | |
*** unrahul_ has quit IRC | 20:04 | |
*** unrahul__ has quit IRC | 20:05 | |
*** gfhellma has joined #openstack-security | 20:06 | |
*** sweston has joined #openstack-security | 20:06 | |
*** ediardo has joined #openstack-security | 20:07 | |
*** pcaruana has quit IRC | 20:11 | |
*** diazjf has joined #openstack-security | 20:12 | |
*** johnsom has joined #openstack-security | 20:13 | |
*** zul has quit IRC | 20:14 | |
*** knangia_ has joined #openstack-security | 20:18 | |
*** diazjf has quit IRC | 20:30 | |
*** knangia has quit IRC | 20:31 | |
*** knangia_ is now known as knangia | 20:33 | |
*** singlethink has quit IRC | 20:36 | |
ccneill | unrahul: I'm getting 401s from Glance in the OSIC cluster with scoped tokens :\ | 20:37 |
*** zul has joined #openstack-security | 20:37 | |
ccneill | trying to test it out in a real template but it's failing | 20:37 |
*** diazjf has joined #openstack-security | 20:42 | |
unrahul | let me check that out ccneill | 20:43 |
ccneill | unrahul: trying to get it working against my devstack instance now | 20:44 |
ccneill | I put up a few comments on your CR | 20:44 |
unrahul | ccneill: okay.. i wonder why the cluster is acting strange :/ | 20:45 |
ccneill | unrahul: it may just be that I don't have my project/domain set properly | 20:47 |
ccneill | looks like it's working on my devstack instance though | 20:47 |
unrahul | nice!.. | 20:48 |
ccneill | oh | 20:48 |
ccneill | nvm | 20:48 |
ccneill | I'm dumb lol >_< it looks like it is working aginst the cluster now | 20:49 |
unrahul | so should we give the endpoint in the glance client.. cause I didnt specifiy the uri to test against the devstack..? | 20:49 |
unrahul | :D | 20:49 |
unrahul | is it a wierd behavior from the cluster.. | 20:49 |
unrahul | or..? | 20:49 |
unrahul | some config thing.? | 20:49 |
ccneill | ¯\_(ツ)_/¯ I think it might be weird behavior from the cluster | 20:50 |
ccneill | nv | 20:52 |
ccneill | nvm | 20:52 |
ccneill | I made the changes I mentioned in my comments and it works now | 20:52 |
ccneill | I think getting the v2 client + specifying the endpoint explicitly makes it work (not sure why..) | 20:52 |
unrahul | yup.. i guess. the original was working because it was v1.. | 20:53 |
unrahul | I am making the changes.. ccneill | 20:53 |
unrahul | also there is that neutron extension.. which there for review.. not required today.. as we wont be using it today.. I guess | 20:53 |
ccneill | yeah I was gonna try to test that out next | 20:56 |
ccneill | looks like the glance one is working with those changes, nice work! | 20:56 |
knangia | cd .. | 20:57 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 20:58 |
unrahul | yup.. thanks ccneill .. not sure.. if our request chaining approach can be wrote around extensions, but this for works for now.. | 20:58 |
ccneill | unrahul: it would be nice to get to a place where we don't have to write any code to chain requests | 20:59 |
ccneill | but probably much more complicated.. | 20:59 |
ccneill | we'll see how this goes | 20:59 |
*** singlethink has joined #openstack-security | 21:02 | |
*** singlethink has quit IRC | 21:03 | |
unrahul | yeah.. that would be cool.. I liked the approach tristanC used in restfuzz.. it sort of makes it easier to see the flow and use creation directly . May be we will do something similar to Syntirbos.. lets see. | 21:04 |
*** singlethink has joined #openstack-security | 21:04 | |
*** JAHoagie has quit IRC | 21:08 | |
*** cleong has quit IRC | 21:09 | |
*** markd_ has quit IRC | 21:12 | |
ccneill | unrahul: looks pretty cool http://softwarefactory-project.io/r/gitweb?p=restfuzz.git;a=blob;f=api/dns.yaml;h=e41b1529d2197da95089d8a8d0589b8b900d1607;hb=HEAD | 21:20 |
*** singlethink has quit IRC | 21:21 | |
*** jass93 has quit IRC | 21:22 | |
*** jass93 has joined #openstack-security | 21:23 | |
unrahul | yeah.. its very visual.. ryt..what is exactly happening.. | 21:23 |
ccneill | not sure how it chains them together, but the inputs/outputs thing is pretty straightforward | 21:23 |
ccneill | to extract the values, etc. | 21:24 |
unrahul | yeah.. | 21:24 |
*** evand has quit IRC | 21:24 | |
ccneill | maybe we should just support the full openAPI spec >_< | 21:24 |
*** evand has joined #openstack-security | 21:25 | |
*** dave-mccowan has quit IRC | 21:26 | |
unrahul | yeah.... taht is something we can push asa road map item.. | 21:26 |
unrahul | then.. if the openAPI specify everything we need.. | 21:26 |
unrahul | then we wont have to create our own schema.. | 21:26 |
ccneill | right | 21:27 |
ccneill | it'll take more work on our part though to also specify reasonable responses for every endpoint | 21:27 |
ccneill | I think it's worth it, but we definitely didn't have time for it this cycle :( | 21:27 |
*** knangia has quit IRC | 21:27 | |
*** ediardo has quit IRC | 21:27 | |
*** amit213 has quit IRC | 21:27 | |
*** tristanC has quit IRC | 21:27 | |
*** tristanC has joined #openstack-security | 21:28 | |
*** sdake_ has joined #openstack-security | 21:28 | |
*** jass93 has quit IRC | 21:30 | |
*** jass93 has joined #openstack-security | 21:30 | |
*** sdake has quit IRC | 21:30 | |
*** ediardo has joined #openstack-security | 21:32 | |
*** mvaldes has quit IRC | 21:32 | |
*** mvaldes has joined #openstack-security | 21:33 | |
*** potluri has quit IRC | 21:33 | |
*** mvaldes has quit IRC | 21:33 | |
*** edtubill has quit IRC | 21:33 | |
*** amit213 has joined #openstack-security | 21:34 | |
ccneill | I think we'd have to specify every kind of response where it could go wrong | 21:34 |
ccneill | so invalid params, invalid token, etc. | 21:34 |
ccneill | I'm sure the projects would appreciate it if we did it for them lol | 21:35 |
*** knangia has joined #openstack-security | 21:35 | |
*** sdake_ is now known as sdake | 21:36 | |
ccneill | hmm.. I'm not sure whether we should put the extension calls in every template.. | 21:39 |
ccneill | like if we put it in DELETE, it will have to create one first for every request.. | 21:39 |
*** markd_ has joined #openstack-security | 21:43 | |
ccneill | argh | 21:49 |
ccneill | keystoneclient requests /v3, gets endpoint from there, and uses that | 21:49 |
ccneill | whnich screws up my testing against devstack :( | 21:49 |
ccneill | boo | 21:50 |
ccneill | looks like that "..%c0%af" string works for all the openstack projects we've looked at.. | 21:55 |
ccneill | I guess we need some kind of cache invalidation mechanism for the extension so that when we delete a resource we can go get another valid one | 21:57 |
unrahul | yeah giving in delete would be a bad idea.. | 21:57 |
unrahul | :D | 21:57 |
unrahul | hehe | 21:57 |
unrahul | that is some kinda universal fail. | 21:58 |
unrahul | cache invalidation..? | 21:58 |
mdong | hmm…there’s no easy way to do that with the memoization as it is written | 21:58 |
unrahul | oh.. yeah | 21:58 |
mdong | because the cache only exists per function | 21:58 |
ccneill | right | 21:58 |
ccneill | v_v | 21:58 |
unrahul | :? | 21:58 |
unrahul | :/ | 21:58 |
ccneill | so.. I accidentally deleted the ubuntu image on our cluster... O:-) | 21:59 |
ccneill | the extension works though lol >_< | 21:59 |
mdong | maybe we shouldn’t be memoizing those extension calls at all, and only memoize the get_token calls | 21:59 |
ccneill | ergh | 21:59 |
mdong | cause if our template says GET, then we should really actually go and get the resource | 22:00 |
ccneill | agreed, but it's gonna add to our performance woes | 22:00 |
mdong | instead of getting the cache | 22:00 |
ccneill | let me see what it looks like | 22:00 |
unrahul | yeah the performance would be affected | 22:01 |
mdong | well, how often does it come up that we get the same resource twice with the same requestlib arguments? should be never, right? | 22:01 |
mdong | cause each of our requests should be a separate fuzz string? | 22:01 |
mdong | and so they would at least have the same data, and so it shouldn’t be cached anyway? | 22:01 |
mdong | *wouldn’t have the same data | 22:02 |
ccneill | dammit, I need to stop testing this with DELETE requests v_v | 22:02 |
ccneill | so it looks like it only makes the get_id templates once per template | 22:03 |
ccneill | get_id requests* | 22:04 |
ccneill | so if it's a DELETE template, it'll delete on the first request then fuzz the other params, but the ID will still be a 404 | 22:04 |
ccneill | should work pretty well for the other templates though | 22:04 |
ccneill | not too slow | 22:04 |
unrahul | yeah.. I have not taken into consideration the delete requests for extensions.. | 22:04 |
ccneill | unrahul: it would be pretty hard to do it.. you'd have to not only look at when you send a DELETE request, but whether you got a 204 back | 22:05 |
ccneill | and THEN remove it from the cache | 22:05 |
ccneill | :\ | 22:05 |
ccneill | not impossible, but a lot of moving parts | 22:05 |
unrahul | yeah.. do we need to do it.. or use fake ids for delete.. : (fake ids for delete :D ) | 22:06 |
ccneill | you'd have to have some way of creating a global object that holds the cache so that you could modify it on deletion | 22:06 |
ccneill | right, I'm okay with fake IDs for delete.. | 22:06 |
ccneill | most of what we're testing on a delete request is just "does it handle invalid input" | 22:06 |
ccneill | er, rather | 22:07 |
ccneill | does it handle an invalid identifier | 22:07 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 22:07 |
ccneill | changing headers/etc probably isn't going to do much | 22:07 |
ccneill | main thing would be the auth test I guess | 22:07 |
mdong | have we looked into what all this caching does to the memory footprint? | 22:09 |
*** diazjf has quit IRC | 22:11 | |
*** jmckind has quit IRC | 22:13 | |
ccneill | nah, but probably not much | 22:14 |
ccneill | in total it's caching the args for like 5 function calls, and none of those args are giant objects or anything | 22:15 |
*** edmondsw has quit IRC | 22:15 | |
*** dave-mccowan has joined #openstack-security | 22:15 | |
*** dave-mccowan has quit IRC | 22:16 | |
*** jass93 has quit IRC | 22:17 | |
ccneill | I'd say it's definitely worth it for the decreased request volume no matter the memory cost, at least for the token requests | 22:20 |
*** elmiko is now known as _elmiko | 22:21 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/369734 | 22:28 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 22:46 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Adding Glance extension support to templates https://review.openstack.org/369742 | 22:46 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Adding Glance extension support to templates https://review.openstack.org/369742 | 22:49 |
ccneill | sigh.. I accidentally re-added the @memoize calls to your patch unrahul | 22:49 |
ccneill | by doing a dependency on an old patch v_v | 22:49 |
unrahul | :o | 22:50 |
unrahul | I shall upload another one then ccneill | 22:50 |
ccneill | thanks unrahul | 22:52 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 22:55 |
*** JAHoagie has joined #openstack-security | 22:55 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Adding Glance extension support to templates https://review.openstack.org/369742 | 22:56 |
ccneill | cool | 22:56 |
openstackgerrit | Allen proposed openstack/security-doc: Use hyperlink markup for the link reference title https://review.openstack.org/369746 | 22:56 |
ccneill | unrahul: +1'd your CR | 22:57 |
ccneill | mdong / vinaypotluri, can y'all take a look? | 22:57 |
*** sdake_ has joined #openstack-security | 22:57 | |
unrahul | Hey ccneill thanks for the review.. :) | 22:57 |
ccneill | if we can get these merged, I think we're ready for some serious testing tomorrow | 22:57 |
mdong | sure | 22:57 |
ccneill | :D | 22:57 |
*** singlethink has joined #openstack-security | 22:58 | |
*** singlethink has quit IRC | 22:58 | |
*** singlethink has joined #openstack-security | 22:59 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 22:59 |
unrahul | hey ccneill mdong. can we try to merge the neutron patch as well ... so that we can work on testing from tomorrow..? | 23:00 |
*** sdake has quit IRC | 23:00 | |
ccneill | yep lemme take a look | 23:00 |
unrahul | thanks ccneill | 23:01 |
*** yeison has joined #openstack-security | 23:01 | |
*** yeison has left #openstack-security | 23:01 | |
*** yeison has joined #openstack-security | 23:01 | |
ccneill | so.. I know we're not totally set on using extensions for this functionality going forward | 23:01 |
*** yeison has left #openstack-security | 23:01 | |
ccneill | but I'm wondering if we should make an "openstack utils" file to handle e.g. creating a connection | 23:02 |
ccneill | since it's basically the same between glance/neutron | 23:02 |
ccneill | at least the identity stuff | 23:02 |
unrahul | eh.. that might be a good idea.. considering we would use identity for similar extensions | 23:02 |
ccneill | right | 23:04 |
ccneill | we'll have the same code across all the project extensions, at least while we're doing this testing | 23:04 |
mdong | only had one minor comment, then we’re good to go on that patch | 23:06 |
unrahul | yeah.. I shall do a refactor.. also would like to write some unit tests for these (our unit test coverage has reduced :/) | 23:06 |
unrahul | after these are merged i guess. | 23:06 |
unrahul | yup mdong .. thanks.. I shall upload a patch now. | 23:07 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 23:12 |
unrahul | hey ccneill .. the idea of the random ip and port and mac was a valid mac and port but that is not any resource specific.. so I guess its fine if we return the same.. as long as it is valid.. or should be really random..? what do u think? | 23:14 |
ccneill | hmm | 23:15 |
ccneill | well, I don't know if it will impact this particular use case | 23:15 |
*** JAHoagie has quit IRC | 23:15 | |
ccneill | but if we put it in random_data, I think we want to return a random one each time just in case it needs to be unique | 23:15 |
ccneill | so we don't just succeed on the first one and get collisions on the rest | 23:16 |
ccneill | if we really wanted to get fancy we could have a random_ip and random_ip_generator method.. | 23:16 |
ccneill | random_ip_generator just calls While True: return random_ip() | 23:16 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 23:17 |
unrahul | okay ccneill . | 23:18 |
unrahul | still should be keep everything associated with network in neutron.. as some might wont know there is a random ip generator in the random_data file.. ccneill , what do u say? | 23:20 |
*** ayoung has quit IRC | 23:20 | |
ccneill | well, if we get to a place where you actually install extensions instead of them all shipping with master | 23:21 |
ccneill | you wouldn't want to have to install the neutron plugin to get a random IP | 23:21 |
ccneill | if we're gonna do these project extensions, I think we want to restrict it to functionality that is specific to those projects | 23:21 |
ccneill | so we don't end up repeating ourselves | 23:22 |
ccneill | so e.g. the openstack identity stuff should probably go in a utilities file at some point too so that it's extensible to other projects | 23:22 |
ccneill | (not necessarily worried about it right this moment though) | 23:22 |
*** rcernin has quit IRC | 23:23 | |
unrahul | hmm.. make sense ccneill . | 23:26 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 23:27 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 23:30 |
ccneill | +1'd the network extension CR | 23:32 |
ccneill | great work unrahul ! | 23:32 |
unrahul | ton of patches.. for it.. phew.. finally we can merge it.. i guess. | 23:33 |
unrahul | :) ccneill . | 23:33 |
ccneill | there'd be 2 fewer if I hadn't messed up earlier lol :P | 23:34 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Adding Glance extension support to templates https://review.openstack.org/369742 | 23:34 |
ccneill | ^ that CR should be up-to-date and ready to go | 23:35 |
unrahul | +2d it ccneill . | 23:37 |
unrahul | looks good to me :) | 23:37 |
ccneill | here comes the merge train | 23:42 |
openstackgerrit | Merged openstack/syntribos: Extensions for glance resources https://review.openstack.org/369606 | 23:44 |
unrahul | :D | 23:44 |
unrahul | ah good feeling. | 23:44 |
*** singlethink has quit IRC | 23:45 | |
openstackgerrit | Merged openstack/syntribos: Adding Glance extension support to templates https://review.openstack.org/369742 | 23:46 |
ccneill | boom | 23:46 |
*** jass93 has joined #openstack-security | 23:48 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 23:50 |
unrahul | hey ccneill there was a merge conflict.. fixed it and uploaded the patch. | 23:50 |
tmcpeak | ccneill: you around? | 23:51 |
ccneill | +2'd | 23:51 |
ccneill | sup tmcpeak | 23:51 |
tmcpeak | hey man, you've done some Tempest stuff, yeah? | 23:51 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: An extenstion to retrieve network data from an openstack cloud https://review.openstack.org/369042 | 23:52 |
ccneill | not much, but some yeah | 23:52 |
tmcpeak | I'm trying to get my head around what level of security testing is present in Tempest. Be that, security functional tests, abuse cases, etc | 23:52 |
tmcpeak | do you have any pointers or references to anything good to get me up to speed? | 23:52 |
unrahul | hey ccneill :/ I had to make a small nit.. change.. :o | 23:52 |
tmcpeak | given the OSSP hasn't done much with Tempest I can't imagine there is a ton there, but just want to become aware of current status | 23:52 |
ccneill | unrahul: just noticed | 23:52 |
*** mdong has quit IRC | 23:53 | |
ccneill | tmcpeak: so.. I spent some time trying to get a data generator/response validator thing into tempest_lib while it was still forked from tempest | 23:53 |
ccneill | they ultimately decided that wasn't a good idea | 23:53 |
unrahul | ccneill: its of no consequence.. as both the domains will be same.. but.. in a unlikely case.. if the user want to do something else.. | 23:53 |
tmcpeak | how come? | 23:53 |
ccneill | tmcpeak: they thought it was outside tempest's scope | 23:54 |
ccneill | sec | 23:54 |
unrahul | thanks ccneill . | 23:54 |
ccneill | tmcpeak: http://paste.openstack.org/show/x2MbCCPdk2ntZu7N4l1r/ | 23:56 |
ccneill | from the openstack-qa meeting I proposed it in (after various backflips to submit a blueprint, etc.) | 23:57 |
tmcpeak | ahh, interesting | 23:57 |
tmcpeak | thanks ccneill | 23:57 |
ccneill | so, tl;dr, we now have syntribos | 23:57 |
ccneill | but in its current form, it's definitely not a great replacement | 23:57 |
ccneill | compared to what I was proposing | 23:57 |
tmcpeak | yeah :\ | 23:58 |
ccneill | tmcpeak: here are my 2 patches if you're interested in reviving it and making a separate standalone tool.. | 23:59 |
ccneill | https://review.openstack.org/#/c/216303/6 | 23:59 |
tmcpeak | lol, noooo | 23:59 |
ccneill | https://review.openstack.org/#/c/237263/ | 23:59 |
tmcpeak | just want to understand to what extent security testing is done in Tempest, doesn't seem like it's a main focus | 23:59 |
tmcpeak | I'm seeing a lot of happy path and functional tests, but not much in the way of checking abuse | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!