yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #94887
[Bug 2081732] Re: oslo_utils.secretutils.constant_time_compare is redundant
This was fixed in ceilometer by
https://review.opendev.org/c/openstack/ceilometer/+/931149
** Changed in: ceilometer
Status: New => Fix Released
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/2081732
Title:
oslo_utils.secretutils.constant_time_compare is redundant
Status in Ceilometer:
Fix Released
Status in keystonemiddleware:
Fix Released
Status in OpenStack Compute (nova):
In Progress
Status in octavia:
Fix Released
Status in oslo.utils:
Fix Released
Status in osprofiler:
In Progress
Bug description:
The constant_time_compare function is equivalent to
hmac.compare_digest in Python 3, because the constant_time_compare
function has been available since Python 3.3 .
[1] https://docs.python.org/3/library/hmac.html#hmac.compare_digest
We can get rid of the redundant wrapper and use the built-in
implementation instead.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ceilometer/+bug/2081732/+subscriptions