*** phuongnh has joined #openstack-barbican | 01:04 | |
*** pcaruana has joined #openstack-barbican | 06:43 | |
*** ducnv has quit IRC | 06:56 | |
*** velizarx has joined #openstack-barbican | 07:05 | |
*** jaosorior has quit IRC | 07:15 | |
*** velizarx has quit IRC | 07:43 | |
*** velizarx has joined #openstack-barbican | 07:50 | |
*** salmankhan has joined #openstack-barbican | 09:09 | |
*** pbourke has quit IRC | 09:16 | |
*** pbourke has joined #openstack-barbican | 09:18 | |
*** jaosorior has joined #openstack-barbican | 09:48 | |
*** phuongnh has quit IRC | 10:04 | |
*** serlex has joined #openstack-barbican | 10:25 | |
*** dave-mccowan has joined #openstack-barbican | 10:55 | |
*** dave-mccowan has quit IRC | 11:00 | |
*** dave-mccowan has joined #openstack-barbican | 11:02 | |
*** jaosorior has quit IRC | 12:03 | |
*** vikram_darsi_ has joined #openstack-barbican | 12:12 | |
vikram_darsi_ | Hi Team | 12:13 |
---|---|---|
vikram_darsi_ | Any pointers on how to resolve this issue | 12:13 |
vikram_darsi_ | "ERROR barbicanclient.client [req-b3f2042b-608c-442b-a30b-6bc84b1dc143 admin admin] 4xx Client error: Not Found: Not Found. Sorry but your secret is in another castle." | 12:14 |
*** abishop has joined #openstack-barbican | 12:35 | |
*** raildo has joined #openstack-barbican | 12:39 | |
redrobot | Man, some of our PKCS#11 tests are really terrible. | 12:59 |
*** velizarx has quit IRC | 13:19 | |
*** velizarx has joined #openstack-barbican | 13:21 | |
*** ade_lee has joined #openstack-barbican | 13:23 | |
ade_lee | redrobot, dave-mccowan ping -- rc1 day | 13:31 |
redrobot | 😳😳😳 | 13:31 |
ade_lee | redrobot, dave-mccowan still waiting on second +2 for https://review.openstack.org/#/c/575800/ | 13:33 |
redrobot | is it release day for castellan also? | 13:33 |
redrobot | I thought the libs were due a while back? | 13:33 |
ade_lee | redrobot, thats past -- I'll need to get a feature freeze exception | 13:34 |
redrobot | gotcha | 13:34 |
ade_lee | (been trying to push this change for awhile now) | 13:34 |
redrobot | ade_lee, ack, looking now... give me a sec to refresh my mind on cryptography.io rsa | 13:51 |
ade_lee | redrobot, dave-mccowan -- also need feedback on https://review.openstack.org/#/c/588104 | 14:14 |
dave-mccowan | are you going for a FFE for the client? | 14:28 |
dave-mccowan | .. in addition to castellan | 14:29 |
redrobot | ade_lee, merged the Castellan change. RE: Validation, I think that in general, it's better to re-wrap exceptions though. | 14:34 |
ade_lee | redrobot, we can do that in stein when we add the vault gate | 14:34 |
*** serlex has quit IRC | 14:35 | |
ade_lee | dave-mccowan, I think so | 14:35 |
ade_lee | dave-mccowan, redrobot whats the process for getting a FFE? | 14:35 |
redrobot | I'll take a look at that barbicanclient change later today after I finish updating my patch. | 14:35 |
redrobot | ade_lee, eeeeh... it's been a while since I've had to do that. I think email the ML? | 14:35 |
ade_lee | redrobot, if you dont mind, please look at the client change first - in case I need to do some hoops to get a FFE | 14:36 |
redrobot | ade_lee, ack... I'll bump it up then. | 14:36 |
ade_lee | dave-mccowan, please look too. the client change changes behavior - so I want to be sure to get input from multiple sources | 14:37 |
ade_lee | dave-mccowan, do you know if there is a process other than emailing ML for FFE? | 14:38 |
*** velizarx has quit IRC | 14:39 | |
*** salmankhan has quit IRC | 14:43 | |
*** salmankhan has joined #openstack-barbican | 14:49 | |
ade_lee | dave-mccowan, redrobot so -- maybe we push for FFE for the castellan change , but wait for the barbican-client one? | 14:52 |
ade_lee | as the barbican-client one is a bug fix, we can always backport to rocky later once requirements repo is opened up again | 14:53 |
ade_lee | rm_work, will that work for you guys? | 14:53 |
*** vikram_darsi_ has quit IRC | 15:19 | |
ade_lee | dave-mccowan, redrobot ping | 16:35 |
ade_lee | dave-mccowan, redrobot let me know when ya'll are back -- gotta talk rc1 | 16:49 |
*** rmcall has quit IRC | 16:50 | |
* ade_lee getting lunch | 16:55 | |
*** salmankhan has quit IRC | 16:58 | |
redrobot | ade_lee, what's up? | 17:11 |
redrobot | eh, just missed you... | 17:16 |
ade_lee | redrobot, dave-mccowan so I put up the email for the FFE for castellan | 17:47 |
redrobot | ade_lee, need +1s? | 17:48 |
ade_lee | redrobot, dave-mccowan not going to do the same for the barbican-client change | 17:48 |
ade_lee | redrobot, well - actually, right now , we need to figure out why its not merging .. | 17:48 |
ade_lee | is. passing gate | 17:48 |
ade_lee | so need some help with that .. | 17:49 |
ade_lee | redrobot, for barbican rc1, I think the only change I'm really looking to get in is your change for thales | 17:49 |
ade_lee | redrobot, if we can get it merged early next week, then I'll wait till then to cut rc1. otherwise, we'll have to plan to have rc2 | 17:50 |
ade_lee | and cut rc1 today | 17:50 |
redrobot | ade_lee, ack, I just have to clean up some pep8 errors and I'll get the non-WIP patch up | 17:50 |
ade_lee | redrobot, ok - I'll review as soon as you get it up | 17:51 |
ade_lee | redrobot, in the meantime though, any idea whats going on for castellan patch? | 17:51 |
ade_lee | redrobot, dave-mccowan -- http://logs.openstack.org/00/575800/3/gate/castellan-functional-devstack/3168702/controller/logs/screen-barbican-svc.txt.gz#_Aug_10_16_23_10_113768 | 17:54 |
dave-mccowan | \o | 17:54 |
redrobot | ade_lee, weird... maybe a race condition where two secret stores in parallel are both successfully creating a kek ? | 17:55 |
ade_lee | redrobot, yeah - I dont know .. trying one more recheck .. | 17:57 |
ade_lee | dave-mccowan, so just to re-iterate above | 17:58 |
ade_lee | dave-mccowan, for rc1, I'm basically waiting for redrobot fix for thales | 17:58 |
ade_lee | dave-mccowan, once that is in - I will cut rc1 | 17:58 |
ade_lee | (rather than cutting today and re-cut next week for rc2) | 17:59 |
ade_lee | dave-mccowan, also -- if you can help figure out whats fgoing on in castellan patch not merging that would be great .. | 17:59 |
ade_lee | gonna try one more recheck -- but I'm a little at a loss .. | 18:02 |
dave-mccowan | i remember having that problem with find_or_create() before, with other objects. | 18:03 |
ade_lee | dave-mccowan, oh? what was the issue/fix? | 18:04 |
dave-mccowan | ade_lee maybe this fix https://review.openstack.org/#/c/515339/ | 18:07 |
dave-mccowan | lol... no wonder it looks familiar: https://bugs.launchpad.net/barbican/+bug/1726378 | 18:08 |
openstack | Launchpad bug 1726378 in Barbican "MultipleResultsFound error in _find_or_create_kek_objects()" [High,Triaged] | 18:08 |
dave-mccowan | ade_lee at least we know it's nothing new | 18:09 |
ade_lee | dave-mccowan, um yeah -- | 18:10 |
ade_lee | so how did we get around it? | 18:10 |
*** raildo_ has joined #openstack-barbican | 18:10 | |
ade_lee | coz its rearing its ugly head again? | 18:11 |
dave-mccowan | i think all the timing bugs come out during release week. probably the timing changes when zuul is under higher load. (or gremlins) | 18:12 |
*** raildo has quit IRC | 18:14 | |
ade_lee | dave-mccowan, so recheck till it works? | 18:14 |
dave-mccowan | with fingers crossed | 18:14 |
ade_lee | ugh .. I guess the fix is to put some sort of lock there .. | 18:20 |
dave-mccowan | yea, i'd think the whole point of a create_or_get() function would be to make it atomic. | 18:21 |
openstackgerrit | Doug Hellmann proposed openstack/castellan master: add python 3.6 unit test job https://review.openstack.org/589587 | 18:34 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican master: Refactor PKCS#11 to allow configurable mechanisms https://review.openstack.org/590042 | 19:16 |
redrobot | ade_lee, dave-mccowan ^^ | 19:17 |
*** pcaruana has quit IRC | 19:19 | |
ade_lee | redrobot, ack -- looking | 19:26 |
ade_lee | redrobot, ping | 19:28 |
ade_lee | redrobot, so -- with the sensitive/not-sensitive change - you no longer needed that special directive for thales hsm? | 19:29 |
ade_lee | redrobot, do you recall if changing this would break safenet? | 19:29 |
redrobot | ade_lee, that's correct, we shouldn't need to override the Thales sanity check | 19:37 |
redrobot | ade_lee, as far as I can tell it shouldn't break anything. | 19:37 |
redrobot | there's a few attributes on the keks that barbican could read now instead of just being able to extract the key, but I don't think it matters | 19:38 |
ade_lee | redrobot, ok | 19:39 |
ade_lee | redrobot, you tested all this presumably against thales? | 19:40 |
ade_lee | redrobot, made one comment .. | 19:41 |
redrobot | ade_lee, yep, well, patch 1 | 19:41 |
redrobot | ade_lee, ah yes, good catch, let me fix that real quick | 19:41 |
ade_lee | redrobot, well -- I pointed out something that might have ended up breaking up -- so maybe we should test patch 2 | 19:42 |
ade_lee | (or 3) in this case .. | 19:42 |
ade_lee | does passing an extra non-defined param result in a runtime exception? | 19:43 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican master: Refactor PKCS#11 to allow configurable mechanisms https://review.openstack.org/590042 | 19:43 |
redrobot | ade_lee, yeah | 19:43 |
ade_lee | redrobot, I'll +2 once you confirm that it all works against thales .. | 19:44 |
ade_lee | (including barbican-manage :)) | 19:44 |
redrobot | ade_lee, for sure. I have to run to the vet with my cat right now, but i'll be back before too long. | 19:46 |
ade_lee | redrobot, ok- just update on patch and/or irc | 19:46 |
ade_lee | dave-mccowan, please review | 19:47 |
ade_lee | we might even get this tagged today :/ | 19:47 |
*** ade_lee has quit IRC | 20:25 | |
*** raildo_ has quit IRC | 20:41 | |
*** abishop has quit IRC | 20:47 | |
openstackgerrit | Merged openstack/castellan master: Add code to generate private keys https://review.openstack.org/575800 | 21:09 |
*** dave-mccowan has quit IRC | 21:24 | |
*** dave-mccowan has joined #openstack-barbican | 21:28 | |
rm_work | redrobot / dave-mccowan i guess that's fine, though we'd like to get it in ASAP and backport as far as possible :/ | 21:30 |
*** dave-mccowan has quit IRC | 22:19 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!