*** tosky has quit IRC | 00:06 | |
gmann | o/ | 01:04 |
---|---|---|
*** iurygregory has quit IRC | 01:32 | |
*** johnsom has quit IRC | 04:46 | |
*** johnsom has joined #openstack-tc | 04:49 | |
*** johnsom has quit IRC | 05:18 | |
*** johnsom has joined #openstack-tc | 05:19 | |
*** aprice has quit IRC | 05:27 | |
*** aprice has joined #openstack-tc | 05:27 | |
*** evrardjp has quit IRC | 05:33 | |
*** evrardjp has joined #openstack-tc | 05:33 | |
*** njohnston has quit IRC | 06:03 | |
*** johnsom has quit IRC | 06:27 | |
*** johnsom has joined #openstack-tc | 06:27 | |
*** rm_work has quit IRC | 07:26 | |
*** rm_work has joined #openstack-tc | 07:28 | |
*** ralonsoh has joined #openstack-tc | 07:43 | |
*** gagehugo has quit IRC | 07:51 | |
*** gagehugo has joined #openstack-tc | 07:51 | |
*** slaweq has joined #openstack-tc | 07:58 | |
*** rpittau|afk is now known as rpittau | 08:05 | |
*** dklyle has quit IRC | 08:06 | |
*** iurygregory has joined #openstack-tc | 08:52 | |
*** tosky has joined #openstack-tc | 08:56 | |
*** e0ne has joined #openstack-tc | 11:08 | |
*** slaweq has quit IRC | 11:56 | |
*** slaweq has joined #openstack-tc | 11:57 | |
*** ianychoi_ has quit IRC | 12:10 | |
*** lpetrut has joined #openstack-tc | 12:24 | |
*** Luzi has joined #openstack-tc | 12:36 | |
*** njohnston has joined #openstack-tc | 14:02 | |
ricolin | o/ | 14:06 |
*** Luzi has quit IRC | 14:18 | |
gmann | o/ | 14:24 |
*** lbragstad__ has quit IRC | 14:37 | |
*** lbragstad has joined #openstack-tc | 14:40 | |
gmann | 5 projects left for gerrit breach audit. Zun did but did not update on ML yet so i asked hongbin to do that. | 14:52 |
gmann | keystone might have done it. knikolla ? | 14:53 |
gmann | knikolla: this one https://etherpad.opendev.org/p/code-audit-gerrit-breach-tracker | 14:53 |
*** lpetrut has quit IRC | 15:16 | |
*** dklyle has joined #openstack-tc | 15:34 | |
knikolla | gmann: sorry, i just responded to the mailing list mail saying i did it and all looks good. | 15:59 |
*** bnemec has quit IRC | 16:16 | |
fungi | looks like chef and zun can be crossed off too | 16:23 |
fungi | the responses for those were caught in the ml moderation queue | 16:24 |
knikolla | fungi: does the methodology i used in https://docs.google.com/spreadsheets/d/1m_ggjfZZpzInLrfN9p4dDuv7EkigrERGBlqN3jxnBeE/edit#gid=332092178 look good for the purposes of the audit? | 16:24 |
gmann | knikolla: thanks | 16:27 |
fungi | knikolla: it's probably overkill. we already scripted a complete check that all the git commit ids belong to merged changes in gerrit | 16:28 |
fungi | but yeah, looking at the approvers and patch content is relevant | 16:28 |
*** iurygregory has quit IRC | 16:29 | |
knikolla | there were only 3 changes, so it wasn't that much to do | 16:29 |
fungi | that was the case for a lot of projects since it happened during release freeze | 16:29 |
fungi | (lukcily) | 16:30 |
fungi | (er, luckily) | 16:30 |
fungi | basically we did a bunch of analysis (before we turned anything back on) and ruled out the possibility that commits might have been pushed directly into the repositories bypassing review/gating, and that any changes to group membership allowed accounts to approve changes when they shouldn't have been able to, what we couldn't rule out is that someone's account gerrit rest api credentials were used to | 16:34 |
fungi | review/approve changes without their knowledge | 16:34 |
fungi | so that's basically what projects needed to be on the lookout for: changes they didn't remember reviewing/approving but gerrit says they did | 16:35 |
knikolla | Got it! Makes sense. | 16:47 |
*** bnemec has joined #openstack-tc | 16:50 | |
*** iurygregory has joined #openstack-tc | 17:19 | |
*** e0ne has quit IRC | 17:22 | |
*** rpittau is now known as rpittau|afk | 17:27 | |
*** cloudnull is now known as kecarter | 18:36 | |
*** kecarter is now known as cloudnull | 18:36 | |
*** smcginnis has quit IRC | 20:24 | |
*** smcginnis has joined #openstack-tc | 21:59 | |
*** ralonsoh has quit IRC | 22:03 | |
*** slaweq has quit IRC | 23:21 | |
*** tosky has quit IRC | 23:58 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!