[Yahoo-eng-team] [Bug 1382562] Re: security groups remote_group fails with CIDR in address pairs

2014-10-17 Thread Jeremy Stanley
Thanks Kevin. In that case I've tagged it as a security hardening opportunity (removes a foot-cannon), and switched the advisory task to won't-fix. ** Information type changed from Public Security to Public ** Changed in: ossa Status: Incomplete = Won't Fix ** Tags added: security --

[Yahoo-eng-team] [Bug 1357372] Re: [oss-security] [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)

2014-10-14 Thread Jeremy Stanley
** Summary changed: - Race condition in VNC port allocation when spawning a instance on VMware (CVE-2014-8750) + [oss-security] [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750) ** Changed in: ossa Status: Fix Committed = Fix Released --

[Yahoo-eng-team] [Bug 1379201] Re: openvswitch-datapath-dkms 1.4.6-0ubuntu1.12.04.3: openvswitch kernel module failed to build

2014-10-09 Thread Jeremy Stanley
** Also affects: neutron Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1379201 Title: openvswitch-datapath-dkms 1.4.6-0ubuntu1.12.04.3:

[Yahoo-eng-team] [Bug 1370292] Re: Possible SQL Injection vulnerability in hyperv plugin

2014-10-01 Thread Jeremy Stanley
Switched the bug to public and marked the security advisory task wontfix based on the above explanation. ** Information type changed from Private Security to Public ** Changed in: ossa Status: Incomplete = Won't Fix -- You received this bug notification because you are a member of

[Yahoo-eng-team] [Bug 1357372] Re: Race condition in VNC port allocation when spawning a instance on VMware

2014-09-29 Thread Jeremy Stanley
Could this behavior be controlled by a would-be attacker, or is it only up to random chance? If the former then like bug 1058077/bug 1125378 the VMT would likely deem it a security vulnerability. If the latter like bug 1255609 we would most probably not. ** Also affects: ossa Importance:

[Yahoo-eng-team] [Bug 1369627] Re: libvirt disk.config will have issues when booting two with different config drive values

2014-09-23 Thread Jeremy Stanley
This only affects juno right? (Those changes are only in the master branch?) Just confirming we don't need an advisory for any released versions. ** Also affects: ossa Importance: Undecided Status: New ** Changed in: ossa Status: New = Incomplete -- You received this bug

[Yahoo-eng-team] [Bug 1372375] Re: Attaching LVM encrypted volumes (with LUKS) could cause data loss if LUKS headers get corrupted

2014-09-22 Thread Jeremy Stanley
** Information type changed from Private Security to Public ** Tags added: security ** Changed in: ossa Status: New = Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1372666] [NEW] list_ports().get() times out waiting for response from Neutron API in TestSecurityGroupsBasicOps

2014-09-22 Thread Jeremy Stanley
Public bug reported: This request failed: http://logs.openstack.org/12/123112/1/check/check-tempest-dsvm-neutron- full/cdb7110/logs/screen-n-api.txt.gz#_2014-09-22_14_16_01_028 2014-09-22 14:16:01.028 DEBUG nova.api.openstack.wsgi [req-bb64d882-d91e-4bff-9407-19277208e277

[Yahoo-eng-team] [Bug 1368773] Re: nova.api.openstack.compute.pluginlibvir: error : internal error could not initialize domain event timer

2014-09-17 Thread Jeremy Stanley
** Project changed: openstack-ci = nova -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1368773 Title: nova.api.openstack.compute.pluginlibvir: error : internal error

[Yahoo-eng-team] [Bug 1350766] Re: Race condition: compute intermittently corrupts base images on download from glance

2014-09-08 Thread Jeremy Stanley
I've marked the OSSA task as won't fix to indicate this issue isn't one for which the project vulnerability management team would publish a coordinated security advisory, as the conditions by which it is triggered do not seem to be under direct control of a malicious actor but rather one of volume

[Yahoo-eng-team] [Bug 1365712] Re: Command Execution Possible Through Config File Tampering

2014-09-05 Thread Jeremy Stanley
** Also affects: ossa Importance: Undecided Status: New ** Changed in: ossa Status: New = Incomplete -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1365712] Re: Command Execution Possible Through Config File Tampering

2014-09-05 Thread Jeremy Stanley
Got it. We use security bugs (whether private or public) to track vulnerabilities, and use normal public bugs with the security tag for hardening tasks. ** Tags added: security ** Information type changed from Public Security to Public ** Changed in: ossa Status: Incomplete = Won't Fix

[Yahoo-eng-team] [Bug 1351377] Re: neutron failed to notify nova during nova boot

2014-08-01 Thread Jeremy Stanley
Can you explain what led you to conclude this is a security vulnerability? ** Also affects: ossa Importance: Undecided Status: New ** Changed in: ossa Status: New = Incomplete -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1347318] Re: Revocation events don't handle scoped tokens correctly

2014-07-31 Thread Jeremy Stanley
** Information type changed from Public Security to Public ** No longer affects: ossa -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1347318 Title: Revocation events don't handle

[Yahoo-eng-team] [Bug 1342690] Re: nova allows to bypass neutron permission checking by allowing user to plug instances to external neutron networking

2014-07-30 Thread Jeremy Stanley
*** This bug is a duplicate of bug 1284718 *** https://bugs.launchpad.net/bugs/1284718 ** Information type changed from Private Security to Public ** This bug has been marked a duplicate of bug 1284718 interface-attach to external network a) works and b) results in undeletable instances

[Yahoo-eng-team] [Bug 1163569] Re: security groups don't work with vip and ovs plugin

2014-07-29 Thread Jeremy Stanley
** Tags added: security ** No longer affects: ossa ** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1163569 Title: security

[Yahoo-eng-team] [Bug 1316822] Re: soft reboot of instance does not ensure iptables rules are present

2014-07-07 Thread Jeremy Stanley
After discussing with Andrew and Thierry, I'm convinced that the potential behavior change introduced by a backport of that mitigating commit, when weighed against the amount of social engineering needed to exploit this in Havana, means this bug is probably better just documented as a known

[Yahoo-eng-team] [Bug 1331092] Re: FlatDHCP manager will hand out networks from other tenants

2014-06-17 Thread Jeremy Stanley
Removing OSSA task since we don't need an advisory (non-exploitable). ** No longer affects: ossa -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1331092 Title: FlatDHCP

[Yahoo-eng-team] [Bug 1319640] Re: Console to instance persists even after logging out of Horizon

2014-05-30 Thread Jeremy Stanley
** Information type changed from Public Security to Public ** Tags added: security ** No longer affects: ossa -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1319640

[Yahoo-eng-team] [Bug 1269418] Re: [OSSA 2014-017] nova rescue doesn't put VM into RESCUE status on vmware (CVE-2014-2573)

2014-05-29 Thread Jeremy Stanley
** Summary changed: - nova rescue doesn't put VM into RESCUE status on vmware (CVE-2014-2573) + [OSSA 2014-017] nova rescue doesn't put VM into RESCUE status on vmware (CVE-2014-2573) ** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because

[Yahoo-eng-team] [Bug 1322945] Re: Attaching a IPv6 private subnet to a L3 Router, breaks it and its IPv4 Floating IPs

2014-05-26 Thread Jeremy Stanley
Since you mention this may be a security vulnerability (potential denial of service attack) in a supported release, I've switched the bug from public to public security and added an OSSA task in case it warrants an advisory. ** Information type changed from Public to Public Security ** Also

[Yahoo-eng-team] [Bug 1319319] Re: The web server allows the HTTP TRACE or TRACK methods.

2014-05-26 Thread Jeremy Stanley
** Also affects: openstack-chef Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1319319 Title: The web server allows the

[Yahoo-eng-team] [Bug 1304240] Re: neutron-openvswitch-agent service should be renamed as neutron-plugin-openvswitch-agent

2014-04-09 Thread Jeremy Stanley
No idea why this was opened against the project for our developer community infrastructure--relocating to neutron. ** Project changed: openstack-ci = neutron -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron.

[Yahoo-eng-team] [Bug 1112912] Re: get_firewall_required should use VIF parameter from neutron

2014-04-04 Thread Jeremy Stanley
Great--thanks Nachi! ** Information type changed from Public Security to Public ** No longer affects: ossa -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1112912 Title:

[Yahoo-eng-team] [Bug 1274034] Re: Neutron firewall anti-spoofing does not prevent ARP poisoning

2014-02-17 Thread Jeremy Stanley
Switched to public following discussion with Mark. ** Information type changed from Private Security to Public ** Tags added: security ** Changed in: ossa Status: Incomplete = Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1275062] Re: [OSSA 2014-004] sensitive info in image location is logged when authentication to single tenant swift store fails (CVE-2014-1948)

2014-02-12 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Glance. https://bugs.launchpad.net/bugs/1275062 Title: [OSSA 2014-004] sensitive info in image location is logged

[Yahoo-eng-team] [Bug 1277507] Re: ImportError: No module named passlib.hash

2014-02-07 Thread Jeremy Stanley
The ipaddr failure seems to have probably been an issue with pypi.python.org. That log is for a change to gantt, which does not currently use the restrictive http://pypi.openstack.org/openstack/ mirror. If it should do so, add it to openstack/requirements:projects.txt (it will also get

[Yahoo-eng-team] [Bug 1277507] Re: ImportError: No module named passlib.hash

2014-02-07 Thread Jeremy Stanley
** Also affects: marconi Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1277507 Title: ImportError: No module named passlib.hash Status in

[Yahoo-eng-team] [Bug 1277507] Re: ImportError: No module named passlib.hash

2014-02-07 Thread Jeremy Stanley
** Also affects: gantt Importance: Undecided Status: New ** Also affects: oslo Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone.

[Yahoo-eng-team] [Bug 1259907] Re: check-grenade-dsvm marked as FAILED - n-api/g-api Logs have errors

2014-02-04 Thread Jeremy Stanley
Seems to have been fixed in grenade. ** Changed in: openstack-ci Status: New = Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1259907 Title:

[Yahoo-eng-team] [Bug 1260015] Re: PKI token contains the string ERROR

2014-02-04 Thread Jeremy Stanley
I believe the log error checker resides in the tempest repository. ** Project changed: openstack-ci = tempest -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1260015 Title: PKI token

[Yahoo-eng-team] [Bug 1260723] Re: Invalid OpenStack Nova credentials.

2014-02-04 Thread Jeremy Stanley
** Project changed: openstack-ci = keystone -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1260723 Title: Invalid OpenStack Nova credentials. Status in OpenStack Identity (Keystone):

[Yahoo-eng-team] [Bug 1266711] Re: AttributeError: virConnect instance has no attribute 'registerCloseCallback'

2014-01-07 Thread Jeremy Stanley
** Also affects: openstack-ci Importance: Undecided Status: New ** Changed in: openstack-ci Status: New = In Progress ** Changed in: openstack-ci Importance: Undecided = Critical ** Changed in: openstack-ci Assignee: (unassigned) = Jeremy Stanley (fungi) ** Changed

[Yahoo-eng-team] [Bug 1264972] Re: FAIL: tempest.api.compute.v3.servers.test_server_addresses.ServerAddressesV3Test.test_list_server_addresses

2013-12-30 Thread Jeremy Stanley
** Also affects: nova Importance: Undecided Status: New ** Changed in: openstack-ci Status: New = Incomplete ** Tags added: gate-failure -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1235450] Re: [OSSA 2013-033] Metadata queries from Neutron to Nova are not restricted by tenant (CVE-2013-6419)

2013-12-17 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1235450 Title: [OSSA 2013-033] Metadata queries from Neutron to Nova are

[Yahoo-eng-team] [Bug 1260525] Re: Incomplete XSS fix for ossa/1247675

2013-12-17 Thread Jeremy Stanley
Bug is now a public non-vulnerability, tagged as security hardening, no advisory. Thanks! ** Information type changed from Private Security to Public ** Tags added: security ** Changed in: ossa Status: Incomplete = Invalid -- You received this bug notification because you are a member

[Yahoo-eng-team] [Bug 1247675] Re: [OSSA 2013-036] Insufficient sanitization of Instance Name in Horizon (CVE-2013-6858)

2013-12-16 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1247675 Title: [OSSA 2013-036] Insufficient

[Yahoo-eng-team] [Bug 1242597] Re: [OSSA 2013-032] Keystone trust circumvention through EC2-style tokens (CVE-2013-6391)

2013-12-14 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1242597 Title: [OSSA 2013-032] Keystone trust circumvention through

[Yahoo-eng-team] [Bug 1258566] Re: NOVA scheduler to properly launch a VM or BM instance based on selected flavor

2013-12-06 Thread Jeremy Stanley
Mis-filed. Switching from openstack-ci (developer tools, continuous integration and service hosting) to nova (cloud computing fabric controller). ** Project changed: openstack-ci = nova -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1255419] Re: jenkins tests fails for neutron/grizzly duo to iso8601 version requirement conflict

2013-11-27 Thread Jeremy Stanley
Marking invalid on infrastructure since this is something which has to be fixed within the affected projects. ** Changed in: openstack-ci Status: New = Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Glance.

[Yahoo-eng-team] [Bug 1246159] Re: seed method brings potential security issue

2013-11-11 Thread Jeremy Stanley
** Information type changed from Private Security to Public ** Changed in: ossa Status: Incomplete = Invalid ** Tags added: security -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1246160] Re: shuffle method bring potential security issue

2013-11-11 Thread Jeremy Stanley
** Information type changed from Private Security to Public ** Changed in: ossa Status: Incomplete = Invalid ** Tags added: security -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1246158] Re: randint method brings potential security issue

2013-11-11 Thread Jeremy Stanley
** Information type changed from Private Security to Public ** Changed in: ossa Status: Incomplete = Invalid ** Tags added: security -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1247194] Re: Jenkins fails due to test_register_http_image error

2013-11-08 Thread Jeremy Stanley
** No longer affects: openstack-ci ** Changed in: glance Status: New = Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Glance. https://bugs.launchpad.net/bugs/1247194 Title: Jenkins fails due to

[Yahoo-eng-team] [Bug 1234181] Re: stable/grizzly patches are failing jenkins in check-tempest-devstack-vm-neutron

2013-10-03 Thread Jeremy Stanley
This is dying somewhere in the middle of a devstack setup while running commands via the quantumclient compat wrapper, and is only affecting stable as far as we've seen, so I'm pretty confident the issue is not on the infrastructure itself. Probably quantumclient, neutron or at worst devstack...

[Yahoo-eng-team] [Bug 1210869] Re: Ratelimiting not working

2013-08-20 Thread Jeremy Stanley
Yes, I agree in this case it doesn't sound like any actual security vulnerability was being addressed by that module, so no OSSA warranted. ** Changed in: ossa Status: Incomplete = Invalid ** Information type changed from Public Security to Public ** Tags added: security -- You

[Yahoo-eng-team] [Bug 1184041] Re: [OSSA 2013-020] Denial of Service in Nova network source security groups (CVE-2013-4185)

2013-08-06 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1184041 Title: [OSSA 2013-020] Denial of Service in Nova

[Yahoo-eng-team] [Bug 1194093] Re: [OSSA 2013-019] Resource limit circumvention in Nova private flavors (CVE-2013-2256)

2013-08-06 Thread Jeremy Stanley
** Changed in: ossa Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1194093 Title: [OSSA 2013-019] Resource limit

[Yahoo-eng-team] [Bug 1205546] Re: babel 1.0 dependency pytz isn't found

2013-07-27 Thread Jeremy Stanley
** Changed in: ceilometer Status: In Progress = Invalid ** Changed in: cinder Status: In Progress = Invalid ** Changed in: ironic Status: In Progress = Invalid ** Changed in: keystone Status: In Progress = Invalid ** Changed in: nova Status: In Progress =

[Yahoo-eng-team] [Bug 1182271] Re: Nova unit tests fail on CentOS 6 when python-jinja2 package is installed

2013-07-19 Thread Jeremy Stanley
Abandoned that change. Apparently it should now be possible to simply uncap requests since we've started doing a pip install -U to work around the previoys site packages related breakage. I'll propose that revert to nova instead and see how it fares. ** Changed in: openstack-ci Status: In

[Yahoo-eng-team] [Bug 1131030] Re: volume didnt become available within 180 seconds

2013-06-11 Thread Jeremy Stanley
I've bumped into the same error in a couple of grenade runs... possibly related? http://logs.openstack.org/32346/1/check/gate-grenade-devstack-vm/9021/console.html.gz http://logs.openstack.org/32002/3/check/gate-grenade-devstack-vm/9450/console.html.gz ** Changed in: nova Status: Invalid

[Yahoo-eng-team] [Bug 1132835] Re: Nova unit tests not running, but still passing for stable/essex

2013-06-03 Thread Jeremy Stanley
This was fixed in a commit appearing in the unversioned EOL tag. ** Changed in: nova/essex Status: Fix Committed = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova).

[Yahoo-eng-team] [Bug 1185905] Re: User tokens logged by keystoneclient.middleware.auth_token

2013-05-30 Thread Jeremy Stanley
*** This bug is a duplicate of bug 1004114 *** https://bugs.launchpad.net/bugs/1004114 I think this is one of the facets of the debug-level credential logging which is being solved several ways in different places? Marking as a duplicate of bug 1004114 but readjust if this is separate. **

[Yahoo-eng-team] [Bug 1178800] Re: dhcp unit tests prompt for sudo password

2013-05-14 Thread Jeremy Stanley
The switch from quantal to precise slaves took place yesterday without incident, so this regression is no longer present. ** Changed in: openstack-ci Status: In Progress = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1134163] Re: Job pep8 fails according can't satisfy test-requires

2013-02-27 Thread Jeremy Stanley
We appreciate the heads up to CI on this issue since it's impacting testing broadly across multiple projects, but it looks like it will need to be fixed in the indivual projects using the pyparsing module so I'm marking it invalid for CI. ** Changed in: openstack-ci Status: New = Invalid

<    1   2   3