openstackgerrit | guang-yee proposed openstack/keystone master: update documentation for X.509 tokenless auth https://review.opendev.org/669790 | 00:28 |
---|---|---|
*** gyee has quit IRC | 00:28 | |
*** rcernin has quit IRC | 00:34 | |
*** rcernin has joined #openstack-keystone | 00:35 | |
*** dklyle has joined #openstack-keystone | 00:49 | |
*** irclogbot_1 has joined #openstack-keystone | 00:55 | |
*** irclogbot_1 has quit IRC | 01:00 | |
*** imacdonn has quit IRC | 01:14 | |
*** imacdonn has joined #openstack-keystone | 01:15 | |
*** irclogbot_2 has joined #openstack-keystone | 01:25 | |
*** rafaelweingartne has quit IRC | 01:32 | |
*** irclogbot_2 has quit IRC | 01:34 | |
*** irclogbot_3 has joined #openstack-keystone | 02:25 | |
*** irclogbot_3 has quit IRC | 02:30 | |
*** altlogbot_0 has joined #openstack-keystone | 02:47 | |
*** altlogbot_0 has quit IRC | 02:52 | |
*** awalende has joined #openstack-keystone | 02:59 | |
*** awalende has quit IRC | 03:03 | |
*** irclogbot_1 has joined #openstack-keystone | 03:21 | |
*** irclogbot_1 has quit IRC | 03:26 | |
openstackgerrit | pengyuesheng proposed openstack/python-keystoneclient master: Bump the openstackdocstheme extension to 1.20 https://review.opendev.org/668795 | 03:38 |
*** irclogbot_0 has joined #openstack-keystone | 03:51 | |
*** whoami-rajat has joined #openstack-keystone | 03:55 | |
*** irclogbot_0 has quit IRC | 03:56 | |
*** dklyle has quit IRC | 04:06 | |
*** rcernin has quit IRC | 04:54 | |
*** irclogbot_1 has joined #openstack-keystone | 04:59 | |
*** new_student1411 has joined #openstack-keystone | 05:07 | |
*** pcaruana has joined #openstack-keystone | 05:13 | |
*** jistr has quit IRC | 05:15 | |
*** new_student14119 has joined #openstack-keystone | 05:15 | |
openstackgerrit | Colleen Murphy proposed openstack/keystonemiddleware master: Add validation of app cred access rules https://review.opendev.org/633369 | 05:16 |
*** irclogbot_1 has quit IRC | 05:16 | |
*** jistr has joined #openstack-keystone | 05:18 | |
*** new_student1411 has quit IRC | 05:18 | |
*** altlogbot_1 has joined #openstack-keystone | 06:09 | |
*** altlogbot_1 has quit IRC | 06:14 | |
*** irclogbot_2 has joined #openstack-keystone | 06:35 | |
*** irclogbot_2 has quit IRC | 06:40 | |
*** ivve has joined #openstack-keystone | 06:46 | |
*** dancn has joined #openstack-keystone | 06:47 | |
*** awalende has joined #openstack-keystone | 07:23 | |
*** xek has joined #openstack-keystone | 07:36 | |
*** shyamb has joined #openstack-keystone | 07:49 | |
*** aning_ has quit IRC | 07:55 | |
*** shyamb has quit IRC | 07:59 | |
*** altlogbot_3 has joined #openstack-keystone | 08:01 | |
*** altlogbot_3 has quit IRC | 08:04 | |
*** aning has joined #openstack-keystone | 08:07 | |
*** aning__ has joined #openstack-keystone | 08:10 | |
*** altlogbot_2 has joined #openstack-keystone | 08:11 | |
*** aning has quit IRC | 08:12 | |
*** altlogbot_2 has quit IRC | 08:16 | |
*** altlogbot_1 has joined #openstack-keystone | 08:17 | |
*** tkajinam has quit IRC | 08:19 | |
*** altlogbot_1 has quit IRC | 08:22 | |
*** altlogbot_1 has joined #openstack-keystone | 08:23 | |
*** altlogbot_1 has quit IRC | 08:28 | |
*** shyamb has joined #openstack-keystone | 08:46 | |
*** altlogbot_0 has joined #openstack-keystone | 08:53 | |
*** altlogbot_0 has quit IRC | 08:58 | |
*** irclogbot_1 has joined #openstack-keystone | 08:59 | |
*** irclogbot_1 has quit IRC | 09:04 | |
*** shyamb has quit IRC | 10:05 | |
*** irclogbot_0 has joined #openstack-keystone | 10:31 | |
*** irclogbot_0 has quit IRC | 10:38 | |
*** shyamb has joined #openstack-keystone | 10:40 | |
*** irclogbot_2 has joined #openstack-keystone | 10:41 | |
*** irclogbot_2 has quit IRC | 10:44 | |
*** rafaelweingartne has joined #openstack-keystone | 10:53 | |
rafaelweingartne | Hello guys, we noticed that Keystone is not pushing event messages to RabbitMQ;it seems related to "CONF.notification_format " being "cadf" by default. | 10:54 |
rafaelweingartne | Looking at the code, it looks like if we set the config to 'basic', then it would work.However, we wonder. If we want to use cadf. Do we need some extra config?I am assuming Keystone will keep using oslo.messaging for this job as well. | 10:54 |
*** ivve has quit IRC | 11:01 | |
*** ivve has joined #openstack-keystone | 11:01 | |
*** altlogbot_1 has joined #openstack-keystone | 11:03 | |
*** shyam89 has joined #openstack-keystone | 11:08 | |
*** altlogbot_1 has quit IRC | 11:08 | |
*** shyamb has quit IRC | 11:08 | |
*** tesseract has joined #openstack-keystone | 11:08 | |
*** altlogbot_1 has joined #openstack-keystone | 11:12 | |
*** altlogbot_1 has quit IRC | 11:16 | |
*** shyam89 has quit IRC | 11:39 | |
*** shyam89 has joined #openstack-keystone | 11:48 | |
*** altlogbot_0 has joined #openstack-keystone | 12:07 | |
*** altlogbot_0 has quit IRC | 12:08 | |
*** markvoelker has quit IRC | 12:45 | |
*** viks___ has quit IRC | 12:46 | |
*** viks___ has joined #openstack-keystone | 12:48 | |
*** dancn has quit IRC | 12:50 | |
*** raildo has joined #openstack-keystone | 13:03 | |
*** whoami-rajat has quit IRC | 13:25 | |
*** whoami-rajat has joined #openstack-keystone | 13:25 | |
*** shyam89 has quit IRC | 13:33 | |
*** vishalmanchanda has quit IRC | 13:35 | |
*** irclogbot_0 has joined #openstack-keystone | 13:35 | |
*** irclogbot_0 has quit IRC | 13:38 | |
*** irclogbot_2 has joined #openstack-keystone | 14:09 | |
*** FlorianFa has quit IRC | 14:11 | |
openstackgerrit | Nate Johnston proposed openstack/keystonemiddleware master: Fix context issue for neutron audit https://review.opendev.org/508659 | 14:12 |
*** altlogbot_0 has joined #openstack-keystone | 14:13 | |
*** ivve has quit IRC | 14:14 | |
openstackgerrit | Nate Johnston proposed openstack/keystonemiddleware master: Fix context issue for neutron audit https://review.opendev.org/508659 | 14:26 |
*** awalende has quit IRC | 14:27 | |
openstackgerrit | Vadym Markov proposed openstack/oslo.policy master: Correctly handle IO errors at policy file load https://review.opendev.org/670571 | 14:27 |
*** awalende has joined #openstack-keystone | 14:27 | |
*** awalende has quit IRC | 14:31 | |
*** bnemec is now known as beekneemech | 14:34 | |
*** hoonetorg has quit IRC | 14:40 | |
*** rafaelweingartne has quit IRC | 14:41 | |
*** TheJulia is now known as needssleep | 14:52 | |
*** markvoelker has joined #openstack-keystone | 14:53 | |
*** kplant has joined #openstack-keystone | 14:55 | |
*** markvoelker has quit IRC | 14:56 | |
*** hoonetorg has joined #openstack-keystone | 14:56 | |
*** awalende has joined #openstack-keystone | 14:59 | |
*** awalende has quit IRC | 15:04 | |
kplant | could anyone recommend an article for configuring keystone-to-keystone federation? | 15:06 |
*** ayoung has quit IRC | 15:12 | |
*** ayoung has joined #openstack-keystone | 15:12 | |
*** Krenair has quit IRC | 15:20 | |
*** Krenair has joined #openstack-keystone | 15:34 | |
*** ayoung has quit IRC | 15:44 | |
*** ayoung has joined #openstack-keystone | 15:48 | |
openstackgerrit | Michael Bayer proposed openstack/keystone master: Allow JsonBlob to accommodate SQL NULL result sets https://review.opendev.org/670592 | 15:59 |
*** gyee has joined #openstack-keystone | 16:01 | |
cmurphy | somewhat dense change but could i ask for reviews on https://review.opendev.org/633369 it's green now | 16:04 |
openstackgerrit | Vadym Markov proposed openstack/oslo.policy master: Correctly handle IO errors at policy file load https://review.opendev.org/670571 | 16:04 |
kmalloc | cmurphy: reading. | 16:05 |
cmurphy | ty | 16:05 |
cmurphy | also an easier ksm one https://review.opendev.org/659994 | 16:05 |
kmalloc | the migrations and ro for all stuff is really going slow because of the construction | 16:05 |
kmalloc | at least code review i can do with the noise | 16:05 |
kmalloc | cmurphy: so far i like it... but i just read the commit message no code :P | 16:06 |
kmalloc | >.> | 16:06 |
kmalloc | <.< | 16:06 |
kmalloc | ^_^ | 16:06 |
cmurphy | that's half the battle | 16:06 |
kmalloc | one comment, a release note would be good to add (followup is fine) | 16:07 |
cmurphy | ah good point | 16:07 |
kmalloc | is this the last blueprint?! woooooo | 16:07 |
cmurphy | i think so | 16:07 |
kmalloc | is the _path_matches intended to convert to PCRE compat regex? | 16:10 |
kmalloc | (re module) | 16:10 |
kmalloc | cmurphy: it might actually be easier (long term) to create path groups where {tag} is a token and ** is a token, then iterate through and re-construct the path replacing {tag} with * and ** with .*. | 16:13 |
kmalloc | I know.. that comment is stupid dense. | 16:14 |
cmurphy | kmalloc: yeah it's supposed to be converting it from a glob to a regex, definitely would like to make that prettier and more sustainable | 16:14 |
kmalloc | yeah best bet is to straight up split into groups and then iterate and swap, prevents odd behavior where {tag}* [bad rule] turns into potentially ** | 16:15 |
kmalloc | and then turns into .* inappropriately | 16:15 |
kmalloc | i think the rules are more fragile with this conversion than they need to be, but.... I am not seeing a reason to swap it here. | 16:16 |
kmalloc | we should fix in a followup. | 16:16 |
kmalloc | I would like to see some explicit glob->regex conversion tests. | 16:16 |
kmalloc | not through the middleware itself. but really just confirm the _path_matches works as expected. | 16:17 |
cmurphy | i am happy to change it now, it's definitely hairy and if it's messed up it's a security vulnerability | 16:17 |
* kmalloc nods. | 16:17 | |
kmalloc | i'm still reading it | 16:17 |
kmalloc | making sure it doesn't break anything | 16:17 |
kmalloc | any glob->regex is going to be risky, i don't care which one we have to start as long as we iterate to make it better in the long run | 16:18 |
kmalloc | but a high confidence that we default to a broken rule means denial over overly broad acceptance is my only concern :) | 16:18 |
kmalloc | so, do we have an example of the {tag} based path we're subbing {tag} to *. | 16:19 |
kmalloc | erm to "*" not "*." | 16:19 |
cmurphy | kmalloc: in the client fixtures line 370 and 385 | 16:21 |
kmalloc | ++ yeah haven't gotten through the whole review. | 16:22 |
*** awalende has joined #openstack-keystone | 16:29 | |
*** awalende has quit IRC | 16:33 | |
kmalloc | cmurphy: ok i have comments on the glob->regex | 16:34 |
kmalloc | cmurphy: i'm still reviewing but wanted to get those up fast for you. | 16:34 |
cmurphy | thanks kmalloc | 16:35 |
*** xek has quit IRC | 17:53 | |
*** xek has joined #openstack-keystone | 17:53 | |
*** kplant has quit IRC | 18:04 | |
*** new_student14119 has quit IRC | 18:19 | |
openstackgerrit | Merged openstack/keystonemiddleware master: print auth version for request strategy in debug https://review.opendev.org/659994 | 18:27 |
openstackgerrit | Michael Bayer proposed openstack/keystone master: Allow JsonBlob to accommodate SQL NULL result sets https://review.opendev.org/670592 | 18:46 |
*** irclogbot_2 has quit IRC | 18:49 | |
*** edmondsw_ has quit IRC | 18:49 | |
*** irclogbot_2 has joined #openstack-keystone | 18:52 | |
kmalloc | zzzeek: for the null jsonblob, should it explicitly cast to a {} instead of a None being in the spirit of empty json? otherwise that change looks fine to me. | 19:02 |
kmalloc | s/cast/return | 19:03 |
zzzeek | kmalloc: are you referring to the test case ? | 19:04 |
kmalloc | no the actual return | 19:04 |
kmalloc | so, if value is None, return {} | 19:04 |
zzzeek | kmalloc: the actual return is accurate IMO | 19:04 |
kmalloc | being that {} is valid "json" in python parlance | 19:04 |
zzzeek | JSON has 'null', that's valid json | 19:04 |
zzzeek | >>> import json | 19:05 |
zzzeek | >>> json.loads('null') is None | 19:05 |
kmalloc | ah. | 19:05 |
kmalloc | i was thinking the inverse | 19:05 |
kmalloc | nvm, lgtm | 19:05 |
zzzeek | {} OTOH is not None, it's an empty dict :) | 19:05 |
kmalloc | construction outside my house is making my brain ... angry | 19:05 |
kmalloc | and it's been going on for 2 weeks... only another ... 1-2 months of this to go | 19:06 |
zzzeek | kmalloc: same here ! sqla has JSON datatypes which is why ive been aroudn this block already | 19:06 |
zzzeek | (construction outside) | 19:06 |
kmalloc | yeah they're replacing gas mains here =/ | 19:06 |
kmalloc | dude, construction SUCKS. | 19:06 |
zzzeek | we have a contractor putting in posts he hit my sprinkler lines twice | 19:06 |
kmalloc | anyway, +2 to your change, upgrading. | 19:06 |
kmalloc | *eyeroll* HOW DO YOU HIT A ... anyway | 19:07 |
zzzeek | well you dig a hole and htere is it, sorta | 19:07 |
kmalloc | like... do people not even check these things anymore? | 19:07 |
kmalloc | sure... but, you'd think there would be the minimal "is there something here?" before you start digging. | 19:07 |
zzzeek | welp guy just fixed it so. that's done | 19:12 |
*** tesseract has quit IRC | 19:33 | |
*** whoami-rajat has quit IRC | 19:45 | |
*** pcaruana has quit IRC | 20:59 | |
*** raildo has quit IRC | 21:01 | |
*** xek has quit IRC | 22:05 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!