New issue
Advanced search Search tips

Issue 836167 link

Starred by 3 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: ----



Sign in to add a comment

luci-notify/gatekeeper should have an option to not send emails to CL authors

Project Member Reported by serg...@chromium.org, Apr 24 2018

Issue description

V8 runs internal builders on public CLs. This creates a potential risk of exposing internal builder names by sending gatekeeper alerts to external authors unless 'forgiving_optional' is used consistent across all gatekeeper configs. This is somewhat non-obvious and based on logic deep in the gatekeeper implementation: https://cs.chromium.org/chromium/build/scripts/slave/gatekeeper_ng.py?l=685&rcl=fbb9984bd65e325235a5d9b5f41fe7e20556ae39.

To add another layer of protection from mistakes when changing gatekeeper configs or the referenced logic, we should add another explicit per-master setting to not send alerts to authors. Even better if we can teach gatekeeper to use luci-config and pull access information from there, although this is probably going to happen in luci-notify.

See comments on https://crrev.com/i/610587 for context.
 
Labels: -Restrict-View-Google
Cc: cbruni@chromium.org serg...@chromium.org machenb...@chromium.org
Issue v8:7798 has been merged into this issue.
Status: Available (was: Untriaged)

Sign in to add a comment