*** wxy-xiyuan has joined #openstack-keystone | 01:17 | |
wxy-xiyuan | \o I was on vacation last week. Backing now. :) | 01:47 |
---|---|---|
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update log translation hacking check https://review.openstack.org/604245 | 02:11 |
kmalloc | wxy-xiyuan: welcome back. | 02:56 |
* kmalloc afks again. | 02:56 | |
wxy-xiyuan | kmalloc: lol | 03:03 |
kmalloc | cmurphy: re-iterated the -1 on https://review.openstack.org/#/c/603542/, I am a little disappointed in the committer's response to your comment =/ | 03:05 |
kmalloc | cmurphy: let me know if you change your mind re oslo uuid generation, but I think you and I are much in the same state of mind on this one. | 03:05 |
kmalloc | wxy-xiyuan: if you need some brain breaking code review, there is an awful flask patch (~3500 lines) that needs core eyes. that said, afaict the gate is broken at the moment :P | 03:06 |
kmalloc | so... no rush until we get going | 03:06 |
wxy-xiyuan | kmalloc: https://review.openstack.org/#/c/603461 yeah, I'm looking it now. | 03:07 |
kmalloc | wxy-xiyuan: it's brutal... and in as many words: I'm sorry | 03:08 |
kmalloc | ;) | 03:08 |
*** ayoung has quit IRC | 04:00 | |
*** pooja_jadhav has joined #openstack-keystone | 04:33 | |
openstackgerrit | Merged openstack/keystone master: Avoid using dict.get() in assertions https://review.openstack.org/607463 | 04:56 |
*** shyamb has joined #openstack-keystone | 04:59 | |
*** shyamb has quit IRC | 05:05 | |
*** sheel has joined #openstack-keystone | 05:11 | |
*** shyamb has joined #openstack-keystone | 05:20 | |
*** aojea has joined #openstack-keystone | 05:37 | |
*** aojea has quit IRC | 05:48 | |
*** felipemonteiro has quit IRC | 05:49 | |
*** shyamb has quit IRC | 06:02 | |
*** shyamb has joined #openstack-keystone | 06:05 | |
*** rcernin has quit IRC | 07:21 | |
*** shyamb has quit IRC | 07:48 | |
*** belmoreira has joined #openstack-keystone | 08:17 | |
openstackgerrit | Merged openstack/keystone master: Follow Zuul job rename https://review.openstack.org/608337 | 08:17 |
openstackgerrit | Merged openstack/keystone master: Docs: Remove the TokenAuth middleware https://review.openstack.org/572248 | 08:36 |
*** shyamb has joined #openstack-keystone | 08:55 | |
*** jrist has joined #openstack-keystone | 08:57 | |
*** jrist has quit IRC | 09:02 | |
*** jrist has joined #openstack-keystone | 09:13 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Enable foreign keys for unit test https://review.openstack.org/558193 | 09:28 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 09:30 |
*** shyamb has quit IRC | 09:41 | |
*** shyamb has joined #openstack-keystone | 09:43 | |
*** jaosorior has joined #openstack-keystone | 10:26 | |
*** shyamb has quit IRC | 10:29 | |
*** rcernin has joined #openstack-keystone | 10:35 | |
*** gvrangan has joined #openstack-keystone | 10:42 | |
*** shyamb has joined #openstack-keystone | 11:05 | |
*** gvrangan has quit IRC | 11:08 | |
*** rcernin has quit IRC | 11:17 | |
*** belmorei_ has joined #openstack-keystone | 11:48 | |
*** jrist has quit IRC | 11:49 | |
*** jrist has joined #openstack-keystone | 11:50 | |
*** belmoreira has quit IRC | 11:51 | |
*** jrist has quit IRC | 11:54 | |
*** jrist has joined #openstack-keystone | 11:57 | |
*** shyamb has quit IRC | 12:01 | |
*** shyamb has joined #openstack-keystone | 12:01 | |
*** raildo has joined #openstack-keystone | 12:02 | |
*** shyam89 has joined #openstack-keystone | 12:50 | |
*** shyamb has quit IRC | 12:51 | |
*** lbragstad has joined #openstack-keystone | 12:54 | |
*** ChanServ sets mode: +o lbragstad | 12:54 | |
*** shyam89 has quit IRC | 13:09 | |
*** shyam89 has joined #openstack-keystone | 13:11 | |
*** lbragstad has quit IRC | 13:24 | |
*** shyam89 has quit IRC | 13:30 | |
*** lbragstad has joined #openstack-keystone | 13:32 | |
*** ChanServ sets mode: +o lbragstad | 13:32 | |
*** jaosorior has quit IRC | 13:39 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.policy master: Add guidelines for naming policies https://review.openstack.org/606214 | 13:47 |
hrybacki | o/ | 13:49 |
*** sheel has quit IRC | 13:50 | |
lbragstad | is r.o.o a little slow for anyone else? | 13:53 |
*** kukacz has quit IRC | 13:54 | |
*** kukacz has joined #openstack-keystone | 13:54 | |
cmurphy | wb lbragstad | 13:54 |
lbragstad | thanks :) | 13:55 |
lbragstad | i've barely waded through emails, but did everything go well last week? | 13:55 |
cmurphy | lbragstad: ya everything was fine, pretty quiet :) | 14:00 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update doc string for transform_to_group_ids https://review.openstack.org/608681 | 14:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Update doc string for transform_to_group_ids https://review.openstack.org/608681 | 14:03 |
*** munimeha1 has joined #openstack-keystone | 14:08 | |
*** SteelyDan is now known as dansmith | 14:13 | |
kmalloc | lbragstad: you're back! | 14:21 |
kmalloc | lbragstad: don't work too hard this week ;) | 14:21 |
*** beekneemech is now known as bnemec | 14:22 | |
lbragstad | kmalloc good mornin' | 14:31 |
* lbragstad is in a blissful state of delirium | 14:32 | |
lbragstad | hrybacki are we planning on proposing a community goal for T? | 14:34 |
hrybacki | lbragstad: no -- we will need to wrap up the scope bugs in keystone first | 14:35 |
hrybacki | those prob, wont get resolved until T | 14:35 |
hrybacki | and im one handed for six weeks | 14:35 |
gagehugo | o/ | 14:40 |
*** Emine has joined #openstack-keystone | 14:49 | |
*** itlinux has quit IRC | 14:50 | |
cmurphy | lbragstad: kmalloc easy stable review https://review.openstack.org/603355 | 14:52 |
cmurphy | i noticed gagehugo had marked like 5 bugs as duplicates of that one | 14:52 |
gagehugo | cmurphy it was happening nearly every week | 14:53 |
gagehugo | :( | 14:53 |
mbuil | hello guys, not sure if this question belongs exactly to keystone, if not please tell me. Is it expected that an admin user from project_B can remove the floating ips created (and assigned to a VM) by an admin user from project_A? | 15:01 |
*** dklyle has joined #openstack-keystone | 15:04 | |
lbragstad | mbuil yeah - unfortunately that's documented here https://bugs.launchpad.net/keystone/+bug/968696 | 15:06 |
openstack | Launchpad bug 968696 in OpenStack Identity (keystone) ""admin"-ness not properly scoped" [High,In progress] - Assigned to Lance Bragstad (lbragstad) | 15:06 |
lbragstad | mbuil we're working to address it, but it's an involved plan | 15:08 |
lbragstad | and spans nearly every openstack project | 15:08 |
mbuil | lbragstad: waw!!! I see I am not exactly the first one who hit this issue :P | 15:08 |
mbuil | lbragstad: thanks for the pointer. What role would you recommend me to use in for my "users"? | 15:09 |
lbragstad | that is going to depend on your deployment, but there is what we're trying to do upstream | 15:10 |
lbragstad | http://specs.openstack.org/openstack/keystone-specs/specs/keystone/rocky/define-default-roles.html | 15:10 |
lbragstad | and this is how we're fixing those issues in keystone specifically - https://bugs.launchpad.net/keystone/+bugs?field.tag=policy | 15:11 |
mbuil | lbragstad: thanks! I have a long text to read ;) | 15:18 |
lbragstad | mbuil yeah - it's a lot of information | 15:18 |
lbragstad | http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/policy-goals.html attempts to be more concise | 15:19 |
*** Emine has quit IRC | 15:21 | |
mbuil | lbragstad: thanks! | 15:23 |
lbragstad | mbuil no problem - don't hesitate to ask questions if you have any... it's a lengthy topic | 15:38 |
openstackgerrit | Harry Rybacki proposed openstack/keystone master: WIP: Convert projects API to Flask https://review.openstack.org/603451 | 15:41 |
*** itlinux has joined #openstack-keystone | 15:43 | |
*** jrist has quit IRC | 16:07 | |
*** belmorei_ has quit IRC | 16:11 | |
*** jrist has joined #openstack-keystone | 16:12 | |
*** jrist has quit IRC | 16:17 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Repropose JWT specification for Stein https://review.openstack.org/541903 | 16:21 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Repropose JWT specification for Stein https://review.openstack.org/541903 | 16:22 |
*** aojea has joined #openstack-keystone | 16:38 | |
*** aojea has quit IRC | 16:42 | |
*** gyee has joined #openstack-keystone | 16:48 | |
prometheanfire | new oslo-messaging seems to be breaking things http://logs.openstack.org/21/607521/2/check/cross-keystone-py35/908a1c2/testr_results.html.gz | 16:50 |
lbragstad | prometheanfire looks like keystone attempts to mock an internal method of oslo.messaging :( | 17:03 |
lbragstad | https://github.com/openstack/keystone/blob/baa3d9967c18ed53c14a6535e6757fb14006b9d6/keystone/tests/unit/common/test_notifications.py#L1343-L1344 | 17:05 |
kmalloc | lbragstad: yeah, it was (a while ago) a requirement. | 17:06 |
lbragstad | the mock you mean? | 17:06 |
kmalloc | yeah | 17:06 |
kmalloc | with flask i am fairly certain I can undo that ick | 17:06 |
kmalloc | oh nope, different one | 17:07 |
kmalloc | that test should really be removed | 17:07 |
kmalloc | we don't need to test oslo_messaging/cadf | 17:07 |
kmalloc | those libraries test themselves. | 17:08 |
kmalloc | we control "send_audit_notifications and should test/instrument in that | 17:08 |
kmalloc | *eyeroll* | 17:08 |
kmalloc | and this was probably my fault | 17:08 |
kmalloc | anyway. i vote for "rm -rf" that test for now | 17:09 |
kmalloc | lbragstad: unrelated - https://review.openstack.org/#/c/601882/ should be a quick promote from +1 to +2/+a with your comment addressed | 17:10 |
lbragstad | ack | 17:13 |
lbragstad | bah | 17:17 |
kmalloc | ? | 17:18 |
lbragstad | http://logs.openstack.org/21/607521/2/check/cross-keystone-py35/908a1c2/testr_results.html.gz shows that what we're trying to mock is False | 17:18 |
lbragstad | and because we rely on diaper defense with a except Exception | 17:18 |
kmalloc | yeah, just remove the test | 17:18 |
kmalloc | I'll spin up a new test that doesn't suck quickly before I handle the comments on Auth patch | 17:18 |
kmalloc | cmurphy, wxy-xiyuan: Users patch proposal, hopefully wont block auth landing. Users is going to take some time. | 17:19 |
lbragstad | AttributeError: 'NoneType' object has no attribute 'split' | 17:19 |
lbragstad | fails to init a Notifier because of that^ | 17:19 |
kmalloc | cmurphy, wxy-xiyuan: re the temporary split of authentication/_authentication in identity_api. | 17:19 |
lbragstad | thanks kmalloc | 17:20 |
kmalloc | the cleanup requires 100% of /users to be ported. | 17:20 |
kmalloc | lbragstad: so, propose a quick comment out or @skip test | 17:20 |
kmalloc | and i'll push that through | 17:20 |
kmalloc | then we can play cleanup on the test/code here soon | 17:20 |
lbragstad | actually - https://github.com/openstack/oslo.messaging/commit/172cfb33f3ee207531a9e82fbc8293d24009a256 might fix it? | 17:21 |
kmalloc | mebbe | 17:23 |
kmalloc | but i would just self.skipTest() then work on fixing. | 17:23 |
lbragstad | yeah... | 17:23 |
kmalloc | because the fix really should be "don't test oslo.messaging" | 17:23 |
lbragstad | the fix for using rabbit:// isn't released yet | 17:24 |
kmalloc | it's like testing "does python work", we rely on oslo.messaging, we should test our interface to it, not the lib itself. | 17:24 |
lbragstad | agreed | 17:24 |
kmalloc | or we should simply not trust it :P | 17:24 |
lbragstad | we rely on that specific method mock to verify functionality we've written into keystone | 17:28 |
kmalloc | right, so we should abstract out that mechanism to ensure we're not doing something stupid when we pass into CADF. | 17:28 |
kmalloc | OR we wait for rabbit:// | 17:28 |
kmalloc | s/CADF/oslo.messaging | 17:29 |
*** aojea has joined #openstack-keystone | 17:29 | |
lbragstad | prometheanfire actually - installing oslo.messaging with https://github.com/openstack/oslo.messaging/commit/172cfb33f3ee207531a9e82fbc8293d24009a256 locally passes keystone tests locally | 17:38 |
prometheanfire | lbragstad: :D | 17:42 |
lbragstad | so - we can either skip those tests for the time being, remove them, or blacklist version 9.0.0 | 17:42 |
lbragstad | i'd be inclined to do the third option since skipping the tests will mean skipping them all regardless of the version of oslo.messaging installed | 17:43 |
lbragstad | if we blacklist 9.0.0 until version 9.1.0 or 9.0.1 is released, then we at least keep the test coverage (which could still undergo some investigation per kmalloc's point) | 17:44 |
prometheanfire | lbragstad: ya, if it's a bug in oslo-messaging then blacklisting makes sense | 17:44 |
kmalloc | but black listing the release because we mocked an internal method? | 17:44 |
kmalloc | i'm inclined to say skip because any mock of internal stuff that is in an external library is subject to "oh, we broke you... sorry not sorry" | 17:46 |
lbragstad | i'm not saying we shouldn't revisit those tests, most oslo interfaces are pretty solid, so if we're mocking an internal thing of oslo then we probably need to revisit how those tests are written | 17:46 |
openstackgerrit | ayoung proposed openstack/keystone master: Add federated support for get user https://review.openstack.org/448730 | 17:55 |
openstackgerrit | Merged openstack/oslo.policy master: sphinxext: Start parsing 'DocumentedRuleDefault.description' as rST https://review.openstack.org/594222 | 18:00 |
kmalloc | exactly | 18:17 |
*** imacdonn has quit IRC | 18:23 | |
*** imacdonn has joined #openstack-keystone | 18:23 | |
hrybacki | kmalloc: do we have grants documented outside of the api ref? | 18:29 |
kmalloc | hrybacki: probably not | 18:30 |
hrybacki | ack | 18:30 |
cmurphy | kmalloc: i don't think it's appropriate to leave notifications broken for an indefinite amount of time, so no i would prefer not to land the auth patch until there's at least a rough proposal up to unbreak it | 18:43 |
kmalloc | it's going to be the entire user -> flask patch | 18:51 |
kmalloc | i only ask because i don't think i can maintain that patch through any real level of rebasing. | 18:51 |
kmalloc | i don't expect it to take long, but honestly, it took 10 days of work to chase the auth stuff. | 18:52 |
kmalloc | it's a single notification on password change. | 18:52 |
kmalloc | self-service password change* | 18:52 |
kmalloc | everything else has the normal notifications. | 18:53 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Convert auth to flask native dispatching https://review.openstack.org/603461 | 19:31 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Auth flask conversion cleanup https://review.openstack.org/608756 | 19:31 |
lbragstad | knikolla kmalloc does https://review.openstack.org/#/c/373983/ have any intersection with what we talked about at the PTG? | 19:57 |
lbragstad | specifically with the keystone as an idp proxy? | 19:57 |
*** lbragstad has quit IRC | 20:37 | |
*** lbragstad has joined #openstack-keystone | 20:37 | |
*** ChanServ sets mode: +o lbragstad | 20:37 | |
*** pcaruana has quit IRC | 20:49 | |
*** raildo has quit IRC | 20:57 | |
kmalloc | lbragstad: will need to look in a bit | 20:59 |
*** prometheanfire has left #openstack-keystone | 20:59 | |
lbragstad | kmalloc ack - wanted to ping in case you haven't seen it yet | 21:00 |
*** itlinux has quit IRC | 21:08 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Auth flask conversion cleanup https://review.openstack.org/608756 | 21:43 |
*** aojea has quit IRC | 21:44 | |
*** aojea has joined #openstack-keystone | 21:45 | |
*** aojea has quit IRC | 21:49 | |
openstackgerrit | Merged openstack/keystone master: Add release names to api-ref https://review.openstack.org/608212 | 22:00 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement scaffolding for upgrade checks https://review.openstack.org/608785 | 22:26 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement scaffolding for upgrade checks https://review.openstack.org/608785 | 22:31 |
*** munimeha1 has quit IRC | 22:50 | |
*** rcernin has joined #openstack-keystone | 22:50 | |
*** dave-mccowan has joined #openstack-keystone | 22:51 | |
kmalloc | cmurphy, ayoung: I don't think i can move render_token into api, it becomes hell for circular references, unfortunately rbac enforcer must rely on it | 23:07 |
kmalloc | so, going to roll that part back and leave it in common. | 23:07 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Auth flask conversion cleanup https://review.openstack.org/608756 | 23:14 |
*** lbragstad has quit IRC | 23:16 | |
*** gyee has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!