*** jamielennox|away is now known as jamielennox | 00:00 | |
*** JAHoagie has quit IRC | 00:07 | |
*** tmcpeak has quit IRC | 00:16 | |
*** Granate has joined #openstack-security | 00:19 | |
*** Granate has left #openstack-security | 00:19 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Glance template tweaks https://review.openstack.org/370493 | 00:24 |
---|---|---|
ccneill | so this is interesting.. somehow I managed to get invalid image types into my db o_O | 00:28 |
ccneill | YES | 00:28 |
ccneill | XSS POPPED | 00:29 |
ccneill | MUAHAHA | 00:29 |
ccneill | wow, you know it's good when you ssh into a box and get this: | 00:39 |
ccneill | -bash: fork: Cannot allocate memory │< X-Openstack-Request-Id: req-e4033ad6-55a5-43a4-8a31-eb5eaf41e403 | 00:40 |
ccneill | vagrant@vagrant-ubuntu-trusty-64:~$ top │< Date: Mon, 12 Sep 2016 20:53:22 GMT | 00:40 |
ccneill | -bash: fork: Cannot allocate memory │< | 00:40 |
ccneill | -bash: xmalloc: cannot allocate 4112 bytes (3670016 bytes allocated) │* Connection #0 to host localhost left intact | 00:40 |
ccneill | Connection to 127.0.0.1 closed. | 00:40 |
ccneill | oops | 00:40 |
*** yeison has joined #openstack-security | 00:43 | |
yeison | Se ha solicitado una sesión de mensajería musical. Por favor, seleccione el icono de MM para aceptarla. | 00:45 |
yeison | Se ha solicitado una sesión de mensajería musical. Por favor, seleccione el icono de MM para aceptarla. | 00:45 |
yeison | Se ha solicitado una sesión de mensajería musical. Por favor, seleccione el icono de MM para aceptarla. | 00:45 |
*** yeison has left #openstack-security | 00:45 | |
*** ccneill has quit IRC | 00:49 | |
*** jass93 has joined #openstack-security | 00:54 | |
*** vinaypotluri has quit IRC | 01:22 | |
*** salv-orlando has joined #openstack-security | 01:41 | |
*** salv-orl_ has quit IRC | 01:43 | |
*** woodster_ has quit IRC | 01:50 | |
*** yeison has joined #openstack-security | 01:55 | |
*** yeison has left #openstack-security | 01:56 | |
*** yeison has joined #openstack-security | 02:06 | |
*** yuanying has quit IRC | 02:47 | |
*** diazjf has joined #openstack-security | 02:51 | |
*** sdake has joined #openstack-security | 03:01 | |
*** diazjf has quit IRC | 03:07 | |
*** austin987 has quit IRC | 03:26 | |
*** knangia has quit IRC | 03:41 | |
*** vinaypotluri has joined #openstack-security | 03:45 | |
*** mdong has joined #openstack-security | 03:50 | |
*** yuanying has joined #openstack-security | 03:51 | |
*** sdake has quit IRC | 05:03 | |
*** JAHoagie has joined #openstack-security | 05:15 | |
*** rcernin has joined #openstack-security | 05:17 | |
*** sdake has joined #openstack-security | 05:22 | |
*** markvoelker has quit IRC | 05:41 | |
*** pcaruana has joined #openstack-security | 06:04 | |
*** pcaruana is now known as pcaruana|afk| | 06:13 | |
*** vinaypotluri has quit IRC | 06:22 | |
*** sdake has quit IRC | 06:36 | |
*** pcaruana|afk| is now known as pcaruana | 06:40 | |
*** jamielennox is now known as jamielennox|away | 06:45 | |
*** mdong has quit IRC | 06:50 | |
*** salv-orlando has quit IRC | 06:50 | |
*** salv-orlando has joined #openstack-security | 06:51 | |
*** liverpooler has joined #openstack-security | 07:01 | |
*** zul has joined #openstack-security | 07:10 | |
openstackgerrit | Merged openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 07:20 |
*** salv-orl_ has joined #openstack-security | 07:40 | |
*** markvoelker has joined #openstack-security | 07:42 | |
*** salv-orlando has quit IRC | 07:43 | |
*** markvoelker has quit IRC | 07:48 | |
*** zul has quit IRC | 07:57 | |
*** jamielennox|away is now known as jamielennox | 07:57 | |
*** gfhellma has joined #openstack-security | 08:21 | |
*** gfhellma has quit IRC | 08:32 | |
*** tkelsey has joined #openstack-security | 08:36 | |
*** markvoelker has joined #openstack-security | 09:44 | |
*** Trident has joined #openstack-security | 09:48 | |
*** markvoelker has quit IRC | 09:49 | |
*** salv-orl_ has quit IRC | 10:01 | |
openstackgerrit | Merged openstack/security-doc: Use hyperlink markup for the link reference title https://review.openstack.org/369746 | 10:14 |
*** salv-orlando has joined #openstack-security | 11:02 | |
*** dave-mccowan has joined #openstack-security | 11:06 | |
*** salv-orlando has quit IRC | 11:06 | |
*** Guest84617 has joined #openstack-security | 11:11 | |
Guest84617 | hi | 11:12 |
Guest84617 | echo | 11:12 |
*** Guest84617 has left #openstack-security | 11:14 | |
*** salv-orlando has joined #openstack-security | 11:28 | |
*** edmondsw has joined #openstack-security | 11:42 | |
*** markvoelker has joined #openstack-security | 11:45 | |
*** markvoelker has quit IRC | 11:50 | |
*** sdake has joined #openstack-security | 12:38 | |
*** markvoelker has joined #openstack-security | 12:38 | |
*** _elmiko is now known as elmiko | 13:02 | |
*** liverpooler has quit IRC | 13:03 | |
*** sdake_ has joined #openstack-security | 13:14 | |
*** salv-orlando has quit IRC | 13:15 | |
*** sdake has quit IRC | 13:16 | |
*** singlethink has joined #openstack-security | 13:32 | |
*** cleong has joined #openstack-security | 13:44 | |
*** gmurphy has quit IRC | 13:47 | |
*** gmurphy has joined #openstack-security | 13:47 | |
*** diazjf has joined #openstack-security | 13:49 | |
*** diazjf has quit IRC | 13:52 | |
*** diazjf has joined #openstack-security | 14:01 | |
*** jass93 has quit IRC | 14:06 | |
*** diazjf has quit IRC | 14:10 | |
*** JAHoagie has quit IRC | 14:20 | |
*** diazjf has joined #openstack-security | 14:20 | |
*** Trident has quit IRC | 14:41 | |
*** Trident has joined #openstack-security | 14:41 | |
*** mvaldes has joined #openstack-security | 14:42 | |
*** tmcpeak has joined #openstack-security | 14:45 | |
*** knangia has joined #openstack-security | 14:48 | |
*** liverpooler has joined #openstack-security | 14:49 | |
*** diazjf has quit IRC | 14:55 | |
*** edtubill has joined #openstack-security | 14:57 | |
*** edtubill has quit IRC | 14:57 | |
*** edtubill has joined #openstack-security | 14:58 | |
*** edtubill has quit IRC | 15:00 | |
*** diazjf has joined #openstack-security | 15:06 | |
*** zul has joined #openstack-security | 15:12 | |
*** mvaldes1 has joined #openstack-security | 15:17 | |
*** pcaruana has quit IRC | 15:19 | |
*** mvaldes has quit IRC | 15:19 | |
*** salv-orlando has joined #openstack-security | 15:19 | |
*** mvaldes has joined #openstack-security | 15:20 | |
*** salv-orlando has quit IRC | 15:22 | |
*** zul has quit IRC | 15:22 | |
*** mvaldes1 has quit IRC | 15:23 | |
*** woodster_ has joined #openstack-security | 15:36 | |
*** vinaypotluri has joined #openstack-security | 15:48 | |
*** salv-orlando has joined #openstack-security | 15:49 | |
*** mvaldes has quit IRC | 15:56 | |
*** mvaldes has joined #openstack-security | 15:57 | |
*** JAHoagie has joined #openstack-security | 16:02 | |
*** jass93 has joined #openstack-security | 16:04 | |
*** diazjf has quit IRC | 16:26 | |
*** rcernin has quit IRC | 16:26 | |
*** diazjf has joined #openstack-security | 16:33 | |
*** gfhellma has joined #openstack-security | 16:34 | |
*** mdong has joined #openstack-security | 16:34 | |
*** ccneill has joined #openstack-security | 16:34 | |
ccneill | looks like my Horizon XSS is a dupe. womp womp :( https://bugs.launchpad.net/horizon/+bug/1622690 | 16:37 |
openstack | Launchpad bug 1622690 in OpenStack Dashboard (Horizon) "Potential XSS in image create modal or angular table" [High,Fix committed] - Assigned to Richard Jones (r1chardj0n3s) | 16:37 |
*** diazjf has quit IRC | 16:41 | |
*** mvaldes has quit IRC | 16:43 | |
*** browne has joined #openstack-security | 16:49 | |
ccneill | tristanC: I'm ./unstack && ./stack -ing to see if the issue I reported is fully resolved. at this point it looks like a dupe | 16:49 |
ccneill | unfortunately I have a conflict during the OSSP meeting in a few minutes :\ | 16:49 |
hyakuhei | ccneill Sounds like you're having fun | 16:55 |
ccneill | hyakuhei: only always | 16:55 |
ccneill | :P | 16:55 |
ccneill | was really hoping I had finally found something serious | 16:55 |
ccneill | can I also say how cool it is to be able to tear down & spin up devstack with one command? | 16:57 |
*** mvaldes has joined #openstack-security | 16:57 | |
ccneill | mdong: family meeting? | 17:03 |
*** gfhellma has quit IRC | 17:03 | |
*** mwturvey has joined #openstack-security | 17:04 | |
*** mvaldes has quit IRC | 17:20 | |
*** mdong has quit IRC | 17:24 | |
*** jass93 has quit IRC | 17:37 | |
*** sicarie has joined #openstack-security | 17:40 | |
*** gfhellma has joined #openstack-security | 17:41 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Minor modifications to the neutron templates https://review.openstack.org/371023 | 17:42 |
*** tkelsey has quit IRC | 17:45 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: A minor naming change for a neutron extension https://review.openstack.org/371024 | 17:45 |
*** jass93 has joined #openstack-security | 17:57 | |
openstackgerrit | Merged openstack/syntribos: A minor naming change for a neutron extension https://review.openstack.org/371024 | 17:59 |
*** diazjf has joined #openstack-security | 18:06 | |
*** mdong has joined #openstack-security | 18:10 | |
mdong | sorry for skipping on the ossp meeting unrahul, I had the same conflict as ccneill and didnt realize it | 18:12 |
*** liverpooler has quit IRC | 18:14 | |
*** pcaruana has joined #openstack-security | 18:22 | |
*** sdake_ is now known as sdake | 18:26 | |
*** mvaldes has joined #openstack-security | 18:27 | |
*** diazjf has quit IRC | 18:38 | |
*** mvaldes has quit IRC | 18:41 | |
*** mvaldes has joined #openstack-security | 18:42 | |
*** gfhellma has quit IRC | 18:43 | |
*** diazjf has joined #openstack-security | 18:49 | |
*** gfhellma has joined #openstack-security | 18:55 | |
unrahul | hey mdong .. yup.. | 18:58 |
unrahul | mdong: ccneill should be release a new version of syntribos? | 18:58 |
*** mdong_ has joined #openstack-security | 18:59 | |
*** diazjf has quit IRC | 18:59 | |
*** mdong has quit IRC | 19:02 | |
*** mdong_ is now known as mdong | 19:02 | |
ccneill | like on pypi? | 19:03 |
ccneill | probably | 19:03 |
unrahul | yup | 19:03 |
ccneill | the one thing I think we might want to solve first is an easy install process (which I'm trying to figure out in the CR I have open right now) | 19:04 |
ccneill | i.e. being able to use the default payloads/etc without having to do a bunch of folder-creating, moving files, etc. | 19:04 |
ccneill | but I haven't worked on it much since we started testing since I think WE can live without it for the time being | 19:05 |
unrahul | mm.. yeah.. that makes senses.. ccneill it would make using the tool way more convenient | 19:06 |
ccneill | yep | 19:06 |
ccneill | unfortunately I haven't figured it all out yet lol | 19:06 |
ccneill | I think it's gonna involve using pbr's data files, but that has its own issues | 19:06 |
ccneill | if we just force everyone to use a venv it should be fine, but I'm not sure how to enforce that with pbr | 19:07 |
*** salv-orlando has quit IRC | 19:07 | |
unrahul | +1 :) we can may be push a patch for it after the tests. in october.. ? yeah,... or we could use some init sub commands and download all things.. | 19:07 |
openstackgerrit | Merged openstack/syntribos: Glance template tweaks https://review.openstack.org/370493 | 19:07 |
unrahul | yeah.. and some ppl are hell bent on not using venv at times .. and everything breaks .. that wont be that great also i guess.. :| | 19:08 |
ccneill | ¯\_(ツ)_/¯ | 19:13 |
ccneill | they can always install everything manually I guess | 19:14 |
*** jass93 has quit IRC | 19:22 | |
*** diazjf has joined #openstack-security | 19:23 | |
*** ametts has joined #openstack-security | 19:26 | |
*** sicarie has quit IRC | 19:29 | |
*** pcaruana has quit IRC | 19:32 | |
*** sicarie has joined #openstack-security | 19:44 | |
*** sdake has quit IRC | 19:49 | |
*** sdake_ has joined #openstack-security | 19:49 | |
*** rcernin has joined #openstack-security | 19:53 | |
*** ametts has quit IRC | 20:01 | |
*** diazjf has quit IRC | 20:04 | |
ccneill | argh.. our cluster is acting weird. can't even run syntribos with the neutron templates sometimes because it 401's on the networks.json call :\ | 20:06 |
ccneill | seems to only respond with 200 every 5th request or so >_< | 20:07 |
ccneill | whew, there we go | 20:08 |
mdong | yeah, I was noticing that too | 20:08 |
mdong | I can only test in chinks at a time | 20:08 |
mdong | er | 20:08 |
mdong | chunks | 20:08 |
mdong | >< | 20:08 |
*** diazjf has joined #openstack-security | 20:10 | |
ccneill | :S same | 20:11 |
*** ametts has joined #openstack-security | 20:13 | |
unrahul | :/ | 20:14 |
unrahul | not sure why though.. | 20:14 |
unrahul | rate limiting or something.. no idea. | 20:15 |
ccneill | that should throw a 429 though I think | 20:15 |
ccneill | ¯\_(ツ)_/¯ | 20:15 |
ccneill | not sure | 20:16 |
unrahul | :/ | 20:16 |
unrahul | again | 20:16 |
*** mvaldes has quit IRC | 20:17 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/371094 | 20:17 |
ccneill | what do y'all think about making debug logging a flag..? | 20:19 |
ccneill | or at least having an option to disable it | 20:19 |
ccneill | e.g. right now I'm generating logs over and over but I don't care about any of them | 20:19 |
mdong | can you set the logging config option to /dev/null? | 20:19 |
ccneill | hm yeah, that would work | 20:20 |
ccneill | can't specify it from the command line though :\ | 20:21 |
unrahul | I think we had a discussion and decided against it.. as some might turn it off when it shouldnt be. | 20:21 |
ccneill | /dev/null doesn't work since it tries to create a folder | 20:21 |
ccneill | unrahul: I agree it should be enabled by default, but I think there are legit cases for not using it sometimes | 20:24 |
ccneill | if you're in a read-only environment and can't create a folder for example | 20:24 |
ccneill | or in CI environment where the debug log will probably be deleted and never used | 20:24 |
ccneill | or this edge case where I'm trying to test syntribos itself, not the actual endpoint | 20:25 |
unrahul | ccneill: hmm.. agreed.. valid scenarios . if we are making this possible, it would be good to warn the user that no logging is enabled when the tool is run. | 20:29 |
mdong | well we’d have to do something with the log path string that’s printed at the end of every run, I’d imagine we’d just do it there | 20:29 |
ccneill | yep ^ +1 | 20:29 |
unrahul | +! | 20:30 |
unrahul | +1 | 20:30 |
ccneill | and we can leave it off as a command line option so that you have to actually edit the config file to turn it off | 20:31 |
*** mvaldes has joined #openstack-security | 20:31 | |
*** tkelsey has joined #openstack-security | 20:42 | |
*** ametts has quit IRC | 20:42 | |
*** tkelsey has quit IRC | 20:47 | |
*** JAHoagie has quit IRC | 20:57 | |
*** diazjf has quit IRC | 21:02 | |
*** diazjf has joined #openstack-security | 21:05 | |
*** diazjf has quit IRC | 21:06 | |
openstackgerrit | Merged openstack/syntribos: Updated from global requirements https://review.openstack.org/371128 | 21:08 |
*** gfhellma has quit IRC | 21:09 | |
*** salv-orlando has joined #openstack-security | 21:11 | |
*** diazjf has joined #openstack-security | 21:11 | |
*** gfhellma has joined #openstack-security | 21:12 | |
*** diazjf has quit IRC | 21:14 | |
*** catintheroof has joined #openstack-security | 21:15 | |
*** salv-orlando has quit IRC | 21:18 | |
*** salv-orlando has joined #openstack-security | 21:22 | |
*** diazjf has joined #openstack-security | 21:44 | |
*** tkelsey has joined #openstack-security | 21:44 | |
*** jraim has quit IRC | 21:45 | |
*** sweston has quit IRC | 21:45 | |
*** hyakuhei has quit IRC | 21:45 | |
*** mvaldes has quit IRC | 21:46 | |
*** jamielennox has quit IRC | 21:46 | |
*** mhayden has quit IRC | 21:46 | |
*** amit213 has quit IRC | 21:47 | |
*** tkelsey has quit IRC | 21:48 | |
*** JAHoagie has joined #openstack-security | 21:48 | |
*** sweston has joined #openstack-security | 21:49 | |
*** jraim has joined #openstack-security | 21:49 | |
*** amit213 has joined #openstack-security | 21:51 | |
*** diazjf has quit IRC | 21:51 | |
*** hyakuhei has joined #openstack-security | 21:53 | |
*** jass93 has joined #openstack-security | 21:57 | |
*** mhayden has joined #openstack-security | 22:00 | |
*** jamielennox has joined #openstack-security | 22:01 | |
*** cleong has quit IRC | 22:05 | |
*** singlethink has quit IRC | 22:09 | |
*** edmondsw has quit IRC | 22:14 | |
*** mdong has quit IRC | 22:15 | |
openstackgerrit | Merged openstack/security-doc: Add marker files https://review.openstack.org/370376 | 22:16 |
*** tmcpeak has quit IRC | 22:25 | |
*** diazjf has joined #openstack-security | 22:31 | |
*** salv-orlando has quit IRC | 22:32 | |
*** diazjf has quit IRC | 22:45 | |
*** salv-orlando has joined #openstack-security | 22:46 | |
*** gfhellma has quit IRC | 22:53 | |
*** diazjf has joined #openstack-security | 22:54 | |
*** diazjf has quit IRC | 23:12 | |
*** jass93 has quit IRC | 23:21 | |
*** catintheroof has quit IRC | 23:21 | |
*** elmiko is now known as _elmiko | 23:37 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unittest for neutron client extension https://review.openstack.org/371219 | 23:37 |
*** markvoelker has quit IRC | 23:39 | |
*** JAHoagie has quit IRC | 23:40 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unittest for neutron client extension https://review.openstack.org/371219 | 23:42 |
*** tkelsey has joined #openstack-security | 23:45 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 23:47 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Minor modifications to the neutron templates https://review.openstack.org/371023 | 23:48 |
*** tkelsey has quit IRC | 23:49 | |
*** ccneill has quit IRC | 23:57 | |
*** sicarie has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!