/srv/irclogs.ubuntu.com/2024/09/25/#ubuntu-security.txt

=== hkeoauxyzozlvajw is now known as efirnffutkirrdpr
=== efirnffutkirrdpr is now known as georgiag
ahasenackhi #security, is there a preferred way to declare profile transitions, I have this in an MP I'm reviewing:12:57
ahasenack+  /usr/sbin/chronyd Px,12:57
ahasenackthe alternative would be12:57
ahasenack /usr/sbin/chronyd Px -> chrony,12:57
ahasenackfor example12:57
ahasenack(the crony profile declares both the path and the name)12:57
ahasenackoh, wait, my mistake, it only declares the path12:57
ahasenack /usr/sbin/chronyd flags=(attach_disconnected) {12:58
ahasenack...12:58
ahasenack}12:58
ahasenackso I guess /usr/sbin/chronyd Px -> /usr/sbin/chronyd, would look silly12:58
leosilvageorgiag: ^ any idea? 15:44
tewardmdeslaur: did the security tracker get updated for CVEs so it **no longer accepts Package specific searches**?21:53
tewardon ubuntu.com/security i mean21:53
tewardbecause it looks that way so we can no longer easily search for a specific package's CVEs, etc.21:54
tewardat least on the frontend.21:55
tewardalso security team the Security API is **incorrect** and defined enums are missing defaults.  This means your openapi json spec or swagger 2.0 spec is wrong.22:02
mdeslaurteward: hrm, they keep rewriting that...yeah, looks like search by package is gone22:44
mdeslaursarnold: do you remember where we can file a bug for that? ^22:45
tewardmdeslaur: the API still has it so i know its doable.  tell whoever is rewriting the frontend to **stop** until they check with you22:45
tewardalso i have a partially updated openapi 3.0 spec json to replace the swagger 2.0 json thats there and unsupported now.22:45
mdeslauryou want me to speak to the web nerds? eww22:45
tewardmdeslaur: if I do it it comes with the stigma that by them breaking it its now a community level problem :P22:46
mdeslaur:)22:46
tewardjust let them know they need to fix it and worst case I rain Hell on IS :P22:47
tewardalso i know theres a few API mechanisms that are Dangerous in the documentation for the API, I hope they have some security control in place heh.22:47
tewardmaybe i need to talk to these Web Nerds and help them produce an actually usable openapi spec document...  *slapped for suggestion*22:48
tewardmdeslaur: worst case i write a django frontend that uses the API to replicate the searches but ideally Web Team restores what they broke22:49
mdeslaurthere's a bug tracker on github for the website I think, once we get it, you can file all your grievances there :)22:49
tewardheheheh you should warn IS that the demon of an angry sysadmin will be unleashed then xD22:50
mdeslaurpoor github, hoepfully they rate-limit :)22:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!