← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 2081732] Re: oslo_utils.secretutils.constant_time_compare is redundant

 

This was fixed in ceilometer by
https://review.opendev.org/c/openstack/ceilometer/+/931149

** Changed in: ceilometer
       Status: New => Fix Released

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/2081732

Title:
  oslo_utils.secretutils.constant_time_compare is redundant

Status in Ceilometer:
  Fix Released
Status in keystonemiddleware:
  Fix Released
Status in OpenStack Compute (nova):
  In Progress
Status in octavia:
  Fix Released
Status in oslo.utils:
  Fix Released
Status in osprofiler:
  In Progress

Bug description:
  The constant_time_compare function is equivalent to
  hmac.compare_digest in Python 3, because the constant_time_compare
  function has been available since Python 3.3 .

  [1] https://docs.python.org/3/library/hmac.html#hmac.compare_digest

  We can get rid of the redundant wrapper and use the built-in
  implementation instead.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ceilometer/+bug/2081732/+subscriptions