*** hrybacki has quit IRC | 00:01 | |
*** henrynash has joined #openstack-keystone | 00:07 | |
*** xianghuihuihui has joined #openstack-keystone | 00:32 | |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Convert shell tests to requests-mock https://review.openstack.org/110210 | 00:33 |
---|---|---|
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Change unscoped token fallback to be session aware https://review.openstack.org/104771 | 00:33 |
*** gokrokve_ has joined #openstack-keystone | 00:42 | |
*** ayoung has quit IRC | 00:44 | |
*** gokrokve has quit IRC | 00:45 | |
*** gokrokve_ has quit IRC | 00:46 | |
*** gokrokve has joined #openstack-keystone | 01:12 | |
*** gokrokve has quit IRC | 01:17 | |
*** jogo has left #openstack-keystone | 01:21 | |
*** gokrokve has joined #openstack-keystone | 01:22 | |
*** gokrokve has quit IRC | 01:28 | |
*** gokrokve has joined #openstack-keystone | 01:29 | |
*** xianghuihuihui has quit IRC | 01:31 | |
*** gokrokve has quit IRC | 01:33 | |
*** gokrokve has joined #openstack-keystone | 01:35 | |
openstackgerrit | A change was merged to openstack/keystone: Add pluggable range functions for token flush https://review.openstack.org/101726 | 01:36 |
*** oomichi has joined #openstack-keystone | 01:37 | |
*** stevemar has joined #openstack-keystone | 02:01 | |
*** xianghui has joined #openstack-keystone | 02:05 | |
*** xianghui has quit IRC | 02:18 | |
*** diegows has quit IRC | 02:18 | |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Isolate get_discovery function https://review.openstack.org/107569 | 02:22 |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Allow unauthenticated discovery https://review.openstack.org/107570 | 02:22 |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Control identity plugin reauthentication https://review.openstack.org/107555 | 02:22 |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Use token and discovery fixture in identity tests https://review.openstack.org/107554 | 02:22 |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Version independent password authentication plugin https://review.openstack.org/81147 | 02:22 |
*** bvandenh_ has quit IRC | 02:23 | |
*** xianghui has joined #openstack-keystone | 02:31 | |
*** jamielennox is now known as jamielennox|away | 02:35 | |
*** shakamunyi has joined #openstack-keystone | 02:41 | |
*** shakamunyi has quit IRC | 03:00 | |
*** mitz_ has quit IRC | 03:11 | |
*** mitz has joined #openstack-keystone | 03:14 | |
*** xianghui has quit IRC | 03:22 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/keystone: Updated from global requirements https://review.openstack.org/111620 | 03:23 |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/111621 | 03:23 |
*** topol has joined #openstack-keystone | 03:29 | |
*** chandankumar has joined #openstack-keystone | 03:36 | |
openstackgerrit | wanghong proposed a change to openstack/keystone: trustor_user_id not available in v2 trust token https://review.openstack.org/101829 | 03:40 |
*** xianghui has joined #openstack-keystone | 03:40 | |
*** wanghong has quit IRC | 03:40 | |
*** xianghui has quit IRC | 03:49 | |
openstackgerrit | Steve Martinelli proposed a change to openstack/keystone: Remove debug CADF payload for every authN request https://review.openstack.org/111634 | 03:58 |
*** jamielennox|away is now known as jamielennox | 04:00 | |
*** xianghui has joined #openstack-keystone | 04:02 | |
openstackgerrit | A change was merged to openstack/keystone: Update the config file https://review.openstack.org/111162 | 04:40 |
*** gabriel-bezerra has quit IRC | 04:41 | |
*** gabriel-bezerra has joined #openstack-keystone | 04:41 | |
*** k4n0 has joined #openstack-keystone | 04:54 | |
openstackgerrit | Steve Martinelli proposed a change to openstack/keystone: Remove debug CADF payload for every authN request https://review.openstack.org/111634 | 05:08 |
openstackgerrit | Steve Martinelli proposed a change to openstack/python-keystoneclient: Add docs for how to create an OAuth auth instance https://review.openstack.org/109013 | 05:14 |
*** jaosorior has joined #openstack-keystone | 05:18 | |
openstackgerrit | Joe Gordon proposed a change to openstack/keystone: Don't override tox envdir for pep8 and cover jobs https://review.openstack.org/111644 | 05:31 |
*** topol has quit IRC | 05:42 | |
*** stevemar has quit IRC | 05:43 | |
*** stevemar has joined #openstack-keystone | 05:44 | |
*** k4n0 has quit IRC | 05:44 | |
*** gokrokve has quit IRC | 05:47 | |
*** ajayaa has joined #openstack-keystone | 05:53 | |
*** ukalifon has joined #openstack-keystone | 05:54 | |
*** k4n0 has joined #openstack-keystone | 05:58 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/keystone: Imported Translations from Transifex https://review.openstack.org/106939 | 06:06 |
*** ukalifon has left #openstack-keystone | 06:06 | |
ajayaa | Hi. When I do a git pull on my master branch rand run tox after that, it throws out garbage. | 06:07 |
ajayaa | Which means that the syntax is somewhere wrong. Has anyone faced this issue? | 06:08 |
openstackgerrit | Jamie Lennox proposed a change to openstack/keystonemiddleware: Load session from builtin session loader https://review.openstack.org/111655 | 06:12 |
ajayaa | jamielennox, | 06:13 |
jamielennox | ajayaa: that doesn't sound right, the master branch should be passing | 06:13 |
jamielennox | what tox job are you runnign | 06:14 |
ajayaa | jamielennox, tox -epy27 | 06:14 |
ajayaa | This is the second time I am facing this issue. However If I do a hard reset to a earlier commit then it works. | 06:14 |
ajayaa | I am doing something wrong, which I am not able to figure out. | 06:15 |
*** rm_work is now known as rm_work|away | 06:18 | |
*** afazekas has quit IRC | 06:41 | |
jamielennox | ajayaa: do you have the output handy? | 06:41 |
ajayaa | output of "tox -epy27"? | 06:48 |
ajayaa | jamielennox, | 06:48 |
jamielennox | ajayaa: yea | 06:48 |
ajayaa | just a sec | 06:49 |
ajayaa | jamielennox, http://paste.openstack.org/show/89938/ | 06:50 |
jamielennox | hmm, that generally means an import error or something | 06:50 |
jamielennox | have you tried removing the tox environment and running it again? | 06:51 |
ajayaa | do you mean delete everything under .tox? | 06:51 |
openstackgerrit | A change was merged to openstack/python-keystoneclient: Redact tokens in request headers https://review.openstack.org/110117 | 06:53 |
openstackgerrit | Steve Martinelli proposed a change to openstack/keystone: Update CADF auditing example to show non-payload information https://review.openstack.org/111657 | 06:53 |
jamielennox | ajayaa: that will work | 07:00 |
jamielennox | but .tox/py27 | 07:00 |
jamielennox | ajayaa: it will just rebuild it when next you run tox | 07:01 |
*** marekd|away is now known as marekd | 07:01 | |
ajayaa | jamielennox, That worked btw. I think I should file a bug for this. When you are running low on data or slow internet connection, this could be a blocker for development. :) | 07:09 |
jamielennox | ajayaa: ok, cool - it's relatively common because tox won't automatically update your pip packages | 07:09 |
jamielennox | there is something you can do to just update tox but i don't remember the command off the top of my head | 07:10 |
ajayaa | jamielennox, no problem. Thanks. :) | 07:11 |
*** rm_work|away is now known as rm_work | 07:11 | |
*** stevemar has quit IRC | 07:11 | |
marekd | ajayaa: you can try tox -repy27 | 07:16 |
marekd | ajayaa: which will rebuild your packages, but that's sometimes not enough. That 'garbage' comes sometimes from the error in your code. | 07:17 |
marekd | ajayaa: bad import for instance (a typo is enough) - then the Python interpreter will not complain but simply spit out that garbage | 07:17 |
marekd | sadly i don't know the good way to automatically find where is the error - i usually go through the changes and look for silly mistakes. | 07:18 |
marekd | anyway, -r == rebuild virtualenv | 07:18 |
ajayaa | marekd, agree. That's the price we will have to pay for using an interpreted language, I guess. | 07:19 |
ajayaa | I will try to document these things in a blog post or something, so that it gets indexed by google. | 07:20 |
marekd | ajayaa: i am not sure...tox is somehow screwed up at this point. | 07:20 |
marekd | ajayaa: make a typo in an import and run the Python code from the interpreter - it will point out there is somethinf wrong (raise ImportError) | 07:21 |
marekd | ajayaa: and I *always* run -pep8 test before i run py27 | 07:21 |
ajayaa | marekd, So it is a problem with tox then. In this particular case (git pull) pep8 passes without a problem. | 07:22 |
marekd | jamielennox: Hey. You are probably half on you way home, but I wanted to ask if you could add https://review.openstack.org/#/c/107393/ and https://review.openstack.org/#/c/106751/ yo your review queue :-) | 07:23 |
marekd | ajayaa: because pep8 can pass and you still might have some stupid typo | 07:23 |
marekd | which makes py27 test produce garbage. | 07:23 |
marekd | *maybe* there is a way to catch the problem with tox - I don't know it :( | 07:24 |
marekd | ajayaa: anyway, if you find out a solution, let me know :-) | 07:25 |
ajayaa | marekd, sure. :) | 07:25 |
openstackgerrit | wanghong proposed a change to openstack/keystone: trustor_user_id not available in v2 trust token https://review.openstack.org/101829 | 07:29 |
*** ajayaa has quit IRC | 07:33 | |
*** wanghong has joined #openstack-keystone | 07:35 | |
*** afazekas has joined #openstack-keystone | 07:41 | |
*** ajayaa has joined #openstack-keystone | 07:46 | |
openstackgerrit | Jamie Lennox proposed a change to openstack/python-keystoneclient: Add get_auth_plugin_name function https://review.openstack.org/111665 | 07:49 |
*** shausy has joined #openstack-keystone | 07:51 | |
*** jamielennox is now known as jamielennox|away | 07:51 | |
bjornar | os keystone endpoint-get command supposed to work= | 07:58 |
*** henrynash has quit IRC | 08:40 | |
openstackgerrit | Ajaya Agrawal proposed a change to openstack/keystone: Implemented caching in identity layer. https://review.openstack.org/110575 | 08:46 |
*** gabriel-bezerra has quit IRC | 08:46 | |
*** k4n0 has quit IRC | 08:46 | |
*** gabriel-bezerra has joined #openstack-keystone | 08:49 | |
*** shafeek has joined #openstack-keystone | 08:51 | |
*** gabriel-bezerra has joined #openstack-keystone | 08:51 | |
*** k4n0 has joined #openstack-keystone | 08:59 | |
*** ajayaa has quit IRC | 09:02 | |
*** ajayaa has joined #openstack-keystone | 09:14 | |
*** k4n0 has quit IRC | 09:22 | |
*** k4n0 has joined #openstack-keystone | 09:25 | |
ajayaa | Hi. Openstack projects such as trove are moving to keystonemiddleware project. Shouldn't it be added to global-requirements.txt? | 09:52 |
openstackgerrit | Jeffrey Zhang proposed a change to openstack/keystone: Redirect stdout and stderr when using subprocess https://review.openstack.org/51610 | 09:52 |
openstackgerrit | Ilya Pekelny proposed a change to openstack/keystone: Use metadata.create_all() to fill a test database https://review.openstack.org/93558 | 09:59 |
openstackgerrit | Ilya Pekelny proposed a change to openstack/keystone: Comparision of database models and migrations. https://review.openstack.org/80630 | 09:59 |
*** i159 has joined #openstack-keystone | 10:03 | |
*** RockKuo_Office has joined #openstack-keystone | 10:08 | |
i159 | bknudson1: Hi! I have a problem with pep8 tests. An error raised on the module which I didn't chenged: "" | 10:09 |
i159 | /keystone/tests/core.py:29:1: H302 import only modules.'from oslo.config import fixture as config_fixture' does not import a module | 10:09 |
i159 | from oslo.config import fixture as config_fixture | 10:09 |
i159 | bknudson1: Did this bug concerned you? | 10:11 |
i159 | bknudson1: and this is module in oslo.config, btw... | 10:12 |
*** k4n0 has quit IRC | 10:16 | |
shafeek | good day | 10:24 |
shafeek | any information on developing extensions for keystone | 10:24 |
shafeek | I need to create an extension that will update a password on a third party system when an update is done on the user i keystone | 10:25 |
*** k4n0 has joined #openstack-keystone | 10:30 | |
shafeek | anyone? | 10:49 |
openstackgerrit | A change was merged to openstack/python-keystoneclient: Use keystoneclient.exceptions https://review.openstack.org/108675 | 10:56 |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/keystone: Updated from global requirements https://review.openstack.org/111620 | 10:59 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/keystone: Enable filtering of services by name https://review.openstack.org/110904 | 11:04 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/keystone: Filter users by email https://review.openstack.org/110970 | 11:04 |
*** RockKuo_Office has quit IRC | 11:16 | |
*** dhellmann_ has quit IRC | 11:42 | |
*** dhellmann has joined #openstack-keystone | 11:42 | |
*** diegows has joined #openstack-keystone | 11:43 | |
*** shafeek is now known as keystone_noob | 12:08 | |
*** rharwood_ has joined #openstack-keystone | 12:11 | |
*** raildo1 has joined #openstack-keystone | 12:13 | |
*** jimbaker` has joined #openstack-keystone | 12:14 | |
*** ajayaa has quit IRC | 12:16 | |
*** nkinder has joined #openstack-keystone | 12:17 | |
*** xianghui has quit IRC | 12:19 | |
*** jimbaker has quit IRC | 12:19 | |
*** raildo has quit IRC | 12:19 | |
*** rharwood has quit IRC | 12:19 | |
*** rharwood_ is now known as rharwood | 12:19 | |
*** cjellick has joined #openstack-keystone | 12:22 | |
*** cjellick has quit IRC | 12:24 | |
*** cjellick has joined #openstack-keystone | 12:24 | |
*** xianghui has joined #openstack-keystone | 12:26 | |
*** ajayaa has joined #openstack-keystone | 12:26 | |
keystone_noob | hi | 12:28 |
keystone_noob | im in the process of creating an extension to keystone | 12:29 |
keystone_noob | what this will do is update a third party system when a user changes hi sor her user details on keystone | 12:29 |
keystone_noob | i'm reading the the docs now | 12:29 |
*** gabriel-bezerra has quit IRC | 12:29 | |
keystone_noob | but could anybody shed some more light on how i might go about doing this | 12:30 |
keystone_noob | Any information would be greatly appreciated | 12:30 |
*** gabriel-bezerra has joined #openstack-keystone | 12:30 | |
*** gordc has joined #openstack-keystone | 12:41 | |
*** ajayaa has quit IRC | 12:45 | |
*** gabriel-bezerra has quit IRC | 12:45 | |
*** gabriel-bezerra has joined #openstack-keystone | 12:46 | |
openstackgerrit | Matthieu Huin proposed a change to openstack/keystone: Remove unsupported command ShibRequireAll https://review.openstack.org/111709 | 12:48 |
*** cjellick_ has joined #openstack-keystone | 12:57 | |
*** ajayaa has joined #openstack-keystone | 12:58 | |
*** cjellick has quit IRC | 13:00 | |
*** jasondotstar has joined #openstack-keystone | 13:01 | |
*** k4n0 has quit IRC | 13:01 | |
*** cjellick_ has quit IRC | 13:02 | |
*** radez_g0n3 is now known as radez | 13:05 | |
*** ajayaa has quit IRC | 13:05 | |
*** samuelmz has joined #openstack-keystone | 13:07 | |
*** cjellick has joined #openstack-keystone | 13:08 | |
*** cjellick has quit IRC | 13:09 | |
*** cjellick has joined #openstack-keystone | 13:09 | |
*** henrynash has joined #openstack-keystone | 13:11 | |
*** ajayaa has joined #openstack-keystone | 13:13 | |
*** joesavak has joined #openstack-keystone | 13:15 | |
*** henrynash has quit IRC | 13:18 | |
*** bknudson1 has quit IRC | 13:19 | |
marekd | mhu: Thanks for the patch. Did you check if removig ShibRequireAll is backwards compatible (w/ apache 2.2)? | 13:23 |
openstackgerrit | A change was merged to openstack/keystone: Catch correct oslo.db exception https://review.openstack.org/108935 | 13:26 |
*** ukalifon3 has joined #openstack-keystone | 13:27 | |
*** ukalifon has joined #openstack-keystone | 13:30 | |
*** topol has joined #openstack-keystone | 13:31 | |
*** chandankumar has quit IRC | 13:31 | |
*** ukalifon3 has quit IRC | 13:32 | |
*** chandankumar has joined #openstack-keystone | 13:33 | |
mhu | marekd, if you remove it when using apache 2.2, you'd get the default behavior of granting access if any rule for any module is verified | 13:36 |
mhu | if you have only mod_shib up, like I assume it should be in most keystone setups, I don't think it is a problem | 13:37 |
*** oomichi has quit IRC | 13:40 | |
mhu | marekd, I am actually digging into the doc and I am encountering a problem to set up federation. When trying to access https://sp-test:5000/v3/OS-FEDERATION/identity_providers/testIdP/protocols/saml2/auth for a token, I get the redirection to the IdP login page alright, but then I am sent back to https://sp-test:5000/Shibboleth.sso/SAML/POST which ends up being somehow interpreted as a keystone url ( 'PATH_TRANSLATED': '/var/www/keystone/main/Shi | 13:41 |
mhu | bboleth.sso/SAML2/POST' ). Have you ever met this problem ? | 13:41 |
dstanek | dolphm: the cover fix broke pip? | 13:43 |
mhu | I have a hunch it's a problem with the vhost config, some conflict between the <Location /Shibboleth.sso> directive and "WSGIScriptAlias / /var/www/keystone/main" | 13:43 |
marekd | mhu: sorry, i am back. | 13:43 |
marekd | mhu: what client are you using? | 13:44 |
marekd | mhu: if cli/keystoneclient you should not be redirected to any 'webpage' | 13:44 |
mhu | marekd, for now I am just doing a GET through firefox, I haven't played with ECP yet | 13:44 |
*** shausy has quit IRC | 13:44 | |
dolphm | dstanek: i don't know... is there supposed to be a gate failure associated with the new bug? if so, i just haven't seen it | 13:45 |
mhu | all I want is to make sure I have the shibboleth part correctly set up, for now | 13:45 |
dolphm | keystone_noob: keystone can emit notifications for things like that already (i'm not sure if we emit notifications on user event, specifically, though) | 13:46 |
marekd | mhu: do you think you could share your config with me? | 13:46 |
dolphm | keystone_noob: with notifications, it'd be easier to implement a listener on rabbit/whatever to talk to your third party system | 13:46 |
marekd | mhu: at least the vhost | 13:46 |
mhu | marekd, sure, no prob | 13:46 |
*** gabriel-bezerra has quit IRC | 13:47 | |
*** gabriel-bezerra has joined #openstack-keystone | 13:47 | |
mhu | marekd, here it is http://paste.openstack.org/show/89999/ | 13:48 |
*** ajayaa has quit IRC | 13:49 | |
*** david-lyle has joined #openstack-keystone | 13:49 | |
*** ayoung has joined #openstack-keystone | 13:49 | |
*** bknudson has joined #openstack-keystone | 13:51 | |
openstackgerrit | Raildo Mascena de Sousa Filho proposed a change to openstack/identity-api: API documentation for Hierarchical Multitenancy https://review.openstack.org/111355 | 13:51 |
marekd | mhu i am not sure if it matters but I would move WSGIScriptAliasMatch above the WSGIScriptAlias. | 13:52 |
mhu | marekd, okay I'll give it a shot | 13:52 |
mhu | I think I'll also follow the doc and default config as in here https://github.com/openstack/keystone/blob/master/httpd/wsgi-keystone.conf | 13:52 |
mhu | my vhost was generated with devstack ... | 13:52 |
dstanek | dolphm: it looks like infra wants us to have separate venv for every tox environment | 13:53 |
marekd | mhu: i think you vhost is fine in general. | 13:53 |
dolphm | dstanek: yeah, but where is the problem of having only one occurring? | 13:53 |
marekd | mhu: i am curious what 'Satisfy Any' in Location means? | 13:54 |
dstanek | that's a good question - i'm trying to run throught the build scripts now | 13:54 |
marekd | mhu: and why you changed it. | 13:55 |
marekd | mhu: is it apache 2.4 specific ? | 13:55 |
marekd | mhu: maybe that's the problem. | 13:55 |
marekd | mhu: docs say to setup shib handler, so calls to host/Shibboleth.sso/* are handled by Shibboleth, not Keystone nor anything else. | 13:56 |
mhu | marekd, that was in the SP doc I followed to set it up, I think it makes the shibboleth urls available from outside | 13:56 |
mhu | makes sense, let me give it a try | 13:56 |
mhu | ahah, progress ! I replaced "Satisfy Any" and now I have a 401 error. :) | 13:58 |
marekd | rollbackto Satisfy Any and add "SetHandler shib" | 13:58 |
marekd | mhu: who issues this 401 - Keystone, Shibboleth? | 14:00 |
mhu | marekd, keystone | 14:00 |
dstanek | dolphm: http://git.openstack.org/cgit/openstack-infra/config/commit/?id=c68d0224 | 14:00 |
marekd | uhm, so add this "SetHandler shib" | 14:00 |
marekd | I think this might help. | 14:01 |
mhu | marekd, I did already, this is how I got the 401 error | 14:01 |
mhu | "Unable to lookup user" with empty value | 14:01 |
marekd | do you have REMOTE_USER in /etc/shibboleth/shibboleth2.xml ? | 14:02 |
marekd | (grep for it) | 14:02 |
dolphm | dstanek: so ours is *never* present now? shouldn't we be failing every change? | 14:02 |
mhu | marekd, I commented it out as mentioned in the doc | 14:02 |
marekd | mhu: I am just making sure as sometimes we forget... :-) | 14:03 |
dstanek | dolphm: unless somehow there is already a .tox/pep8 | 14:03 |
marekd | mhu: mapping rules? | 14:04 |
marekd | mhu: maybe your rules produce empty set of groups which results in Unauthorized | 14:04 |
marekd | mhu: i would change the rule so it always issues an existing group | 14:04 |
*** ajayaa has joined #openstack-keystone | 14:05 | |
mhu | marekd, ok, I will try a simpler ruleset. But I am puzzled by the empty user value | 14:05 |
dolphm | dstanek: gating this, sort of just to see what happens https://review.openstack.org/#/c/106939/ | 14:06 |
marekd | mhu: there are couple of things i'd try but i don't think anymore this is vhost conf issue since you are reaching Keystone. | 14:11 |
*** gabriel-bezerra has quit IRC | 14:11 | |
nkinder | dolphm, dstanek: are you guys discussing the sporadic pep8 gate failures? | 14:11 |
marekd | mhu: on the other things there can be many poential problems. | 14:12 |
dstanek | nkinder: yes | 14:12 |
dolphm | nkinder: yes | 14:12 |
nkinder | dstanek: yeah, it's an odd problem (and the logs are fairly useless) | 14:12 |
*** gabriel-bezerra has joined #openstack-keystone | 14:12 | |
dstanek | nkinder: what's weird is that the infra scripts should fail every time | 14:13 |
mhu | marekd: :/ I'll keep looking, thanks for the help, at least the situation evolved :) | 14:13 |
marekd | mhu: set log level to debug in your vhost configuration | 14:14 |
marekd | and see | 14:14 |
marekd | the stacktrace | 14:14 |
marekd | you should get to the line that raised the exception. | 14:14 |
*** ukalifon has quit IRC | 14:19 | |
*** ajayaa has quit IRC | 14:20 | |
*** jgriffith is now known as Guest71676 | 14:23 | |
*** ajayaa has joined #openstack-keystone | 14:23 | |
*** andreaf has joined #openstack-keystone | 14:32 | |
*** ukalifon1 has joined #openstack-keystone | 14:32 | |
*** jdennis has quit IRC | 14:34 | |
mhu | marekd, I solved my problem by removing "external" as a possible auth method in /etc/keystone/keystone.conf | 14:51 |
mhu | turns out a REMOTE_USER env variable was set, with a value of '' | 14:51 |
marekd | mhu: LOL | 14:52 |
*** thedodd has joined #openstack-keystone | 14:52 | |
marekd | mhu: do you know what set the value? | 14:52 |
marekd | apache maybe? | 14:52 |
mhu | marekd, yeah, very smart, eh ? | 14:52 |
mhu | marekd, I am going to look into this, this might be a problem others will encounter | 14:52 |
marekd | mhu: well, it's safe to remove 'external' from keystone.conf but you had double checked that REMOTE_USER was not set by shibboleth.. | 14:53 |
mhu | marekd, yeah it's an acceptable workaround for now, but I really want to find out why REMOTE_USER was set, and with a stupid value | 14:55 |
mhu | and if it cannot be circumvented, maybe this should be patched to discard empty values https://github.com/openstack/keystone/blob/master/keystone/auth/controllers.py#L468 | 14:55 |
marekd | mhu: true. | 14:56 |
*** ajayaa has quit IRC | 14:57 | |
marekd | mhu: I would simply grep for REMOTE_USER in /etc/{httpd,apache} and /etc/shibboleth :-) | 14:57 |
mhu | marekd, got matches in /etc/shibboleth/upgrade.xsl and /etc/shibboleth/example-shibboleth2.xml ... I don't think they're used by shibd anyway | 15:00 |
marekd | mhu: it's apache 2.4? | 15:00 |
mhu | marekd, yes | 15:00 |
*** gokrokve has joined #openstack-keystone | 15:02 | |
keystone_noob | thanks dolphm | 15:05 |
keystone_noob | ive figured out how to write extensions | 15:05 |
keystone_noob | but notifications would be the way to go | 15:05 |
*** KimJ has joined #openstack-keystone | 15:07 | |
dolphm | dstanek: can you squash the four backports here on stable/icehouse into one? https://bugs.launchpad.net/keystone/+bug/1230279 | 15:10 |
uvirtbot | Launchpad bug 1230279 in keystone "malformed endpoint URLs are destroying the API" [Medium,Fix released] | 15:10 |
*** keystone_noob has quit IRC | 15:12 | |
dstanek | dolphm: sure | 15:13 |
dolphm | dstanek: do indicate in the commit message that's 4 squashed patches from master though | 15:14 |
*** jdennis has joined #openstack-keystone | 15:18 | |
*** ukalifon1 has quit IRC | 15:23 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/keystone: Updated from global requirements https://review.openstack.org/111620 | 15:29 |
*** chandankumar has quit IRC | 15:29 | |
*** gyee has joined #openstack-keystone | 15:30 | |
*** morganfainberg_Z is now known as morganfainberg | 15:35 | |
morganfainberg | mornin. | 15:36 |
dolphm | o/ | 15:40 |
*** hrybacki has joined #openstack-keystone | 15:43 | |
morganfainberg | bknudson, re: https://review.openstack.org/#/c/109041 I don't want to change functionality when move the code from the provider common to the provider manager. | 15:46 |
morganfainberg | bknudson, the bug you pointed out i'll get fixed in the next patch. Any other cleanup I'd like to change separate of moving the code around. | 15:47 |
morganfainberg | dolphm, i'm going to toss the federation domain stuff on the agenda for tomorrow. | 15:47 |
morganfainberg | federation user domain that is | 15:48 |
morganfainberg | dolphm, it's a blocker for non-persistent tokens | 15:48 |
dolphm | morganfainberg: ack | 15:48 |
morganfainberg | dolphm, solving it one way or the other needs tohappen (ignore user domain or add a domain to that section) - i don't care which :) | 15:48 |
dolphm | morganfainberg: this is just a matter of auth_token populating the X_USER_DOMAIN_ID X_USER_DOMAIN_NAME headers, right? | 15:49 |
morganfainberg | dolphm, and revocation events look for the domain for the user | 15:49 |
morganfainberg | dolphm, and i'm not sure what else might be *yet*. at least those two are the starting point | 15:50 |
morganfainberg | dolphm, my bigger concern is we have special cased a token format for federated users. | 15:50 |
morganfainberg | dolphm, so we have v2, v3, v3.federated now (maybe more variations?) | 15:51 |
*** rwsu has joined #openstack-keystone | 15:51 | |
dolphm | morganfainberg: is there a list of potential solutions somewhere we can discuss the merits of? | 15:52 |
morganfainberg | dolphm, i think the theree solutions are in the review: 1) IdpID == domain_id for federated users, 2) "reserved" federated domain, like default, 3) fix auth_token/other code | 15:53 |
morganfainberg | dolphm, i'll add those to the agenda as bullet points | 15:54 |
hrybacki | morganfainberg: I hope this isn't a silly question. I'm not sure how to raise an Unauthorized exception via tests to trigger line 1169 on https://review.openstack.org/#/c/105031/14/keystonemiddleware/auth_token.py -- I've tried a couple of things but haven't had much luck. Any pointers? | 15:57 |
morganfainberg | hrybacki, it's not a silly question, even without reading it | 15:57 |
hrybacki | :) | 15:58 |
morganfainberg | hrybacki, it'll involve i think httpretty | 15:58 |
morganfainberg | hrybacki, or mock-requests. | 15:58 |
morganfainberg | hrybacki, jamielennox|away is likely the best resource on that. | 15:58 |
*** gabriel-bezerra has quit IRC | 15:58 | |
hrybacki | morganfainberg: nods -- I set up a mock URI but I couldn't figure out what kind of token to pass that wouldn't get caught by _is _token_valid (or whatever) | 15:58 |
morganfainberg | hrybacki, a uuid token | 15:59 |
hrybacki | okay | 15:59 |
morganfainberg | hrybacki, or at least uuid token should be the test case for the verify_token retry=falst (i assume thats what you're trying to write a test for) | 15:59 |
hrybacki | also for more general knowledge, how the exceptions are triggered aren't exaclty clear via readinh through middlewares exceptions or the common api exceptions | 16:00 |
*** gabriel-bezerra has joined #openstack-keystone | 16:00 | |
hrybacki | morganfainberg: yep | 16:00 |
morganfainberg | hrybacki, middleware has some ick in it | 16:00 |
hrybacki | morganfainberg: I need a shot of 'more hours in the day' along with one for 'more keystone knowledge' so I can resolve that sort of ick | 16:01 |
morganfainberg | hrybacki, the second part will come, I'm sure! | 16:01 |
morganfainberg | hrybacki, i'd recommend lots and lots of coffee for the former, but... uhm. | 16:01 |
*** openstackgerrit has quit IRC | 16:01 | |
*** openstackgerrit_ has joined #openstack-keystone | 16:02 | |
morganfainberg | hrybacki, i just got yelled at for that, and am down to 1 medium coffee a day (no other caffiene) | 16:02 |
hrybacki | morganfainberg: uhm | 16:02 |
hrybacki | morganfainberg: couldn't do that | 16:02 |
hrybacki | morganfainberg: so my sympathies =/ | 16:02 |
*** openstackgerrit_ is now known as openstackgerrit | 16:03 | |
dstanek | dolphm: squashed | 16:04 |
dolphm | hrybacki: try chugging green tea; it's got less caffeine but comes with bonus chemicals to compensate | 16:04 |
dolphm | dstanek: danke | 16:04 |
hrybacki | dolphm: any recommended brands? | 16:05 |
dolphm | hrybacki: Stash | 16:05 |
morganfainberg | hrybacki, kilogram | 16:05 |
morganfainberg | hrybacki, *great* tea. Stash is good and more available | 16:05 |
hrybacki | I'll look into those. I love a good grean tea / earl grey | 16:06 |
dstanek | i buy stash from amazon every once in a while | 16:06 |
dolphm | hrybacki: http://www.amazon.com/dp/B003D4F2US/ yep! | 16:06 |
dolphm | hrybacki: it's not as fussy as loose leaf and stash is definitely better than anything i've had from my grocery store | 16:07 |
morganfainberg | dstanek, last time i bought stash from amazon, i accidently got the ~20pack of boxes | 16:08 |
morganfainberg | dstanek, or they accidently shipped me the 20-pack of boxes | 16:08 |
*** gabriel-bezerra has quit IRC | 16:09 | |
morganfainberg | dstanek, I *STILL* have mint tea | 16:09 |
hrybacki | dolphm++ :) | 16:09 |
*** gabriel-bezerra has joined #openstack-keystone | 16:09 | |
*** hyakuhei has joined #openstack-keystone | 16:09 | |
dstanek | wow, that would last a long, long time for me | 16:09 |
dolphm | morganfainberg: i've had that happen with amazon. you order quantity=1 and then send you palettes=1 or whatever | 16:10 |
dolphm | i got a ton of steak knives that way | 16:10 |
morganfainberg | dolphm, not complaining most of the time | 16:10 |
morganfainberg | dolphm, hahah steak knives?! hahahahahah | 16:10 |
dolphm | everyone got steak knives for christmas *shrug* | 16:10 |
morganfainberg | really.. | 16:14 |
morganfainberg | oh *phew* thought i lost all my scrollback | 16:14 |
*** gokrokve has quit IRC | 16:26 | |
*** chandankumar has joined #openstack-keystone | 16:29 | |
*** i159 has quit IRC | 16:30 | |
*** henrynash has joined #openstack-keystone | 16:31 | |
dolphm | lbragstad: lance, can you put up a backport to icehouse for https://bugs.launchpad.net/ossa/+bug/1348820 | 16:31 |
uvirtbot | Launchpad bug 1348820 in ossa "Token issued_at time changes on /v3/auth/token GET requests" [High,Confirmed] | 16:31 |
dolphm | bknudson: same to you for https://bugs.launchpad.net/ossa/+bug/1349597 and https://bugs.launchpad.net/ossa/+bug/1347961 | 16:32 |
uvirtbot | Launchpad bug 1349597 in keystone "Domain-scoped tokens don't get revoked" [High,In progress] | 16:32 |
dolphm | danke :D | 16:32 |
*** vhoward has left #openstack-keystone | 16:32 | |
dolphm | although i guess that last one hasn't landed yet | 16:32 |
lbragstad | dolphm: sure thing | 16:34 |
lbragstad | https://bugs.launchpad.net/ossa/+bug/1348820 needs both https://review.openstack.org/#/c/109602/3 and https://review.openstack.org/#/c/109747/ | 16:35 |
uvirtbot | Launchpad bug 1348820 in ossa "Token issued_at time changes on /v3/auth/token GET requests" [High,Confirmed] | 16:35 |
dolphm | lbragstad: squash those into a single patch for stable/ | 16:37 |
lbragstad | ok | 16:37 |
openstackgerrit | Marek Denis proposed a change to openstack/python-keystoneclient: SAML2 federated authentication for ADFS. https://review.openstack.org/111771 | 16:38 |
openstackgerrit | ayoung proposed a change to openstack/python-keystoneclient: Enumerate Projects with Unscoped Tokens https://review.openstack.org/106838 | 16:41 |
lbragstad | dolphm: bknudson https://review.openstack.org/#/c/111772/ | 16:45 |
bknudson | dolphm: I don't know that it's worth it to take the revocation event fixes in piecemeal for the backport. | 16:45 |
bknudson | probably should just take all of them through the mysql fix | 16:46 |
ayoung | bknudson, are you going to apply them to the client, or are we going to have to go through the whole series a second time? | 16:46 |
bknudson | ayoung: I'll also apply them to the client | 16:46 |
bknudson | I don't think all of them apply to the client | 16:47 |
ayoung | bknudson, thanks | 16:47 |
ayoung | bknudson, can you get https://review.openstack.org/#/c/81166/ in before you make them? | 16:47 |
bknudson | ayoung: I'll base them on top of that | 16:48 |
ayoung | bknudson, can you approve the patch? | 16:48 |
ayoung | or, short of that, take ownership of it? | 16:48 |
*** richm has joined #openstack-keystone | 16:49 | |
bknudson | ok, I'll take a look at it. | 16:49 |
ayoung | bknudson, thanks. This whole effort is meaningless unless we set up auth_token middleware to consume the revocation events | 16:50 |
*** afazekas has quit IRC | 16:51 | |
bknudson | sure, and we need revocation events to work | 16:51 |
ayoung | yep | 16:52 |
amerine_ | I'm lost, I thought there was a way for someone with the "admin" role to get get a token with another project/tentants context. | 16:54 |
*** amerine_ is now known as ameirne | 16:54 | |
*** ameirne is now known as amerine | 16:54 | |
ayoung | bknudson, its frustrating that it is split across three repos. To be honest, the python rule that things need to be in separate repos to be separate packages is damaging to security concerns. | 16:54 |
ayoung | amerine, only if they have a role assignment on that other project | 16:55 |
amerine | ayoung: Yeah, that's what I'm doing now. I just remembered wrong I guess. :-( | 16:55 |
bknudson | it's going to be hard to keep track of and require extra work to keep requirements up to date | 16:55 |
ayoung | right now there is no restriction on token-for-token exchanges for the same user | 16:55 |
ayoung | bknudson, ++ | 16:55 |
ayoung | bknudson, its pretty much the norm for native servers to to ship server, common, and client, all out of one code base. | 16:56 |
ayoung | I know the databases all have to do that. | 16:56 |
*** ajayaa has joined #openstack-keystone | 16:57 | |
openstackgerrit | Morgan Fainberg proposed a change to openstack/keystone: Remove `with_lockmode` use from Trust SQL backend. https://review.openstack.org/97059 | 16:59 |
*** henrynash has quit IRC | 17:01 | |
*** gokrokve has joined #openstack-keystone | 17:02 | |
ajayaa | morganfainberg, ayoung, dolphm https://review.openstack.org/#/c/110575/ | 17:12 |
ajayaa | please approve it. | 17:12 |
openstackgerrit | Morgan Fainberg proposed a change to openstack/keystone: Make token_provider_api contain token persistence https://review.openstack.org/109041 | 17:29 |
*** shakamunyi has joined #openstack-keystone | 17:30 | |
openstackgerrit | Morgan Fainberg proposed a change to openstack/keystone: Do not override venvs https://review.openstack.org/111781 | 17:39 |
*** david-lyle has quit IRC | 17:41 | |
*** david-lyle has joined #openstack-keystone | 17:42 | |
*** david-lyle has quit IRC | 17:46 | |
*** marcoemorais has joined #openstack-keystone | 17:49 | |
*** jimbaker` has quit IRC | 17:57 | |
*** jimbaker has joined #openstack-keystone | 18:01 | |
*** jimbaker has quit IRC | 18:01 | |
*** jimbaker has joined #openstack-keystone | 18:01 | |
*** abhishek has joined #openstack-keystone | 18:07 | |
abhishek | hi all, can any one please review this patch, https://review.openstack.org/#/c/107482/ | 18:08 |
abhishek | thank you | 18:08 |
*** browne has joined #openstack-keystone | 18:12 | |
*** gabriel-bezerra has quit IRC | 18:14 | |
browne | so i notice in the default policy.json, there is a rule for a service role. and it appears glance at least is assigned service role to the service project. any reason the other service users are not also using the service role? | 18:15 |
ayoung | morganfainberg, are you waiting on someone else to review https://review.openstack.org/#/c/105031/14 ? | 18:25 |
ayoung | I'm willing to pull the trigger, but you only +1ed. | 18:26 |
morganfainberg | ayoung, the +1 was related to my comment | 18:27 |
morganfainberg | lacking a test | 18:27 |
morganfainberg | ayoung, i've been talking with hrybacki since then, but initially it was "we need this and it can be a follow-on, but we need it" | 18:27 |
*** amcrn has joined #openstack-keystone | 18:28 | |
morganfainberg | ayoung, i'll double check there wasn't anything else post lunch and move it through unless i think it needs another pair of eyes. | 18:28 |
ayoung | morganfainberg, but you gave a +1 to the review itself | 18:28 |
ayoung | not a +2 | 18:28 |
morganfainberg | ayoung, correct, because it was missing the test. | 18:28 |
morganfainberg | ayoung, and i didn't know if hrybacki wanted to put it in *that* review or as a followon | 18:29 |
ayoung | morganfainberg, so if he submits it with the test you will upgrade to a +2 | 18:29 |
morganfainberg | ayoung, post lunch, based on my convos w/ him, i'll look it over and go to +2 even without the patch | 18:29 |
ayoung | cool | 18:29 |
* ayoung heads out | 18:29 | |
*** ayoung has quit IRC | 18:29 | |
*** abhishek has quit IRC | 18:35 | |
*** chandankumar has quit IRC | 18:42 | |
*** ajayaa has quit IRC | 18:58 | |
hrybacki | morganfainberg, ayoung: I've emailed jamie -- I'll submit a follow up in whichever way he recommends based on my message | 19:08 |
morganfainberg | hrybacki, ++ i'm off to lunch, as i told ayoung i'll review and upgrade ot +2 once i'm back | 19:09 |
hrybacki | morganfainberg++ enjoy lunch! | 19:09 |
morganfainberg | brring anything else major (don't think there is anything elsE) | 19:09 |
hrybacki | shouldn't be unless you spot another snafu | 19:09 |
dolphm | morganfainberg: did the bot ever wake up on keystonemiddleware project? | 19:17 |
morganfainberg | dolphm, yeah it should be now | 19:17 |
morganfainberg | dolphm, it was a bug in config grouping it to keystone in lp | 19:17 |
morganfainberg | dolphm, that has been changed | 19:18 |
dolphm | morganfainberg: yay! i also wanted to make a release this week | 19:18 |
dolphm | like, now, maybe | 19:18 |
morganfainberg | dolphm, do we want to get hrybacki 's session change in? | 19:18 |
dolphm | morganfainberg: yes, but i don't want to wait either :P | 19:18 |
lbragstad | dstanek: ping, do you know if the tests import the module, run all the tests, and then move on? I'm trying something with the try_import method in o-i but it's not patching properly | 19:18 |
morganfainberg | dolphm, well i can press go on hrybacki 's now. | 19:19 |
dolphm | morganfainberg: link? | 19:19 |
morganfainberg | https://review.openstack.org/#/c/105031/14 | 19:19 |
morganfainberg | dolphm, i ws going to review post lunch | 19:19 |
morganfainberg | it's missing a test but he's working with jamielennox|away to do it the correct way | 19:19 |
hrybacki | morganfainberg++ | 19:19 |
dstanek | lbragstad: yes, i believe that is what happens; after the list of tests is generated | 19:20 |
morganfainberg | so it can go in as is and i trust hrybacki and jamielennox|away to get a followup test | 19:20 |
morganfainberg | dolphm, i just haven't looked at it since last week so i don't want to blindly +2 w/o checking again, but gyee and ayoung +2'd already | 19:20 |
morganfainberg | dolphm, it hasn't changed otherwise since the patch with the retrty bug | 19:21 |
lbragstad | dstanek: ok, so in that case, I should have to re import the module under test | 19:21 |
dolphm | morganfainberg: i think i'd rather wait for 1.2 for this | 19:21 |
morganfainberg | dolphm, works for me | 19:21 |
lbragstad | in order for my patch to properly work? | 19:22 |
dolphm | morganfainberg: only because we'd be shipping two highly impactful changes at once | 19:22 |
dstanek | lbragstad: why do that? are you trying to implement dolphm's suggestion? | 19:22 |
lbragstad | yes | 19:22 |
morganfainberg | dolphm, ++ no complaints with the logic :) | 19:22 |
morganfainberg | dolphm, i need to get to lunch now. but be back shortly | 19:22 |
hrybacki | when is the 1.2 ? | 19:23 |
lbragstad | I want to make sure that when the import bombs, we handle the case | 19:23 |
dolphm | morganfainberg: i'll go ahead and cut 1.1 now, and then this can go in whenever | 19:23 |
dstanek | lbragstad: then you don't need to import it - you can set the module variable to something and test | 19:23 |
*** packet has joined #openstack-keystone | 19:23 | |
dolphm | hrybacki: whenever we feel appropriate | 19:23 |
*** henrynash has joined #openstack-keystone | 19:24 | |
lbragstad | dstanek: I'm wrapping my test with @mock.patch('keystone.common.serializer.importutils', return_value=None) | 19:24 |
dstanek | lbragstad: i don't think you event have to mock it - you can just update the module level variable right? | 19:26 |
dstanek | lbragstad: something like set serializer.lxml to None and make sure you get the correct behavior | 19:27 |
lbragstad | dstanek: ok, let me try that quick and see what happens | 19:28 |
lbragstad | dstanek: btw, this is what I have so far: http://pasteraw.com/m85le312cg731mafzelartl8tj48wv8 | 19:28 |
morganfainberg | dolphm, do you want to mark https://bugs.launchpad.net/keystone/havana/+bug/1335046 as wont fix? or are we actually going to fix before we eol Havana? | 19:28 |
uvirtbot | Launchpad bug 1335046 in keystone/havana "project_additional_attribute_mapping not loaded on Havana" [Low,Triaged] | 19:28 |
nkinder | dstanek: is there a recheck bug for that pep8 gate failure? | 19:29 |
morganfainberg | dolphm, only asking because of the security-support whatever that ends up meaning | 19:29 |
morganfainberg | nkinder, 1352134 the pip one where pip doesn't exist? | 19:29 |
dolphm | bknudson: am i blind, or is there not a patch with Closes-Bug for https://bugs.launchpad.net/ossa/+bug/1349597 | 19:29 |
morganfainberg | bug 1352134 | 19:29 |
uvirtbot | Launchpad bug 1349597 in keystone "Domain-scoped tokens don't get revoked" [High,In progress] | 19:29 |
uvirtbot | Launchpad bug 1352134 in keystone "/bin/pip: No such file or directory in pep8 and cover jobs" [Undecided,In progress] https://launchpad.net/bugs/1352134 | 19:29 |
nkinder | morganfainberg: that'd be the one | 19:29 |
morganfainberg | nkinder, and the fix is gating | 19:29 |
bknudson | dolphm: it should have been this one: https://review.openstack.org/#/c/109820/ | 19:30 |
morganfainberg | nkinder, https://review.openstack.org/#/c/111644/ if you want to keep your eye on it | 19:31 |
bknudson | I might have forgotten to change Partial-Bug to Closes-Bug when I opened a new bug... | 19:31 |
bknudson | yep, https://review.openstack.org/#/c/109820/2..3//COMMIT_MSG | 19:31 |
dstanek | morganfainberg: i still don't understand how this can be transient...i thought that we always built with a clean environment | 19:31 |
nkinder | morganfainberg: awesome | 19:31 |
morganfainberg | dstanek, some nodes have pep8 built (venv wise) some dont | 19:32 |
morganfainberg | dstanek, if it isn't built, you don't get the output and it fails, if it is built, we get some bogus pip-freeze | 19:32 |
dolphm | bknudson: thanks! i thought there was a patch last week lol | 19:32 |
dstanek | morganfainberg: how would .tox/pep8/bin exist? is infra manually making that venv? | 19:33 |
*** chandankumar has joined #openstack-keystone | 19:33 | |
morganfainberg | dstanek, we re-use pep8 nodes | 19:33 |
morganfainberg | dstanek, they aren't tempest nodes. | 19:33 |
morganfainberg | dstanek, or something like that | 19:34 |
dstanek | morganfainberg: ah, i was under the impression that we always started with a clean directory | 19:34 |
*** topol has quit IRC | 19:34 | |
morganfainberg | dstanek, i *think* pep8 and a few others are reused | 19:34 |
morganfainberg | dstanek, or they're re-used in some cases *shrug* | 19:34 |
*** radez is now known as radez_g0n3 | 19:35 | |
*** henrynash_ has joined #openstack-keystone | 19:37 | |
openstackgerrit | Lance Bragstad proposed a change to openstack/keystone: Refactor serializer import to XmlBodyMiddleware https://review.openstack.org/111108 | 19:38 |
*** henrynash has quit IRC | 19:39 | |
*** henrynash_ is now known as henrynash | 19:39 | |
openstackgerrit | henry-nash proposed a change to openstack/keystone-specs: Endpoint policy extension https://review.openstack.org/99842 | 19:40 |
henrynash | anyone know how I can change the owner of a patch (e.g. a spec)…i.e. if I am taking it over? | 19:42 |
openstackgerrit | Lance Bragstad proposed a change to openstack/keystone: Refactor serializer import to XmlBodyMiddleware https://review.openstack.org/111108 | 19:42 |
dolphm | henrynash: git commit --amend --author="Henry Nash <henry@ibm>" | 19:43 |
henrynash | dolphm: nice, thanks | 19:43 |
dolphm | henrynash: assuming you mean commit Author, not review owner (which is immutable without opening a new review) | 19:43 |
dolphm | morganfainberg: hrybacki: 1.1 is out https://pypi.python.org/pypi/keystonemiddleware | 19:44 |
dolphm | hopefully the gate doesn't fall apart now | 19:44 |
henrynash | dolphm: the “Owner” that shows in the Gerrit review page was waht I was after…maybe that’s the immuatble one? | 19:44 |
hrybacki | dolphm++ thanks for the heads up :) | 19:44 |
morganfainberg | henrynash, owner can't be changed iirc | 19:45 |
morganfainberg | henrynash, but author and committer can | 19:45 |
dolphm | henrynash: that's the immutable one - that's just whoever opened the review originally, and it doesn't affect anything too useful | 19:45 |
henrynash | morganfainberg, dolphm: thanks… | 19:45 |
*** ayoung has joined #openstack-keystone | 19:47 | |
openstackgerrit | henry-nash proposed a change to openstack/keystone-specs: Endpoint policy extension https://review.openstack.org/99842 | 19:49 |
*** packet has quit IRC | 20:09 | |
*** henrynash has quit IRC | 20:12 | |
openstackgerrit | Dolph Mathews proposed a change to openstack/identity-api: add name filter on list services https://review.openstack.org/111818 | 20:27 |
*** packet has joined #openstack-keystone | 20:28 | |
*** marcoemorais has quit IRC | 20:34 | |
*** chandankumar has quit IRC | 20:34 | |
*** marcoemorais has joined #openstack-keystone | 20:35 | |
*** notstevemar has joined #openstack-keystone | 20:37 | |
*** andreaf has quit IRC | 20:40 | |
*** henrynash has joined #openstack-keystone | 20:42 | |
*** andreaf has joined #openstack-keystone | 20:43 | |
*** dolphm is now known as notdolphm | 20:50 | |
*** jsavak has joined #openstack-keystone | 21:00 | |
openstackgerrit | Steve Martinelli proposed a change to openstack/python-keystoneclient: Add docs for how to create an OAuth auth instance https://review.openstack.org/109013 | 21:01 |
openstackgerrit | A change was merged to openstack/keystone: Don't override tox envdir for pep8 and cover jobs https://review.openstack.org/111644 | 21:02 |
openstackgerrit | Matthieu Huin proposed a change to openstack/keystone: Improve instructions about federation https://review.openstack.org/111709 | 21:03 |
*** joesavak has quit IRC | 21:03 | |
openstackgerrit | A change was merged to openstack/keystone: Fix revoking domain-scoped tokens https://review.openstack.org/109820 | 21:06 |
*** fifieldt has quit IRC | 21:07 | |
*** jasondotstar has quit IRC | 21:08 | |
notdolphm | bknudson: yay ^^ | 21:10 |
bknudson | notdolphm: y, didn't have to rebase on 111644 | 21:11 |
openstackgerrit | A change was merged to openstack/keystone: Do not override venvs https://review.openstack.org/111781 | 21:12 |
bknudson | I wonder where https://review.openstack.org/#/c/109125/ is now... | 21:13 |
openstackgerrit | A change was merged to openstack/keystone: Imported Translations from Transifex https://review.openstack.org/106939 | 21:13 |
bknudson | I'll just recheck no bug it. | 21:14 |
bknudson | notdolphm: or would it be safer to rebase? | 21:14 |
notdolphm | bknudson: i haven't seen it all day. rebase so it starts fresh | 21:15 |
bknudson | ok, I'll rebase. | 21:15 |
notdolphm | bknudson: it'll have all the tox fixes that way too :) | 21:15 |
bknudson | y, that's what I was hoping to avoid the pip fail | 21:15 |
notdolphm | i guess it'll be tested with those either way. don't mind me! | 21:16 |
bknudson | oh, really? | 21:16 |
bknudson | I suppose it merges | 21:16 |
notstevemar | lbragstad, gyee notdolphm morganfainberg bknudson a request to think of a structure for notifications for role_assignemts? https://etherpad.openstack.org/p/notifications-for-role-assignments | 21:16 |
*** notdolphm is now known as dolphm | 21:16 | |
*** fifieldt has joined #openstack-keystone | 21:22 | |
openstackgerrit | Nathan Kinder proposed a change to openstack/keystone: Allow LDAP lock attributes to be used as enable attributes https://review.openstack.org/104408 | 21:22 |
*** afazekas has joined #openstack-keystone | 21:23 | |
*** hrybacki_ has joined #openstack-keystone | 21:23 | |
notstevemar | updated the etherpad... | 21:26 |
*** hrybacki has quit IRC | 21:27 | |
*** hrybacki_ has quit IRC | 21:28 | |
bknudson | do we need the tox.ini change back in stable/icehouse, too? | 21:29 |
bknudson | (looks like it | 21:29 |
*** notstevemar has quit IRC | 21:31 | |
*** ByteSore has quit IRC | 21:34 | |
*** jkappert has quit IRC | 21:36 | |
openstackgerrit | Morgan Fainberg proposed a change to openstack/keystone: Remove `with_lockmode` use from Trust SQL backend. https://review.openstack.org/97059 | 21:37 |
openstackgerrit | Rodrigo Duarte proposed a change to openstack/keystone: Add parent_project_id field https://review.openstack.org/111840 | 21:39 |
openstackgerrit | Rodrigo Duarte proposed a change to openstack/keystone: Base methods to handle hierarchical projects https://review.openstack.org/111841 | 21:39 |
openstackgerrit | Rodrigo Duarte proposed a change to openstack/keystone: Create, update and delete hierarchical projects https://review.openstack.org/111842 | 21:39 |
bknudson | https://review.openstack.org/111845 is the backport | 21:42 |
*** henrynash has quit IRC | 21:46 | |
*** packet has quit IRC | 21:49 | |
*** dhellmann is now known as dhellmann_ | 21:53 | |
*** jsavak has quit IRC | 21:56 | |
dolphm | bknudson: yes! thanks | 21:59 |
openstackgerrit | Morgan Fainberg proposed a change to openstack/python-keystoneclient: Mark the keystoneclient s3_token middleware deprecated https://review.openstack.org/111847 | 22:04 |
*** cjellick_ has joined #openstack-keystone | 22:08 | |
*** cjellick has quit IRC | 22:12 | |
*** cjellick_ has quit IRC | 22:13 | |
*** bknudson has quit IRC | 22:21 | |
*** ByteSore has joined #openstack-keystone | 22:35 | |
*** jkappert has joined #openstack-keystone | 22:35 | |
*** thedodd has quit IRC | 22:42 | |
*** morganfainberg is now known as morganfainberg_Z | 22:44 | |
*** bknudson has joined #openstack-keystone | 22:49 | |
*** gokrokve has quit IRC | 22:55 | |
*** gokrokve has joined #openstack-keystone | 22:56 | |
*** KimJ has quit IRC | 22:57 | |
dstanek | lbragstad: you around? | 22:59 |
openstackgerrit | A change was merged to openstack/keystone: Remove debug CADF payload for every authN request https://review.openstack.org/111634 | 23:01 |
*** gordc has quit IRC | 23:04 | |
*** david-lyle has joined #openstack-keystone | 23:11 | |
*** jaosorior has quit IRC | 23:12 | |
openstackgerrit | A change was merged to openstack/keystone: Add a test for revoking a scoped token from an unscoped https://review.openstack.org/109125 | 23:14 |
*** rwsu has quit IRC | 23:19 | |
*** marcoemorais has quit IRC | 23:33 | |
*** marcoemorais1 has joined #openstack-keystone | 23:33 | |
nkinder | bknudson: thanks for re-reviewing my trusts unit test patch! | 23:34 |
bknudson | nkinder: I try to re-review things. | 23:35 |
*** rwsu has joined #openstack-keystone | 23:40 | |
*** marcoemorais1 has quit IRC | 23:45 | |
*** marcoemorais has joined #openstack-keystone | 23:46 | |
*** marcoemorais has quit IRC | 23:46 | |
*** marcoemorais has joined #openstack-keystone | 23:47 | |
*** oomichi has joined #openstack-keystone | 23:49 | |
openstackgerrit | David Stanek proposed a change to openstack/keystone: Refactor serializer import to XmlBodyMiddleware https://review.openstack.org/111108 | 23:57 |
*** stevemar has joined #openstack-keystone | 23:57 | |
*** david-lyle has quit IRC | 23:58 | |
*** david-lyle has joined #openstack-keystone | 23:58 | |
*** david-lyle has quit IRC | 23:58 | |
*** david-lyle has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!