*** dikonoor has joined #openstack-security | 00:09 | |
*** knangia has quit IRC | 00:12 | |
*** vinaypotluri has quit IRC | 00:12 | |
*** dikonoor has quit IRC | 00:18 | |
*** markvoelker has joined #openstack-security | 00:22 | |
*** markvoelker has quit IRC | 00:27 | |
*** BR5C003Y_D00 has joined #openstack-security | 00:47 | |
*** dave-mcc_ has joined #openstack-security | 00:54 | |
*** zul has joined #openstack-security | 00:55 | |
*** dave-mccowan has quit IRC | 00:55 | |
*** BR5C003Y_D00 has quit IRC | 00:59 | |
*** browne has quit IRC | 01:04 | |
*** zul has quit IRC | 01:08 | |
*** zul has joined #openstack-security | 01:12 | |
*** encodingcollecto has joined #openstack-security | 01:22 | |
*** jass93_ has joined #openstack-security | 01:25 | |
*** dave-mccowan has joined #openstack-security | 01:27 | |
*** dave-mcc_ has quit IRC | 01:29 | |
*** encodingcollecto has quit IRC | 01:57 | |
*** dave-mccowan has quit IRC | 02:01 | |
*** gouthamr has quit IRC | 02:07 | |
*** yuanying has quit IRC | 02:27 | |
*** sdake has joined #openstack-security | 03:14 | |
*** knangia has joined #openstack-security | 03:32 | |
*** sdake_ has joined #openstack-security | 03:45 | |
*** sdake has quit IRC | 03:47 | |
*** yuanying has joined #openstack-security | 04:13 | |
*** agireud has quit IRC | 04:16 | |
*** diazjf has joined #openstack-security | 04:19 | |
*** agireud has joined #openstack-security | 04:24 | |
*** markvoelker has joined #openstack-security | 04:25 | |
*** markvoelker has quit IRC | 04:30 | |
*** salv-orlando has joined #openstack-security | 04:41 | |
*** yuanying has quit IRC | 04:45 | |
*** liverpooler has quit IRC | 04:45 | |
*** salv-orlando has quit IRC | 04:46 | |
*** yuanying has joined #openstack-security | 04:54 | |
*** salv-orlando has joined #openstack-security | 05:07 | |
*** diazjf has quit IRC | 05:09 | |
*** markvoelker has joined #openstack-security | 05:26 | |
*** markvoelker has quit IRC | 05:31 | |
*** knangia has quit IRC | 05:52 | |
*** liverpooler has joined #openstack-security | 06:02 | |
*** yuanying has quit IRC | 06:02 | |
*** liverpooler has quit IRC | 06:07 | |
*** liverpooler has joined #openstack-security | 06:07 | |
*** sdake_ has quit IRC | 06:11 | |
*** rcernin has joined #openstack-security | 06:15 | |
*** markvoelker has joined #openstack-security | 06:27 | |
*** salv-orlando has quit IRC | 06:29 | |
*** markvoelker has quit IRC | 06:32 | |
*** salv-orlando has joined #openstack-security | 06:36 | |
*** shohel has joined #openstack-security | 06:40 | |
*** salv-orlando has quit IRC | 06:41 | |
*** tesseract- has joined #openstack-security | 07:11 | |
*** salv-orlando has joined #openstack-security | 07:14 | |
*** yuanying has joined #openstack-security | 07:14 | |
*** pcaruana has joined #openstack-security | 07:26 | |
*** markvoelker has joined #openstack-security | 07:28 | |
*** markvoelker has quit IRC | 07:32 | |
*** salv-orl_ has joined #openstack-security | 07:56 | |
*** salv-orlando has quit IRC | 07:58 | |
*** jass93_ has quit IRC | 08:06 | |
*** jass93_ has joined #openstack-security | 08:11 | |
*** qwertyco_ has joined #openstack-security | 08:15 | |
*** jass93_ has quit IRC | 08:18 | |
*** jass93_ has joined #openstack-security | 08:19 | |
*** qwertyco_ has quit IRC | 08:21 | |
*** qwertyco has joined #openstack-security | 08:21 | |
*** qwertyco is now known as qwertyco_ | 08:24 | |
*** qwertyco_ has quit IRC | 08:26 | |
*** qwertyco has joined #openstack-security | 08:26 | |
*** lhinds is now known as lhinds|away | 08:47 | |
*** qwertyco has quit IRC | 08:58 | |
*** qwertyco has joined #openstack-security | 08:58 | |
*** qwertyco has quit IRC | 08:58 | |
*** qwertyco has joined #openstack-security | 08:59 | |
*** qwertyco has quit IRC | 09:14 | |
*** qwertyco has joined #openstack-security | 09:14 | |
*** SlapChopGraty has joined #openstack-security | 09:18 | |
*** SlapChopGraty has left #openstack-security | 09:20 | |
*** qwertyco has quit IRC | 09:21 | |
*** qwertyco has joined #openstack-security | 09:21 | |
*** qwertyco has quit IRC | 09:37 | |
*** qwertyco has joined #openstack-security | 09:37 | |
*** salv-orl_ has quit IRC | 09:51 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 09:53 |
---|---|---|
*** woodster_ has quit IRC | 10:00 | |
*** salv-orlando has joined #openstack-security | 10:23 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 10:46 |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 10:46 |
hyakuhei- | Thanks sic | 10:55 |
*** d0ugal has quit IRC | 11:05 | |
*** d0ugal has joined #openstack-security | 11:06 | |
*** kun_huang has quit IRC | 11:10 | |
*** kun_huang has joined #openstack-security | 11:11 | |
*** usuario has joined #openstack-security | 11:48 | |
usuario | hello? | 11:48 |
hyakuhei- | hi | 11:51 |
*** hyakuhei- has quit IRC | 11:52 | |
*** hyakuhei- has joined #openstack-security | 11:52 | |
*** hyakuhei- has quit IRC | 11:52 | |
*** hyakuhei- has joined #openstack-security | 11:52 | |
*** hyakuhei- is now known as hyakuhei | 11:52 | |
usuario | U know how I cant stop the /tree command? | 11:57 |
usuario | he is reading the OS in sequency | 11:57 |
usuario | And I cant stop it | 11:57 |
*** usuario has quit IRC | 11:59 | |
*** gouthamr has joined #openstack-security | 12:02 | |
*** salv-orlando has quit IRC | 12:24 | |
*** qwertyco has quit IRC | 12:24 | |
*** qwertyco has joined #openstack-security | 12:24 | |
*** lamt has quit IRC | 12:25 | |
*** edmondsw has joined #openstack-security | 12:26 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 12:30 |
*** markvoelker has joined #openstack-security | 12:31 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/382814 | 12:37 |
*** liverpooler has quit IRC | 12:56 | |
*** dave-mccowan has joined #openstack-security | 13:04 | |
*** ayoung has joined #openstack-security | 13:04 | |
*** agireud has quit IRC | 13:10 | |
*** shohel has quit IRC | 13:11 | |
*** agireud has joined #openstack-security | 13:18 | |
*** zul has quit IRC | 13:30 | |
*** zul has joined #openstack-security | 13:33 | |
*** mvaldes has joined #openstack-security | 13:54 | |
*** sdake has joined #openstack-security | 13:59 | |
*** hongbin has joined #openstack-security | 14:06 | |
*** sdake has quit IRC | 14:15 | |
*** mvaldes1 has joined #openstack-security | 14:15 | |
*** mvaldes has quit IRC | 14:17 | |
*** liverpooler has joined #openstack-security | 14:23 | |
*** gouthamr has quit IRC | 14:29 | |
*** gouthamr has joined #openstack-security | 14:31 | |
*** qwertyco has quit IRC | 14:41 | |
*** diazjf has joined #openstack-security | 14:46 | |
*** diazjf has quit IRC | 14:48 | |
*** tmcpeak has joined #openstack-security | 14:50 | |
*** capnoday has joined #openstack-security | 14:53 | |
*** capnoday has quit IRC | 14:55 | |
*** DuncanT has quit IRC | 14:55 | |
*** woodrow has quit IRC | 14:55 | |
*** capnoday has joined #openstack-security | 14:55 | |
*** sweston has quit IRC | 14:55 | |
*** dougwig has quit IRC | 14:55 | |
*** ediardo has quit IRC | 14:55 | |
*** fyxim has quit IRC | 14:55 | |
*** diazjf has joined #openstack-security | 14:58 | |
*** salv-orlando has joined #openstack-security | 14:59 | |
*** diazjf has quit IRC | 15:01 | |
*** mvaldes1 has quit IRC | 15:05 | |
*** mvaldes has joined #openstack-security | 15:05 | |
*** jass93_ has quit IRC | 15:08 | |
*** fyxim has joined #openstack-security | 15:11 | |
*** diazjf has joined #openstack-security | 15:15 | |
*** dougwig has joined #openstack-security | 15:18 | |
*** sweston has joined #openstack-security | 15:20 | |
*** woodrow has joined #openstack-security | 15:25 | |
*** DuncanT has joined #openstack-security | 15:36 | |
*** vinaypotluri has joined #openstack-security | 15:42 | |
*** ediardo has joined #openstack-security | 15:43 | |
*** diazjf has quit IRC | 15:44 | |
*** diazjf has joined #openstack-security | 15:45 | |
*** knangia has joined #openstack-security | 15:46 | |
*** unrahul has quit IRC | 15:52 | |
*** unrahul has joined #openstack-security | 15:52 | |
*** woodburn has joined #openstack-security | 15:54 | |
*** rcernin has quit IRC | 16:01 | |
*** ccneill has joined #openstack-security | 16:17 | |
*** jass93_ has joined #openstack-security | 16:18 | |
unrahul | Hey ccneill u thr? | 16:20 |
unrahul | Hey michaelxin ccneill do we have a meeting now? | 16:20 |
ccneill | unrahul: sorry, should've mentioned this earlier. we're having a security engineering hack day today | 16:23 |
ccneill | probably won't be super active today on IRC (though I'll at least lurk in our OSSP meeting and chime in with syntribos updates) | 16:24 |
tmcpeak | security engineering hack day sounds legit | 16:24 |
unrahul | Hey ccneill sounds cool | 16:24 |
ccneill | tmcpeak: been agitating for it for a long time.. :) | 16:25 |
tmcpeak | good man :) | 16:26 |
*** eoroot has joined #openstack-security | 16:28 | |
*** eoroot has left #openstack-security | 16:28 | |
*** tesseract- has quit IRC | 16:31 | |
*** eoroot has joined #openstack-security | 16:31 | |
eoroot | hello | 16:32 |
*** eoroot has left #openstack-security | 16:32 | |
*** mdong has joined #openstack-security | 16:34 | |
*** diazjf has quit IRC | 16:42 | |
*** tkelsey has joined #openstack-security | 16:45 | |
*** mvaldes has quit IRC | 16:47 | |
*** mvaldes has joined #openstack-security | 16:47 | |
dave-mccowan | tmcpeak ping | 16:51 |
tmcpeak | dave-mccowan: yo! how's it going? | 16:51 |
dave-mccowan | hi travis. good. i ran into a bandit issue, and found there is already a bug open. | 16:52 |
dave-mccowan | https://bugs.launchpad.net/bandit/+bug/1622615 | 16:52 |
openstack | Launchpad bug 1622615 in Bandit "Bandit reports 'json.load' as 'yaml.load'" [Undecided,New] | 16:52 |
dave-mccowan | bandit is mistaking json.load() with yaml.load() | 16:52 |
dave-mccowan | do you already know about this? | 16:52 |
tmcpeak | dave-mccowan: no, that sounds sub-optimal :D | 16:52 |
tmcpeak | I'll check it out today, thanks! | 16:52 |
dave-mccowan | looking at the code, it looks like anything.load() would also trigger the blacklist, as long as the yaml library is also imported. | 16:53 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/380554 | 16:53 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/bandit: Updated from global requirements https://review.openstack.org/383105 | 16:53 |
dave-mccowan | tmcpeak i'd be happy to help with the fix. i just wanted to check that it wasn't a known issue or limitation of the design. let me know if i can help. | 16:54 |
tmcpeak | dave-mccowan: that's awesome, should be a simple fix, I think we just need to include the full qualname of the yaml.load | 16:54 |
dave-mccowan | tmcpeak what would happen if i "import yaml as foo" and then called "foo.load()"? (not sure if that's a requirement...) | 16:55 |
tmcpeak | tkelsey: ^ do you remember? | 16:56 |
tmcpeak | I think this works as expected | 16:56 |
tmcpeak | dave-mccowan: would love your help on the fix though | 16:59 |
tkelsey | humm? | 17:00 |
tmcpeak | if you alias an import | 17:00 |
dave-mccowan | tmcpeak ok. i just assigned it to myself. | 17:00 |
tmcpeak | dave-mccowan: thanks! | 17:00 |
tkelsey | it should detect alias stuff fine | 17:00 |
tkelsey | but it should not get it confused :-/ | 17:01 |
*** sdake has joined #openstack-security | 17:01 | |
*** jamielennox|away has quit IRC | 17:02 | |
*** woodster_ has joined #openstack-security | 17:05 | |
*** jamielennox|away has joined #openstack-security | 17:16 | |
*** jamielennox|away is now known as jamielennox | 17:16 | |
tmcpeak | dave-mccowan: an interesting design choice we made :P https://github.com/openstack/bandit/blob/master/bandit/plugins/yaml_load.py#L58 | 17:32 |
dave-mccowan | tmcpeak yea, that code doesn't seem very smart. | 17:33 |
tmcpeak | agreed :) | 17:33 |
tmcpeak | especially since qualname is for that exact thing | 17:34 |
dave-mccowan | tmcpeak should this code be removed, and the check added to blacklists/calls.py? | 17:36 |
openstackgerrit | Merged openstack/bandit: Updated from global requirements https://review.openstack.org/383105 | 17:39 |
dave-mccowan | tmcpeak nevermind. i see how to use qualname in this case. | 17:41 |
tmcpeak | dave-mccowan: thanks! | 17:41 |
dave-mccowan | tmcpeak quick question... i've forgotten how to run bandit out of my tree, instead of the version that is pip installed on my server. | 17:45 |
tmcpeak | sigmavirus: ^ | 17:45 |
tmcpeak | what was that magics you used for that? | 17:45 |
tmcpeak | I think there's s —develop or something | 17:46 |
tmcpeak | otherwise you can do 'pip install -e .' or something | 17:46 |
sigmavirus | the -e. is the magic | 17:48 |
dave-mccowan | sigmavirus any way to run the source directly from the tree? this would be handy to run bandit inside a debugger. | 17:49 |
sigmavirus | dave-mccowan: that's it | 17:50 |
sigmavirus | pip install -e. will install it from source and any modifications you make will get picked up | 17:50 |
sigmavirus | because it does symlinks not a real install | 17:50 |
sigmavirus | -e stands for editable | 17:50 |
dave-mccowan | sigmavirus cool. thanks. | 17:51 |
sigmavirus | tox -e venv does something similar too iirc | 17:51 |
*** jass93__ has joined #openstack-security | 17:56 | |
*** tkelsey has quit IRC | 17:56 | |
*** jass93_ has quit IRC | 17:58 | |
*** diazjf has joined #openstack-security | 18:23 | |
openstackgerrit | Andreas Jaeger proposed openstack/bandit: Enable release notes translation https://review.openstack.org/383200 | 18:24 |
openstackgerrit | Dave McCowan proposed openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 18:31 |
*** mdong has quit IRC | 18:33 | |
*** mdong has joined #openstack-security | 18:35 | |
*** mvaldes has quit IRC | 18:35 | |
*** mvaldes has joined #openstack-security | 18:35 | |
openstackgerrit | Deepak proposed openstack/anchor: Changed the home-page link https://review.openstack.org/383314 | 18:41 |
*** capnoday has quit IRC | 18:46 | |
*** jamielennox has quit IRC | 19:03 | |
openstackgerrit | Deepak proposed openstack/bandit: Changed the home-page url link https://review.openstack.org/383415 | 19:04 |
*** jamielennox|away has joined #openstack-security | 19:05 | |
*** jamielennox|away is now known as jamielennox | 19:06 | |
*** salv-orlando has quit IRC | 19:13 | |
*** nkinder has quit IRC | 19:15 | |
*** nkinder has joined #openstack-security | 19:16 | |
sigmavirus | tmcpeak: ^ Do we want to point to the developer docs instead of the wiki? | 19:18 |
tmcpeak | sigmavirus: what's this? | 19:19 |
sigmavirus | tmcpeak: https://review.openstack.org/383415 | 19:19 |
tmcpeak | sigmavirus: no, I think we want to keep it at the wiki | 19:19 |
tmcpeak | only developers would use the developer docs | 19:19 |
sigmavirus | probably same for anchor then, eh? | 19:19 |
sigmavirus | https://review.openstack.org/383314 | 19:19 |
tmcpeak | sigmavirus: yep | 19:19 |
tmcpeak | good call | 19:20 |
*** Canaimero-e64b8 has joined #openstack-security | 19:20 | |
*** agireud has quit IRC | 19:21 | |
sigmavirus | tmcpeak: always be suspicious of reviews like that proposed in batches | 19:21 |
tmcpeak | sigmavirus: yep yep | 19:21 |
*** Canaimero-e64b8 has left #openstack-security | 19:22 | |
*** agireud has joined #openstack-security | 19:29 | |
*** agireud has quit IRC | 19:33 | |
openstackgerrit | Merged openstack/bandit: Enable release notes translation https://review.openstack.org/383200 | 19:34 |
*** agireud has joined #openstack-security | 19:43 | |
*** jass93_ has joined #openstack-security | 19:46 | |
*** jass93__ has quit IRC | 19:48 | |
*** dave-mccowan has quit IRC | 19:49 | |
*** dave-mccowan has joined #openstack-security | 19:58 | |
*** dave-mcc_ has joined #openstack-security | 20:01 | |
*** dave-mccowan has quit IRC | 20:04 | |
*** agireud has quit IRC | 20:06 | |
*** sdake has quit IRC | 20:09 | |
openstackgerrit | Dave McCowan proposed openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 20:18 |
*** salv-orlando has joined #openstack-security | 20:27 | |
*** ludeatbest has joined #openstack-security | 20:31 | |
*** ludeatbest has quit IRC | 20:33 | |
*** mvaldes has quit IRC | 20:34 | |
*** browne has joined #openstack-security | 20:40 | |
*** dave-mcc_ has quit IRC | 20:41 | |
*** mvaldes has joined #openstack-security | 21:00 | |
*** zooey has joined #openstack-security | 21:01 | |
*** dave-mccowan has joined #openstack-security | 21:01 | |
*** ayoung has quit IRC | 21:02 | |
*** zooey has quit IRC | 21:10 | |
*** zooey has joined #openstack-security | 21:10 | |
*** zooey has joined #openstack-security | 21:10 | |
*** diazjf has quit IRC | 21:13 | |
*** diazjf has joined #openstack-security | 21:25 | |
*** gfhellma has joined #openstack-security | 21:26 | |
tmcpeak | browne: yo | 21:27 |
tmcpeak | sigmavirus: | 21:27 |
tmcpeak | https://review.openstack.org/#/c/383245/ | 21:27 |
tmcpeak | +A por favor? | 21:27 |
*** gouthamr has quit IRC | 21:27 | |
*** gouthamr has joined #openstack-security | 21:31 | |
*** gouthamr has quit IRC | 21:32 | |
*** gouthamr has joined #openstack-security | 21:35 | |
*** gouthamr has quit IRC | 21:37 | |
*** agireud has joined #openstack-security | 21:37 | |
browne | tmcpeak: what's up | 21:42 |
browne | oh, i'll review | 21:43 |
tmcpeak | sweet, thanks | 21:43 |
*** rcernin has joined #openstack-security | 21:47 | |
*** diazjf has quit IRC | 21:51 | |
openstackgerrit | Merged openstack/bandit: Use qualname list to avoid false positive on load() https://review.openstack.org/383245 | 21:51 |
*** rcernin has quit IRC | 21:59 | |
*** rcernin has joined #openstack-security | 21:59 | |
*** sdake has joined #openstack-security | 22:13 | |
*** mdong has quit IRC | 22:13 | |
*** mdong has joined #openstack-security | 22:14 | |
*** ayoung has joined #openstack-security | 22:21 | |
*** mvaldes has quit IRC | 22:35 | |
*** mdong has quit IRC | 22:37 | |
*** tmcpeak has quit IRC | 22:59 | |
*** salv-orlando has quit IRC | 23:01 | |
*** gouthamr has joined #openstack-security | 23:01 | |
*** ayoung has quit IRC | 23:05 | |
*** hongbin has quit IRC | 23:08 | |
*** ccneill_ has joined #openstack-security | 23:09 | |
*** ccneill has quit IRC | 23:11 | |
*** gfhellma has quit IRC | 23:14 | |
*** jass93_ has quit IRC | 23:32 | |
*** zooey has left #openstack-security | 23:34 | |
*** rcernin has quit IRC | 23:36 | |
*** ayoung has joined #openstack-security | 23:49 | |
*** pcaruana has quit IRC | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!