Wednesday, 2015-11-11

notmorganjamielennox: done and done00:00
notmorganjamielennox: yeah that makes a lot of sense00:00
*** samleon has quit IRC00:02
jamielennoxsurprised it hadn't come up before00:02
notmorganjamielennox: i am always kind of shocked at what has/has not comeup before00:04
*** dims has joined #openstack-keystone00:08
*** richm has quit IRC00:09
*** shaleh has joined #openstack-keystone00:10
*** gordc has quit IRC00:12
*** jasonsb has quit IRC00:13
*** jasonsb has joined #openstack-keystone00:13
*** shaleh is now known as shaleh|away00:15
*** shaleh|away is now known as shaleh00:15
*** dims has quit IRC00:16
*** jasonsb has quit IRC00:18
*** EinstCrazy has quit IRC00:23
*** jbell8 has quit IRC00:26
*** meker12 has quit IRC00:26
*** sshen has joined #openstack-keystone00:27
openstackgerritSean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently  https://review.openstack.org/24387700:28
sshenHello there, a question on revoking tokens. In Horizon/django_openstack_auth, horizon session token is revoked when switching project. How does this revocation affect a trust created with the revoked token? Does it get revoked as well?00:30
sshenThis is when Keystone V3 is enabled. django_openstack_auth revokes the token by "DELETE /v3/auth/tokens".00:32
sshenI can see a revoke event from "GET /v3/OS-REVOKE/events" with "issued_before" and "audit_id" of the token.00:33
sshenAnyone please?00:35
jamielennoxsshen: trusts should be fine, the trust is set up based on the user and project behind the token and not the token itself00:39
sshenjamielennox: Thanks. I'm seeing some issues with launching heat stack from horizon with failure to authenticate with keystone, and heat-engine is attempting with the revoked token in some of the failed cases.00:45
jamielennoxi'm not sure what would be happening there00:45
jamielennoxi mean if you instigate something with horizon to heat then it will do some operations with the user token00:46
jamielennoxi think00:46
sshenI made some patch in horizon to issue a new token and pass it to heat client (instead of the horizon token that would be revoked), then I don't see any problem.00:47
sshenSo if the trust is intacted when revoking the token, then it could be something happening between horizon and heat before the trust is created.00:48
sshenThanks for the confirmation on the trust revocation.00:49
openstackgerritLin Hua Cheng proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816100:50
jamielennoxi'm mostly surprised that horizon is revoking tokens within a user session00:55
*** gyee has joined #openstack-keystone00:56
*** ChanServ sets mode: +v gyee00:56
sshenit's happening when switching projects - the token being revoked was project-scoped00:57
sshenhttps://github.com/openstack/django_openstack_auth/blob/master/openstack_auth/views.py#L23700:59
*** mylu has joined #openstack-keystone01:00
*** sshen_ has joined #openstack-keystone01:06
*** sshen has quit IRC01:06
*** spandhe has quit IRC01:06
*** spandhe has joined #openstack-keystone01:07
openstackgerritJamie Lennox proposed openstack/keystone: Move AuthContext middleware into it's own file  https://review.openstack.org/24388201:11
*** EinstCrazy has joined #openstack-keystone01:12
*** hidekazu has joined #openstack-keystone01:14
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Use keystoneauth  https://review.openstack.org/23509001:24
*** shaleh has quit IRC01:26
*** dims has joined #openstack-keystone01:27
*** mylu has quit IRC01:29
*** mylu has joined #openstack-keystone01:30
*** mylu has quit IRC01:30
*** mylu has joined #openstack-keystone01:30
*** jasonsb has joined #openstack-keystone01:31
*** mylu has quit IRC01:31
*** mylu has joined #openstack-keystone01:32
*** mylu has quit IRC01:36
*** mylu_ has joined #openstack-keystone01:36
*** harlowja has quit IRC01:38
*** harlowja_ has joined #openstack-keystone01:38
*** EinstCra_ has joined #openstack-keystone01:40
*** mylu_ has quit IRC01:40
*** EinstCrazy has quit IRC01:43
*** tyagiprince2010 has quit IRC01:49
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Address hacking check H405.  https://review.openstack.org/24388901:54
openstackgerritLin Hua Cheng proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816101:55
*** browne has quit IRC01:56
*** edmondsw has quit IRC02:04
*** RichardRaseley has joined #openstack-keystone02:05
*** spandhe has quit IRC02:12
*** woodster_ has quit IRC02:29
*** RichardRaseley has quit IRC02:40
*** mylu has joined #openstack-keystone02:41
*** su_zhang has joined #openstack-keystone02:42
*** RichardRaseley has joined #openstack-keystone02:52
*** mylu has quit IRC02:54
*** lhcheng_ has quit IRC02:58
*** meker12 has joined #openstack-keystone03:00
*** jamielennox is now known as jamielennox|away03:00
*** jamielennox|away is now known as jamielennox03:10
*** sshen_ is now known as sshen03:12
*** su_zhang has quit IRC03:15
*** RichardRaseley has quit IRC03:16
*** RichardRaseley has joined #openstack-keystone03:16
*** gildub has joined #openstack-keystone03:16
openstackgerritHidekazu Nakamura proposed openstack/python-keystoneclient: Add missing end single quote  https://review.openstack.org/24390203:17
*** sshen has quit IRC03:22
*** hightall has joined #openstack-keystone03:22
*** sshen has joined #openstack-keystone03:23
*** gyee has quit IRC03:23
*** pumaranikar has joined #openstack-keystone03:29
*** btully has quit IRC03:32
*** jerrygb has quit IRC03:33
*** jerrygb has joined #openstack-keystone03:34
*** agireud has joined #openstack-keystone03:34
*** fawadkhaliq has joined #openstack-keystone03:39
*** agireud has quit IRC03:39
*** agireud has joined #openstack-keystone03:41
*** dave-mcc_ has quit IRC03:45
*** dims has quit IRC03:46
*** r-daneel has quit IRC03:47
*** pumaranikar has quit IRC03:49
*** hightall has quit IRC03:50
*** roxanaghe has joined #openstack-keystone04:01
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/24392304:03
openstackgerritOpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements  https://review.openstack.org/24392404:03
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/24392504:03
*** RichardRaseley has quit IRC04:05
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/23903904:07
*** jbell8 has joined #openstack-keystone04:08
*** stevemar_ has joined #openstack-keystone04:13
*** ChanServ sets mode: +o stevemar_04:13
*** lhcheng has joined #openstack-keystone04:14
*** ChanServ sets mode: +v lhcheng04:14
*** stevemar_ has quit IRC04:16
*** fawadkhaliq has quit IRC04:17
*** roxanaghe has quit IRC04:21
*** RichardRaseley has joined #openstack-keystone04:24
openstackgerritMerged openstack/keystone: Add exception unit tests with different message types  https://review.openstack.org/23930704:25
*** links has joined #openstack-keystone04:28
*** RichardRaseley has quit IRC04:29
*** meker12 has quit IRC04:29
*** hogepodge has quit IRC04:35
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826404:36
*** lhcheng has quit IRC04:39
*** hightall has joined #openstack-keystone04:39
*** lhcheng has joined #openstack-keystone04:41
*** ChanServ sets mode: +v lhcheng04:41
*** lhcheng has quit IRC04:43
*** lhcheng has joined #openstack-keystone04:44
*** ChanServ sets mode: +v lhcheng04:44
*** jbell8 has quit IRC04:51
*** mylu has joined #openstack-keystone04:56
openstackgerritDave Chen proposed openstack/keystone: Fix the wrong method name  https://review.openstack.org/24395104:56
*** fawadkhaliq has joined #openstack-keystone05:02
*** lhcheng has quit IRC05:06
*** btully has joined #openstack-keystone05:07
openstackgerritHidekazu Nakamura proposed openstack/keystone: Update development environment set up doc  https://review.openstack.org/22302005:11
*** btully has quit IRC05:11
*** rha has quit IRC05:12
*** roxanaghe has joined #openstack-keystone05:13
*** btully has joined #openstack-keystone05:14
*** links has quit IRC05:26
*** jerrygb has quit IRC05:28
*** stevemar_ has joined #openstack-keystone05:29
*** ChanServ sets mode: +o stevemar_05:29
*** jerrygb has joined #openstack-keystone05:29
*** su_zhang has joined #openstack-keystone05:30
*** stevemar_ has quit IRC05:31
*** jerrygb has quit IRC05:33
*** su_zhang has quit IRC05:47
*** roxanaghe has quit IRC05:50
*** mylu has quit IRC05:58
*** links has joined #openstack-keystone05:58
*** roxanaghe has joined #openstack-keystone06:00
*** fawadkhaliq has quit IRC06:01
*** fawadkhaliq has joined #openstack-keystone06:02
*** fawadk has joined #openstack-keystone06:03
*** fawadkhaliq has quit IRC06:04
*** marzif_ has joined #openstack-keystone06:06
*** bttully has joined #openstack-keystone06:06
*** btully has quit IRC06:07
*** bttully is now known as btully06:07
*** urulama__ is now known as urulama06:07
*** btully is now known as Guest8083906:08
*** daemontool has quit IRC06:08
*** pnavarro has quit IRC06:23
*** roxanaghe has quit IRC06:28
*** jamielennox is now known as jamielennox|away06:29
*** jbell8 has joined #openstack-keystone06:30
*** jaosorior has joined #openstack-keystone06:34
*** spandhe has joined #openstack-keystone06:36
*** gildub has quit IRC06:43
*** browne has joined #openstack-keystone06:57
*** mylu has joined #openstack-keystone06:58
*** mylu has quit IRC07:03
*** spandhe has quit IRC07:07
*** lsmola has joined #openstack-keystone07:16
*** henrynash has joined #openstack-keystone07:22
*** ChanServ sets mode: +v henrynash07:22
*** stevemar_ has joined #openstack-keystone07:29
*** ChanServ sets mode: +o stevemar_07:29
*** jerrygb has joined #openstack-keystone07:30
*** stevemar_ has quit IRC07:32
*** ninag has joined #openstack-keystone07:35
*** jerrygb has quit IRC07:36
*** ninag has quit IRC07:40
*** jamielennox|away has quit IRC07:41
*** jasonsb_ has joined #openstack-keystone07:41
*** jasonsb has quit IRC07:43
*** x58 has quit IRC07:43
*** afazekas|sick has quit IRC07:44
*** mordred has quit IRC07:44
*** x58 has joined #openstack-keystone07:45
*** rha has joined #openstack-keystone07:48
*** rha has quit IRC07:49
*** afazekas has joined #openstack-keystone07:50
*** rha has joined #openstack-keystone07:50
*** x58 has quit IRC07:52
*** x58 has joined #openstack-keystone07:53
*** fawadk has quit IRC07:57
*** fawadkhaliq has joined #openstack-keystone07:58
*** gb21 has quit IRC08:12
*** fawadkhaliq has quit IRC08:13
*** gb21 has joined #openstack-keystone08:14
openstackgerrithenry-nash proposed openstack/keystone-specs: Augment token to indicate if it is scoped to the admin project  https://review.openstack.org/24223208:15
*** henrynash has quit IRC08:17
*** henrynash has joined #openstack-keystone08:17
*** ChanServ sets mode: +v henrynash08:17
*** spandhe has joined #openstack-keystone08:19
*** spandhe_ has joined #openstack-keystone08:20
*** spandhe has quit IRC08:24
*** spandhe_ is now known as spandhe08:24
*** jamielennox|away has joined #openstack-keystone08:31
*** jamielennox|away is now known as jamielennox08:31
*** ChanServ sets mode: +v jamielennox08:31
*** Guest80839 has quit IRC08:34
*** stevemar_ has joined #openstack-keystone08:35
*** ChanServ sets mode: +o stevemar_08:35
*** stevemar_ has quit IRC08:38
*** mylu has joined #openstack-keystone08:47
*** jbell8 has quit IRC08:48
*** mylu has quit IRC08:51
*** jbell8 has joined #openstack-keystone08:56
*** spandhe has quit IRC08:59
*** e0ne has joined #openstack-keystone08:59
*** fhubik has joined #openstack-keystone08:59
*** spandhe has joined #openstack-keystone09:03
*** fhubik is now known as fhubik_brb09:03
*** browne has quit IRC09:09
*** yangyapeng has joined #openstack-keystone09:11
*** fawadkhaliq has joined #openstack-keystone09:12
*** fawadkhaliq has quit IRC09:23
*** fhubik_brb is now known as fhubik09:25
*** spandhe has quit IRC09:25
*** fhubik is now known as fhubik_brb09:29
*** hightall has quit IRC09:30
*** henrynash has quit IRC09:33
*** odyssey4me_ is now known as odyssey4me09:33
*** btully has joined #openstack-keystone09:39
*** belmoreira has joined #openstack-keystone09:41
*** btully has quit IRC09:44
*** fawadkhaliq has joined #openstack-keystone09:44
*** mordred has joined #openstack-keystone09:45
*** jistr has joined #openstack-keystone09:45
*** hidekazu has quit IRC09:59
*** aix has joined #openstack-keystone10:08
*** fhubik_brb is now known as fhubik10:25
*** jaosorior has quit IRC10:26
*** urulama has quit IRC10:26
*** urulama has joined #openstack-keystone10:27
*** jaosorior has joined #openstack-keystone10:27
*** jaosorior has quit IRC10:30
*** jaosorior has joined #openstack-keystone10:30
*** stevemar_ has joined #openstack-keystone10:36
*** ChanServ sets mode: +o stevemar_10:36
*** markvoelker has quit IRC10:37
*** lhcheng has joined #openstack-keystone10:37
*** ChanServ sets mode: +v lhcheng10:37
*** stevemar_ has quit IRC10:38
*** BAKfr has quit IRC10:45
*** BAKfr has joined #openstack-keystone10:47
*** yangyapeng has quit IRC11:07
*** EinstCra_ has quit IRC11:07
*** gildub has joined #openstack-keystone11:17
*** stevemar_ has joined #openstack-keystone11:23
*** ChanServ sets mode: +o stevemar_11:23
*** fawadkhaliq has quit IRC11:26
*** stevemar_ has quit IRC11:26
*** btully has joined #openstack-keystone11:27
openstackgerritMerged openstack/python-keystoneclient: Iterate over copy of session.adapters keys in Python2/3  https://review.openstack.org/23166711:30
*** EinstCrazy has joined #openstack-keystone11:31
*** btully has quit IRC11:32
*** lhcheng has quit IRC11:33
*** fawadkhaliq has joined #openstack-keystone11:34
*** fawadkhaliq has quit IRC11:35
*** fawadkhaliq has joined #openstack-keystone11:36
*** urulama has quit IRC11:36
*** fhubik is now known as fhubik_brb11:36
*** urulama has joined #openstack-keystone11:36
*** markvoelker has joined #openstack-keystone11:37
*** fhubik_brb is now known as fhubik11:40
*** dims has joined #openstack-keystone11:41
*** markvoelker has quit IRC11:42
*** fhubik is now known as fhubik_brb11:47
openstackgerritKseniya Tychkova proposed openstack/oslo.policy: Draft implementation of LDAP RBAC blueprint  https://review.openstack.org/24405911:57
*** stevemar_ has joined #openstack-keystone12:00
*** ChanServ sets mode: +o stevemar_12:00
*** doug-fis_ is now known as doug-fish12:02
*** fawadkhaliq has quit IRC12:02
*** e0ne has quit IRC12:11
samueldmqbknudson: hi12:18
samueldmqbknudson: about change #207226 "Config option for insecure responses"12:18
*** e0ne has joined #openstack-keystone12:18
samueldmqbknudson: does it make sense to have "debug=False" and "insecure_debug=True" ?12:19
*** fhubik_brb is now known as fhubik12:28
*** openstackgerrit has quit IRC12:31
*** openstackgerrit has joined #openstack-keystone12:32
*** fhubik is now known as fhubik_brb12:35
*** jerrygb has joined #openstack-keystone12:37
*** urulama has quit IRC12:38
*** urulama has joined #openstack-keystone12:38
*** fhubik_brb is now known as fhubik12:39
*** markvoelker has joined #openstack-keystone12:53
*** markvoelker has quit IRC12:58
*** dims has quit IRC12:59
*** fawadkhaliq has joined #openstack-keystone12:59
*** pauloewerton has joined #openstack-keystone13:03
openstackgerritDmitry Tantsur proposed openstack/keystonemiddleware: Make "Auth Token confirmed use of %s apis" debug level  https://review.openstack.org/24409213:05
*** gildub has quit IRC13:10
*** gordc has joined #openstack-keystone13:10
*** fhubik has quit IRC13:24
openstackgerritMerged openstack/keystone: Add reno for release notes management  https://review.openstack.org/24326913:26
*** diana_clarke has left #openstack-keystone13:30
*** edmondsw has joined #openstack-keystone13:31
*** richm has joined #openstack-keystone13:32
*** fawadkhaliq has quit IRC13:32
*** fawadkhaliq has joined #openstack-keystone13:32
*** ninag has joined #openstack-keystone13:37
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826413:40
*** dave-mccowan has joined #openstack-keystone13:41
openstackgerritChangBo Guo(gcb) proposed openstack/keystone: Use the oslo.utils.reflection to extract the class name  https://review.openstack.org/24149413:54
*** markvoelker has joined #openstack-keystone13:54
*** markvoelker has quit IRC13:58
*** gb21 has quit IRC14:02
*** gordc has quit IRC14:02
openstackgerritMerged openstack/python-keystoneclient: Add missing end single quote  https://review.openstack.org/24390214:03
*** links has quit IRC14:04
*** gordc has joined #openstack-keystone14:04
*** josecastroleon has joined #openstack-keystone14:04
*** petertr7_away is now known as petertr714:05
*** tyagiprince2010 has joined #openstack-keystone14:06
tyagiprince2010Hello everyone.. I want to understand the caching in the keystone.. Please guide me to the right path..14:06
*** fawadkhaliq has quit IRC14:07
*** agireud has quit IRC14:08
*** arif-ali has quit IRC14:08
*** bdossant has joined #openstack-keystone14:10
openstackgerritMerged openstack/keystone: Create tests for set_default_is_domain in LDAP  https://review.openstack.org/22953614:11
*** su_zhang has joined #openstack-keystone14:13
*** dims has joined #openstack-keystone14:15
*** agireud has joined #openstack-keystone14:15
*** arif-ali has joined #openstack-keystone14:15
*** markvoelker has joined #openstack-keystone14:15
*** tyagiprince2010 has quit IRC14:16
*** aix has quit IRC14:18
*** csoukup has quit IRC14:19
*** dims has quit IRC14:23
*** urulama has quit IRC14:25
*** urulama has joined #openstack-keystone14:25
*** dims has joined #openstack-keystone14:26
*** marzif_ has quit IRC14:29
openstackgerritAlexander Makarov proposed openstack/keystone-specs: Unified delegation spec  https://review.openstack.org/18981614:32
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826414:39
*** bradjones|away is now known as bradjones14:40
*** btully has joined #openstack-keystone14:40
*** david-ly_ has joined #openstack-keystone14:41
*** su_zhang has quit IRC14:42
*** david-lyle has quit IRC14:42
lbragstadi just scrolled through the open reviews in gerrit, but checking here too. No one has a patch for migrating revocation_events to core do they?14:48
*** aix has joined #openstack-keystone14:49
*** fhubik has joined #openstack-keystone14:52
*** thiagop has joined #openstack-keystone14:55
lbragstadah, found it - https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:bp/move-extensions,n,z15:01
lbragstadstevemar_ do all of those have to be worked in a series?15:01
*** fawadkhaliq has joined #openstack-keystone15:01
stevemar_lbragstad: not necessarily, but the db migrations have to be ordered, 082, 083, and so forth15:02
stevemar_lbragstad: i think most of those are ready or close to ready15:03
*** dims has quit IRC15:03
openstackgerritAlexander Makarov proposed openstack/keystone: Move region configuration to a critical section  https://review.openstack.org/22217315:05
openstackgerritAlexander Makarov proposed openstack/keystone: Move region configuration to a critical section  https://review.openstack.org/22217315:05
amakarovbknudson, hi!15:05
amakarov^^15:05
*** slberger has joined #openstack-keystone15:06
amakarovbknudson, I've answered your comments there and will be grateful if you suggest me how to do that race condition test correctly :)15:06
*** csoukup has joined #openstack-keystone15:07
openstackgerritPaulo Ewerton Gomes Fragoso proposed openstack/keystone: Manager support for project delete cascade  https://review.openstack.org/24414915:09
lbragstadstevemar_ cool, it if makes it easier to do them in order that's fine15:11
lbragstadstevemar_ just curious if they were required to be that way15:11
lbragstadstevemar_ I'll review that series15:11
stevemar_lbragstad: that would be awesome, bknudson took a few good hacks at them already15:12
*** marzif_ has joined #openstack-keystone15:20
*** petertr7 is now known as petertr7_away15:24
*** timcline has joined #openstack-keystone15:26
*** HenryG has quit IRC15:34
*** henrynash has joined #openstack-keystone15:34
*** ChanServ sets mode: +v henrynash15:34
*** HenryG has joined #openstack-keystone15:38
openstackgerrithenry-nash proposed openstack/keystone: Use list_role_assignments to get assignments by role_id  https://review.openstack.org/24252915:39
openstackgerrithenry-nash proposed openstack/keystone: Create new version of assignment driver interface  https://review.openstack.org/24285315:42
openstackgerrithenry-nash proposed openstack/keystone: Use list_role_assignments to get projects/domains for user  https://review.openstack.org/24251315:43
*** tonytan4ever has joined #openstack-keystone15:44
openstackgerrithenry-nash proposed openstack/keystone: Show defect in list_user_ids that only lists direct user assignments  https://review.openstack.org/24256415:44
openstackgerrithenry-nash proposed openstack/keystone: Fix defect in list_user_ids that only lists direct user assignments  https://review.openstack.org/24257415:45
*** henrynash has quit IRC15:45
*** roxanaghe has joined #openstack-keystone15:54
*** diazjf has joined #openstack-keystone15:58
openstackgerritNathan Kinder proposed openstack/keystone: Remove hardcoded LDAP group schema from emulated enabled mix-in  https://review.openstack.org/24417315:59
*** ninag has quit IRC16:00
*** ninag has joined #openstack-keystone16:00
*** openstackgerrit has quit IRC16:02
*** openstackgerrit has joined #openstack-keystone16:03
*** hogepodge has joined #openstack-keystone16:03
*** tonytan4ever has quit IRC16:04
*** ninag has quit IRC16:05
*** thedodd has joined #openstack-keystone16:05
*** ninag has joined #openstack-keystone16:06
*** david-ly_ is now known as david-lyle16:07
*** ninag has quit IRC16:08
*** ninag has joined #openstack-keystone16:08
*** woodster_ has joined #openstack-keystone16:10
*** marzif__ has joined #openstack-keystone16:11
*** timcline_ has joined #openstack-keystone16:12
*** jasonsb has joined #openstack-keystone16:12
*** belmoreira has quit IRC16:13
*** boris-42_ has joined #openstack-keystone16:13
lbragstadstevemar_ ok, i reviewed most of that series16:14
lbragstadstevemar_ it looks like most of those patches are being maintained by various people?16:14
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/24392316:15
*** notmorga1 has joined #openstack-keystone16:16
*** ChanServ sets mode: +v notmorga116:16
*** gordc_ has joined #openstack-keystone16:16
*** EmilienM has quit IRC16:17
*** notmorgan has quit IRC16:17
*** gordc has quit IRC16:17
*** jasonsb_ has quit IRC16:17
*** timcline has quit IRC16:17
*** marzif_ has quit IRC16:17
*** boris-42 has quit IRC16:17
*** sileht has quit IRC16:17
*** EmilienM_ has joined #openstack-keystone16:17
*** EmilienM_ is now known as EmilienM16:18
*** notmorga1 is now known as notmorgan16:18
*** ayoung has joined #openstack-keystone16:18
*** ChanServ sets mode: +v ayoung16:18
*** sileht has joined #openstack-keystone16:19
*** albertom has joined #openstack-keystone16:19
*** boris-42_ is now known as boris-4216:19
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/23903916:20
*** fhubik is now known as fhubik_brb16:21
openstackgerritDave Chen proposed openstack/keystone: Fix the wrong method name  https://review.openstack.org/24395116:24
*** fhubik_brb is now known as fhubik16:25
*** davechen has joined #openstack-keystone16:28
*** gyee has joined #openstack-keystone16:28
*** ChanServ sets mode: +v gyee16:28
*** josecastroleon has quit IRC16:32
*** haneef_ has quit IRC16:36
*** marzif__ has quit IRC16:39
*** fhubik has quit IRC16:45
*** slberger1 has joined #openstack-keystone16:48
*** slberger has quit IRC16:50
*** urulama has quit IRC16:52
*** urulama has joined #openstack-keystone16:53
*** tonytan4ever has joined #openstack-keystone17:01
*** thedodd has quit IRC17:04
*** thedodd has joined #openstack-keystone17:04
*** bdossant has quit IRC17:05
*** RichardRaseley has joined #openstack-keystone17:10
*** petertr7_away is now known as petertr717:11
*** diazjf has quit IRC17:13
*** diazjf has joined #openstack-keystone17:14
*** diazjf has quit IRC17:15
*** jistr is now known as jistr|off17:16
*** jistr|off has quit IRC17:16
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/24392317:19
*** petertr7 is now known as petertr7_away17:22
*** petertr7_away is now known as petertr717:22
*** urulama has quit IRC17:24
*** urulama has joined #openstack-keystone17:25
*** ayoung has quit IRC17:27
*** davechen has left #openstack-keystone17:31
openstackgerritPaulo Ewerton Gomes Fragoso proposed openstack/keystone: API support for project cascade delete  https://review.openstack.org/24424817:35
*** markvoelker has quit IRC17:35
*** diazjf has joined #openstack-keystone17:36
*** spandhe has joined #openstack-keystone17:38
*** browne has joined #openstack-keystone17:44
*** shaleh has joined #openstack-keystone17:46
*** e0ne has quit IRC17:47
openstackgerritNathan Kinder proposed openstack/keystone: Remove hardcoded LDAP group schema from emulated enabled mix-in  https://review.openstack.org/24417317:49
*** petertr7 is now known as petertr7_away17:50
*** petertr7_away is now known as petertr717:51
*** su_zhang has joined #openstack-keystone17:53
*** tonytan4ever has quit IRC17:58
*** ninag has quit IRC18:02
*** ninag has joined #openstack-keystone18:02
*** ninag_ has joined #openstack-keystone18:04
*** ninag has quit IRC18:06
*** mylu has joined #openstack-keystone18:08
*** harlowja_ has quit IRC18:08
*** ninag_ has quit IRC18:09
*** henrynash has joined #openstack-keystone18:11
*** ChanServ sets mode: +v henrynash18:11
*** itlinux has joined #openstack-keystone18:12
*** diazjf has quit IRC18:13
*** mylu has quit IRC18:13
*** mylu has joined #openstack-keystone18:14
*** diazjf has joined #openstack-keystone18:15
*** itlinux has quit IRC18:16
openstackgerritAlberto Murillo proposed openstack/keystone: disable admin_token by default  https://review.openstack.org/18546418:17
*** jaosorior has quit IRC18:17
*** ninag has joined #openstack-keystone18:18
*** mylu has quit IRC18:18
*** itlinux has joined #openstack-keystone18:20
stevemar_lbragstad: i did the first few migrations, then davechen came in with endpoint filter18:21
lbragstadstevemar_ ah, cool18:21
*** e0ne has joined #openstack-keystone18:22
stevemar_lbragstad: might be a while til i get back to those patches, i came down with a cold and it's kicking my ass :(18:22
shalehlbragstad: did you see my reply to your comment on the new_endpoint_ref review? I'd like you to turn that -1 into a + :-)18:23
shalehlbragstad: thanks for the nitpicks BTW. Learning a bunch from the process.18:23
shalehlbragstad: stanek has not been around much the last few days or I would have badgered him already :-)18:24
*** mylu has joined #openstack-keystone18:25
*** urulama has quit IRC18:26
*** urulama has joined #openstack-keystone18:26
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_service_ref() consistently  https://review.openstack.org/23828318:26
lbragstadshaleh awesome, checking now18:27
lbragstadstevemar_ was that an invitation to address comments in your reviews?!18:27
*** diazjf has quit IRC18:27
*** boris-42 has quit IRC18:28
openstackgerrithenry-nash proposed openstack/keystone-specs: Augment token to indicate if it is scoped to the admin project  https://review.openstack.org/24223218:29
*** mylu has quit IRC18:29
*** mylu has joined #openstack-keystone18:29
*** itlinux has quit IRC18:29
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_region_ref() consistently  https://review.openstack.org/23830218:31
*** itlinux has joined #openstack-keystone18:31
*** markvoelker has joined #openstack-keystone18:31
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_endpoint_ref consistently  https://review.openstack.org/23775818:31
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_service_ref() consistently  https://review.openstack.org/23828318:32
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_region_ref() consistently  https://review.openstack.org/23830218:32
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_domain_ref consistently  https://review.openstack.org/24261518:32
*** mylu has quit IRC18:33
*** mylu has joined #openstack-keystone18:34
lbragstadshaleh ok, looks good to me.18:34
lbragstadshaleh i'll let dstanek follow up separately if he has additional concerns18:34
lbragstadstevemar_ I have a few cycles now if you want me to respin them18:35
shalehlbragstad: thanks. I am playing the rebase shell game now.18:35
*** gordc_ is now known as gordc18:35
lbragstadstevemar_ or I can wait and be the one to +2 when they are ready18:35
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_role_ref consistently  https://review.openstack.org/24270418:39
*** mylu has quit IRC18:39
*** mylu has joined #openstack-keystone18:40
shalehthat "rebase change" button is noisy18:40
samueldmqshaleh: after that, don't forget another 'git review -d' in the case you need further changes later18:42
*** mylu_ has joined #openstack-keystone18:42
*** harlowja has joined #openstack-keystone18:42
*** RichardRaseley has quit IRC18:42
*** mylu has quit IRC18:42
samueldmqshaleh: because that's going to be a commit you don't have locally, that's why I use to rebase locally and re-submit :)18:42
*** mylu_ has quit IRC18:43
*** mylu has joined #openstack-keystone18:44
*** harlowja_ has joined #openstack-keystone18:44
shalehsamueldmq: the rebase button does not appear to drop existing reviews whereas a new upload does18:44
*** harlowja has quit IRC18:44
shalehsamueldmq: BTW for thanks for nits, much appreciated.18:45
*** fawadkhaliq has quit IRC18:45
*** tyagiprince2010 has joined #openstack-keystone18:46
*** mylu has quit IRC18:46
samueldmqshaleh: my pleasure :)18:46
*** mylu has joined #openstack-keystone18:46
*** mylu has quit IRC18:47
shalehthese changes have been very monotonous. I have some emacs functions to help but it was easy to get lost in the braces and parens.18:47
*** mylu has joined #openstack-keystone18:47
tyagiprince2010Hii, I am trying to configure keystone according to my needs but I am unable to understand it. The thing I want to understand now is regarding caching.18:48
*** dims has joined #openstack-keystone18:48
tyagiprince2010I made a user and assigned it a token.. I am using pki token mechanism.18:48
tyagiprince2010Hii, I am trying to configure keystone according to my needs but I am unable to understand it. The thing I want to understand now is regarding caching. I made a user and assigned it a pki token. Then i deleted the user but the token was in the cache (I guess) and the user was still able to boot an instance and do various other activities.18:49
openstackgerrithenry-nash proposed openstack/keystone-specs: Correct a few token examples  https://review.openstack.org/24426618:49
shalehwho wants to tell tyagiprince2010 about PKI?18:50
tyagiprince2010Anyone please.. :P18:51
shalehtyagiprince2010: sorry, not my experience18:51
*** mylu has quit IRC18:52
tyagiprince2010shaleh: no issue. Waiting for adam young to come help me with some issues :P18:52
*** itlinux has quit IRC18:54
*** itlinux has joined #openstack-keystone18:55
tyagiprince2010shaleh: whats ur expertise?18:55
*** doug-fish has quit IRC18:56
shalehtyagiprince2010: I am still a journeyman, no expertise yet :-) My focus has been on K2K federation thus far.18:56
*** doug-fish has joined #openstack-keystone18:57
*** ayoung has joined #openstack-keystone18:58
*** ChanServ sets mode: +v ayoung18:58
*** daemontool has joined #openstack-keystone18:59
*** petertr7 is now known as petertr7_away18:59
slberger1what major problems could I run into if I upgraded Keystone to Liberty while all other services were still Kilo?19:01
*** slberger1 has left #openstack-keystone19:01
*** slberger1 has joined #openstack-keystone19:02
*** petertr7_away is now known as petertr719:02
*** doug-fish has quit IRC19:02
*** mylu has joined #openstack-keystone19:03
shalehslberger1: which token type are you using?19:04
slberger1@shaleh, fernet19:05
*** mylu has quit IRC19:06
*** tonytan4ever has joined #openstack-keystone19:06
*** mylu has joined #openstack-keystone19:07
*** mylu has quit IRC19:07
shalehslberger1: hmm, dunno. I have heard of success with UUID. Maybe others here or on the ops channel would know.19:07
*** mylu has joined #openstack-keystone19:08
slberger1@shaleh, thanks19:09
*** doug-fish has joined #openstack-keystone19:16
*** RichardRaseley has joined #openstack-keystone19:18
*** petertr7 is now known as petertr7_away19:20
*** urulama has quit IRC19:21
*** urulama has joined #openstack-keystone19:21
*** itlinux has quit IRC19:22
*** diazjf has joined #openstack-keystone19:25
tyagiprince2010shaleh: hey shaleh, could you provide me a web written document in simple language cuz I couldnt get why there is a need for federation.19:26
shalehtyagiprince2010: federation enables clouds ran by different people to share. Simple as that. Today it is only identity, so my ID badge let's me into your building. Eventually it will allow sharing resources. So my ID badge will let me use the vehicles from your factory at my factory.19:28
*** lhcheng has joined #openstack-keystone19:29
*** ChanServ sets mode: +v lhcheng19:29
tyagiprince2010shaleh: but why do we need this? I mean suppose i own a cloud. Why would I want somebody to use my resource? and what kind of resource are you talking about?19:30
*** lhcheng_ has joined #openstack-keystone19:30
*** josecastroleon has joined #openstack-keystone19:32
*** andery-mp has joined #openstack-keystone19:32
*** lhcheng has quit IRC19:33
*** aix has quit IRC19:33
andery-mpdstanek: Could you please see one more time my review https://review.openstack.org/#/c/215481/ I've added one patch as Brant asked me to add some tests. Thank you.19:34
*** mnaser has joined #openstack-keystone19:34
mnaserI've ran into this article that shows Fernet tokens are 400% slower to validate overall, "Determining why Fernet appears to be significantly slower that previously reported is my next mission. Stay tuned!" had no updates... has there been any investigations regarding the performance of fernet tokens? - http://dolphm.com/benchmarking-openstack-keystone-token-formats/#devstack-stable-kilo19:35
lbragstadmnaser yes19:36
mnaserlbragstad awesome, I found this outstanding issue as well .. https://bugs.launchpad.net/keystone/+bug/1489061 - dont know if that has to be updated19:36
openstackLaunchpad bug 1489061 in OpenStack Identity (keystone) "fernet token validation is slow" [Medium,Confirmed]19:36
*** RichardRaseley has quit IRC19:36
*** josecastroleon has quit IRC19:36
lbragstadwe introduced a couple patches to add caching around catalog retrieval and getting role assignments (both of which can be expensive).19:36
openstackgerritNathan Kinder proposed openstack/keystone: Remove hardcoded LDAP group schema from emulated enabled mix-in  https://review.openstack.org/24417319:37
lbragstadmnaser the patch to add caching to get_catalog landed in master, after liberty was cut19:37
lbragstadmnaser the patch to add caching to role assignments is still in review19:37
shalehtyagiprince2010: Imagine you have a collection of interesting data sitting around as Swift objects. I have some interesting code that could work on your data. Through federation (one day) I could process your data from my cloud and we both have quotas, history, CADF, etc.19:37
mnaserlbragstad: ah, so the latest liberty release is likely affected by this issue then19:38
lbragstadmnaser we're also looking at refactoring performance around revocation_events, which is something that is required by fernet19:38
lbragstadmnaser yes19:38
*** mylu has quit IRC19:38
lbragstadmnaser mfisch was one of the first people to hit the problem19:38
lbragstadif not *the* first19:38
*** petertr7_away is now known as petertr719:38
mnaserlbragstad: i see, i appreciate the information.. i'll see if slowly moving to working on master for our deployment is a possiblity..19:38
*** mylu has joined #openstack-keystone19:38
*** RichardRaseley has joined #openstack-keystone19:39
lbragstadmnaser fwiw, the performance related issued around fernet are closely tied to the size of the catalog in your deployment19:39
mnaser11 endpoints in total19:40
lbragstadmnaser since fernet doesn't store a token reference in the backend, keystone rebuilds the catalog and auth context when it validates a token, resulting in trips to the database to rebuild everything19:40
mnaseryeah i can imagine this causing a load, i can imagine a small workaround is moving to the templated catalog backend19:40
mnaserservice catalogs don't exactly change that often19:41
lbragstadmnaser exactly19:41
*** andery-mp has quit IRC19:41
lbragstadmnaser which was another reason for us to add caching to it19:41
lbragstadmnaser https://review.openstack.org/#/c/215212/  and https://review.openstack.org/#/c/215715/19:41
mnaseri really wish we could track off master but that would be a lot of work19:42
mnaserand im not sure howi t would work on a stability point of view19:43
lbragstadmnaser these were the performance improvements we notices with those two patches - https://gist.github.com/dolph/3bf24039b83a147eeb5c19:43
lbragstadmnaser yeah, i'm not sure if we can backport those to liberty, but i can check19:43
*** mylu has quit IRC19:44
*** mylu has joined #openstack-keystone19:45
*** mylu has quit IRC19:45
*** swebb has joined #openstack-keystone19:46
*** RichardRaseley has quit IRC19:48
*** mylu has joined #openstack-keystone19:50
mnaserlbragstad: from a deployment standpoint, it would be very ideal19:50
samueldmqhey keystoners!19:50
samueldmqIdentity API v3 only job is now non-voting in DevStack! https://review.openstack.org/#/c/241452/19:50
samueldmqstevemar_: jamielennox ^19:51
lbragstadmnaser understandable, let me do some checking19:51
samueldmqo/19:51
*** itlinux has joined #openstack-keystone19:53
*** RichardRaseley has joined #openstack-keystone19:54
*** lhcheng_ is now known as lhcheng19:54
*** ChanServ sets mode: +v lhcheng19:54
*** su_zhang has quit IRC19:55
*** su_zhang has joined #openstack-keystone19:56
shalehsamueldmq: yay20:01
openstackgerritLin Hua Cheng proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816120:02
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Address hacking check H405.  https://review.openstack.org/24388920:05
*** e0ne has quit IRC20:06
samueldmqshaleh: o/20:06
*** mylu has quit IRC20:07
*** mylu has joined #openstack-keystone20:07
*** su_zhang has quit IRC20:08
*** mylu has quit IRC20:11
*** petertr7 is now known as petertr7_away20:13
*** petertr7_away is now known as petertr720:13
openstackgerritwerner mendizabal proposed openstack/keystone: Consolidate the fernet provider validate_v3_token()  https://review.openstack.org/19687720:16
openstackgerritMerged openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/23903920:16
*** RichardRaseley has quit IRC20:20
*** petertr7 is now known as petertr7_away20:23
*** petertr7_away is now known as petertr720:23
*** petertr7 is now known as petertr7_away20:25
*** tonytan4ever has quit IRC20:26
*** petertr7_away is now known as petertr720:28
*** urulama has quit IRC20:28
*** urulama has joined #openstack-keystone20:29
openstackgerritSean Perry proposed openstack/keystone: Use unit.new_group_ref consistently  https://review.openstack.org/24327620:32
openstackgerritSean Perry proposed openstack/keystone: WIP Use unit.new_user_ref consistently  https://review.openstack.org/24387720:33
openstackgerritayoung proposed openstack/keystone: implied roles  https://review.openstack.org/24261420:37
htrutaguys that understand bandit20:42
htrutawhy isn't it ok to use try/except/pass specifying an exception in the except20:42
htrutaIMO, it should only catch the raw try/except/pass logic20:42
*** itlinux has quit IRC20:43
*** tonytan4ever has joined #openstack-keystone20:46
*** csoukup has quit IRC20:47
*** belmoreira has joined #openstack-keystone20:53
*** su_zhang has joined #openstack-keystone20:53
tjcocozzhtruta +120:57
*** su_zhang has quit IRC20:57
openstackgerritMerged openstack/keystone: Add test for security error with no message  https://review.openstack.org/23930020:58
*** su_zhang has joined #openstack-keystone20:59
*** zao has left #openstack-keystone20:59
*** lnxnut has joined #openstack-keystone20:59
shalehI see some test using "assertIs(True, foo)" and others using "assertTrue(foo)". Which one is preferred?21:02
openstackgerritHenrique Truta proposed openstack/keystone: Tests for projects acting as domains  https://review.openstack.org/21121921:02
openstackgerritHenrique Truta proposed openstack/keystone: Manager support for projects acting as domains  https://review.openstack.org/21344821:02
openstackgerritHenrique Truta proposed openstack/keystone: Projects acting as domains  https://review.openstack.org/23128921:03
openstackgerritHenrique Truta proposed openstack/keystone: Removes project.domain_id FK  https://review.openstack.org/23327421:03
openstackgerritHenrique Truta proposed openstack/keystone: Change project name constraints  https://review.openstack.org/15837221:03
openstackgerritHenrique Truta proposed openstack/keystone: Add is_domain parameter to get_project_by_name  https://review.openstack.org/21060021:03
shalehhtruta: https://github.com/openstack/bandit/blob/master/examples/try_except_pass.py21:04
shalehhtruta: if that helps21:04
henrynashdstanek, gyee, ayoung: any chance that one of you could take a quick look at https://review.openstack.org/#/c/242529/ - pretty easy I think and looks ready to go in…21:05
ayounghenrynash, was just reviewing your changes to the is_admin spec21:05
ayounghenrynash, do we really need to support V2 tokens this way?21:06
htrutashaleh: thanks. It did. but I still don't understand why the second case is bad, even if we put a specific exception21:06
henrynashayoung: so I wasn’t sure, to be honest, execpt if we think v2 tokens are going to be arround for a long time, then that means people couldn’t change their policy files to the new mechanism while they still had to cope with v2 tokens21:07
shalehhtruta: because it does not handle any OTHER exception that might occur21:07
shalehhtruta: try: foo; except FooException: pass21:07
shalehhtruta: what if that throws a BarException?21:07
ayounghenrynash, So the issue is that with V2, I am not certain how that would play with the policy check anyway21:07
ayoungI wasthinking along the lines of "make admins use V3"21:08
htrutashaleh: in my case, I don't care about BarException, it is a very specific logic that is successfull if FooException occurs, so I just move on21:08
*** mylu has joined #openstack-keystone21:08
ayounghenrynash, so...the other issue was that I don't know how to update the V2 docs21:09
*** pauloewerton has quit IRC21:09
henrynashayoung: on that, nor do I !!21:09
shalehhtruta: so you need to add some kind of indicator that says "I am only handling FooException"21:09
henrynashayoung: why don’t you thnk that v2 would work with policy checks?21:10
ayounghenrynash, because most of the V2 calls I've seen byopass policy inside Keystone...but I guess thatis orthoganal21:10
henrynashayoung: in keystone, that’s true21:11
ayounghenrynash, I kindof suspect that policy is broken for V221:11
*** daemontool has quit IRC21:11
htrutashaleh: I see21:11
ayoungIt just means a lot more testing21:11
shalehhtruta: if your are sure there is: https://github.com/openstack/bandit/blob/master/docs/source/tests/try_except_pass.rst#config-options21:11
ayounghenrynash,  Will require two config values: `admin_domain_name` and21:11
ayoung`admin_project_name` to allow the specification for the `admin` project. If21:11
ayoungonly `admin_domain_name` is specified, then the project acting as that21:11
ayoungdomain will be used.21:11
ayoungI'd rather not do that21:11
ayounghenrynash, lets leave it that both admin_project_name and admin_project_domain_name must be specified.  Period.21:12
shalehhtruta: if you add a "except Exception as e: raise e" below the pass line does that help?21:12
shalehhtruta: or is it specifically complaining that your are squelching FooException?21:13
henrynashayoung: brb21:13
htrutashaleh: it does not help. raising FooException is the normal flow. If it is raised, nothing else is raised21:13
htrutashaleh: but IMO, this flag you showed should be set False21:14
shalehhtruta: Reading the docs, their assertion is you should log the fact that you dropped the Exception on the floor. The check is that you simply pass and do nothing else.21:15
shalehhtruta: would a log(DEBUG, "ignoreing XYZ") be acceptable?21:15
openstackgerritMerged openstack/keystoneauth: Add XML matcher  https://review.openstack.org/24327121:16
*** timcline_ has quit IRC21:16
*** nbalaji has joined #openstack-keystone21:16
htrutashaleh: hm... I guess that would work21:17
shalehhtruta: in my experience those "I am supposed to ignore them" exceptions end up biting you at some point. The logging may help someone some day.21:18
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826421:19
htrutashaleh: that's not exactly the case, cause I'm not ignoring it, I'm using it to control the flow. take a look at L110 https://review.openstack.org/#/c/158372/118/keystone/resource/core.py21:19
nbalajirandom question:I am using keystone to authenticate the admin user and it looks like the first token to produce is not authorized for object storage but the tokens produced afterwards are fine to work as an auth token. Any ideas why this is hapenning?21:20
*** lhcheng has quit IRC21:23
shalehhtruta: hmm. You are ignoring the ProjectNotFound. That just happens to be an acceptable thing in this code. The linter cannot know that. A debug log would quiet the linter. If I were writing that code, I would have the catch right after the call to self.driver.get_project_by_name() and use a return instead of a pass. That way the exception block is as small as possible.21:24
*** RichardRaseley has joined #openstack-keystone21:25
openstackgerritayoung proposed openstack/keystone-specs: Augment token to indicate if it is scoped to the admin project  https://review.openstack.org/24223221:26
htrutashaleh: cool. I'll consider that. thanks21:26
*** gordc has quit IRC21:27
shalehhtruta: no problem21:27
*** lnxnut has quit IRC21:29
openstackgerritTom Cocozzello proposed openstack/keystone: Validate Distinguished Names  https://review.openstack.org/24100521:32
shalehhtruta: I put my thought into the review21:42
htrutashaleh: cool. thanks21:43
*** gordc has joined #openstack-keystone21:44
*** timcline has joined #openstack-keystone21:44
shalehhtruta: I am not keen on your solution of having it return msg when the msg may be bogus because the project did not exist.21:45
shalehhtruta: simply returning with no value may be sufficient.21:45
htrutashaleh: just saw it. nice approach21:46
*** belmoreira has quit IRC21:46
shalehhtruta: as I said, you should always try to make your exception blocks as small and directed as possible. You also want to convey intent. The implication of the existing try block is the return from get_project() is relevant. But it isn't.21:47
*** RichardRaseley has quit IRC21:47
openstackgerritLance Bragstad proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816121:47
*** RichardRaseley has joined #openstack-keystone21:48
*** mylu has quit IRC21:59
*** csoukup has joined #openstack-keystone22:00
openstackgerritNathan Kinder proposed openstack/keystone: Remove hardcoded LDAP group schema from emulated enabled mix-in  https://review.openstack.org/24417322:02
*** thedodd has quit IRC22:02
htrutashaleh: perfect. thanks for the tips22:02
*** thedodd has joined #openstack-keystone22:02
shalehhtruta: no worries22:03
shalehtjcocozz: I just -1'ed your Validate DN review. If you would like to hash things out in a PM session, let me know.22:05
* tjcocozz looking22:05
*** lhcheng has joined #openstack-keystone22:07
*** ChanServ sets mode: +v lhcheng22:07
*** ninag has quit IRC22:08
*** ninag has joined #openstack-keystone22:08
*** ninag has quit IRC22:13
openstackgerritLin Hua Cheng proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816122:14
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Address hacking check H405.  https://review.openstack.org/24388922:15
jamielennoxbknudson: i cannot see a way to get those exception strings generated22:15
jamielennoxwe would essentially need to stop autogenerating the api rst files22:15
jamielennoxdo you know any other way?22:16
bknudsonjamielennox: I'd have to try some stuff out.22:16
bknudsonThere's http://sphinx-doc.org/domains.html#directive-py:exception22:17
bknudsonand you can reference another excpetion in http://sphinx-doc.org/domains.html#role-py:exc22:17
jamielennoxbknudson: right and i'm looking through the autodoc docs, but they are automatically generated and not something i think i have control off22:17
*** petertr7 is now known as petertr7_away22:17
shalehlbragstad: jenkins is happy now, please push by endpoint_ref review22:18
jamielennoxbknudson: these would seem to go in the rst files though rather than something in the .py22:19
jamielennoxwhere would they go? the module doc?22:20
bknudsonjamielennox: you can put .. py:exception:: in the module docstring ... I did it before somewhere but I can't find it now.22:20
bknudsonotherwise I wonder if you can't put """ """ right after the E1 = E222:20
*** timcline has quit IRC22:21
bknudsonlike """ :exc:`keystoneauth.exception.Whatever` """22:21
openstackgerritBrant Knudson proposed openstack/keystone: Correct docstring warnings  https://review.openstack.org/24433322:21
*** edmondsw has quit IRC22:23
openstackgerritLin Hua Cheng proposed openstack/keystonemiddleware: Address hacking check H405.  https://review.openstack.org/23816122:23
*** mylu has joined #openstack-keystone22:24
shalehhow can Lin both upload a change and +2 a change?22:25
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Address hacking check H405.  https://review.openstack.org/24388922:26
bknudsonshaleh: core reviewers can +2 any change in keystonemiddleware.22:26
lhchengshaleh: I just fixed the nit from previous comment22:26
*** doug-fish has quit IRC22:27
shalehlhcheng: no offense intended lhcheng. It just surprised me.22:27
openstackgerritLance Bragstad proposed openstack/keystone: Add Fernet FAQ  https://review.openstack.org/24433722:27
*** doug-fish has joined #openstack-keystone22:28
lhchengshaleh: by doing this, we try to to reduce overhead of waiting for author to fix the comment.22:28
lbragstaddolphm stevemar_ ^22:28
shalehlhcheng: makes sense22:28
lhchengshaleh: no worries :)22:28
bknudsonI saw that the latest gerrit will allow you to make edits in the UI.22:28
lhchengbknudson: sweet!22:28
shalehlbragstad: jenkins is happy now, please push by endpoint_ref review22:29
* shaleh puts the food down so he can type better22:29
*** doug-fis_ has joined #openstack-keystone22:30
openstackgerritLin Hua Cheng proposed openstack/keystoneauth: Address hacking check H405  https://review.openstack.org/24388922:31
shalehlbragstad: thanks22:31
lbragstadshaleh no problem, thanks for the quick turn-arounds22:31
*** doug-fish has quit IRC22:32
shalehlbragstad: np. The last two will be users and projects.22:32
shalehBoth are fairly large22:32
lbragstadsweet22:32
openstackgerritTom Cocozzello proposed openstack/keystone: Validate Distinguished Names  https://review.openstack.org/24100522:33
shalehI am finishing projects currently. I need to spin up a devstack with LDAP to finish the users22:33
shalehtjcocozz: is ldap3 working for your code too now?22:33
*** mylu has quit IRC22:33
openstackgerritMerged openstack/keystone: Use list_role_assignments to get assignments by role_id  https://review.openstack.org/24252922:33
tjcocozzshaleh, yes it is :)22:33
shalehtjcocozz: excellent22:34
*** RichardRaseley has quit IRC22:34
*** doug-fis_ has quit IRC22:34
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826422:35
*** ninag has joined #openstack-keystone22:38
*** gordc has quit IRC22:38
*** RichardRaseley has joined #openstack-keystone22:38
*** doug-fish has joined #openstack-keystone22:43
*** pgbridge has quit IRC22:44
openstackgerritBrant Knudson proposed openstack/keystone: Document release notes process  https://review.openstack.org/24434322:46
*** doug-fish has quit IRC22:47
*** pgbridge has joined #openstack-keystone22:49
shalehtjcocozz: is there a reason you use the ldap module in the tests instead of just mocking out a pass and an exception?22:54
shalehtjcocozz: you only prove that errors occur. You never prove the code works :-)22:55
*** ninag has quit IRC22:57
*** ninag has joined #openstack-keystone22:57
*** ninag has quit IRC23:02
*** roxanaghe has quit IRC23:07
*** roxanaghe has joined #openstack-keystone23:08
openstackgerritJamie Lennox proposed openstack/python-keystoneclient: Map keystoneclient exceptions to keystoneauth  https://review.openstack.org/24386923:08
jamielennoxbknudson: it's not finished yet, but is the pattern ^ ok with you?23:09
bknudsonjamielennox: y, if it works... not sure what "A link to" means?23:10
bknudsonbtw -- are all these symbols deprecated?23:10
jamielennoxbknudson: I could use alias or reference to23:10
jamielennoxumm, i'm going to say not yet23:10
openstackgerritRon De Rose proposed openstack/keystone: Limit the number of roles a user can be assigned within a project  https://review.openstack.org/23994823:10
bknudsonI think "Alias" is good.23:10
jamielennoxat some point we're going to have to say that you should use keystoneauth1.session instead of the client one and deprecate ksc.session23:11
jamielennoxi think we deprecate the exceptions at that time23:11
bknudsonok, not ready to deprecate yet.23:11
jamielennoxbut i don't want to worry about that just yet23:11
bknudsonthere are some references to these exceptions in docstrings so could switch those now23:11
*** roxanaghe has quit IRC23:12
jamielennoxi don't mind, i expect the keystoneclient.exceptions to be used with the keystoneclient.session and same with keystoneauth23:13
*** BAKfr has quit IRC23:14
*** csoukup has quit IRC23:15
*** mylu has joined #openstack-keystone23:15
*** BAKfr has joined #openstack-keystone23:17
*** diazjf has quit IRC23:18
jamielennoxbknudson: whilst your here your -1 on https://review.openstack.org/#/c/243882/ you just want me to update the entrypoint in setup.cfg rather than import it from __init__.py23:18
bknudsonjamielennox: y, I figured you'd have to change setup.cfg23:19
jamielennoxbknudson: ok, that's easy i just wanted to check that's what you meant23:20
jamielennoxi just thought this way was a bit easier as i didn't have to update the class location in tests etc23:21
bknudsonthat's why we change setup.cfg and the paste file with #egg so that we had a level of indirection23:21
bknudsonit's easier for now but I think it's going to be confusing going forward since it's harder to grep for uses of it.23:22
*** gildub has joined #openstack-keystone23:24
*** slberger1 has left #openstack-keystone23:26
stevemar_lbragstad: not an invitation, just a heads up :)23:30
stevemar_samueldmq: nice23:30
*** diazjf has joined #openstack-keystone23:33
*** boris-42 has joined #openstack-keystone23:33
openstackgerritSteve Martinelli proposed openstack/keystone-specs: Correct a few token examples  https://review.openstack.org/24426623:37
openstackgerritMerged openstack/keystone: Use unit.new_endpoint_ref consistently  https://review.openstack.org/23775823:37
openstackgerritJamie Lennox proposed openstack/python-keystoneclient: Map keystoneclient exceptions to keystoneauth  https://review.openstack.org/24386923:39
*** su_zhang has quit IRC23:41
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/23826423:43
*** doug-fish has joined #openstack-keystone23:47
*** doug-fish has quit IRC23:50
shalehsamueldmq: remember us talking about the possibility of a parent patchset due to groups with enabled=True. Yeah it might come to that. I had the ones in test_v3_identity because the tox run fails without it.23:52
*** diazjf has quit IRC23:54
stevemar_looks like no more py26 anywhere23:58

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!