Wednesday, 2015-03-04

*** jkf has joined #openstack-barbican00:08
*** nkinder has joined #openstack-barbican00:09
*** zz_dimtruck is now known as dimtruck00:11
*** igueths has joined #openstack-barbican00:16
*** igueths has quit IRC00:22
*** kgriffs is now known as kgriffs|afk00:23
*** bdpayne has quit IRC00:34
*** alee has joined #openstack-barbican00:37
*** jkf has quit IRC00:43
*** gyee has quit IRC00:51
*** jaosorior has quit IRC01:02
*** gyee has joined #openstack-barbican01:04
*** crc32 has quit IRC01:11
*** dimtruck is now known as zz_dimtruck01:13
*** zz_dimtruck is now known as dimtruck01:42
*** kfox1111 has quit IRC01:42
*** kebray has joined #openstack-barbican01:48
openstackgerritSteve Heyman proposed openstack/barbican: Let functional tests run with older tempest  https://review.openstack.org/16101401:52
*** jamielennox is now known as jamielennox|away01:59
*** dimtruck is now known as zz_dimtruck02:11
openstackgerritSteve Heyman proposed openstack/barbican: Let functional tests run with older tempest  https://review.openstack.org/16101402:17
*** igueths has joined #openstack-barbican02:23
*** zz_dimtruck is now known as dimtruck02:33
*** kebray has quit IRC02:34
*** jamielennox|away is now known as jamielennox02:37
*** jamielennox is now known as jamielennox|away02:52
*** jamielennox|away is now known as jamielennox02:55
*** jamielennox is now known as jamielennox|away02:56
*** SheenaG1 has joined #openstack-barbican02:56
*** jamielennox|away is now known as jamielennox02:57
*** dimtruck is now known as zz_dimtruck03:13
*** SheenaG1 has quit IRC03:23
*** gyee has quit IRC03:29
*** SheenaG1 has joined #openstack-barbican03:30
*** SheenaG1 has quit IRC03:33
*** zz_dimtruck is now known as dimtruck03:52
*** SheenaG1 has joined #openstack-barbican04:15
*** SheenaG1 has quit IRC04:24
*** kgriffs|afk has quit IRC04:28
*** kgriffs|afk has joined #openstack-barbican04:37
*** kgriffs|afk is now known as kgriffs04:37
*** dimtruck is now known as zz_dimtruck04:44
*** openstackgerrit has quit IRC04:46
*** openstackgerrit has joined #openstack-barbican04:52
*** reaperhulk has quit IRC04:54
*** jillysciarilly has quit IRC04:55
*** reaperhulk has joined #openstack-barbican05:04
*** jillysciarilly has joined #openstack-barbican05:04
*** igueths has quit IRC05:27
*** woodster_ has quit IRC05:30
*** jamielennox is now known as jamielennox|away05:32
*** openstack has joined #openstack-barbican05:35
*** kebray has joined #openstack-barbican05:50
*** kebray has quit IRC05:50
*** kebray has joined #openstack-barbican05:53
openstackgerritOpenStack Proposal Bot proposed openstack/barbican: Imported Translations from Transifex  https://review.openstack.org/16110506:07
*** lbragstad has quit IRC06:08
*** lbragstad has joined #openstack-barbican06:10
*** woodster_ has joined #openstack-barbican06:10
*** lbragstad has quit IRC06:19
*** lbragstad has joined #openstack-barbican06:22
*** alee has quit IRC06:54
*** alee has joined #openstack-barbican07:07
*** lbragstad has quit IRC07:08
*** david-lyle_afk has joined #openstack-barbican07:33
*** kebray has quit IRC07:37
*** openstackgerrit has quit IRC07:49
*** openstackgerrit has joined #openstack-barbican07:49
*** chlong has quit IRC08:20
*** woodster_ has quit IRC08:20
-openstackstatus- NOTICE: Zuul check queue stuck due to reboot maintenance window at one of our cloud providers - no need to recheck changes at the moment, they won't move forward.08:29
*** ChanServ changes topic to "Zuul check queue stuck due to reboot maintenance window at one of our cloud providers - no need to recheck changes at the moment, they won't move forward."08:29
*** jaosorior has joined #openstack-barbican09:01
*** openstack has joined #openstack-barbican15:27
*** lisaclark1 has joined #openstack-barbican15:27
*** alee has quit IRC15:33
*** zz_dimtruck is now known as dimtruck15:34
*** jorge_munoz has joined #openstack-barbican15:37
*** igueths has joined #openstack-barbican15:39
openstackgerritEverardo Padilla Saca proposed openstack/barbican: Add missing python requierements for tests  https://review.openstack.org/16127915:51
*** xaeth is now known as xaeth_afk15:56
*** lbragstad has joined #openstack-barbican15:56
openstackgerritMerged openstack/barbican: Let functional tests run with older tempest  https://review.openstack.org/16101416:02
*** xaeth_afk is now known as xaeth16:05
*** rellerreller has quit IRC16:07
*** kfox1111 has joined #openstack-barbican16:22
kfox1111morning.16:22
iguethskfox1111: Morning.16:23
kfox1111Anyone else have a chance to look at the vm integration spec? It would be really nice to have more reviewers before Thursday.16:27
openstackgerritThomas Dinkjian proposed openstack/python-barbicanclient: Adds positive orders functional tests  https://review.openstack.org/15845416:27
*** igueths has quit IRC16:31
*** igueths has joined #openstack-barbican16:34
openstackgerritEverardo Padilla Saca proposed openstack/barbican: Add missing python requirements for tests  https://review.openstack.org/16127916:39
*** igueths has quit IRC16:43
*** kgriffs is now known as kgriffs|afk16:58
*** lisaclark1 has quit IRC16:59
*** lisaclark1 has joined #openstack-barbican17:03
*** atiwari has quit IRC17:03
openstackgerritgreghaynes proposed openstack/barbican: Create snakeoil certificate plugin  https://review.openstack.org/14057517:06
*** kgriffs|afk is now known as kgriffs17:10
-openstackstatus- NOTICE: Issue solved, gate slowly digesting accumulated changes17:14
*** lisaclark1 has quit IRC17:14
openstackgerritMerged openstack/barbican: Imported Translations from Transifex  https://review.openstack.org/16110517:15
openstackgerritMerged openstack/barbican: Fixed Binary Encoding to Secret Stores  https://review.openstack.org/15741017:19
*** rellerreller has joined #openstack-barbican17:25
*** jkf has joined #openstack-barbican17:31
arunkantalee, there?17:32
woodster_hockeynut, is there a functional test that verifies client's can't spoof the X-Project-Id header when Keystone auth is enabled on Barbican?17:34
woodster_tdink, sorry forgot to add you to above ^^^17:35
woodster_hockeynut, tdink, I thought we had a that test in there at one time, but didn't see it in the functional tests17:36
*** kfarr has joined #openstack-barbican17:37
*** gyee has joined #openstack-barbican17:47
*** xaeth is now known as xaeth_afk17:59
*** bdpayne has joined #openstack-barbican18:08
*** lisaclark1 has joined #openstack-barbican18:27
*** kgriffs is now known as kgriffs|afk18:45
*** gyee has quit IRC18:49
*** kgriffs|afk is now known as kgriffs18:55
*** kgriffs is now known as kgriffs|afk18:58
arunkantalee, woodster_, question on per secret ACL 1) How container ACL applies to secrets associated with it? Does secrets associated with that container has same ACL as container ACL? If one of container's secret has ACL defined, then how ACL is dervied for that secret? is it union or what ever ACL that secret has?19:11
arunkant2) Did not find anything in spec, about update of existing ACL on a secret/ container. Is partial ACL update allowed (via PATCH)?19:13
*** ChanServ changes topic to "Barbican Kilo Mid-Cycle Sprint Feb. 16-18, Austin, TX. https://wiki.openstack.org/wiki/Sprints/BarbicanKiloSprint"19:15
*** gyee has joined #openstack-barbican19:19
openstackgerritMerged openstack/castellan: Updating HACKING.rst  https://review.openstack.org/16000919:24
jaosoriorredrobot: ping19:25
*** igueths has joined #openstack-barbican19:47
iguethsHi all.19:47
*** lisaclark1 has quit IRC19:47
*** lisaclark1 has joined #openstack-barbican19:48
*** lisaclark1 has quit IRC19:51
openstackgerritJuan Antonio Osorio Robles proposed openstack/barbican: Support X-Project-Id coming from the request headers  https://review.openstack.org/16137719:51
jaosoriorigueths: hey man19:52
*** rm_mobile has joined #openstack-barbican19:52
iguethsjaosorior: How goes it today?19:53
jaosoriorigueths: aaah, pretty good man, you?19:53
*** kgriffs|afk is now known as kgriffs19:54
iguethsjaosorior: Not too bad, just writing up a unit test and hoping that nothing is going to complain too loudly about indents with dict value assignment and such, although I'm trying to conform to what's already present...Rather a slow process though.19:56
reaperhulkigueths: the tox job (tox -e pep8) will run flake8+hacking against your code to tell if you if it conforms to the style requirements in the gate19:58
*** lisaclark1 has joined #openstack-barbican19:59
*** dave-mccowan has joined #openstack-barbican20:01
iguethsreaperhulk: Good to know...Thanks!20:01
*** igueths has quit IRC20:02
reaperhulkredrobot: the IRC topic somehow got changed back to the old midcycle topic20:02
*** igueths has joined #openstack-barbican20:03
*** lisaclark1 has quit IRC20:05
*** kgriffs is now known as kgriffs|afk20:06
elmikohey barbicaneers, is it possible to use the barbicanclient with a v2 keystone Session object?20:09
elmiko(just trying to make sure i have all the bases covered)20:09
jaosoriorelmiko: yup20:09
elmikohmm20:09
elmikojaosorior: when i try to make a session object like the first example here http://docs.openstack.org/developer/python-keystoneclient/using-sessions.html i get errors when making the barbican client20:10
jaosoriormind pasting the errors?20:10
elmikosure20:11
elmikohmm, maybe i have a pbkac error. let me try one more time20:13
*** igueths has quit IRC20:13
elmikojaosorior: http://paste.openstack.org/show/188061/20:14
elmikotop part is my code, bottom is the error20:14
elmikofyi, if i use the v3 keystone endpoint and uncomment the domains, it works20:15
jaosoriorwell20:15
jaosorioryou use a v3 plugin20:15
jaosoriorwith a v2 endpoint20:15
elmikoi thought that was odd too, but i was following the example from the keystoneclient docs. maybe it's an error20:15
jaosorioridentity.v3.Password(**passwd_kwargs) -> v3 plugin20:16
elmikoyea20:16
jaosorioryeah20:16
jaosoriorlooks weird to me20:16
jaosorior:/ have never tried that20:16
elmikolook at http://docs.openstack.org/developer/python-keystoneclient/using-sessions.html20:16
jaosorioryeah, I saw that documentation you sent20:16
jaosoriorthat's...weird20:16
jaosoriormorgainfainberg: are you around?20:16
elmikoi'll give it a quick try with v220:17
*** kgriffs|afk is now known as kgriffs20:17
*** kgriffs is now known as kgriffs|afk20:17
jaosorioror lbragstad20:17
lbragstado/20:18
jaosoriorlbragstad: hey man, is the documentation OK? seems that there is a v2.0 endpoint being used in a v3 plugin. as mentioned here: http://docs.openstack.org/developer/python-keystoneclient/using-sessions.html and that causes an error that elmiko posted here: http://paste.openstack.org/show/188061/ so... we are a bit confused20:19
elmikoi think it's a bug in the docs, i was able to make a barbicanclient if i use keystoneclient.auth.identity.v2.Password20:20
jaosoriorelmiko: alright20:21
*** lisaclark1 has joined #openstack-barbican20:21
elmikoi'll make a bug report20:22
elmikojaosorior: thanks for the help =)20:22
lbragstadelmiko: jaosorior that does look like the docs are out of date20:22
elmikolbragstad: thanks, i'll post a bug report20:23
lbragstadelmiko: thanks, I'll pass this along to jamielennox|away20:23
jaosoriorlbragstad: thanks man20:24
lbragstadjaosorior: no problem, elmiko feel free to ping me the bug report whenever you have the chance to open it20:24
elmikolbragstad: will do20:25
*** igueths has joined #openstack-barbican20:27
*** lisaclark1 has quit IRC20:28
*** lisaclark1 has joined #openstack-barbican20:29
*** chlong has joined #openstack-barbican20:30
*** kgriffs|afk is now known as kgriffs20:39
*** rellerreller has quit IRC20:39
elmikolbragstad: https://bugs.launchpad.net/python-keystoneclient/+bug/142830920:43
openstackLaunchpad bug 1428309 in python-keystoneclient "[DOC] error on "Using Sessions" page in example code" [Undecided,New]20:43
lbragstadelmiko: thank you sir20:43
elmikolbragstad: glad to help20:44
*** rm_mobile has quit IRC20:44
*** kebray has joined #openstack-barbican20:46
*** kebray has quit IRC20:47
openstackgerritIgor Gueths proposed openstack/barbican: Ensure that external secret refs cannot be added to containers or otherwise.  https://review.openstack.org/16141720:55
*** lisaclark1 has quit IRC20:55
iguethsHere goes take 1...20:56
*** jkf has quit IRC20:58
SheenaG1igueths: I thought you were out until tomorrow?20:59
iguethsSheenaG1: I'm on a bus back to SA.21:01
iguethsSheenaG1: And yeah while that's technically true, I wanted to get this out before I got way too involved with other stuff and ran out of time /again/21:02
SheenaG1igueths: ah okay21:02
*** kgriffs is now known as kgriffs|afk21:03
woodster_igueths, nice, gotta check it out21:06
*** kgriffs|afk is now known as kgriffs21:08
jaosoriorhahaha igueths, I just read the URL that you set up for testing: http://kegeratorsarecool.com21:09
iguethsjaosorior: Lol21:09
iguethsIn other news, nice blog post I'm currently reading about attacks against old crusty export ciphers http://blog.cryptographyengineering.com/2015/03/attack-of-week-freak-or-factoring-nsa.html21:10
jaosoriorigueths: Though I'm not entirely sure what the value for CONF.host_ref is when running the unit tests21:10
jaosoriorigueths: perhaps you should mock the host_ref21:12
iguethsjaosorior: When test calling utils.hostname_for_refs it appears to be whatever is configured as the FQDN.21:12
jaosoriorfor testing purposes21:12
woodster_arunkant, alee, the per secret idea was intended to be simple for Kilo, so no complex logic between secrets and containers21:16
jaosoriorwoodster_, arunkant: still waiting for legal to tell me if I'll be able to help there....21:17
jaosoriorhow much time is there to implement that?21:17
woodster_igueths, you can use 'set_override(key, value)' to override configuration for testing...see line #40 as an example: https://github.com/openstack/barbican/blob/master/barbican/tests/database_utils.py#L4021:19
arunkantwoodster_, Okay..so container ACL does not extend to its associated secrets ? Then container ACL seems of very limited benefit.21:19
woodster_jaosorior do you mean per secret ACL?21:19
jaosoriorwoodster_: yup21:19
woodster_arunkant, that's correct, but we were trying to scope down for Kilo. I'll add this to the Liberty etherpad though21:20
iguethsjaosorior: I'll look into the mocking thing, although for the record following is the current default:21:21
woodster_jaosorior, awesome!21:21
iguethsigueths@holly:~/rackspace/git/openstack-barbican/barbican/common$ python -i validators.py21:21
igueths>>> print CONF.host_href21:21
iguethshttp://localhost:931121:21
iguethswoodster_: Thanks will check it out!21:21
jaosoriorwoodster_: uh... well, I asked legal if I can help with that blueprint, but I still get no reply, that's why I asked, how much time is there to implement that?21:22
arunkantwoodster_, Okay..what about the partial update of ACL . does it need to be supported?21:22
woodster_igueths, were you able to find tooling to let you see the in-line comments folks put in gerrit reviews?21:23
arunkantwoodster_, adding new users in ACL list for a given operation?21:23
woodster_arunkant, alee: I believe we discussed that a complete update of the white list (a true PUT) would be sufficient for Kilo21:25
iguethswoodster_: Haven't gotten a chance to check out the cli stuff yet, although looking at my own CR in the web UI I just might be able to make it work. It's hard to tell because my focus tends to jump all over the place for some reason, although once I'm able to start reading again from top to bottom things are pretty clear at that point.21:26
arunkantwoddster_, okay..did not see in spec ..that was trying to confirm..thanks21:26
woodster_igueths, yeah there is some power javascript foo working on that page. I can't cut/paste into it either which is annoying.21:27
woodster_arunkant, were you thinking of doing working for that spec too?21:27
iguethswoodster_: So what part of my testing were you thinking could benefit from doing the set_override thing?21:27
woodster_igueths, I was thinking you wanted to set the value of host_ref to a specific value21:28
arunkantwoodster_, As discussed with alee last week. Yes I am working on its impl21:28
iguethswoodster_: I don't think so in this instance anyway, at present what I'm trying to do is make sure that the validation method will throw exception.SecretRefValidationErrorException if an secret_ref is found that doesn't match the configured value.21:30
woodster_arunkant, are you also working on the quota support changes?21:40
woodster_igueths, I gave you your first -1...manly tweaking though, so don't fret!21:40
arunkantwoodster, no. Venkat (tsv) is working on it21:40
woodster_igueths, this is like virtual hazing21:41
woodster_arunkant, ha, sorry that's right21:41
woodster_arunkant, too many things going on right now21:42
openstackgerritJohn Vrbanac proposed openstack/barbican: Fixing race-condition for order processing in workers  https://review.openstack.org/16143121:43
iguethswoodster_: Hahaha ok21:43
*** lisaclark1 has joined #openstack-barbican21:44
iguethswoodster_: So if I'm reading your comment correctly just refactor the wording a bit?21:46
woodster_arunkant, jaosorior, good to get traction on the per secret stuff.21:46
woodster_igueths, yeah I'd prefer that...I didn't want folks to think that was a security vulnerabilty. We are really just wanting to do a thorough validation of the input data.21:47
iguethswoodster_: Yeah wasn't trying to get it to read like one.../me will fix that.21:48
woodster_jaosorior are you looking for something juicy to sink your virtual teeth into?21:48
jaosoriorwoodster_: what's up?21:50
*** lisaclark1 has quit IRC21:58
openstackgerritIgor Gueths proposed openstack/barbican: Ensure that external secret refs cannot be added to containers or otherwise.  https://review.openstack.org/16141722:00
*** crc32 has joined #openstack-barbican22:01
*** kgriffs is now known as kgriffs|afk22:06
openstackgerritThomas Dinkjian proposed openstack/python-barbicanclient: First set of negative secrets tests.  https://review.openstack.org/16144222:09
*** kgriffs|afk is now known as kgriffs22:12
*** chlong has quit IRC22:12
*** jamielennox|away is now known as jamielennox22:14
woodster_jaosorior, well, we did have this 'high' bp that no one is working on: https://blueprints.launchpad.net/barbican/+spec/data-remove-tenant-secret-assoc22:16
jaosoriorwoodster_: That sounds like it's refactoring work, so that could actually work out without having to go through the whole process22:17
iguethsHm doesn't seem possible to stream Gerrit comments to a terminal...22:18
woodster_jaosorior, yep. It would require an alembic file to though :)22:19
woodster_igueths, so are you able to resolve any of those comments individually at least?22:19
jaosoriorwoodster_: Usually that stuff is just fine22:20
jaosoriorwoodster_: Is there a deadline I should take into account?22:20
woodster_redrobot, would it be ok for jaosorior to get this ^^^ done by the Kilo release?22:23
openstackgerritThomas Dinkjian proposed openstack/python-barbicanclient: First set of negative secrets tests.  https://review.openstack.org/16144222:24
iguethswoodster_: I'm still trying to get to where I can see them.22:25
*** dimtruck is now known as zz_dimtruck22:26
woodster_igueths, so this view is a flat list of comments per line of code, but that is annoying to go back and forth to code to see the lines affected22:27
woodster_jaosorior, maybe take a look at the blueprint and see if it is somthing you could finish in the time remaining for Kilo?22:28
jaosoriorwoodster_: how much time was there?22:29
woodster_igueths, you might also try to change the 'diff view'...go to 'settings' and then 'preferences'.22:29
iguethswoodster_: Ah ok...I'll play around with that and see what I can get.22:29
woodster_jaosorior, well the feature freeze is the 19th...would that be too little time?22:30
jaosoriorwoodster_: yeah... specially cause I'll be on vacations next week22:31
jaosoriorOn Friday I fly to Madrid22:32
woodster_jaosorior, yeah I'm out next week as well22:33
woodster_jaosorior, so that leaves you with a couple of days though :)22:33
jaosoriorOf nobody have it by then. Then it could happen22:34
woodster_jaosorior, one approach is to put up a CR that does the refactor work only (no alembic). Then someone else could make a dependent CR to that one that does the alembic stuff?22:34
woodster_igueths, I tried to copy/paste that page into a gist, but it strips out the comments22:36
iguethsWell shit.22:36
jaosoriorWould also be nice if pepper could review this today https://review.openstack.org/#/c/157068/ that way I could do the client and documentation CRs tomorrow22:37
iguethsGoing to play around with the keyboard shortcuts...Maybe there's something there I can use.22:37
woodster_igueths, so that unified view didn't help?22:38
jaosoriorAnd thus, finish that blueprint22:38
iguethswoodster_: I haven't tried that yet.22:38
woodster_igueths, you can also change your view to an 'old view'...might strip off some of the fancy that is mucking up your reader?22:40
iguethswoodster_: Possibly.22:41
woodster_igueths: check out https://gist.github.com/jfwood/fdafc883fecdc599cbe022:47
woodster_igueths...so that is what we see on the diff page (i added square brackets and user names for the comments). Comments are usually referring to the lines right above them.22:48
woodster_hockeynut, tdink are you there?22:50
*** jkf has joined #openstack-barbican22:53
jaosoriorPeople, not pepper22:54
woodster_reaperhulk, redrobot, can you review this CR?: https://review.openstack.org/#/c/157068/22:55
woodster_jvrbanac: ^^^?22:55
*** crc32 has quit IRC22:55
*** paul_glass has quit IRC23:00
*** SheenaG1 has quit IRC23:04
openstackgerritDouglas Mendizábal proposed openstack/python-barbicanclient: WIP: Fix devstack gate  https://review.openstack.org/16146623:09
openstackgerritIgor Gueths proposed openstack/barbican: Ensure that external secret refs cannot be added to containers or otherwise.  https://review.openstack.org/16141723:15
elmikois there a known issue with using barbicanclient.client.Client.secrets.list ?23:30
*** crc32 has joined #openstack-barbican23:33
elmikonvm, pbkac23:35
openstackgerritMerged openstack/barbican: Enable secret decrypt through 'payload' resource  https://review.openstack.org/15706823:39
*** chlong has joined #openstack-barbican23:42
openstackgerritJohn Vrbanac proposed openstack/barbican: Creating indexes for foreign keys  https://review.openstack.org/16148123:43
*** chlong has quit IRC23:46
*** chlong has joined #openstack-barbican23:46
reaperhulk^-- this is important and people should review it (it's a pretty easy review)23:47

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!