*** austin987 has joined #openstack-security | 00:13 | |
*** jamielennox is now known as jamielennox|away | 00:14 | |
*** markvoelker has joined #openstack-security | 00:29 | |
*** ccneill has quit IRC | 00:33 | |
*** browne has quit IRC | 00:48 | |
*** ccneill-phone has quit IRC | 01:15 | |
*** diazjf has joined #openstack-security | 01:20 | |
*** gfhellma has quit IRC | 01:20 | |
*** vinaypotluri has quit IRC | 01:22 | |
*** diazjf has quit IRC | 01:22 | |
openstackgerrit | qinchunhua proposed openstack/bandit: Update flake8 ignore list https://review.openstack.org/372818 | 01:24 |
---|---|---|
*** diazjf has joined #openstack-security | 01:36 | |
*** diazjf has quit IRC | 01:38 | |
*** salv-orl_ has joined #openstack-security | 01:42 | |
*** nkinder has joined #openstack-security | 01:43 | |
*** salv-orlando has quit IRC | 01:45 | |
*** dikonoor has joined #openstack-security | 01:47 | |
*** knangia has quit IRC | 01:51 | |
*** markvoelker has quit IRC | 02:02 | |
*** markvoelker has joined #openstack-security | 02:02 | |
*** sdake has quit IRC | 02:06 | |
*** sdake has joined #openstack-security | 02:06 | |
*** sdake has quit IRC | 02:18 | |
*** jamielennox|away is now known as jamielennox | 02:20 | |
*** nkinder has quit IRC | 02:35 | |
*** dave-mccowan has quit IRC | 02:41 | |
*** zul has joined #openstack-security | 02:52 | |
*** woodster_ has quit IRC | 03:00 | |
*** markvoelker has quit IRC | 03:02 | |
*** markvoelker has joined #openstack-security | 03:02 | |
*** vinaypotluri has joined #openstack-security | 03:55 | |
*** dikonoor has quit IRC | 04:43 | |
*** sdake has joined #openstack-security | 04:46 | |
*** markvoelker has quit IRC | 04:46 | |
*** dikonoor has joined #openstack-security | 04:48 | |
*** dikonoo has joined #openstack-security | 05:02 | |
*** dikonoor has quit IRC | 05:05 | |
*** dikonoor has joined #openstack-security | 05:16 | |
*** dikonoo has quit IRC | 05:19 | |
*** markvoelker has joined #openstack-security | 05:47 | |
*** markvoelker has quit IRC | 05:52 | |
*** dikonoor has quit IRC | 05:55 | |
*** dikonoor has joined #openstack-security | 06:12 | |
openstackgerrit | avnish proposed openstack/anchor: Update home page link in cfg file https://review.openstack.org/372919 | 06:19 |
*** markvoelker has joined #openstack-security | 06:48 | |
*** pcaruana has joined #openstack-security | 06:50 | |
*** markvoelker has quit IRC | 06:52 | |
*** austin987 has quit IRC | 06:56 | |
openstackgerrit | avnish proposed openstack/security-analysis: modify the home-page info with the developer documentation https://review.openstack.org/372959 | 07:03 |
*** knangia has joined #openstack-security | 07:13 | |
*** rcernin has joined #openstack-security | 07:19 | |
openstackgerrit | zhangyanxian proposed openstack/syntribos: A spelling mistake needs to be fixed https://review.openstack.org/372989 | 07:35 |
openstackgerrit | zhangyanxian proposed openstack/syntribos: A spelling mistake needs to be fixed https://review.openstack.org/372989 | 07:36 |
*** salv-orlando has joined #openstack-security | 07:42 | |
*** vinaypotluri has quit IRC | 07:42 | |
*** salv-orl_ has quit IRC | 07:44 | |
*** markvoelker has joined #openstack-security | 07:49 | |
*** markvoelker has quit IRC | 07:53 | |
*** markvoelker has joined #openstack-security | 08:50 | |
*** markvoelker has quit IRC | 08:54 | |
*** knangia has quit IRC | 09:51 | |
*** freerunner has quit IRC | 09:52 | |
*** freerunner has joined #openstack-security | 09:52 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding "input()" to the blacklist calls list https://review.openstack.org/372394 | 10:19 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding test for assignment to __builtins__ https://review.openstack.org/372633 | 10:24 |
*** dikonoor has quit IRC | 10:39 | |
*** dikonoor has joined #openstack-security | 10:53 | |
*** dikonoo has joined #openstack-security | 11:21 | |
*** dikonoor has quit IRC | 11:22 | |
*** dikonoo has quit IRC | 11:26 | |
*** dikonoo has joined #openstack-security | 11:33 | |
*** dave-mccowan has joined #openstack-security | 11:59 | |
*** nkinder has joined #openstack-security | 12:09 | |
*** edmondsw has joined #openstack-security | 12:12 | |
*** markvoelker has joined #openstack-security | 12:24 | |
*** ayoung has quit IRC | 12:30 | |
*** _elmiko_ is now known as elmiko | 12:59 | |
*** markd__ has joined #openstack-security | 13:07 | |
*** markd__ has quit IRC | 13:08 | |
*** liverpooler has quit IRC | 13:08 | |
*** liverpooler has joined #openstack-security | 13:09 | |
*** sdake has quit IRC | 13:17 | |
*** jass93 has joined #openstack-security | 13:39 | |
*** salv-orl_ has joined #openstack-security | 13:42 | |
*** jass93 has quit IRC | 13:44 | |
*** salv-orlando has quit IRC | 13:45 | |
*** jass93 has joined #openstack-security | 13:45 | |
*** sdake has joined #openstack-security | 13:49 | |
*** mvaldes has joined #openstack-security | 13:50 | |
*** cleong has joined #openstack-security | 13:58 | |
*** markvoelker has quit IRC | 14:02 | |
*** markvoelker has joined #openstack-security | 14:09 | |
*** sdake_ has joined #openstack-security | 14:09 | |
*** sdake has quit IRC | 14:11 | |
*** woodster_ has joined #openstack-security | 14:12 | |
*** ayoung has joined #openstack-security | 14:15 | |
*** knangia has joined #openstack-security | 14:24 | |
*** diazjf has joined #openstack-security | 14:26 | |
*** diazjf has quit IRC | 14:34 | |
*** jmckind has joined #openstack-security | 14:44 | |
*** edtubill has joined #openstack-security | 14:57 | |
*** dikonoo has quit IRC | 14:59 | |
*** diazjf has joined #openstack-security | 15:03 | |
*** mvaldes1 has joined #openstack-security | 15:09 | |
*** mvaldes has quit IRC | 15:11 | |
*** vinaypotluri has joined #openstack-security | 15:19 | |
*** hongbin has joined #openstack-security | 15:21 | |
hongbin | hi security team, a question. if a user submit a private bug and attach patch in the private bug, how do i proceed with that bug/patch (not sure how to do code review outside of gerrit). | 15:23 |
*** jgrassler has joined #openstack-security | 15:24 | |
*** diazjf has quit IRC | 15:36 | |
*** diazjf has joined #openstack-security | 15:54 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding Template files for the compute service https://review.openstack.org/373443 | 16:06 |
*** browne has joined #openstack-security | 16:08 | |
lhinds | hongbin: patches can be attached to launchpad for cores to look at. | 16:09 |
*** mdong has joined #openstack-security | 16:10 | |
openstackgerrit | Merged openstack/syntribos: A spelling mistake needs to be fixed https://review.openstack.org/372989 | 16:19 |
*** diazjf has quit IRC | 16:23 | |
*** diazjf has joined #openstack-security | 16:25 | |
*** diazjf has quit IRC | 16:26 | |
openstackgerrit | Merged openstack/bandit: Adding "input()" to the blacklist calls list https://review.openstack.org/372394 | 16:31 |
*** ccneill has joined #openstack-security | 16:40 | |
*** gfhellma has joined #openstack-security | 16:45 | |
hongbin | lhinds: ack. i guess if the patch looks good, the next step is to publish it to gerrit? | 16:54 |
*** rcernin has quit IRC | 16:55 | |
openstackgerrit | Vinay Potluri proposed openstack/syntribos: Adding Nova template files https://review.openstack.org/373464 | 16:57 |
*** ccneill has quit IRC | 17:03 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding Template files for the compute service https://review.openstack.org/373443 | 17:11 |
*** popeye74 has joined #openstack-security | 17:14 | |
*** pcaruana has quit IRC | 17:14 | |
*** liverpooler has quit IRC | 17:20 | |
lhinds | hongbin: the VMT team will let you know how it works in the launchpad issue | 17:21 |
lhinds | main thing is to make sure its marked as a 'security issue' in launchpad | 17:22 |
lhinds | hongbin: https://security.openstack.org/vmt-process.html | 17:22 |
*** liverpooler has joined #openstack-security | 17:24 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding nova templates for Syntribos https://review.openstack.org/373478 | 17:25 |
*** liverpooler has quit IRC | 17:27 | |
*** ccneill has joined #openstack-security | 17:36 | |
*** Canaimero-15d has joined #openstack-security | 17:53 | |
*** Canaimero-15d has quit IRC | 17:53 | |
*** popeye74_ has joined #openstack-security | 17:55 | |
*** popeye74 has quit IRC | 17:56 | |
*** mvaldes1 has quit IRC | 17:57 | |
*** popeye74_ has quit IRC | 18:04 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added nova templates (hypervisors to external events) https://review.openstack.org/372772 | 18:19 |
*** mvaldes has joined #openstack-security | 18:23 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding Template files for the compute service https://review.openstack.org/373443 | 18:25 |
*** diazjf has joined #openstack-security | 18:27 | |
*** sdake_ is now known as sdake | 18:50 | |
*** lamt has joined #openstack-security | 18:57 | |
*** markvoelker has quit IRC | 19:03 | |
*** markvoelker has joined #openstack-security | 19:07 | |
*** diazjf has quit IRC | 19:16 | |
*** gfhellma has quit IRC | 19:25 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding nova templates for Syntribos https://review.openstack.org/373478 | 19:31 |
vinaypotluri | ccneill: i saw your comments on my patch to give the version numbers. According to the example the version no. is 2.1 . Should i just follow the example ? | 19:35 |
vinaypotluri | http://developer.openstack.org/api-ref/compute/?expanded=update-server-detail#service-urls | 19:35 |
*** diazjf has joined #openstack-security | 19:41 | |
*** salv-orlando has joined #openstack-security | 19:42 | |
*** salv-orl_ has quit IRC | 19:45 | |
*** gfhellma has joined #openstack-security | 19:51 | |
*** jmckind_ has joined #openstack-security | 19:51 | |
*** jmckind has quit IRC | 19:53 | |
mdong | so, I think the service URL is gonna be more complicated than that | 20:01 |
mdong | I’m not 100% sure, but I think the service URL is going to be of the form /v2/{project id}/whatever | 20:02 |
mdong | because when I use the python novaclient to list hypervisors, it actually makes a call to /v2/9671b079fe3f4fc096ac619139e8d207/os-hypervisors/detail | 20:03 |
mdong | and it 404’s unless I have that there | 20:03 |
*** jass93 has quit IRC | 20:04 | |
*** diazjf has quit IRC | 20:05 | |
*** tmcpeak1 has quit IRC | 20:06 | |
*** jass93 has joined #openstack-security | 20:07 | |
*** tmcpeak has joined #openstack-security | 20:07 | |
*** tmcpeak1 has joined #openstack-security | 20:10 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding nova templates for Syntribos https://review.openstack.org/373478 | 20:12 |
*** tmcpeak2 has joined #openstack-security | 20:12 | |
ccneill | hrmm | 20:12 |
ccneill | mdong: we might have to add an extension to pull configuration options then | 20:13 |
mdong | yeah, I’m writing a get_project_id function into the identity client | 20:13 |
mdong | we’d have to then call that in all of our templates | 20:13 |
ccneill | right | 20:13 |
*** tmcpeak has quit IRC | 20:13 | |
ccneill | :\ wish there was another way, but we've known that this might be needed for a while | 20:13 |
*** tmcpeak1 has quit IRC | 20:16 | |
mdong | yeah, it makes our templates look disgusting | 20:17 |
mdong | like | 20:17 |
mdong | https://gist.github.com/MCDong/445249b7238c4d766f464bc3498f8bf2 | 20:17 |
ccneill | yeah.. | 20:18 |
ccneill | sigh | 20:18 |
ccneill | this is tempting me to look into a YAML replacement for our templates... | 20:18 |
ccneill | we could at least simplify the syntax a bit | 20:19 |
mdong | yeah, definitely | 20:20 |
ccneill | I posted a comment | 20:20 |
ccneill | of what I think we could do | 20:20 |
ccneill | still not perfect, but less verbose | 20:20 |
ccneill | we just assume that you have a "client.py", and we only let you import from the extensions directoy | 20:21 |
ccneill | directory* | 20:21 |
ccneill | which we probably should've done from the start anyway.. | 20:21 |
*** diazjf has joined #openstack-security | 20:23 | |
mdong | it’s definitely better, but I don’t know about assuming the existence of “client.py” | 20:24 |
ccneill | commented with another possibility | 20:24 |
ccneill | it's more involved | 20:25 |
mdong | for example, the random data extension probably shouldnt have a client | 20:25 |
mdong | cause it’s not a client for anything | 20:25 |
ccneill | and makes our templates significantly less like a real raw HTTP request.. which sort of defeats the point | 20:25 |
ccneill | well, we can hack around that by just importing all the available functions in __init__.py and using the module itself | 20:25 |
ccneill | so you can have as many files as you want, but you just have to import them into __init__.py | 20:26 |
ccneill | s/them/the functions you want to export/ | 20:26 |
mdong | I really like the second idea, except instead of having each template marked up, we could have a “definitions file” that lives in the templates directory | 20:26 |
ccneill | yeah, actually that would be really nice | 20:27 |
ccneill | that way we don't have to put the CALL_EXTERNAL for the token in _every_ template | 20:27 |
ccneill | and we don't have to build some weird parser to determine the end of the request template and the beginning of the definitions section, we can just load a vars.json or something | 20:29 |
*** diazjf has quit IRC | 20:30 | |
mdong | and we could replace all of the CALL_EXTERNAL lines with something like {<filename>:<variable name>} | 20:31 |
*** diazjf has joined #openstack-security | 20:32 | |
*** evand has quit IRC | 20:35 | |
*** evand has joined #openstack-security | 20:35 | |
vinaypotluri | ccneill: mdong do you think we should use uuid for names https://review.openstack.org/#/c/373464/1/examples/templates/nova/servers_action/create_image.template | 20:37 |
vinaypotluri | unrahul: knangia what do you think ? | 20:38 |
ccneill | vinaypotluri: yeah, that's a good idea | 20:38 |
ccneill | that way it's easier to tell them apart in horizon and such | 20:38 |
vinaypotluri | wouldnt that increase the overhead ? | 20:38 |
vinaypotluri | ok | 20:38 |
ccneill | ¯\_(ツ)_/¯ not by much | 20:38 |
ccneill | I think it's probably worth it | 20:39 |
vinaypotluri | cool | 20:39 |
unrahul | +1 vinaypotluri .. like ccneill said.. it might be a good idea to check. | 20:51 |
vinaypotluri | +2 :) | 20:52 |
vinaypotluri | unrahul: here do you mean empty line ?https://review.openstack.org/#/c/373464/1/examples/templates/nova/servers_admin/migrate.template | 20:53 |
*** jass93 has quit IRC | 20:53 | |
unrahul | yup | 20:57 |
*** lamt has quit IRC | 21:05 | |
*** browne has quit IRC | 21:09 | |
openstackgerrit | Vinay Potluri proposed openstack/syntribos: Adding Nova template files https://review.openstack.org/373464 | 21:11 |
*** browne has joined #openstack-security | 21:22 | |
*** browne has quit IRC | 21:24 | |
*** salv-orlando has quit IRC | 21:26 | |
*** salv-orlando has joined #openstack-security | 21:26 | |
*** mvaldes has quit IRC | 21:27 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding Template files for the compute service https://review.openstack.org/373443 | 21:30 |
*** jass93 has joined #openstack-security | 21:31 | |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding nova templates for Syntribos https://review.openstack.org/373478 | 21:36 |
*** cleong has quit IRC | 21:37 | |
*** gfhellma has quit IRC | 21:40 | |
ccneill | knangia: looks like that weird double quote character got in there again | 21:43 |
*** edtubill has quit IRC | 21:43 | |
ccneill | in ["user"] inside the token CALL_EXTERNAL line | 21:43 |
*** diazjf has quit IRC | 21:45 | |
*** edmondsw has quit IRC | 21:46 | |
*** mdong_ has joined #openstack-security | 21:52 | |
knangia | ohh yaa, Charles, will correct it . | 21:52 |
*** mdong has quit IRC | 21:55 | |
*** mdong_ is now known as mdong | 21:55 | |
*** lamt has joined #openstack-security | 21:56 | |
mdong | erm…so…I’m trying to get the nova extension to play nice with the glance extension, because to create a server you need a valid image | 21:59 |
mdong | and long story short, doing a “GET /v2.0” to the cluster’s Glance port results in a 500 error | 21:59 |
mdong | that is - when it doesn’t 401 | 21:59 |
mdong | ccneill, unrahul - can you check it out and tell me what you get? | 22:00 |
*** jass93 has quit IRC | 22:00 | |
mdong | cause right now even running the glance tests fail | 22:00 |
unrahul | Hey mdong I have a docs appointment will be back in sometime | 22:01 |
ccneill | get w/o token returns 401 for me | 22:01 |
mdong | I’m doing it with the token | 22:01 |
unrahul | Did it die? 😐 | 22:01 |
mdong | and it alternates between 401 and 500 | 22:01 |
ccneill | hmm.. maybe we blew it up with the OVA testing? lol | 22:01 |
mdong | I have no idea what happened, since it was fine on Friday | 22:01 |
unrahul | There must a ton of fake images in the glance registry | 22:02 |
ccneill | dunno | 22:02 |
unrahul | May be that's why | 22:02 |
unrahul | 😯 | 22:02 |
ccneill | that's probably true ^ | 22:02 |
mdong | so I haven’t setup a local instance of devstack yet | 22:04 |
mdong | how do I go about doing that? | 22:04 |
dave-mccowan | hyakuhei ping | 22:04 |
*** jmckind_ has quit IRC | 22:04 | |
ccneill | GET /v2/ returns alternating 401/404 for me.. 90% 401 | 22:05 |
ccneill | GET /v2 returns alternating 401/302 to /v2/ | 22:05 |
mdong | the 404 will tell you that its an unknown api version | 22:05 |
*** jass93 has joined #openstack-security | 22:05 | |
mdong | and if you do /v2.0/, I get a 500 error | 22:05 |
ccneill | <h1>404 Not Found</h1> | 22:05 |
ccneill | The resource could not be found.<br /><br /> | 22:05 |
ccneill | weird.. with a scoped token? | 22:06 |
mdong | yeah... | 22:06 |
ccneill | hmm, I'm not seeing that on my end | 22:06 |
ccneill | that's strange | 22:06 |
ccneill | /v2/images alternates 401/200 for me | 22:06 |
ccneill | so it's not totally down | 22:06 |
mdong | huh... | 22:07 |
mdong | with a scoped token, GET /v2/ give me a | 22:07 |
mdong | <h1>404 Not Found</h1> | 22:07 |
mdong | Unknown API version specified<br /><br /> | 22:07 |
mdong | same with a GET /v2/images for that matter | 22:08 |
ccneill | now I'm just getting 401s.. | 22:11 |
ccneill | 404 with a new token from keystone | 22:12 |
ccneill | ¯\_(ツ)_/¯ | 22:12 |
mdong | you don’t see the 500s or the unknown API version in the 404? | 22:19 |
*** jass93 has quit IRC | 22:24 | |
mdong | well I’ll submit my WIP extension just so we can get started editing the templates | 22:25 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added nova extension client https://review.openstack.org/373547 | 22:25 |
ccneill | nah I haven't seen any 500s | 22:25 |
ccneill | which is strange, and makes me think that something is going on with keystone.. | 22:26 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added nova extension client https://review.openstack.org/373547 | 22:33 |
*** gfhellma has joined #openstack-security | 22:34 | |
mdong | so, what happens if you do this curl command | 22:35 |
mdong | curl -i -s -k -X 'GET' \ | 22:35 |
mdong | -H 'User-Agent: python-glanceclient' -H 'Content-Type: application/octet-stream' -H 'X-Auth-Token: 1e922dfc89d041af968db354b87f0c55' \ | 22:35 |
mdong | 'http://172.99.106.231:9696/v2.0' | 22:35 |
mdong | ccneill: cause for me that gets me a 500 | 22:35 |
openstackgerrit | Khanak Nangia proposed openstack/syntribos: Adding nova templates for Syntribos https://review.openstack.org/373478 | 22:35 |
mdong | …er... | 22:35 |
*** diazjf has joined #openstack-security | 22:35 | |
ccneill | <_< | 22:35 |
mdong | >< | 22:35 |
ccneill | >_> | 22:35 |
mdong | welp | 22:36 |
mdong | on the plus side it 401’s anyway so no harm done right? >< | 22:39 |
*** tmcpeak2 has quit IRC | 22:39 | |
*** gfhellma has quit IRC | 22:48 | |
*** elmiko is now known as _elmiko | 22:51 | |
*** nkinder has quit IRC | 22:52 | |
*** markvoelker has quit IRC | 23:03 | |
*** tmcpeak has joined #openstack-security | 23:03 | |
*** markvoelker has joined #openstack-security | 23:03 | |
dave-mccowan | tmcpeak ping | 23:06 |
*** hongbin has quit IRC | 23:11 | |
*** diazjf has quit IRC | 23:25 | |
*** jeremiah20x has joined #openstack-security | 23:35 | |
*** jeremiah20x has quit IRC | 23:35 | |
*** Alexey_Abashkin_ has joined #openstack-security | 23:45 | |
openstackgerrit | Merged openstack/syntribos: Adding Nova template files https://review.openstack.org/373464 | 23:45 |
*** Alexey_Abashkin has quit IRC | 23:46 | |
*** jass93 has joined #openstack-security | 23:47 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!