*** Jackneill has quit IRC | 00:15 | |
*** Jackneill has joined #openstack-security | 00:28 | |
*** gyee has quit IRC | 01:40 | |
*** rcernin has quit IRC | 02:24 | |
*** rcernin has joined #openstack-security | 02:31 | |
*** rcernin has quit IRC | 03:23 | |
*** rcernin has joined #openstack-security | 03:31 | |
*** rcernin has quit IRC | 03:46 | |
*** rcernin has joined #openstack-security | 04:23 | |
*** rcernin has quit IRC | 04:28 | |
*** rcernin has joined #openstack-security | 04:29 | |
*** rcernin has quit IRC | 05:36 | |
*** rcernin has joined #openstack-security | 05:37 | |
*** rcernin has quit IRC | 05:51 | |
*** rcernin has joined #openstack-security | 05:56 | |
*** rcernin has quit IRC | 06:10 | |
*** rcernin has joined #openstack-security | 06:14 | |
*** rcernin has quit IRC | 06:28 | |
*** jawad_axd has joined #openstack-security | 07:23 | |
*** redrobot has quit IRC | 08:35 | |
openstackgerrit | Brian Rosmaita proposed openstack/security-doc master: Add OSSN-0086 https://review.opendev.org/733116 | 11:37 |
---|---|---|
*** Guest27280 has joined #openstack-security | 13:22 | |
*** Guest27280 is now known as redrobot | 13:25 | |
*** jawad_axd has quit IRC | 15:20 | |
*** gyee has joined #openstack-security | 15:42 | |
*** trident has quit IRC | 16:09 | |
*** trident has joined #openstack-security | 16:12 | |
mnaser | fungi: is there any reason why this was not released over embargo disclosure :( | 16:16 |
mnaser | this is a fun surprise in the middle of the ptg | 16:16 |
fungi | mnaser: it's not directly fixable | 16:17 |
fungi | i was trying to convince them to make it public sooner, but it's not an advisory, it's configuration guidance accompanied by some patches | 16:17 |
mnaser | fungi: right, i just kinda saw patches and figured it's something we need to patch.. | 16:18 |
fungi | only if you're using scaleio/vxflexos storage driver | 16:18 |
fungi | it was effectively ignored until we implemented a policy to limit embargo durations, and then right before the embargo was scheduled to expire and become public suddenly folks wanted to work on a solution for it | 16:20 |
fungi | and asked to extend the embargo beyond its expiration | 16:21 |
fungi | i didn't feel like extending for two weeks was in everyone's best interests | 16:25 |
fungi | better that users of that driver know sooner what the security limitations are | 16:26 |
fungi | (especially since one of the bits of guidance there is that it's unsafe in combination with bare metal instances, and there's no solution to that other than to stop using them together) | 16:27 |
openstackgerrit | Merged openstack/security-doc master: Add OSSN-0086 https://review.opendev.org/733116 | 17:35 |
openstackgerrit | Andreas Jaeger proposed openstack/security-analysis master: Switch to newer openstackdocstheme version https://review.opendev.org/733316 | 18:54 |
openstackgerrit | Andreas Jaeger proposed openstack/security-specs master: Switch to newer openstackdocstheme version https://review.opendev.org/733317 | 18:55 |
openstackgerrit | Andreas Jaeger proposed openstack/security-analysis master: Switch to newer openstackdocstheme version https://review.opendev.org/733316 | 19:21 |
*** rcernin has joined #openstack-security | 23:14 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!