*** dimtruck is now known as zz_dimtruck | 00:01 | |
*** kgriffs|afk is now known as kgriffs | 00:07 | |
*** crc32 has quit IRC | 00:30 | |
*** david-lyle is now known as david-lyle_afk | 00:31 | |
*** zz_dimtruck is now known as dimtruck | 00:37 | |
*** kebray has quit IRC | 00:41 | |
*** jkf has quit IRC | 00:48 | |
*** arunkant_work has quit IRC | 00:50 | |
*** bdpayne has quit IRC | 00:52 | |
*** elmiko has quit IRC | 00:55 | |
*** jaosorior has quit IRC | 01:14 | |
*** ayoung has joined #openstack-barbican | 01:41 | |
*** ayoung has quit IRC | 01:46 | |
*** lisaclark1 has joined #openstack-barbican | 01:49 | |
*** ayoung has joined #openstack-barbican | 02:01 | |
*** kgriffs is now known as kgriffs|afk | 02:12 | |
*** dimtruck is now known as zz_dimtruck | 02:23 | |
*** kgriffs|afk is now known as kgriffs | 03:16 | |
*** kgriffs is now known as kgriffs|afk | 03:25 | |
*** bdpayne has joined #openstack-barbican | 03:28 | |
*** bdpayne has quit IRC | 03:30 | |
*** kebray has joined #openstack-barbican | 04:11 | |
*** woodster_ has quit IRC | 04:13 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Add code to generate a CSR in the stored key case https://review.openstack.org/150670 | 04:34 |
---|---|---|
*** kebray has quit IRC | 04:44 | |
*** zz_dimtruck is now known as dimtruck | 05:07 | |
*** Nirupama has joined #openstack-barbican | 05:20 | |
*** lisaclark1 has quit IRC | 05:20 | |
*** woodster_ has joined #openstack-barbican | 05:32 | |
*** dimtruck is now known as zz_dimtruck | 05:53 | |
*** jaosorior has joined #openstack-barbican | 05:56 | |
*** woodster_ has quit IRC | 07:53 | |
*** chlong has quit IRC | 08:08 | |
*** ajc_ has joined #openstack-barbican | 09:18 | |
*** jamielennox is now known as jamielennox|away | 10:36 | |
*** chlong has joined #openstack-barbican | 10:43 | |
*** jamielennox|away is now known as jamielennox | 10:44 | |
*** jamielennox is now known as jamielennox|away | 10:56 | |
*** ajc_ has quit IRC | 10:58 | |
*** jaosorior has quit IRC | 11:06 | |
*** jaosorior has joined #openstack-barbican | 11:06 | |
*** woodster_ has joined #openstack-barbican | 12:44 | |
*** darrenmoffat has quit IRC | 13:46 | |
*** darrenmoffat has joined #openstack-barbican | 13:46 | |
*** Nirupama has quit IRC | 13:53 | |
*** openstackstatus has joined #openstack-barbican | 14:20 | |
*** ChanServ sets mode: +v openstackstatus | 14:20 | |
-openstackstatus- NOTICE: zuul isn't running jobs since ~10:30 utc, investigation underway | 14:23 | |
*** ChanServ changes topic to "zuul isn't running jobs since ~10:30 utc, investigation underway" | 14:23 | |
*** miqui_ has joined #openstack-barbican | 14:39 | |
*** rellerreller has joined #openstack-barbican | 14:47 | |
*** kfarr has joined #openstack-barbican | 15:00 | |
*** kfarr has quit IRC | 15:01 | |
*** kfarr has joined #openstack-barbican | 15:02 | |
*** kfarr has quit IRC | 15:03 | |
*** ametts has joined #openstack-barbican | 15:04 | |
*** kfarr has joined #openstack-barbican | 15:04 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Renamed outputted keys from base model https://review.openstack.org/151668 | 15:25 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Trivial refactors to secret controller https://review.openstack.org/151670 | 15:27 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Delete comments that are no longer valid https://review.openstack.org/151672 | 15:29 |
*** zz_dimtruck is now known as dimtruck | 15:30 | |
*** paul_glass has joined #openstack-barbican | 15:31 | |
*** lisaclark1 has joined #openstack-barbican | 15:33 | |
*** lisaclark1 has quit IRC | 15:34 | |
*** lisaclark1 has joined #openstack-barbican | 15:34 | |
openstackgerrit | Nathan Reller proposed openstack/barbican-specs: Content Types https://review.openstack.org/145073 | 15:38 |
*** lisaclark1 has quit IRC | 15:40 | |
*** lisaclark1 has joined #openstack-barbican | 15:41 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Initial directory changes and files for python-babricanclient functional tests https://review.openstack.org/151409 | 15:53 |
openstackgerrit | Merged openstack/barbican: Handle SystemExit properly in migration script https://review.openstack.org/150756 | 16:07 |
*** kebray has joined #openstack-barbican | 16:10 | |
*** ChanServ changes topic to "Barbican Kilo Mid-Cycle Sprint Feb. 16-18, Austin, TX. https://wiki.openstack.org/wiki/Sprints/BarbicanKiloSprint" | 16:11 | |
-openstackstatus- NOTICE: zuul is running again and changes have been reenqueud. seehttp://status.openstack.org/zuul/ before rechecking if in doubt | 16:11 | |
*** lisaclark1 has quit IRC | 16:14 | |
jaosorior | alee: Thanks for the +2 mr. :D | 16:15 |
alee | jaosorior, yer welcome. Ditto for you. | 16:15 |
alee | jaosorior, I got three more out there waiting for a +2 .. nudge, nudge, say no more .. | 16:16 |
*** lisaclark1 has joined #openstack-barbican | 16:17 | |
jaosorior | Hahaha I saw. But those me longer to review since I have to do some research about them. Trying my best to get them as fast as possible though | 16:17 |
*** SheenaG1 has joined #openstack-barbican | 16:18 | |
*** kebray has quit IRC | 16:19 | |
*** david-lyle_afk is now known as david-lyle | 16:19 | |
*** kebray has joined #openstack-barbican | 16:20 | |
jaosorior | * those take me longer to review | 16:20 |
alee | jaosorior, understood -- some are a little bigger too | 16:22 |
*** crc32 has joined #openstack-barbican | 16:31 | |
rm_work | alee: remember the logic you pasted for checking access to a shared secret yesterday? | 16:38 |
rm_work | it was like... | 16:38 |
rm_work | what the "if" would look like | 16:39 |
rm_work | to check all the conditions | 16:39 |
rm_work | I can't find it in my scrollback | 16:39 |
alee | rm_work, I'm writing that up now -- let me reformulate it .. | 16:40 |
*** kgriffs|afk is now known as kgriffs | 16:42 | |
rm_work | ok, I was going to post it in a comment on the change but I am guessing you are just writing up the new changeset so I'll just reference it | 16:44 |
alee | rm_work, if (can_read_shared and (user_in_whitelist or group_in_whitelist or project_in_whitelist) or ((project==creator_project and not creator_only) or user==creator)) | 16:45 |
alee | I think this works .. | 16:45 |
rm_work | I think you're missing a parens | 16:45 |
rm_work | or something | 16:45 |
alee | rm_work, if (can_read_shared and (user_in_whitelist or group_in_whitelist or project_in_whitelist)) or ((project==creator_project and not creator_only) or user==creator) | 16:46 |
alee | yup | 16:46 |
rm_work | :P | 16:46 |
rm_work | yep | 16:46 |
rm_work | i stole that and put it in my comment with your name on it :) | 16:47 |
alee | :) | 16:47 |
alee | rm_work, I'm thinking of breaking it up into two specs | 16:47 |
alee | just to make things clearer | 16:48 |
rm_work | yeah might be best | 16:49 |
rm_work | though we'd also like to get this merged ASAP | 16:49 |
alee | defintiely -- I'm hope to have a new version out today | 16:50 |
alee | (for both specs) | 16:50 |
woodster_ | alee, rellerreller, can you guys add commit 'flags' to your blueprint commit messages, per this link?: https://wiki.openstack.org/wiki/GitCommitMessages (in the 'including external references' section) | 16:55 |
woodster_ | alee, rellerreller, so this is an example: https://review.openstack.org/#/c/125798/ | 16:55 |
*** lisaclark1 has quit IRC | 16:55 | |
woodster_ | alee, rellereller, these flag aid in searching for blueprints, esp. by the doc, api and security working group teams | 16:56 |
*** woodster_ has quit IRC | 16:56 | |
*** woodster_ has joined #openstack-barbican | 16:56 | |
*** lisaclark1 has joined #openstack-barbican | 17:00 | |
*** lisaclark1 has quit IRC | 17:01 | |
*** lisaclark1 has joined #openstack-barbican | 17:03 | |
*** kebray has quit IRC | 17:05 | |
*** gyee has joined #openstack-barbican | 17:11 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Initial directory changes and files for python-babricanclient functional tests https://review.openstack.org/151409 | 17:18 |
*** lisaclark1 has quit IRC | 17:28 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Initial directory changes and files for python-babricanclient functional tests https://review.openstack.org/151409 | 17:32 |
*** lisaclark1 has joined #openstack-barbican | 17:37 | |
*** rellerreller has quit IRC | 17:40 | |
*** bdpayne has joined #openstack-barbican | 17:40 | |
*** rellerreller has joined #openstack-barbican | 17:53 | |
*** crc32 has quit IRC | 18:02 | |
*** crc32 has joined #openstack-barbican | 18:08 | |
*** mjg59 has quit IRC | 18:09 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Initial directory changes and files for python-babricanclient functional tests https://review.openstack.org/151409 | 18:11 |
*** mjg59 has joined #openstack-barbican | 18:13 | |
*** lisaclark1 has quit IRC | 18:14 | |
*** crc32 has quit IRC | 18:23 | |
*** lisaclark1 has joined #openstack-barbican | 18:27 | |
*** dimtruck is now known as zz_dimtruck | 18:28 | |
openstackgerrit | Nathan Reller proposed openstack/barbican-specs: Content Types https://review.openstack.org/145073 | 18:40 |
rellerreller | woodster_ thank for the link. I updated the content types CR commit message. | 18:41 |
-openstackstatus- NOTICE: Gerrit and Zuul will be offline from 1900 to 1930 UTC for project renames | 18:42 | |
*** lisaclark1 has quit IRC | 18:50 | |
*** lisaclark1 has joined #openstack-barbican | 18:50 | |
*** lisaclark1 has quit IRC | 18:56 | |
*** lisaclark1 has joined #openstack-barbican | 18:59 | |
*** lisaclark1 has joined #openstack-barbican | 18:59 | |
*** lisaclark1 has quit IRC | 19:01 | |
*** SheenaG11 has joined #openstack-barbican | 19:01 | |
*** SheenaG1 has quit IRC | 19:03 | |
*** lisaclark1 has joined #openstack-barbican | 19:04 | |
*** jaosorior has quit IRC | 19:06 | |
-openstackstatus- NOTICE: Gerrit and Zuul are offline until 1930 UTC for project renames | 19:06 | |
*** ChanServ changes topic to "Gerrit and Zuul are offline until 1930 UTC for project renames" | 19:06 | |
*** jkf has joined #openstack-barbican | 19:09 | |
*** lisaclark1 has quit IRC | 19:11 | |
*** lisaclark1 has joined #openstack-barbican | 19:16 | |
chellygel | going to run and grab lunch! i'll be on google hangouts! | 19:24 |
*** ChanServ changes topic to "Barbican Kilo Mid-Cycle Sprint Feb. 16-18, Austin, TX. https://wiki.openstack.org/wiki/Sprints/BarbicanKiloSprint" | 19:28 | |
-openstackstatus- NOTICE: Gerrit is back online | 19:29 | |
*** SheenaG11 has quit IRC | 19:31 | |
rellerreller | alee Can you please review my updated content types spec? I think it is good now. I only changed the commit message since the last review. | 19:49 |
alee | rellerreller, looking | 19:49 |
rellerreller | alee Thanks! | 19:49 |
alee | rellerreller, done | 19:52 |
rellerreller | alee Thanks and have a good weekend. | 19:55 |
alee | rellerreller, you too -- #gopats ! | 19:55 |
*** rellerreller has quit IRC | 19:55 | |
*** openstackgerrit has quit IRC | 20:06 | |
*** openstackgerrit has joined #openstack-barbican | 20:07 | |
*** david-lyle has quit IRC | 20:25 | |
*** crc32 has joined #openstack-barbican | 20:38 | |
*** SheenaG1 has joined #openstack-barbican | 20:41 | |
*** zz_dimtruck is now known as dimtruck | 20:46 | |
*** lisaclark1 has quit IRC | 20:57 | |
*** lisaclark1 has joined #openstack-barbican | 21:04 | |
*** kebray has joined #openstack-barbican | 21:12 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 21:12 |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 21:27 |
*** lisaclark1 has quit IRC | 21:28 | |
*** chellygelz has joined #openstack-barbican | 21:33 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 21:37 |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: All of the containers behaviors and container smoke tests https://review.openstack.org/151787 | 21:42 |
*** kebray has quit IRC | 21:43 | |
*** kebray has joined #openstack-barbican | 21:44 | |
openstackgerrit | Ade Lee proposed openstack/barbican-specs: Add spec for per-secret policy https://review.openstack.org/127353 | 22:07 |
*** miqui_ is now known as miqui_away | 22:07 | |
alee | rm_work, woodster_ ^^ | 22:07 |
rm_work | woo | 22:08 |
alee | some late friday afternoon easy reading | 22:08 |
*** crc32 has quit IRC | 22:09 | |
redrobot | alee I would like to get morganfainberg and maybe some other Keystone eyes on that BP | 22:14 |
* morganfainberg tries hard to pretend to be not lurking, "is it working? :P" | 22:15 | |
redrobot | morganfainberg hehe... on a Friday afternoon even... I just want to make sure we're not going off the deep end. :) | 22:16 |
*** morganfainberg is now known as NotLurkingHere | 22:17 | |
NotLurkingHere | >.> | 22:18 |
rm_work | wow that's a hell of a rewrite alee | 22:18 |
rm_work | +106/-131 | 22:18 |
NotLurkingHere | phew | 22:19 |
NotLurkingHere | spec review :( never easy on friday | 22:19 |
*** NotLurkingHere is now known as morganfainberg | 22:19 | |
*** crc32 has joined #openstack-barbican | 22:20 | |
rm_work | alee: I like that you had to specify what "secret creator" is ("the user that created the secrets") | 22:20 |
morganfainberg | added some comments/questions into that spec | 22:35 |
rm_work | about to submit mine too | 22:35 |
*** SheenaG1 has quit IRC | 22:38 | |
rm_work | alee: posted | 22:42 |
*** morganfainberg is now known as outforteaorcoffe | 22:47 | |
rm_work | OMFG https://review.openstack.org/#/c/125798/ someone workflow this for the love of all that is holy | 22:50 |
rm_work | redrobot: ^^ | 22:50 |
*** kgriffs is now known as kgriffs|afk | 22:56 | |
woodster_ | rm_work, no can doo, sorry | 23:05 |
rm_work | woodster_: T_T_T_T | 23:05 |
woodster_ | rm_work, clung gave me heck for approving my own CR in the early days of the project, stuck with me ever since :) | 23:07 |
rm_work | woodster_: hehe alright, but you can bug redrobot :P | 23:08 |
rm_work | or someone else | 23:08 |
woodster_ | rm_work this place is clearing out fast after 5pm... | 23:09 |
rm_work | T_T | 23:09 |
woodster_ | two bps in one CR?? Oh noooo who did that happen? | 23:10 |
woodster_ | how that is | 23:10 |
woodster_ | alee, ^^^ | 23:10 |
*** dimtruck is now known as zz_dimtruck | 23:15 | |
*** chellygelz has quit IRC | 23:15 | |
reaperhulk | about to drop a big CR, sorry :p | 23:20 |
woodster_ | on a Friday > 5pm?? :) | 23:21 |
reaperhulk | yep | 23:22 |
reaperhulk | git diff --stat HEAD~ | 23:22 |
reaperhulk | 2 files changed, 578 insertions(+), 313 deletions(-) | 23:22 |
reaperhulk | >:( | 23:22 |
reaperhulk | (I would make that smaller if I possibly could) | 23:22 |
reaperhulk | but "wholesale swap the entire way we do things" is not an incremental model | 23:22 |
openstackgerrit | Paul Kehrer proposed openstack/barbican: Completely refactor PKCS11 plugin https://review.openstack.org/151817 | 23:23 |
*** kebray has quit IRC | 23:27 | |
*** kfarr has quit IRC | 23:30 | |
woodster_ | rm_work, can you look at my comments on https://review.openstack.org/#/c/127353? | 23:31 |
woodster_ | reaperhulk, well if it works and fixes that nasty issue you were fighting, I'll take it as is :) | 23:32 |
reaperhulk | woodster_: it does fix that, but still worth reviewing to the extent possible | 23:32 |
reaperhulk | jvrbanac has a good idea so I'm going to do that quickly | 23:33 |
rm_work | woodster_: it says 3 comments but i can only find one <_< | 23:33 |
rm_work | oh nm i found the other two | 23:33 |
*** ametts has quit IRC | 23:34 | |
openstackgerrit | Paul Kehrer proposed openstack/barbican: Completely refactor PKCS11 plugin https://review.openstack.org/151817 | 23:36 |
woodster_ | rm_work, I don't think the private secret thing has to be complicated | 23:36 |
*** kebray has joined #openstack-barbican | 23:36 | |
rm_work | I feel like your method is MORE complicated tho <_< | 23:38 |
woodster_ | rm_work really? I'm using the same whitelist mechanism already proposed, just changing the policy equation | 23:38 |
rm_work | hmm | 23:40 |
woodster_ | rm_work we would just pass in a boolean to the policy engine such as is_whitelist_specified or some such, so we should be able to bypass those other whitelist operations and default to the current policy behavior as needed | 23:40 |
rm_work | well, i need to reread maybe | 23:40 |
rm_work | my brain is a little shot right now | 23:40 |
woodster_ | frieday? | 23:41 |
woodster_ | reaperhulk, how many of those constants are pkcs11 generic, and how many are vendor specific? | 23:41 |
woodster_ | reaperhulk, maybe only this one :) VENDOR_SAFENET_CKM_AES_GCM = 0x8000011c | 23:42 |
reaperhulk | woodster_: that is the only vendor specific constant, correct | 23:47 |
*** paul_glass has quit IRC | 23:47 | |
rm_work | woodster_: i'll look on Monday. Also, the neutron-lbaas midcycle hackathon/meetup is at RAX all of next week, FYI | 23:49 |
rm_work | so I'll mostly be doing that | 23:49 |
woodster_ | rm_work, ok that sounds good | 23:52 |
woodster_ | reaperhulk, and you added a TODO to parameterize that later, so +2! | 23:53 |
reaperhulk | yeah there are some fun challenges around that or else I would have done that as part of this refactor | 23:53 |
woodster_ | reaperhulk, there always are. The TODO-er can cross those bridges I suppose :) | 23:54 |
woodster_ | have a good weekend folks! | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!