Re: Entire process's environment attached to bugzillas by ABRT

2014-12-02 Thread Richard W.M. Jones
On Tue, Dec 02, 2014 at 03:36:11AM +0100, Zbigniew Jędrzejewski-Szmek wrote: On Sun, Nov 30, 2014 at 08:29:27PM -0500, Rahul Sundaram wrote: Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also OpenNebula (^ONE_) and Vmware (^VI_) doing the same. Seems to be

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-02 Thread Jakub Filak
On Mon, 2014-12-01 at 16:01 +, Richard W.M. Jones wrote: On Mon, Dec 01, 2014 at 03:18:36PM +0100, Zbigniew Jędrzejewski-Szmek wrote: On Sun, Nov 30, 2014 at 01:43:39PM +, Richard W.M. Jones wrote: On Fri, Nov 28, 2014 at 07:39:47AM +0100, Jakub Filak wrote: The discussion I

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-02 Thread Jakub Filak
On Tue, 2014-12-02 at 10:32 +, Richard W.M. Jones wrote: On Tue, Dec 02, 2014 at 03:36:11AM +0100, Zbigniew Jędrzejewski-Szmek wrote: On Sun, Nov 30, 2014 at 08:29:27PM -0500, Rahul Sundaram wrote: Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Richard W.M. Jones
On Sun, Nov 30, 2014 at 08:29:27PM -0500, Rahul Sundaram wrote: Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also OpenNebula (^ONE_) and Vmware (^VI_) doing the same. Seems to be pretty common with virt and cloud stuff. Apart from that I can't think of anything

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Zbigniew Jędrzejewski-Szmek
On Sun, Nov 30, 2014 at 01:43:39PM +, Richard W.M. Jones wrote: On Fri, Nov 28, 2014 at 07:39:47AM +0100, Jakub Filak wrote: The discussion I mentioned above was primarily about OpenStack (but the participants also expressed concerns about sending 'environ' to Bugzilla at all), where

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Richard W.M. Jones
On Mon, Dec 01, 2014 at 03:18:36PM +0100, Zbigniew Jędrzejewski-Szmek wrote: On Sun, Nov 30, 2014 at 01:43:39PM +, Richard W.M. Jones wrote: On Fri, Nov 28, 2014 at 07:39:47AM +0100, Jakub Filak wrote: The discussion I mentioned above was primarily about OpenStack (but the

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Lubomir Rintel
On Sun, 2014-11-30 at 13:43 +, Richard W.M. Jones wrote: On Fri, Nov 28, 2014 at 07:39:47AM +0100, Jakub Filak wrote: The discussion I mentioned above was primarily about OpenStack (but the participants also expressed concerns about sending 'environ' to Bugzilla at all), where people

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Lubomir Rintel
On Mon, 2014-12-01 at 08:59 +, Richard W.M. Jones wrote: On Sun, Nov 30, 2014 at 08:29:27PM -0500, Rahul Sundaram wrote: Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also OpenNebula (^ONE_) and Vmware (^VI_) doing the same. Seems to be pretty common with

Re: Entire process's environment attached to bugzillas by ABRT

2014-12-01 Thread Zbigniew Jędrzejewski-Szmek
On Sun, Nov 30, 2014 at 08:29:27PM -0500, Rahul Sundaram wrote: Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also OpenNebula (^ONE_) and Vmware (^VI_) doing the same. Seems to be pretty common with virt and cloud stuff. Apart from that I can't think of anything

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-30 Thread Richard W.M. Jones
On Fri, Nov 28, 2014 at 07:39:47AM +0100, Jakub Filak wrote: The discussion I mentioned above was primarily about OpenStack (but the participants also expressed concerns about sending 'environ' to Bugzilla at all), where people are regularly storing their passwords and tokens as environment

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-30 Thread Lars Seipel
On Sun, Nov 30, 2014 at 01:43:39PM +, Richard W.M. Jones wrote: How about having abrt just remove or scrub all variables that start with /^OS_/ ? I know it's nasty to have application-specific treatment of environment variables like this, but the number of applications that pass auth

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-30 Thread Rahul Sundaram
Hi On Sun, Nov 30, 2014 at 1:36 PM, Lars Seipel wrote: There's also OpenNebula (^ONE_) and Vmware (^VI_) doing the same. Seems to be pretty common with virt and cloud stuff. Apart from that I can't think of anything else right now. Rackspace, DigitalOcean, Google Computing Engine etc

Entire process's environment attached to bugzillas by ABRT

2014-11-27 Thread Jakub Filak
Hello, As you might know ABRT attaches 'environ' file to its Bugzilla bugs. The file contains a full copy of /proc/[pid]/environ. Even though ABRT highlights black-listed words and encourages users to review the data before submitting them, it may happen that the reporter misses something and

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-27 Thread Jan Kratochvil
On Thu, 27 Nov 2014 16:23:57 +0100, Jakub Filak wrote: Do you find 'environ' attachment valuable or is ABRT just publishing personal information? No but I can imagine in some cases it may be useful. Couldn't there be a way to send additional information upon bug assignee's request? That would

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-27 Thread Zbigniew Jędrzejewski-Szmek
On Thu, Nov 27, 2014 at 07:02:00PM +0100, Jan Kratochvil wrote: On Thu, 27 Nov 2014 16:23:57 +0100, Jakub Filak wrote: Do you find 'environ' attachment valuable or is ABRT just publishing personal information? No but I can imagine in some cases it may be useful. Is this a problem in

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-27 Thread Jakub Filak
On Thu, 2014-11-27 at 19:02 +0100, Jan Kratochvil wrote: On Thu, 27 Nov 2014 16:23:57 +0100, Jakub Filak wrote: Do you find 'environ' attachment valuable or is ABRT just publishing personal information? No but I can imagine in some cases it may be useful. Couldn't there be a way to

Re: Entire process's environment attached to bugzillas by ABRT

2014-11-27 Thread Jakub Filak
On Fri, 2014-11-28 at 00:28 +0100, Zbigniew Jędrzejewski-Szmek wrote: On Thu, Nov 27, 2014 at 07:02:00PM +0100, Jan Kratochvil wrote: On Thu, 27 Nov 2014 16:23:57 +0100, Jakub Filak wrote: Do you find 'environ' attachment valuable or is ABRT just publishing personal information?