| *** markvoelker has joined #openstack-security | 00:13 | |
| *** zul has quit IRC | 00:14 | |
| ccneill | looks like I'm getting slightly better performance testing locally.. | 00:17 |
|---|---|---|
| unrahul | neat! | 00:21 |
| unrahul | I wish we had few more days for neutron.. | 00:21 |
| unrahul | what say ccneill ? | 00:21 |
| unrahul | can we.extend? | 00:21 |
| ccneill | yeah.. I think we may have to revisit our approach a little.. | 00:22 |
| ccneill | especially with this being a short week, and it taking a full day to get all the templates done | 00:22 |
| unrahul | yea.. I guess we had kept 1 or 2 days as `gap` days.. | 00:22 |
| unrahul | it would be helpful if we could extend till tuesday .. | 00:22 |
| ccneill | hmm | 00:24 |
| ccneill | I've been thinking maybe we need to split up to test the remaining projects | 00:24 |
| unrahul | yeah, I agree. | 00:25 |
| unrahul | will give us more time on the project too | 00:25 |
| ccneill | it's going significantly faster locally without burp than remote+burp | 00:29 |
| *** browne has quit IRC | 00:56 | |
| unrahul | awesome ccneill | 01:02 |
| *** jass93 has joined #openstack-security | 01:19 | |
| openstackgerrit | chen.xing proposed openstack/security-doc: Set the picture width https://review.openstack.org/367143 | 01:37 |
| *** knangia has quit IRC | 01:41 | |
| *** zhihui has joined #openstack-security | 01:50 | |
| *** yeison has joined #openstack-security | 02:02 | |
| *** yeison has left #openstack-security | 02:02 | |
| *** julian1 has quit IRC | 02:26 | |
| *** julian1 has joined #openstack-security | 02:27 | |
| *** browne has joined #openstack-security | 02:28 | |
| *** salv-orl_ has joined #openstack-security | 02:30 | |
| *** salv-orlando has quit IRC | 02:33 | |
| *** browne has quit IRC | 02:43 | |
| *** vinaypotluri has quit IRC | 03:02 | |
| *** dikonoor has joined #openstack-security | 03:41 | |
| *** woodster_ has quit IRC | 04:19 | |
| *** zul has joined #openstack-security | 04:27 | |
| *** jass93 has quit IRC | 04:30 | |
| *** jass93 has joined #openstack-security | 04:35 | |
| *** ccneill has quit IRC | 04:51 | |
| *** zul has quit IRC | 05:13 | |
| *** austin987 has quit IRC | 05:17 | |
| *** jass93 has quit IRC | 05:22 | |
| *** zul has joined #openstack-security | 05:23 | |
| *** jass93 has joined #openstack-security | 05:26 | |
| *** austin987 has joined #openstack-security | 05:37 | |
| *** zul has quit IRC | 05:38 | |
| *** pcaruana has joined #openstack-security | 06:23 | |
| *** jamielennox|away is now known as jamielennox | 07:03 | |
| *** tkelsey has joined #openstack-security | 07:04 | |
| *** tesseract- has joined #openstack-security | 07:07 | |
| *** cgross has quit IRC | 08:09 | |
| *** lmiccini_ has joined #openstack-security | 08:09 | |
| *** lmiccini has quit IRC | 08:10 | |
| *** cgross has joined #openstack-security | 08:12 | |
| *** lmiccini_ is now known as lmiccini | 08:23 | |
| *** salv-orlando has joined #openstack-security | 08:30 | |
| *** salv-orl_ has quit IRC | 08:32 | |
| *** sdake has joined #openstack-security | 09:02 | |
| *** lhinds|away is now known as lhinds | 09:05 | |
| *** sdake_ has joined #openstack-security | 09:16 | |
| *** sdake has quit IRC | 09:18 | |
| *** sdake has joined #openstack-security | 09:57 | |
| *** sdake_ has quit IRC | 10:00 | |
| *** shohel has joined #openstack-security | 10:02 | |
| *** sdake_ has joined #openstack-security | 10:31 | |
| *** sdake has quit IRC | 10:33 | |
| *** jass93 has quit IRC | 11:00 | |
| *** jass93 has joined #openstack-security | 11:05 | |
| *** tkelsey has quit IRC | 11:26 | |
| *** dikonoor has quit IRC | 11:30 | |
| *** tkelsey has joined #openstack-security | 11:31 | |
| *** dikonoor has joined #openstack-security | 11:34 | |
| *** zhihui has quit IRC | 12:39 | |
| *** salv-orlando has quit IRC | 12:46 | |
| *** salv-orlando has joined #openstack-security | 12:47 | |
| *** sdake_ is now known as sdake | 12:47 | |
| *** salv-orlando has quit IRC | 12:48 | |
| *** salv-orlando has joined #openstack-security | 12:48 | |
| *** salv-orlando has quit IRC | 12:52 | |
| *** salv-orlando has joined #openstack-security | 12:53 | |
| *** woodster_ has joined #openstack-security | 13:04 | |
| *** sdake has quit IRC | 13:05 | |
| *** _elmiko is now known as elmiko | 13:08 | |
| *** knangia has joined #openstack-security | 13:11 | |
| *** sdake has joined #openstack-security | 13:30 | |
| *** singlethink has joined #openstack-security | 13:38 | |
| *** shohel has quit IRC | 14:03 | |
| *** mvaldes has joined #openstack-security | 14:05 | |
| *** mvaldes1 has joined #openstack-security | 14:09 | |
| *** mvaldes has quit IRC | 14:12 | |
| *** edmondsw has joined #openstack-security | 14:15 | |
| *** zul has joined #openstack-security | 14:16 | |
| *** jmckind has joined #openstack-security | 14:17 | |
| *** jmckind_ has joined #openstack-security | 14:26 | |
| *** jmckind has quit IRC | 14:29 | |
| *** dikonoor has quit IRC | 14:29 | |
| *** zul has quit IRC | 14:51 | |
| *** pcaruana has quit IRC | 15:08 | |
| *** vinaypotluri has joined #openstack-security | 15:17 | |
| *** austin987 has quit IRC | 15:19 | |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 15:20 |
| *** browne has joined #openstack-security | 15:27 | |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 15:28 |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 15:35 |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 15:36 |
| hyakuhei | woot | 15:36 |
| hyakuhei | lhinds ripping through stuff! | 15:37 |
| lhinds | wanted to get that one knocked out | 15:37 |
| lhinds | hey hyakuhei ... | 15:37 |
| lhinds | I have yet to put a rest-framework on top, but being playing around with the idea we chatted about: http://lukehinds.pythonanywhere.com | 15:38 |
| hyakuhei | That looks very exciting | 15:38 |
| lhinds | ignore the front end, not suggesting we replace the wiki, I just tend to design on the front, and layer the rest-framework on top of the model, when I am happy with it | 15:38 |
| lhinds | Releases, is a many to many relation, so should be able to make queries on 'what is there for releases x,y,z' | 15:39 |
| lhinds | but its a very rough WIP still | 15:40 |
| hyakuhei | That's a great step forward lhinds ! | 15:45 |
| *** openstackgerrit has quit IRC | 15:49 | |
| *** tesseract- has quit IRC | 15:49 | |
| *** openstackgerrit has joined #openstack-security | 15:49 | |
| *** zul has joined #openstack-security | 15:52 | |
| *** mdong has joined #openstack-security | 16:13 | |
| *** ccneill has joined #openstack-security | 16:13 | |
| *** singlethink has quit IRC | 16:17 | |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 16:18 |
| lhinds | thanks hyakuhei | 16:18 |
| *** singlethink has joined #openstack-security | 16:20 | |
| *** mvaldes1 has quit IRC | 16:20 | |
| *** lmiccini has quit IRC | 16:21 | |
| *** cgross has quit IRC | 16:22 | |
| *** singlethink has quit IRC | 16:24 | |
| *** sdake has quit IRC | 16:28 | |
| *** singlethink has joined #openstack-security | 16:36 | |
| *** tkelsey has quit IRC | 16:36 | |
| openstackgerrit | Merged openstack/security-doc: Set the picture width https://review.openstack.org/367143 | 16:43 |
| *** cgross has joined #openstack-security | 16:44 | |
| *** lmiccini has joined #openstack-security | 16:47 | |
| *** sicarie has joined #openstack-security | 16:49 | |
| *** markd_ has quit IRC | 16:53 | |
| *** edaught has joined #openstack-security | 16:56 | |
| *** edaught has joined #openstack-security | 16:56 | |
| *** edaught has joined #openstack-security | 16:57 | |
| *** edaught has quit IRC | 16:57 | |
| *** edaught has joined #openstack-security | 16:57 | |
| *** markd_ has joined #openstack-security | 17:05 | |
| *** zul has quit IRC | 17:15 | |
| *** zul has joined #openstack-security | 17:16 | |
| openstackgerrit | Merged openstack/security-doc: Add a glossary link to 'Nginx's https://review.openstack.org/366849 | 17:21 |
| *** ccneill_ has joined #openstack-security | 17:21 | |
| *** ccneill has quit IRC | 17:22 | |
| *** ccneill_ is now known as ccneill | 17:22 | |
| ccneill | did y'all see my message above? I started lagging, not sure if it went through | 17:22 |
| ccneill | unrahul, vinaypotluri, knangia, mdong : just realized something... if we only get an identity token once, it will live for 1 hour, but if our tests take longer to run, you'll just get 401s for all the remaining requests once the token expires... :X | 17:23 |
| ccneill | maybe we have a TTL on our memoization? :\ | 17:23 |
| unrahul | Oh yeah.. We should! Crap actually ccneill it only lasts for 30 mins | 17:24 |
| unrahul | We should do a Ttl option for memoize | 17:24 |
| unrahul | :| | 17:24 |
| knangia | :| | 17:25 |
| ccneill | {"token": {"issued_at": "2016-09-09T00:27:32.493474Z", "audit_ids": ["X4wxvdMiSqWoGg3u4LkbIA"], "methods": ["password"], "expires_at": "2016-09-09T01:27:32.493441Z", "user": {"domain": {"id": "default", "name": "Default"}, "id": "30bc695b28f7475a97f0f3ab0f6fe6a7", "name": "admin"}}} | 17:25 |
| ccneill | looks like mine are set at an hour | 17:25 |
| ccneill | mdong: this might be where some of that discrepancy came in with the XSS tests? | 17:26 |
| unrahul | Ohh.. I thought the default was 30 mins :/ | 17:26 |
| mdong | ahh... | 17:26 |
| unrahul | I have a memoize patch, shall I modify and upload another patch? | 17:26 |
| ccneill | if you just ran XSS it would probably complete before expiry | 17:26 |
| ccneill | unrahul: sounds good | 17:27 |
| unrahul | Yup. | 17:27 |
| *** jass93 has quit IRC | 17:32 | |
| ccneill | pretty cool post from Red Hat about some interesting ways to shoot yourself in the foot in python: https://access.redhat.com/blogs/766093/posts/2592591 | 17:32 |
| sicarie | haha, i just shot that over to tkelsey for inclusion in bandit | 17:32 |
| sicarie | or at least consideration | 17:33 |
| ccneill | yep | 17:33 |
| ccneill | good stuff | 17:33 |
| ccneill | I know they check for asserts, subprocess, some tempfile stuff, and jinja templates | 17:34 |
| ccneill | some of the other things are a little more esoteric, but might find some interesting edge cases that have gone unnoticed | 17:35 |
| *** salv-orlando has quit IRC | 17:49 | |
| *** salv-orlando has joined #openstack-security | 17:49 | |
| *** mvaldes has joined #openstack-security | 17:53 | |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 18:04 |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 18:07 |
| *** sicarie has quit IRC | 18:12 | |
| lhinds | ping hyakuhei - OSSN-0066 has a Trove core +1, so when you're ok with whats there I can get it posted out. | 18:12 |
| openstackgerrit | Luke Hinds proposed openstack/security-doc: Adding OSSN-0066 https://review.openstack.org/368077 | 18:13 |
| openstackgerrit | Merged openstack/anchor: Ignore bootstrap files https://review.openstack.org/330315 | 18:15 |
| *** jass93 has joined #openstack-security | 18:15 | |
| *** sicarie has joined #openstack-security | 18:20 | |
| *** jmckind has joined #openstack-security | 18:32 | |
| *** tkelsey has joined #openstack-security | 18:34 | |
| *** jmckind_ has quit IRC | 18:35 | |
| *** tkelsey has quit IRC | 18:40 | |
| *** jmckind_ has joined #openstack-security | 18:41 | |
| *** jmckind has quit IRC | 18:44 | |
| *** zul has quit IRC | 18:44 | |
| *** zul has joined #openstack-security | 19:00 | |
| openstackgerrit | Rahul U Nair proposed openstack/syntribos: Upgrading memoize to memoize functions with same kwargs as well https://review.openstack.org/367481 | 19:03 |
| *** cgross has quit IRC | 19:22 | |
| *** lmiccini has quit IRC | 19:22 | |
| *** mvaldes has quit IRC | 19:36 | |
| *** sdake has joined #openstack-security | 19:38 | |
| *** sdake has quit IRC | 19:42 | |
| *** sdake has joined #openstack-security | 19:44 | |
| *** mvaldes has joined #openstack-security | 19:50 | |
| *** ccneill has quit IRC | 19:51 | |
| *** jmckind_ has quit IRC | 20:04 | |
| *** zul has quit IRC | 20:10 | |
| *** zul has joined #openstack-security | 20:10 | |
| *** ccneill has joined #openstack-security | 20:15 | |
| *** ju_ has joined #openstack-security | 20:19 | |
| *** ju_ has quit IRC | 20:20 | |
| *** jmckind has joined #openstack-security | 20:26 | |
| *** salv-orl_ has joined #openstack-security | 20:30 | |
| *** jass93 has quit IRC | 20:32 | |
| *** salv-orlando has quit IRC | 20:32 | |
| *** salv-orl_ has quit IRC | 20:33 | |
| *** salv-orlando has joined #openstack-security | 20:34 | |
| *** lmiccini has joined #openstack-security | 20:39 | |
| *** cgross has joined #openstack-security | 20:40 | |
| *** jmckind_ has joined #openstack-security | 20:41 | |
| *** jmckind has quit IRC | 20:44 | |
| mdong | ccneill, unrahul: I’m ready to +2 the memoize change, but I had a comment about the cache key | 20:50 |
| mdong | I think we could avoid importing hashlib and turning everything into a string if we instead do something like | 20:51 |
| mdong | func_id = (args, frozenset(kwargs.items()) | 20:51 |
| ccneill | not importing hashlib sounds good to me, but I'm not sure if that would work? I get an error in ipython when I try that | 20:52 |
| ccneill | is args a list or a tuple.. | 20:52 |
| mdong | I wanna say list | 20:53 |
| ccneill | ah, tuple | 20:53 |
| mdong | completely wrong as always | 20:53 |
| ccneill | In [12]: def x(*args, **kwargs): │ | 20:54 |
| ccneill | ....: print type(args) │ | 20:54 |
| ccneill | ....: │ | 20:54 |
| ccneill | │ | 20:54 |
| ccneill | In [13]: x(1) │ | 20:54 |
| ccneill | <type 'tuple'> | 20:54 |
| ccneill | I wasn't sure myself | 20:54 |
| ccneill | but trying to do the func_id as you suggested with a list failed | 20:54 |
| ccneill | but with a tuple it works fine | 20:54 |
| mdong | I dunno if this would do anything to warrant the change, but I figured it at least cleans up the code a bit | 20:55 |
| *** jass93 has joined #openstack-security | 20:58 | |
| ccneill | +1 let's get rid of hashlib | 20:58 |
| ccneill | hmm.. I guess it kinda depends on what we'll be memoizing | 20:58 |
| mdong | we should only ever be memoizing functions with nonmutable arguments | 21:03 |
| *** jmckind_ has quit IRC | 21:05 | |
| ccneill | right.. guess it doesn't matter then | 21:09 |
| ccneill | was thinking about str() of an object vs. doing frozenset() on it but we shouldn't be doing that anyway | 21:10 |
| unrahul | Yup sounds good mdong and ccneill.. I was also thinking of giving option to pass in Ttl as an argument... | 21:10 |
| unrahul | Should we merge this now and I submit another patch for it..? | 21:10 |
| ccneill | unrahul: let's just edit it now, should be simple changes | 21:10 |
| ccneill | +1 on ttl as config option | 21:10 |
| ccneill | well.. hmm | 21:10 |
| mdong | maybe make it a config option rather than an argument | 21:10 |
| unrahul | I have a docs appointment.. So will take some time to upload another patch | 21:10 |
| ccneill | config option or function param? | 21:10 |
| unrahul | Doctor's | 21:11 |
| ccneill | ah, okay | 21:11 |
| ccneill | no worries | 21:11 |
| unrahul | Function param is better... Ryt? | 21:11 |
| ccneill | we can merge the one you've got and just edit it | 21:11 |
| ccneill | function param would give more flexibility, but only from the standpoint of a developer of syntribos | 21:11 |
| unrahul | Like.. We many use it for many things so.. Passing configuration options would be a bit too much? | 21:11 |
| ccneill | config option lets you configure it more easily as a user, but then you get one TTL across the board for all memoized functions, which might be okay.. | 21:12 |
| mdong | if the end user ever needs to configure it, then it needs to be a config option | 21:12 |
| unrahul | Yeah.. That's also true | 21:12 |
| mdong | and users may very well have different keystone token expiration | 21:12 |
| unrahul | Yup.. | 21:12 |
| unrahul | :/ | 21:12 |
| unrahul | So which way to go? | 21:12 |
| mdong | I say config option, because having the same TTL across the board is a smaller problem | 21:13 |
| unrahul | Hmm.. Yeah... May be we shall go ahead with the config option.. | 21:14 |
| unrahul | And once we migrate to 3.5 | 21:14 |
| unrahul | Devs may use d lru cache decorator from standard lib or something | 21:15 |
| mdong | we’d have to roll our own cache anyway for the TTL | 21:16 |
| ccneill | lol yeah, once that inevitable transition to python 3 happens.. any day now.. :P | 21:16 |
| ccneill | +1 for config option, we'll try it out and see if we need the param later | 21:17 |
| unrahul | Hehe.. Oh yeah.. Rewriting the lru cache decorator, just because we can 😁😎 | 21:26 |
| *** mvaldes has quit IRC | 21:37 | |
| *** mdong has quit IRC | 21:37 | |
| *** mdong has joined #openstack-security | 21:38 | |
| *** elmiko is now known as _elmiko | 22:00 | |
| openstackgerrit | Merged openstack/syntribos: Upgrading memoize to memoize functions with same kwargs as well https://review.openstack.org/367481 | 22:32 |
| *** sdake has quit IRC | 22:40 | |
| *** vinaypotluri has quit IRC | 22:42 | |
| openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/314347 | 22:45 |
| *** singlethink has quit IRC | 22:49 | |
| *** sdake has joined #openstack-security | 23:22 | |
| sdake | tmcpeak ping re tha for kolla | 23:24 |
| *** zul has quit IRC | 23:33 | |
| unrahul | hey ccneill I am back.. | 23:42 |
| unrahul | got a question on the memoize | 23:42 |
| unrahul | u thr? | 23:42 |
| ccneill | yep | 23:42 |
| ccneill | sup? | 23:42 |
| unrahul | should we consider the module name + func name as well when creating the unique id.. as this will eliminate any possible wrong calls if two modules have similarly named func.. ? | 23:42 |
| unrahul | or should we keep it simple? | 23:43 |
| unrahul | mdong: ^ | 23:44 |
| *** sicarie has quit IRC | 23:44 | |
| mdong | it shouldn’t matter, the decorator makes it so that only that specific function is memoized | 23:46 |
| mdong | if we change to (args, frozenset(kwargs.items()) that is | 23:46 |
| mdong | unless I’m misunderstanding? | 23:46 |
| ccneill | unrahul: pretty sure mdong is right, I think I tested it out and it memoizes per-function | 23:47 |
| ccneill | so each func has its own cache | 23:47 |
| unrahul | +1 guys, will do that and push another patch.. | 23:48 |
| unrahul | thanks.. | 23:48 |
| *** jass93 has quit IRC | 23:49 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!