17:00:39 #startmeeting security 17:00:39 Meeting started Thu Mar 23 17:00:39 2017 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:40 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:42 o/ 17:00:43 The meeting name has been set to 'security' 17:00:45 o/ 17:00:47 o/ 17:00:49 o/ 17:01:07 o/ 17:01:27 How's everyone doing today? 17:01:31 o/ 17:01:37 doing well 17:01:39 One more day to Friday 17:01:45 what abt you hyakuhei ? 17:01:47 how are you doing hyakuhei 17:01:50 spring cold :( 17:01:50 tkelsey is on holiday so he won't be hrere 17:02:05 oops :( 17:02:11 Heh, better this week. There's a massive IBM conference so everyone is distracted and my todo list is finally getting shorter :) 17:02:48 great 17:03:27 :) 17:03:37 nice :) 17:04:05 Sweet 17:04:08 welcome mdong 17:04:15 ok, first up is syntribos :) 17:04:18 #topic Syntribos 17:04:43 yup 17:04:48 o/ 17:04:49 * sigmavirus sneaks into the back 17:04:56 so we are running the tests against Cinder 17:05:15 o/ 17:05:19 Got a few 500 errors, also looking into old SSNs and CVEs to see if any of the issues have regressed 17:05:37 * OSSNs 17:05:42 unrahul: are you blocked on cinder by any chance? (pun intended) 17:05:42 Thats it from us on the testing side 17:05:49 :D 17:05:57 good one sigmavirus 17:06:19 Any particular areas of cinder if you guys want us to look into.. ? 17:06:32 hyakuhei: sigmavirus lhinds ^ 17:07:07 nothing comes to mind, unrahul - good job so far 17:07:08 I'm not sure. There's so much plumbing there. We know there's issues with many of the backends... I'm no expert though, sigmavirus - what do you think ? 17:07:34 perhaps the volume encryption parts? 17:07:43 lhinds: that'd be good 17:07:57 I think by default its handled by LUKS, may be some binary fuzzing? 17:08:06 unrahul: +1 17:08:09 +1 17:08:17 thanks all.. 17:08:24 thats it from our side for this week 17:08:49 unrahul: hyakuhei the driver interactions will be hard to test without hardware 17:09:11 How do they get tested atm? 17:09:25 hyakuhei: cinder has lots of 3rd party CI 17:09:39 sigmavirus: ..m.. :/ hyeah.. we are limited in those situations.. 17:09:55 unrahul: right, I was trying to point that out for you =P 17:10:41 yup..we are only testing the default lvm backend that comes with devstack 17:10:44 moving on? 17:10:50 +1 17:11:01 hyakuhei: ^ 17:11:11 ty 17:11:22 #topic Security Docs 17:11:51 asettle has been making some great efforts recently I don't think there's any outstanding reviews 17:11:57 Obviously OSIC - we love you :) 17:12:10 hyakuhei: :P 17:12:12 thank you hyakuhei :) 17:12:26 Is there anything that the wider community needs to look at? 17:12:46 Nop, this week we were a lil slow on the docs front 17:12:58 nothing as of now for reviews or feedback 17:13:42 but, we have assigned more bugs to ourselves, will be working on those 17:13:51 Cool, ok 17:13:56 That's epic you guys. 17:14:02 good job! 17:14:10 :D 17:14:16 :) 17:14:38 #topic OSSN 17:14:42 lhinds ^^ 17:15:07 only one open, which I am likely going to 'won't fix': 17:15:10 https://bugs.launchpad.net/ossn/+bug/1673085 17:15:10 Launchpad bug 1673085 in OpenStack Security Notes "scheduler hints are unbounded and never deleted" [Undecided,New] 17:15:22 from what I understand, this needs a code change. 17:15:29 seems reasonable if that's the case 17:15:45 so I prefer not to send out a note saying you're at risk, and you cannot do anything about it yet :P 17:15:53 Hmm, normally if a code change is required, there's an OSSA. 17:16:03 hyakuhei: my thoughts too. 17:16:50 if anyone wants to jump in on the issue comments, please do so. 17:17:09 done lhinds 17:17:11 I will it another week for Matt to get back too. 17:17:14 thx hyakuhei 17:17:38 that's it for notes. 17:18:04 Cool, I see an keystone trusts note in the queue, is that being processed? 17:18:12 oh rly 17:18:15 let me look. 17:18:35 oh is that embaroged? 17:18:40 I am looking at https://bugs.launchpad.net/ossn 17:19:15 One moment 17:19:20 Yup that's a super secret one 17:19:31 There's nothing wrong with trusts people, go back to your homes, nothing to see here. 17:19:38 I normally see private issues, but only if marked as ossn 17:19:50 Yup i see it as OSSN, private 17:20:06 I'll ping you a link 17:20:10 hmm, ok, I should see that. Thanks! 17:20:27 Cool. 17:20:47 #topic Any Other Business 17:20:52 Anything to bring up guys? 17:21:51 I think we can probably call it here then :) 17:22:48 TY ALL 17:22:49 #endmeeting