*** bencherian has joined #openstack-dev | 00:04 | |
*** littleidea has joined #openstack-dev | 00:06 | |
*** koolhead17 has joined #openstack-dev | 00:10 | |
*** dmarkey_ has quit IRC | 00:23 | |
*** steveb_ has quit IRC | 00:26 | |
*** zul has quit IRC | 00:39 | |
*** andrewsmedina has joined #openstack-dev | 00:43 | |
*** sdake has quit IRC | 00:45 | |
*** rods has quit IRC | 00:50 | |
*** ayoung has quit IRC | 00:50 | |
*** renier has joined #openstack-dev | 00:51 | |
*** garyk has quit IRC | 00:52 | |
*** zul has joined #openstack-dev | 00:57 | |
*** littleidea has quit IRC | 00:58 | |
*** zul has quit IRC | 00:59 | |
*** littleidea has joined #openstack-dev | 00:59 | |
*** andrewsmedina has quit IRC | 01:12 | |
*** matiu has joined #openstack-dev | 01:16 | |
*** matiu has quit IRC | 01:16 | |
*** matiu has joined #openstack-dev | 01:16 | |
*** colinmcnamara has quit IRC | 01:24 | |
*** andrewsmedina has joined #openstack-dev | 01:38 | |
*** colinmcnamara has joined #openstack-dev | 01:41 | |
*** dachary has quit IRC | 01:42 | |
*** dachary has joined #openstack-dev | 01:43 | |
*** zul has joined #openstack-dev | 01:43 | |
*** tserong has joined #openstack-dev | 01:49 | |
*** eglynn__ has joined #openstack-dev | 01:55 | |
*** zul has quit IRC | 01:55 | |
*** eglynn_ has quit IRC | 01:57 | |
*** zul has joined #openstack-dev | 02:03 | |
*** dmarkey has joined #openstack-dev | 02:06 | |
*** pixelbeat has quit IRC | 02:08 | |
*** koolhead17 has quit IRC | 02:13 | |
notmyname | ttx: heads up, swift 1.6.0 reviews not done yet. rax had a delay getting started on the reviews, and here were a couple of patches to backport this evening for issues that were discovered at the last minute. I'll let you know when we have a QA'd release | 02:20 |
---|---|---|
*** zul has quit IRC | 02:22 | |
*** pixelbeat has joined #openstack-dev | 02:23 | |
*** littleidea has quit IRC | 02:27 | |
*** toey has joined #openstack-dev | 02:28 | |
*** zul has joined #openstack-dev | 02:38 | |
*** toey has quit IRC | 02:42 | |
*** roge has quit IRC | 02:49 | |
*** zul has quit IRC | 02:52 | |
*** jaypipes has quit IRC | 02:52 | |
*** colinmcnamara has quit IRC | 02:56 | |
*** colinmcnamara has joined #openstack-dev | 02:59 | |
*** zul has joined #openstack-dev | 03:00 | |
*** xchu_ has joined #openstack-dev | 03:04 | |
*** zul has quit IRC | 03:09 | |
*** xchu_ has quit IRC | 03:10 | |
*** xchu_ has joined #openstack-dev | 03:10 | |
*** jaypipes has joined #openstack-dev | 03:11 | |
*** asalkeld has quit IRC | 03:13 | |
*** zul has joined #openstack-dev | 03:15 | |
*** zul has quit IRC | 03:18 | |
*** zul has joined #openstack-dev | 03:21 | |
*** steveb_ has joined #openstack-dev | 03:29 | |
*** pixelbeat has quit IRC | 03:29 | |
*** dachary has quit IRC | 03:39 | |
*** dachary has joined #openstack-dev | 03:40 | |
*** colinmcnamara has quit IRC | 03:47 | |
*** renier has quit IRC | 03:59 | |
*** renier has joined #openstack-dev | 03:59 | |
*** mokas has joined #openstack-dev | 04:01 | |
*** littleidea has joined #openstack-dev | 04:02 | |
*** asalkeld has joined #openstack-dev | 04:06 | |
*** sunxin has joined #openstack-dev | 04:17 | |
*** sunxin has quit IRC | 04:17 | |
*** sdake has joined #openstack-dev | 04:19 | |
*** sacharya has quit IRC | 04:40 | |
*** andrewsmedina has quit IRC | 05:00 | |
*** steveb_ has quit IRC | 05:14 | |
*** dachary has quit IRC | 05:15 | |
*** dachary has joined #openstack-dev | 05:15 | |
*** amotoki has joined #openstack-dev | 05:26 | |
*** Mandell has joined #openstack-dev | 05:44 | |
*** Hien_ has quit IRC | 05:56 | |
*** Hien has joined #openstack-dev | 05:56 | |
*** hattwick has quit IRC | 06:02 | |
*** littleidea has quit IRC | 06:05 | |
*** dachary has quit IRC | 06:58 | |
*** sniperd has joined #openstack-dev | 07:06 | |
*** EmilienM has joined #openstack-dev | 07:08 | |
*** garyk has joined #openstack-dev | 07:11 | |
*** m4xmr has joined #openstack-dev | 07:11 | |
*** Mandell has quit IRC | 07:14 | |
*** koolhead11 has joined #openstack-dev | 07:14 | |
*** dachary has joined #openstack-dev | 07:20 | |
*** sulochan has joined #openstack-dev | 07:44 | |
*** erikzaadi has joined #openstack-dev | 07:44 | |
*** m4xmr has left #openstack-dev | 07:44 | |
*** sulochan has quit IRC | 07:45 | |
*** sulochan has joined #openstack-dev | 07:46 | |
*** sulochan has joined #openstack-dev | 07:47 | |
*** sulochan has quit IRC | 07:48 | |
*** sulochan has joined #openstack-dev | 07:49 | |
*** sulochan has left #openstack-dev | 07:49 | |
*** zhuadl has joined #openstack-dev | 07:51 | |
*** derekh has joined #openstack-dev | 07:53 | |
*** rbasak has joined #openstack-dev | 07:58 | |
*** bencherian has quit IRC | 08:15 | |
*** fc__ has joined #openstack-dev | 08:16 | |
*** steveb_ has joined #openstack-dev | 08:16 | |
Madkiss | mtaylor: ping | 08:22 |
*** danwent has quit IRC | 08:26 | |
*** danpb has joined #openstack-dev | 08:28 | |
*** darraghb has joined #openstack-dev | 08:32 | |
*** thickskin has joined #openstack-dev | 08:36 | |
ttx | notmyname: ack, standing by | 08:40 |
ttx | zykes-: pong? | 08:41 |
*** hattwick has joined #openstack-dev | 08:43 | |
*** rods has joined #openstack-dev | 08:46 | |
*** johngarbutt has joined #openstack-dev | 08:50 | |
*** maploin has joined #openstack-dev | 09:02 | |
*** maploin has quit IRC | 09:03 | |
*** maploin has joined #openstack-dev | 09:03 | |
*** apevec has joined #openstack-dev | 09:08 | |
asalkeld | russellb, you about? | 09:12 |
asalkeld | you know the state of wsgi in common? | 09:12 |
asalkeld | seems like no one is using it | 09:13 |
asalkeld | checked glance/cinder/nova/ceilometer/heat/keystone/horizon | 09:15 |
*** matiu has quit IRC | 09:23 | |
*** amotoki has quit IRC | 09:30 | |
*** thickskin has left #openstack-dev | 09:35 | |
*** markmc has joined #openstack-dev | 09:41 | |
apevec | asalkeld, is this "wsgi in common" to use the same startup code everywhere? | 09:53 |
apevec | if so, I'd like to propose systemd ready notification there, like the one in keystone: https://github.com/openstack/keystone/commit/abc06716d027d68f0da3b0f559fa7c85a21804d5 | 09:54 |
asalkeld | well I am just looking at the possibility of it | 09:54 |
apevec | what can I do to help? | 09:54 |
asalkeld | well there are a heap of wsgi files | 09:55 |
asalkeld | and I am just trying to figure them out | 09:55 |
*** atul_ has joined #openstack-dev | 09:55 | |
apevec | also in keystone, we have instruction how to run it in httpd: https://github.com/openstack/keystone/tree/master/httpd | 09:55 |
apevec | would this be a common candidate? | 09:56 |
asalkeld | well keystone is run in http now? | 09:56 |
asalkeld | so it is a bit different - no? | 09:57 |
apevec | not by default, it's an option with above | 09:57 |
asalkeld | I see | 09:57 |
asalkeld | probably need to talk about it on the ml | 09:57 |
asalkeld | decide on the best way to go | 09:58 |
apevec | yep | 09:58 |
*** koolhead11 has quit IRC | 09:59 | |
apevec | markmc, re. global cfg for authtoken, was that ever proposed as a patch? | 09:59 |
apevec | Looks very elegant to me, and for backward compat, it could try that first, then fall back to using config from paste ? | 09:59 |
*** atul_ has quit IRC | 09:59 | |
*** atul_ has joined #openstack-dev | 10:00 | |
markmc | apevec, nope, I just knocked that together now | 10:07 |
markmc | apevec, feel free to go ahead with it if you like | 10:08 |
markmc | apevec, the _conf_get() method handles backwards compat - self.conf is what comes from api-paste.ini | 10:08 |
apevec | ah cool | 10:08 |
apevec | ok, I'll try it and submit if it works! | 10:09 |
*** theron has quit IRC | 10:09 | |
*** pixelbeat has joined #openstack-dev | 10:10 | |
*** pixelbeat has quit IRC | 10:14 | |
*** pixelbeat has joined #openstack-dev | 10:15 | |
*** steveb_ has quit IRC | 10:20 | |
pixelbeat | zul, Thoughts on https://review.openstack.org/#/c/10498/ ? | 10:28 |
apevec | pixelbeat, patch merging shouldn't be allowed over w/e :) | 10:33 |
*** zhuadl has quit IRC | 10:34 | |
*** atul_ is now known as koolhead11 | 10:45 | |
*** dachary has quit IRC | 10:49 | |
danpb | anyone else seeing failures from Jenkins this morning | 10:50 |
danpb | https://jenkins.openstack.org/job/gate-tempest-devstack-vm/5277/consoleFull | 10:50 |
danpb | 10:35:36 W: Failed to fetch bzip2:/var/lib/apt/lists/partial/mirror.rackspace.com_ubuntu_dists_precise-updates_universe_binary-i386_Packages Hash Sum mismatch | 10:50 |
danpb | 10:35:36 E: Some index files failed to download. They have been ignored, or old ones used instead. | 10:50 |
danpb | jeblair: anything you're aware of ? ^^^ | 10:51 |
*** koolhead11 has quit IRC | 11:08 | |
*** EmilienM has quit IRC | 11:11 | |
*** EmilienM has joined #openstack-dev | 11:13 | |
*** asalkeld_ has joined #openstack-dev | 11:16 | |
*** dachary has joined #openstack-dev | 11:16 | |
*** asalkeld has quit IRC | 11:19 | |
*** milner has quit IRC | 11:22 | |
*** chrisfer has joined #openstack-dev | 11:25 | |
zul | pixelbeat: its a regression in my opinon and you will get a traceback everytime you run an instance is not good in my book, besides it should probably live in cloud-init | 11:34 |
*** markvoelker has joined #openstack-dev | 11:35 | |
pixelbeat | zul, Well it's just a LOG.debug that's generating the extra logs. I suppose I could try and suppress that as it's not that informative I suppose. OK to revert so, and add log suppression in another commit? | 11:40 |
*** milner has joined #openstack-dev | 11:42 | |
*** maurosr has joined #openstack-dev | 11:42 | |
zul | pixelbeat: sure but my problem is that you are assuming that you are going to be running selinux on the images | 11:42 |
pixelbeat | zul, No assumption of selinux. The `readlink -e /etc/selinux` that is generating the debug output is used to shortcut the procedure when /etc/selinux is not present | 11:43 |
*** maurosr has quit IRC | 11:49 | |
zul | pixelbeat: ok still i think this should be in cloud-init | 11:51 |
pixelbeat | zul, Yep it should be in cloud-init too | 11:52 |
zul | pixelbeat: meaning i think the injection stuff should be as generic as possibly | 11:52 |
zul | er...possible | 11:52 |
*** maurosr has joined #openstack-dev | 11:54 | |
pixelbeat | zul, Well ssh key injection is such a common use case for the injection functionality, I think it's appropriate to add the simple optional extension to setup for a common case where SELinux is enabled in the guest | 11:55 |
pixelbeat | But I agree that cloud-init can be a better solution. That's why I've push cloud-init into EPEL so that it will be available in _future_ | 11:57 |
zul | if its optional then why not make it a flag then | 11:57 |
pixelbeat | There is an implicit flag (/etc/selinux) | 11:57 |
zul | i dont think its a good flag :) why not just add FLAGS.use_selinux and then we would both be happy and distros that doesnt use selinux will be happy too | 11:59 |
pixelbeat | An implicit flag is much better because you may not know what guests are being used | 12:01 |
markmc | zul, why are distros that don't use selinux unhappy? | 12:01 |
markmc | zul, bearing in mind this is about guest support | 12:02 |
markmc | pixelbeat, right, good defaults are preferable to adding to our 500 config options | 12:02 |
*** Shrews has joined #openstack-dev | 12:03 | |
zul | markmc: because i get a traceback everytime i launch an instance because it checks for an /etc/selinux, i dont think the use of readlink is a good in this case because of the traceback | 12:05 |
*** koolhead17 has joined #openstack-dev | 12:05 | |
zul | and i know we are going to get questions about this in Ubuntu | 12:05 |
markmc | zul, the traceback should be fixed | 12:05 |
markmc | zul, I don't think pixelbeat is arguing against fixing a traceback | 12:05 |
markmc | zul, you'll also get questions about SELinux-using guests not working if you disable this | 12:06 |
pixelbeat | Note the traceback is only LOG.debug() | 12:06 |
pixelbeat | Anyway I think we're all agreed. I'll reduce the debugging | 12:06 |
zul | fine with me | 12:07 |
markmc | superb | 12:07 |
*** salgado has joined #openstack-dev | 12:09 | |
*** salgado has joined #openstack-dev | 12:09 | |
Daviey | The real issue is that injection is nasty :) | 12:15 |
*** wiliam has joined #openstack-dev | 12:15 | |
*** eglynn__ is now known as hungry-eglynn | 12:21 | |
koolhead17 | markmc, hi there | 12:23 |
markmc | koolhead17, hi | 12:23 |
*** dubsquared has quit IRC | 12:27 | |
*** avishay has joined #openstack-dev | 12:29 | |
avishay | Hi all. I think I caught a bug in rootwrap in nova? Can someone confirm? | 12:29 |
*** sacharya has joined #openstack-dev | 12:40 | |
*** e1mer has quit IRC | 12:43 | |
*** e1mer has joined #openstack-dev | 12:46 | |
mtaylor | Madkiss: morning | 12:50 |
*** andrewsmedina has joined #openstack-dev | 12:51 | |
*** GheRivero has quit IRC | 12:52 | |
*** lts has joined #openstack-dev | 12:52 | |
*** sniperd has quit IRC | 12:52 | |
Madkiss | mtaylor: Have you had time to look at the bug report? :) | 12:54 |
mtaylor | Madkiss: nope. still making coffee - link/number? | 12:55 |
*** sacharya has quit IRC | 12:55 | |
*** lorin1 has joined #openstack-dev | 12:56 | |
*** andrewsmedina has quit IRC | 12:56 | |
*** hungry-eglynn is now known as eglynn | 12:56 | |
Madkiss | mtaylor: aw c'mon. https://bugs.launchpad.net/openstack-ci/+bug/1028467 | 12:57 |
uvirtbot | Launchpad bug 1028467 in openstack-ci "virtualenv should really set root when it installs things" [Undecided,New] | 12:57 |
Madkiss | Looks like nobody has even taken a look at it. | 12:58 |
markmc | pixelbeat, you can edit that message by fetching it, amending and re-pushing | 13:00 |
*** salgado has quit IRC | 13:01 | |
mtaylor | Madkiss: oh, piddle! sorry, that did, in fact, totally slip through the cracks | 13:03 |
mtaylor | Madkiss: I have assigned to me so that that won't happen again | 13:03 |
*** salgado has joined #openstack-dev | 13:03 | |
*** salgado has joined #openstack-dev | 13:03 | |
*** mcolombo has joined #openstack-dev | 13:05 | |
*** zhuadl has joined #openstack-dev | 13:07 | |
*** ewindisch has quit IRC | 13:08 | |
*** mcolombo has quit IRC | 13:10 | |
*** roge has joined #openstack-dev | 13:10 | |
*** zhuadl has quit IRC | 13:12 | |
*** dolphm has joined #openstack-dev | 13:13 | |
Madkiss | mtaylor: oky, thanks | 13:16 |
Madkiss | mtaylor: In accordance with your comment, I will amend my commit to not install stuff into system locations | 13:17 |
*** sulochan has joined #openstack-dev | 13:17 | |
*** alex88 has joined #openstack-dev | 13:25 | |
*** alex88 has joined #openstack-dev | 13:25 | |
*** kbringard has joined #openstack-dev | 13:26 | |
*** andrewsmedina has joined #openstack-dev | 13:26 | |
*** mcolombo has joined #openstack-dev | 13:27 | |
mtaylor | Madkiss: yeah, it's not something I have the ability to fix short term, but I would like to poke at upstream and see what can be done | 13:28 |
*** theron has joined #openstack-dev | 13:30 | |
*** andrewbogott has joined #openstack-dev | 13:31 | |
*** andrewbogott has joined #openstack-dev | 13:31 | |
*** GheRivero has joined #openstack-dev | 13:32 | |
*** sacharya has joined #openstack-dev | 13:32 | |
*** dolphm has quit IRC | 13:33 | |
smoser | pixelbeat, around? | 13:34 |
*** sdake has quit IRC | 13:35 | |
*** dprince has joined #openstack-dev | 13:35 | |
smoser | hm.. | 13:36 |
smoser | maybe markmc ? | 13:36 |
smoser | https://github.com/openstack/nova/commit/7bac53f97e7c2025e492de7e9c9f5d2451aceee3 | 13:36 |
*** sdake has joined #openstack-dev | 13:36 | |
smoser | doesnt the readlink there potentially expose information about the host? if i launch an instance that has in its filesystem a symlink from '/etc/selinux' to '/etc/selinux' | 13:36 |
smoser | then i can determine if the host had /etc/selinux | 13:36 |
smoser | or any other file | 13:37 |
smoser | wouldn't a simple 'os.path.lexists' be better there? | 13:37 |
pixelbeat | smoser, well I don't read/write the file | 13:39 |
smoser | no. but you give information about the host. | 13:39 |
smoser | just check if the guest has the file instead. | 13:39 |
smoser | if they have a dangling symlink there, then thats their own fault. | 13:39 |
*** markmcclain has joined #openstack-dev | 13:39 | |
smoser | am i missing something? | 13:39 |
pixelbeat | note you can't just os.path.exists() as you need to run as root to handle all mount cases (libguestfs uses fuse, so need root access to look inside guest) | 13:40 |
*** GheRivero has quit IRC | 13:41 | |
smoser | ah. that makes sense. | 13:41 |
smoser | but you agree that i can basically poke around the presense of files in the host (very slowly) this way. | 13:42 |
pixelbeat | True | 13:42 |
smoser | kind of surprised that readlink doesn't have a "assume / is <path>" option | 13:43 |
pixelbeat | I added a new realpath command lately that supports that | 13:43 |
eglynn | russellb: a while back we discussed changing an RPC MEP from cast to call, IIRC your feeling was that this warranted a minor version bump | 13:43 |
pixelbeat | It's a bit too new to rely on though | 13:43 |
smoser | yeah. | 13:43 |
smoser | injection is a mes. | 13:44 |
smoser | this is really just dangerous | 13:44 |
russellb | eglynn: hello, yeah, if it's adding a return value anyway | 13:44 |
russellb | eglynn: if it's only making it synchronous, and no return value is being used, it doesn't really matter much either way | 13:44 |
eglynn | russellb: how 'bout a potential exception being raised? | 13:44 |
pixelbeat | smoser, What I might do is verify returns from readlink with the python function to check a file is within a path | 13:44 |
russellb | unless you just really want to be sure from the calling side that it's synchronous | 13:44 |
eglynn | russellb: wrt ... https://review.openstack.org/#/c/10130/6/nova/compute/manager.py | 13:44 |
russellb | eglynn: if you want to make sure the exception can be raised, the version bump is needed | 13:45 |
eglynn | russellb: cool, can throw in your 2 cents in gerrit? | 13:45 |
smoser | pixelbeat, the chmod there also needs some protection? | 13:45 |
russellb | eglynn: yup | 13:46 |
*** koolhead17 has quit IRC | 13:46 | |
smoser | i can potentially chnage the attributes of a file in the host? | 13:46 |
eglynn | russellb: thank you sir! | 13:46 |
russellb | done | 13:47 |
russellb | arosen: did you typo your name in a commit recently? You got listed as a first contributor in the weekly newsletter as Aaron Orosen, heh. | 13:50 |
*** e1mer has quit IRC | 13:52 | |
*** e1mer has joined #openstack-dev | 13:54 | |
*** ayoung has joined #openstack-dev | 13:55 | |
*** halfss has joined #openstack-dev | 13:58 | |
*** andrewbogott has quit IRC | 13:59 | |
*** e1mer has quit IRC | 13:59 | |
*** andrewbogott has joined #openstack-dev | 14:00 | |
*** andrewbogott has joined #openstack-dev | 14:00 | |
*** maoy has joined #openstack-dev | 14:01 | |
*** e1mer has joined #openstack-dev | 14:05 | |
*** sc68cal has joined #openstack-dev | 14:08 | |
*** mdomsch has joined #openstack-dev | 14:09 | |
*** rpedde_away is now known as rpedde | 14:11 | |
*** dragondm has quit IRC | 14:16 | |
*** Gordonz has joined #openstack-dev | 14:16 | |
*** zhuadl has joined #openstack-dev | 14:16 | |
*** Gordonz has quit IRC | 14:16 | |
*** Gordonz has joined #openstack-dev | 14:16 | |
*** chuckieb has joined #openstack-dev | 14:16 | |
*** dragondm_ has joined #openstack-dev | 14:16 | |
*** dragondm_ is now known as dragondm | 14:16 | |
*** e1mer has quit IRC | 14:16 | |
*** ogelbukh has quit IRC | 14:16 | |
*** ogelbukh has joined #openstack-dev | 14:18 | |
*** edygarcia has joined #openstack-dev | 14:18 | |
*** dubsquared has joined #openstack-dev | 14:19 | |
*** sandywalsh has joined #openstack-dev | 14:21 | |
*** mcolombo has quit IRC | 14:21 | |
*** sdake has quit IRC | 14:23 | |
*** maurosr has quit IRC | 14:24 | |
*** sdake has joined #openstack-dev | 14:25 | |
*** matiu has joined #openstack-dev | 14:25 | |
*** maurosr has joined #openstack-dev | 14:29 | |
*** rnirmal has joined #openstack-dev | 14:29 | |
jeblair | danpb: thanks, loooking into it. | 14:33 |
*** Gordonz has quit IRC | 14:33 | |
*** jaypipes has quit IRC | 14:34 | |
*** dolphm has joined #openstack-dev | 14:34 | |
*** Gordonz has joined #openstack-dev | 14:35 | |
*** littleidea has joined #openstack-dev | 14:36 | |
eglynn | core-tempest folks: anyone have time to look at https://review.openstack.org/10216 ? | 14:40 |
eglynn | (holding up a couple of nova patches being gate-able) | 14:40 |
*** nikhil has quit IRC | 14:43 | |
*** nikhil has joined #openstack-dev | 14:44 | |
*** zhuadl has quit IRC | 14:47 | |
*** Mandell has joined #openstack-dev | 14:51 | |
*** theron has quit IRC | 14:53 | |
jeblair | danpb: it looks like rackspace's ubuntu mirror is broken. I've filed a ticket about the problem, and disabled the use of rackspace nodes for devstack-gate. | 14:53 |
danpb | jeblair: cheers | 14:53 |
*** datsun180b has joined #openstack-dev | 14:54 | |
*** cp16net is now known as cp16net|away | 14:54 | |
*** yuanz has joined #openstack-dev | 14:54 | |
*** jaypipes has joined #openstack-dev | 14:55 | |
*** jtran has joined #openstack-dev | 14:57 | |
*** matiu has quit IRC | 15:00 | |
*** maurosr has quit IRC | 15:02 | |
*** maurosr has joined #openstack-dev | 15:03 | |
*** andrewsmedina has quit IRC | 15:04 | |
*** AlanClark has joined #openstack-dev | 15:04 | |
*** Mandell has quit IRC | 15:06 | |
*** littleidea has quit IRC | 15:07 | |
*** littleidea has joined #openstack-dev | 15:07 | |
*** halfss has quit IRC | 15:09 | |
*** halfss has joined #openstack-dev | 15:09 | |
*** milner has quit IRC | 15:12 | |
*** matiu has joined #openstack-dev | 15:13 | |
*** matiu has quit IRC | 15:13 | |
*** matiu has joined #openstack-dev | 15:13 | |
*** chuckieb has quit IRC | 15:15 | |
*** GheRivero has joined #openstack-dev | 15:19 | |
*** markvoelker has quit IRC | 15:20 | |
*** markvoelker has joined #openstack-dev | 15:21 | |
*** Gordonz has quit IRC | 15:21 | |
*** andrewbogott_ has joined #openstack-dev | 15:22 | |
*** Gordonz has joined #openstack-dev | 15:22 | |
GheRivero | hi people | 15:22 |
*** spiffxp has joined #openstack-dev | 15:23 | |
*** andrewbogott has quit IRC | 15:24 | |
*** andrewbogott_ is now known as andrewbogott | 15:24 | |
*** Gordonz_ has joined #openstack-dev | 15:25 | |
*** milner has joined #openstack-dev | 15:25 | |
*** danwent has joined #openstack-dev | 15:25 | |
*** heckj has joined #openstack-dev | 15:26 | |
*** Gordonz has quit IRC | 15:28 | |
*** halfss has quit IRC | 15:31 | |
*** erikzaadi has quit IRC | 15:34 | |
*** alex88 has quit IRC | 15:39 | |
*** rohitk has joined #openstack-dev | 15:40 | |
*** alex88 has joined #openstack-dev | 15:40 | |
*** alex88 has joined #openstack-dev | 15:40 | |
*** alex88 has quit IRC | 15:40 | |
*** alex88 has joined #openstack-dev | 15:41 | |
dansmith | markmc: FYI, this "lock_checked" change is taking quite a while.. don't think I've forgotten about it :) | 15:41 |
dansmith | mostly because of russellb's unreasonable desire to "test everything thoroughly" | 15:41 |
markmc | dansmith, cool | 15:42 |
markmc | dansmith, glad we can shift the blame onto russellb | 15:42 |
russellb | O.O | 15:42 |
russellb | if the blame is that i like testing too much, i guess i'm ok with that | 15:42 |
dansmith | russellb: I knew it wasn't exactly a strong argument.. :P | 15:43 |
*** yuanz has quit IRC | 15:45 | |
*** reed has joined #openstack-dev | 15:51 | |
*** markmcclain has quit IRC | 15:51 | |
*** nunosantos has joined #openstack-dev | 15:53 | |
andrewbogott | russellb: Could I get a review of https://review.openstack.org/#/c/10035/ ? | 15:53 |
*** joearnold has joined #openstack-dev | 15:55 | |
*** zaitcev has joined #openstack-dev | 15:55 | |
russellb | andrewbogott: honestly, the more you ping me on IRC about the change, the less i want to review it | 15:57 |
russellb | you've pinged so many times ... sorry i haven't gotten to it, but sheesh | 15:58 |
andrewbogott | russellb: fair enough, sorry. | 15:58 |
*** markmcclain has joined #openstack-dev | 15:58 | |
sc68cal | Does anyone here have a good handle on the DNS Domain functionality of nova? I have a strange bug that I'm trying to figure out. https://bugs.launchpad.net/nova/+bug/1027998 | 16:01 |
uvirtbot | Launchpad bug 1027998 in nova "db.dnsdomain_get API calls return no results" [Undecided,New] | 16:01 |
sc68cal | Essentially, I create a dns domain using the CLI tool, and can't get the domains I created returned from the CLI. In addition, the SQLAlchemy calls in the db.api package appear to return no results either | 16:05 |
sc68cal | I've replicated this in DevStack, as well as an install of stable/essex | 16:06 |
*** andrewbogott has left #openstack-dev | 16:06 | |
*** armaan has joined #openstack-dev | 16:06 | |
*** davidkranz has joined #openstack-dev | 16:06 | |
zul | jgriffith: ping | 16:07 |
*** davidkranz_ has quit IRC | 16:07 | |
jgriffith | zul: hey | 16:07 |
jgriffith | zul: Looking now :) | 16:07 |
zul | jgriffith: any idea why its failing? | 16:07 |
jgriffith | zul: Give me ~ 5 and I'll have a look, I might know the issue | 16:08 |
*** mokas has quit IRC | 16:08 | |
zul | jgriffith: ack | 16:08 |
*** andrewsmedina has joined #openstack-dev | 16:11 | |
*** bencherian has joined #openstack-dev | 16:13 | |
*** Gordonz_ has quit IRC | 16:14 | |
*** davidkranz_ has joined #openstack-dev | 16:18 | |
*** davidkranz has quit IRC | 16:20 | |
*** davidkranz has joined #openstack-dev | 16:24 | |
*** davidkranz_ has quit IRC | 16:26 | |
*** sniperd has joined #openstack-dev | 16:27 | |
*** alex88 has quit IRC | 16:32 | |
ttx | notmyname: around ? | 16:33 |
notmyname | ttx: ya | 16:34 |
*** devananda has joined #openstack-dev | 16:34 | |
jgriffith | zul: I'm going to pull this and try running it on my system and see if I can trace through to find the problem | 16:34 |
ttx | notmyname: when all set for 1.6.0, you should push a Final=True commit to milestone-proposed | 16:34 |
notmyname | ttx: ok, I can do that | 16:34 |
zul | jgriffith: ok | 16:34 |
ttx | notmyname: and if that's done today i can pick it up in my tomorrow morning and publish it. | 16:35 |
notmyname | ttx: I'll do it asap | 16:35 |
ttx | notmyname: it's all QA'ed ? | 16:35 |
notmyname | ttx: not finished yet | 16:35 |
ttx | (Final=True should be done as last step) | 16:36 |
*** bhuvan has joined #openstack-dev | 16:36 | |
ttx | notmyname: maybe wait for the QA signoff. I won't have time to push it today anyway (having the evening off) | 16:36 |
ttx | so I'll pick it up early tomorrow morning. | 16:36 |
notmyname | ttx: ya, it will probably get signoff today or tomorrow. I'll push final=true when I have that confirmation | 16:37 |
ttx | notmyname: sounds good! | 16:37 |
*** milner has quit IRC | 16:43 | |
*** rohitk has quit IRC | 16:44 | |
*** jog0 has joined #openstack-dev | 16:48 | |
*** thingee has joined #openstack-dev | 16:49 | |
jgriffith | zul: I'm trying to find the mod I need for devstack for this | 16:50 |
zul | jgriffith: https://review.openstack.org/#/c/10467/ | 16:50 |
jgriffith | zul: thanks! | 16:51 |
jgriffith | zul: So until this lands in devstack I think we're on hold no? | 16:52 |
zul | jgriffith: i think so...needs another core reviewer | 16:52 |
*** martines has quit IRC | 16:52 | |
jgriffith | zul: Right.. but what I'm saying is this is *why* the cinder changes are failing in jenkins | 16:52 |
zul | jgriffith: looks like it | 16:53 |
*** Aaton_off is now known as Aaton | 16:54 | |
*** nunosantos has quit IRC | 16:54 | |
*** heckj has quit IRC | 16:56 | |
*** maploin has quit IRC | 16:56 | |
*** darraghb has quit IRC | 16:57 | |
*** andrewbogott has joined #openstack-dev | 16:57 | |
*** andrewbogott has joined #openstack-dev | 16:57 | |
*** nunosantos has joined #openstack-dev | 17:01 | |
*** bhuvan has quit IRC | 17:03 | |
*** nati_ueno has joined #openstack-dev | 17:04 | |
*** AlanClark has quit IRC | 17:05 | |
*** issackelly has joined #openstack-dev | 17:06 | |
*** issackelly has quit IRC | 17:07 | |
*** nati_ueno has quit IRC | 17:08 | |
*** nati_ueno has joined #openstack-dev | 17:08 | |
*** Ryan_Lane has quit IRC | 17:09 | |
*** issackelly has joined #openstack-dev | 17:09 | |
*** adjohn has joined #openstack-dev | 17:09 | |
*** danpb has quit IRC | 17:09 | |
*** matwood has joined #openstack-dev | 17:09 | |
*** jdurgin has joined #openstack-dev | 17:13 | |
*** sstent has quit IRC | 17:16 | |
*** derekh has quit IRC | 17:16 | |
*** sstent has joined #openstack-dev | 17:17 | |
*** matwood has quit IRC | 17:22 | |
*** mokas has joined #openstack-dev | 17:22 | |
*** rohitk has joined #openstack-dev | 17:22 | |
*** martines has joined #openstack-dev | 17:23 | |
*** jaypipes has quit IRC | 17:25 | |
*** milner has joined #openstack-dev | 17:25 | |
*** mokas has quit IRC | 17:26 | |
*** apevec has quit IRC | 17:30 | |
*** jaypipes has joined #openstack-dev | 17:34 | |
*** cp16net|away is now known as cp16net | 17:35 | |
ayoung | dolphm, I am not too clear on one of your PKI comments. Got a second to elucidate? | 17:38 |
*** sniperd has quit IRC | 17:38 | |
*** sniperd has joined #openstack-dev | 17:38 | |
*** notmyname has quit IRC | 17:39 | |
dolphm | ayoung: sure | 17:40 |
*** notmyname has joined #openstack-dev | 17:40 | |
*** ChanServ sets mode: +v notmyname | 17:40 | |
ayoung | dolphm, reissue versus authenticate with tokens? | 17:40 |
ayoung | The authenticate call seems like it is there to validate the tokens. Why would we want to issue a new one, especially WRT the whole sliding window issue that we fixed? | 17:41 |
ayoung | I don't recall the conversation. | 17:41 |
dolphm | ayoung: validation is totally seperate ... when you POST /tokens with a token in the request body, the goal is to exchange your token for a different one, usually because the token you have is not associated with a tenant, and you want one back *with* a tenant | 17:42 |
*** matiu has quit IRC | 17:43 | |
ayoung | dolphm, right. hence all the checks for the tenant id. | 17:43 |
ayoung | But if you ask for a token for a given tenant ID, and there is already one issued for that id, shouldnt we reuse the issued token? | 17:43 |
dolphm | ayoung: the fact that we (until recently ;]) produced a new token on every POST /tokens is just due to the expected semantics of POST -- in diablo, we returned an existing token if one existed, just like you're doing now | 17:44 |
ayoung | dolphm, so...ther one issue is that we don't distinguish between the reissue window and the expiration window. I think we need a new window | 17:45 |
ayoung | if a token is to be used for a long running job, you don't want to ask for a token and then get one that will expire in 5 minutes. | 17:45 |
dolphm | resissue window == expiration window, no? | 17:45 |
dolphm | ayoung: default token duration is 24 hours, right? | 17:46 |
ayoung | dolphm, right now, yes, in that we would only issue a new token if the old is invalid | 17:46 |
dolphm | ayoung: # Amount of time a token should remain valid (in seconds) # expiration = 86400 | 17:46 |
ayoung | but what if we have a 24hour duration, and the user asks for a token at 23hrs and 59 minutes? | 17:47 |
dolphm | ayoung: depends on their authentication method | 17:47 |
dolphm | ayoung: if they provide username & password, they get back a fresh 24 hour token | 17:47 |
ayoung | dolphm, I don't agree. | 17:47 |
ayoung | UID/PW will still elad to a proliferation of tokens. | 17:47 |
dolphm | ayoung: if they authenticate with their existing token (with 1 minute left on the clock) they get back a second token with the same expire time | 17:47 |
ayoung | none of the CLIs cache tokens, only record UID/PW | 17:48 |
ayoung | so each CLI call will generate a new token | 17:48 |
ayoung | obviously, token->token should not extend lifespan | 17:48 |
dolphm | ayoung: CLI's aren't the only client implementations | 17:48 |
ayoung | dolphm, that is true, and irrelevant :) | 17:48 |
ayoung | any client impl might have this problem | 17:49 |
davidkranz | eglynn: Hopefully this can go through now https://review.openstack.org/#/c/10552/ | 17:49 |
*** mokas has joined #openstack-dev | 17:49 | |
dolphm | ayoung: maybe i don't understand the problem you're describing? | 17:49 |
ayoung | dolphm, if everytime a user auths with UID/PW we generate a new token, we will have a huge number of tokens | 17:49 |
dolphm | ayoung: the CLI implementation naively authenticating for every command is just due to it's simple design | 17:49 |
ayoung | all will be valid, and all will have to stick around | 17:49 |
dolphm | ayoung: but only for 24 hours or whatever | 17:50 |
*** matiu has joined #openstack-dev | 17:50 | |
ayoung | dolphm, but if you run a script that ends up calling to keystone 2500 times you should not have 2500 tokens | 17:50 |
dolphm | ayoung: old tokens are small and easily flushable, and PKI tokens don't need to be persisted on the keystone-side, right? | 17:50 |
ayoung | dolphm, wrong | 17:50 |
dolphm | ayoung: which part | 17:50 |
ayoung | due to the new checks, we have to hold on to them | 17:51 |
*** Mandell has joined #openstack-dev | 17:51 | |
ayoung | now..it might be possible to only hold on to the hash_id | 17:51 |
dolphm | ayoung: hold onto old tokens past expiration or hold onto PKI tokens? | 17:51 |
ayoung | dolphm, when we create a PKI token, the id is the whole document, and it is hashed and put into id_hash | 17:51 |
ayoung | in the SQL imp | 17:52 |
ayoung | the more I think about it, however, the more I think that we don't need to store the whole id, just the hash...I need to make sure that will work for the upgrade path, though | 17:52 |
dolphm | ayoung: what's the persisted id / hash id used for later? | 17:53 |
ayoung | dolphm, only becasue the SQL impl needs a primary key, and there are length constraints for the column | 17:53 |
*** jakedahn_zz is now known as jakedahn | 17:53 | |
ayoung | the huge PKI ID can;'t be a primary key or index | 17:53 |
*** maurosr has quit IRC | 17:54 | |
*** dachary has quit IRC | 17:54 | |
dolphm | ayoung: what do you need to store it for? (assuming you *do* issue *new* tokens on every POST /tokens) | 17:55 |
ayoung | If we issue new tokens, we don't need to store the whole token, but we need the id_hash to ensure that we know when a toen has been revoked | 17:57 |
dolphm | ayoung: ah, i forgot about token revocation | 17:57 |
*** rods has quit IRC | 17:58 | |
dolphm | ayoung: that's a good solution then, i think | 17:58 |
ayoung | dolphm, the reissue window is a good solution? | 17:58 |
ayoung | actually, we could recaculate a reissue window off the expiry. That is probably how most people would want to think about it anyway | 17:59 |
*** epim has joined #openstack-dev | 18:00 | |
*** matwood has joined #openstack-dev | 18:00 | |
dolphm | ayoung: (just storing the hash for token revocation purposes == good solution) ... i would lean toward no on reissuing tokens, but i'm more concerned with good docs on the expected behavior :) | 18:00 |
ayoung | dolphm, are you sure that, prior to my change, keystone did not reissue tokens on UID/Password resubmits? | 18:02 |
dolphm | ayoung: you're basically suggesting something like... if REMAINING_TOKEN_LIFESPAN > FULL_TOKEN_DURATION / 2: reissue_token() | 18:02 |
*** danwent has quit IRC | 18:02 | |
dolphm | ayoung: pretty sure -- authenticate() always returned the uuid.uuid4().hex generated at the beginning of the method if auth was successful | 18:03 |
ayoung | dolphm, well, I would use a different formula, but yes. Maybe more like if REMAINING_TOKEN_LIFESPAN - NOW < THRESHOLD: reissue_token() | 18:03 |
*** GheRivero has quit IRC | 18:03 | |
ayoung | dolphm, why does this not just fill up the databases with single use tokens? | 18:03 |
dolphm | ayoung: doesn't it, though? | 18:04 |
ayoung | dolphm, do you have system you can test on? Mine all have the new code on them right now. | 18:04 |
ayoung | actually, I might have one...1 sec | 18:05 |
dolphm | ayoung: sure | 18:05 |
*** Ryan_Lane has joined #openstack-dev | 18:05 | |
ayoung | dolphm, ok, so token-get returns a new one everytime... | 18:06 |
vishy | jgriffith: https://jenkins.openstack.org/job/gate-tempest-devstack-vm/5321/artifact/logs/screen-c-sch.txt | 18:06 |
*** Gordonz has joined #openstack-dev | 18:07 | |
*** anniec has joined #openstack-dev | 18:07 | |
*** maurosr has joined #openstack-dev | 18:07 | |
jgriffith | vishy: Thanks! | 18:12 |
dansmith | erlang | 18:12 |
dansmith | oops | 18:12 |
*** rohitk has quit IRC | 18:12 | |
*** gyee has joined #openstack-dev | 18:12 | |
*** gyee has quit IRC | 18:12 | |
*** rohitk has joined #openstack-dev | 18:12 | |
jtran | dtroyer, what's "F17"? | 18:13 |
*** salgado has quit IRC | 18:13 | |
*** maurosr has quit IRC | 18:13 | |
*** sulochan has quit IRC | 18:13 | |
dolphm | ayoung: "an identical token may have been created already. if so, return the token_data as it is also identical" <-- except you don't actually return the existing token | 18:14 |
zaitcev | jtran: Fedora 17 | 18:14 |
*** gyee has joined #openstack-dev | 18:14 | |
jtran | ooh ok. | 18:14 |
jtran | thx, zaitcev | 18:14 |
*** Gordonz_ has joined #openstack-dev | 18:14 | |
ayoung | dolphm, true. And technically impossible, now that the time stamp is in the token. | 18:14 |
*** Gordonz_ has quit IRC | 18:15 | |
*** edygarcia has quit IRC | 18:17 | |
*** Gordonz has quit IRC | 18:18 | |
*** ron-slc has joined #openstack-dev | 18:18 | |
dprince | ayoung: Question on singing_dir... it needs to be unique for each service right? Based on what I see in auth_token that appears to be the case... | 18:19 |
ayoung | dolphm, so that code is correct, you realize. The value of exist_token will be identical to token_data | 18:19 |
ayoung | dprince, no | 18:19 |
ayoung | it is a cache, and can be shared | 18:19 |
dprince | ayoung: signing not singing. (although perhaps we do need a singing dir too!) | 18:19 |
dprince | But it gets chowned as write only to that user/group that creates it. | 18:20 |
ayoung | dprince, however, there is nothing wrong with making one per service. | 18:20 |
ayoung | dprince, should be ok | 18:20 |
ayoung | the first service requests the certs and populate | 18:20 |
ayoung | s | 18:20 |
*** PotHix has joined #openstack-dev | 18:21 | |
dprince | I'm actually hitting this exception "TODO: Need to find an Exception to raise here." | 18:21 |
ayoung | I guess there is the potential for an early failure there in some sort of race condition, | 18:21 |
dprince | (a real gem) | 18:21 |
ayoung | dprince, do you have PKI enabled? | 18:21 |
dprince | nope | 18:21 |
ayoung | or is this just in provisioning a system? | 18:21 |
* ayoung RCA dog look | 18:21 | |
*** maurosr has joined #openstack-dev | 18:22 | |
dprince | I'm hitting this when installing a system. | 18:22 |
*** edygarcia has joined #openstack-dev | 18:22 | |
dprince | All services on the same box, glance, keystone, nova, swift, etc. | 18:22 |
*** maoy has quit IRC | 18:23 | |
dolphm | dprince: i've seen that comment before .. where is it? | 18:23 |
ayoung | dprince, ah,,,, | 18:23 |
ayoung | dolphm, auth_token | 18:23 |
ayoung | middleware, init | 18:23 |
ayoung | line 155 | 18:23 |
ayoung | ish | 18:23 |
*** maurosr has quit IRC | 18:23 | |
dolphm | ayoung: found it | 18:24 |
dolphm | ayoung: doesn't that just raise an excepting trying to raise a string? | 18:24 |
ayoung | dolphm, I think that dprince is using the Fedora RPMS as opposed to Devstack. dprince corect? | 18:25 |
dolphm | ayoung: * doesn't raising a string raise it's own exception? | 18:25 |
ayoung | dolphm, it breaks the init process | 18:25 |
dprince | ayoung: Yes. This is SmokeStack. | 18:25 |
ayoung | OK...we have a couple options | 18:25 |
ayoung | we can remove the check and let things fail later | 18:25 |
ayoung | we can make one dir per service | 18:25 |
dprince | dolphm: yes. The way that exception is raised is also a problem. But that isn't what I'm getting at here... | 18:25 |
ayoung | or we can safely share the dir | 18:25 |
*** maoy has joined #openstack-dev | 18:25 | |
dprince | ayoung: Those were my questions for you! | 18:26 |
dolphm | ayoung: can you start with logging an error? LOG.error("Can't write to %s" % self.signing_dirname) | 18:26 |
dprince | I just spent the last 20 minutes considering several of those options and I started getting confused. | 18:26 |
ayoung | dprince, I seen no reason to try and minimize the number of REST calls to fetch certs....probably the safest bet is "one dir per service" | 18:26 |
dprince | Seems like automatically naming the directories would be nice.... | 18:27 |
ayoung | right now the dir name is | 18:27 |
ayoung | conf.get('signing_dir' | 18:27 |
ayoung | with a default of '/tmp/keystone-signing') | 18:27 |
dprince | I suppose we should maybe just update the auth_token examples in each project (Nova, Glance, Swift). | 18:27 |
ayoung | dprince, so set that value explicitly and it should work: | 18:27 |
dprince | /tmp/keystone-signing-nova for example. | 18:27 |
ayoung | dprince, precisely | 18:28 |
dprince | Yep. I did that myself and it works great. I feel like we should do that in the various projects too... If I push paste file updates to Nova, Glance, Swift, etc to use the unique directory names would you buy that? | 18:28 |
dtroyer | jtran: Fedora 17 | 18:29 |
dprince | ayoung: ^^ essentially would make it clear to end users that separate directories are fine (recommended even). | 18:29 |
ayoung | dprince, I would buy into that, yes | 18:30 |
dprince | ayoung: OKay. I'll do that then. That would make me happier about this I think. | 18:30 |
dprince | ayoung: I think that's it then. Thanks sir. | 18:31 |
dprince | ayoung: Oh. Well. There is the exception itself... we need to fix that. | 18:31 |
ayoung | dprince, I am actually happy that people are tripping over bugs in PKI. I think the more noise it makes, the more solid the impl will be in the long run | 18:31 |
ayoung | dprince, yeah, I can fix that exception | 18:31 |
dprince | ayoung: deal. | 18:32 |
*** matwood has quit IRC | 18:32 | |
*** matwood has joined #openstack-dev | 18:32 | |
dolphm | ayoung: i finally see what you're doing in that try / except ... | 18:33 |
dolphm | ayoung: in the outer try / except, don't you really only want to catch keystone.exception.Conflict? | 18:33 |
dolphm | ayoung: i would assume that's the only condition in which you'd want to verify that a duplicate token already exists | 18:34 |
*** maurosr has joined #openstack-dev | 18:34 | |
ayoung | dolphm, yes, That code verifies that. If it does not exist, there is an exception, and it is not one that we can handle. | 18:35 |
ayoung | Since it is such an edge condition, I am oK with running the query a second time | 18:35 |
ayoung | dprince, https://bugs.launchpad.net/keystone/+bug/1031008 | 18:35 |
uvirtbot | Launchpad bug 1031008 in keystone "Report better error when signing dir is not writable" [Undecided,New] | 18:35 |
*** yapeng has quit IRC | 18:36 | |
dprince | ayoung: THanks. Do you think I should create a ticket for the other issue... its sort of just a config file/doc thing. | 18:37 |
dprince | ayoung: ? | 18:37 |
ayoung | dprince, yes, lets make sure we don't lose it. | 18:37 |
ayoung | It is a real issue, and should be in a ticket. If you got burnt by it, so will others. | 18:37 |
ayoung | the thing is, I am wondering if I should still provide a better sharing mechanism, or a better default dir name? | 18:38 |
ayoung | dprince, is there a way to get the "good name" of a service when it is runnning? | 18:38 |
dprince | I though about using 'admin_user'. | 18:39 |
ayoung | Also, it might not just be REST services that need to validate tokens....it might not be sufficient to use nova, or glance, | 18:39 |
*** avishay has quit IRC | 18:39 | |
ayoung | unless they all run as the same user | 18:39 |
dprince | ayoung: https://review.openstack.org/10555 | 18:41 |
ayoung | dprince, how about /tmp/keystone-<username> | 18:41 |
davidkranz | https://review.openstack.org/#/c/10552/ is failing with what I think is a bogus timeout, not a real test failure. Any one know how to kick this change to get jenkins to try again? | 18:41 |
dprince | ayoung: I thought it bad to expose the username in the /tmp directory name. | 18:41 |
ayoung | dprince, why ? | 18:42 |
dprince | ayoung: Oh. You mean just the username of the process that is running? | 18:42 |
ayoung | dprince, yes | 18:43 |
dprince | ayoung: That is probably fine I guess. I was thinking you mean one of the username params used for auth_token setup. | 18:43 |
dprince | ayoung: As a default username would seem fine I think. | 18:44 |
ayoung | dprince, let me think about it. I think it is the right abstraction. | 18:44 |
ayoung | Need to go do a daycare pickup. I'll let it ferment until then | 18:44 |
dprince | ayoung: No harm in setting them per service either though... That is a valid approach. | 18:45 |
dprince | ayoung: Cool. Later then. | 18:45 |
*** matwood has quit IRC | 18:49 | |
*** epim has quit IRC | 18:51 | |
*** epim has joined #openstack-dev | 18:51 | |
*** rohitk has quit IRC | 18:56 | |
*** rnirmal has quit IRC | 18:56 | |
*** danwent has joined #openstack-dev | 19:00 | |
*** vishy is now known as vishy-afk | 19:03 | |
*** dachary has joined #openstack-dev | 19:03 | |
*** rkukura has quit IRC | 19:05 | |
*** rkukura has joined #openstack-dev | 19:05 | |
*** dhellmann has joined #openstack-dev | 19:08 | |
*** armaan has left #openstack-dev | 19:09 | |
*** sulochan has joined #openstack-dev | 19:12 | |
*** bhuvan has joined #openstack-dev | 19:12 | |
*** sulochan has left #openstack-dev | 19:12 | |
bhuvan | dhellmann: can you please review the revised (keyring) patch, https://review.openstack.org/#/c/9497/ when you find time? | 19:13 |
*** datsun180b has quit IRC | 19:14 | |
dhellmann | bhuvan: did you see the replies to your message on the mailing list? | 19:15 |
*** nunosantos has quit IRC | 19:16 | |
*** salgado has joined #openstack-dev | 19:18 | |
* bhuvan is going through the email from dhellmann, in the list | 19:18 | |
dhellmann | bhuvan: Look for the other responses, too. I do not want to rush accepting this patch. We need you to work through the use cases beyond a single person with a single login. | 19:21 |
*** nunosantos has joined #openstack-dev | 19:23 | |
*** vishy-afk is now known as vishy | 19:23 | |
vishy | jgriffith: looks like that issue was temporary: https://review.openstack.org/#/c/10538/ | 19:25 |
jgriffith | vishy: Yeah, but there's a number of issues | 19:25 |
jgriffith | vishy: So the volume_types is removed from Cinder | 19:25 |
jgriffith | vishy: err.. vm_types | 19:26 |
vishy | jgriffith: right, scheduler needs to be changed to remove that stuff | 19:26 |
jgriffith | vishy: I don't think that's the problem with the tgt changes though | 19:26 |
jgriffith | vishy: Yeah, I have the changes to scheduler ready to go | 19:26 |
jgriffith | vishy: Just trying to resolve the attach issues with the tgt patch first | 19:26 |
*** eglynn is now known as eglynn-GOFAR | 19:26 | |
*** salgado has quit IRC | 19:28 | |
vishy | jgriffith: could be because of https://review.openstack.org/#/c/10549/ | 19:31 |
*** Ryan_Lane has quit IRC | 19:31 | |
*** littleidea_ has joined #openstack-dev | 19:34 | |
*** salgado has joined #openstack-dev | 19:34 | |
*** salgado has joined #openstack-dev | 19:34 | |
*** novas0x2a|laptop has joined #openstack-dev | 19:34 | |
*** salgado has quit IRC | 19:34 | |
*** salgado has joined #openstack-dev | 19:35 | |
*** littleidea has quit IRC | 19:35 | |
*** littleidea_ is now known as littleidea | 19:35 | |
*** jgriffith has quit IRC | 19:39 | |
*** steveb_ has joined #openstack-dev | 19:46 | |
*** matwood has joined #openstack-dev | 19:48 | |
*** armaan has joined #openstack-dev | 19:49 | |
*** armaan has left #openstack-dev | 19:49 | |
dprince | hypervisor_hostname = Column("hypervisor_hostname", String(255)) | 19:50 |
*** mokas has quit IRC | 19:51 | |
*** salgado has quit IRC | 19:51 | |
*** jgriffith has joined #openstack-dev | 19:52 | |
*** jgriffith is now known as Guest14662 | 19:52 | |
Guest14662 | vishy: Ahhhh | 19:52 |
Guest14662 | vishy: I'll bet that's it | 19:53 |
Guest14662 | exit | 19:53 |
*** Guest14662 has quit IRC | 19:53 | |
*** mokas has joined #openstack-dev | 19:53 | |
*** jgriffith has joined #openstack-dev | 19:56 | |
*** wiliam has quit IRC | 19:57 | |
*** rnirmal has joined #openstack-dev | 20:02 | |
*** matwood has quit IRC | 20:02 | |
*** nati_uen_ has joined #openstack-dev | 20:02 | |
*** milner has quit IRC | 20:03 | |
*** nati_ueno has quit IRC | 20:06 | |
*** salgado has joined #openstack-dev | 20:06 | |
*** salgado has joined #openstack-dev | 20:06 | |
*** salgado has joined #openstack-dev | 20:06 | |
*** mokas has quit IRC | 20:07 | |
*** eglynn-GOFAR is now known as eglynn | 20:09 | |
ayoung | dprince, I take it you tested your keystone change? | 20:13 |
dprince | ayoung: yesir | 20:15 |
ayoung | dprince, how'd you test? | 20:15 |
creiht | eglynn: thanks for jumping on that xml volume creation bug | 20:15 |
dprince | ayoung: swift wouldn't start (due to permissions issues). I laid that code in place and I got /tmp/keystone-signing-swift... and swift started. | 20:16 |
eglynn | creiht: np! | 20:16 |
ayoung | dprince, nice | 20:16 |
*** Ruetobas has quit IRC | 20:16 | |
ayoung | dprince, I'm going to give it a run on devstack. If all works there, I'll merge | 20:16 |
dprince | ayoung: while I've got you... lets talk about migrations! | 20:16 |
dprince | ayoung: I've got one that works for Postgresql and MySQL I think... | 20:17 |
dprince | ayoung: (in python) | 20:17 |
dprince | ayoung: Any reason you used .sql files for the 002 migrations? | 20:17 |
ayoung | dprince, yep | 20:17 |
ayoung | I was doing a column mod, and sqlalchemy couldn't handle that | 20:17 |
dprince | ayoung: If I were to replace it with a python version would you be cool with that? | 20:17 |
ayoung | dprince, does your version maintiain the data? | 20:18 |
dprince | ayoung: I *think* I hit the same issue and I was able to work around it by grabbing another version of the metadata (after renaming the column). | 20:18 |
ayoung | dprince, so...the other thing is that I think I want to go back to the old schema. See my previous conversation with dolphm for context | 20:18 |
clarkb | python-glanceclient reviewers can you take a look at https://review.openstack.org/#/c/10438/ ? A small change to fix the coverage testing for python-glanceclient | 20:18 |
ayoung | RIght now, we are storing the token data for PKI which is huge | 20:18 |
ayoung | If we don't really need that, we can store just the id_hash | 20:19 |
ayoung | but I am not yet convinced | 20:19 |
dprince | ayoung: So... you plan on dropping id_hash and just haveing the id (pkey) again? | 20:19 |
dprince | ayoung: Still. You've already done it... so the right thing to do is to make a new migration to move forwards. | 20:19 |
ayoung | dprince, plan is too firm a word. Lets say I am entertaining the idea, but not using the best china in doing so... | 20:19 |
ayoung | dprince, nah, this migration could just be undone | 20:20 |
ayoung | we don't need to support random middle versions of the code. just upgrades from essex | 20:20 |
ayoung | but... | 20:21 |
dprince | ayoung: I'm not sure we take that stance on all OpenStack projects.... there are some deployments following upstream a bit more closely. | 20:21 |
*** mokas has joined #openstack-dev | 20:22 | |
ayoung | dprince, right. THe thing is, I am not yet ready to commit to rolling it back anyway. I like having the token in there, as we can then re-issue them | 20:22 |
dprince | ayoung: anyway. Thanks for the info on possibly re-working the migrations for this. Good to know. In anycase I'd like Postgres to work too so I may push this fix for that. | 20:22 |
ayoung | which makes sense in some cases | 20:22 |
ayoung | postgres should work with my sqlite sql script | 20:22 |
dprince | Which will most likely use python... | 20:22 |
*** datsun180b has joined #openstack-dev | 20:22 | |
ayoung | try it that way first before adding a new patch | 20:22 |
dprince | ayoung: that would be a manual hack | 20:23 |
dprince | ayoung: I want something that works out of the box... aka. keystone-manage db_sync | 20:23 |
ayoung | but I would be OK redoing the whole thing in python if we could get it down to one file | 20:23 |
ayoung | I'd say that is preferred | 20:23 |
dprince | ayoung: Yep. That is my goal here. | 20:23 |
dprince | ayoung: single file in python that supports all 3... sqlite, mysql, postgres. | 20:24 |
*** lorin1 has left #openstack-dev | 20:24 | |
ayoung | dprince, I was told that postgres would ues the sqlite script. I take it that was lie? | 20:24 |
*** lorin1 has joined #openstack-dev | 20:24 | |
ayoung | a lie | 20:24 |
*** Ruetobas has joined #openstack-dev | 20:24 | |
dprince | ayoung: Well... Not calling it a lie... But it didn't work for me. | 20:25 |
dprince | ayoung: So I'm fixing it. | 20:25 |
ayoung | dprince, +1 | 20:25 |
ayoung | dprince, I just tested your fix on devstack. Works as expected. I will trigger the merge | 20:26 |
dprince | ayoung: Great. THanks man. | 20:27 |
*** johnpur has joined #openstack-dev | 20:28 | |
*** ChanServ sets mode: +v johnpur | 20:28 | |
*** steveb_ has quit IRC | 20:34 | |
*** markvoelker has quit IRC | 20:34 | |
*** marktvoelker has joined #openstack-dev | 20:35 | |
*** Ryan_Lane has joined #openstack-dev | 20:35 | |
*** dprince has quit IRC | 20:36 | |
*** nati_uen_ has quit IRC | 20:36 | |
*** nati_ueno has joined #openstack-dev | 20:36 | |
*** rods has joined #openstack-dev | 20:37 | |
davidkranz | jaypipes: What did you do to kick the admin password change to retry the build? | 20:39 |
notmyname | ttx: LP updated post-facto with swift 1.6.0 blueprints | 20:39 |
*** apevec has joined #openstack-dev | 20:40 | |
*** apevec has joined #openstack-dev | 20:40 | |
jaypipes | davidkranz: put "recheck" into a review comment :) | 20:41 |
davidkranz | jaypipes: How clever :) | 20:41 |
jaypipes | davidkranz: and check here for progress on our little tempest-devstack-vm monster: https://jenkins.openstack.org/zuul/status :) | 20:42 |
davidkranz | jaypipes: Hmm. Not sure what that means. | 20:43 |
jaypipes | davidkranz: that link just gives the latest status of the jobs that Zuul handles (which the tempest gate is part of) | 20:44 |
jaypipes | davidkranz: after that, you'd have to ask jeblair ;P | 20:44 |
davidkranz | jaypipes: OK. Wasn't sure what "monster" referred to.. | 20:44 |
jaypipes | davidkranz: oh, just meaning that tempest's intricate relationship with the many core projects as well as devstack and devstack-gate make it a bit of a beast ;) | 20:45 |
jaypipes | davidkranz: as far as interdependencies go... | 20:45 |
davidkranz | jaypipes: OK, got it. | 20:45 |
*** reed has quit IRC | 20:47 | |
markmc | jeblair, I guess you'd be shocked if I was to say "hi james, everything's working great!" :) | 20:48 |
markmc | jeblair, why do URLs like https://review.openstack.org/10155/ not work any more? | 20:48 |
*** sc68cal has quit IRC | 20:48 | |
*** milner has joined #openstack-dev | 20:48 | |
jeblair | markmc: it seems to only dislike the trailing / | 20:49 |
markmc | jeblair, ahhhrrr! | 20:49 |
jeblair | markmc: to be fair, gerrit only offers a non-training / version of that url as the permalink... off the top of my head, i don't know if trailing / ever worked... | 20:49 |
jeblair | markmc: it's certainly possible it did, and we somehow broke that with an apache change... | 20:50 |
jeblair | markmc: (or that it was a recent change in gerrit that we didn't notice) | 20:50 |
markmc | jeblair, looks like I've send a bunch of mail before with the trailing slash | 20:52 |
markmc | jeblair, so I guess it worked at one stage | 20:52 |
* markmc shrugs | 20:52 | |
markmc | jeblair, no big deal, teaches me for manually creating my own permalinks :) | 20:52 |
*** s0mik has joined #openstack-dev | 20:53 | |
*** salgado_ has joined #openstack-dev | 20:53 | |
*** salgado has quit IRC | 20:55 | |
*** salgado_ has quit IRC | 20:56 | |
*** salgado has joined #openstack-dev | 20:57 | |
*** mokas has quit IRC | 20:57 | |
*** flaviamissi has joined #openstack-dev | 21:00 | |
*** dachary has quit IRC | 21:01 | |
*** zhuadl has joined #openstack-dev | 21:01 | |
*** dachary has joined #openstack-dev | 21:01 | |
*** novas0x2a|laptop has quit IRC | 21:02 | |
*** bencherian has quit IRC | 21:04 | |
*** asalkeld_ is now known as asalkeld | 21:04 | |
*** andrewbogott has quit IRC | 21:05 | |
*** andrewbogott has joined #openstack-dev | 21:06 | |
*** andrewbogott has joined #openstack-dev | 21:06 | |
*** novas0x2a|laptop has joined #openstack-dev | 21:06 | |
*** salgado has quit IRC | 21:07 | |
*** maurosr has quit IRC | 21:07 | |
*** dragondm has quit IRC | 21:08 | |
*** dragondm has joined #openstack-dev | 21:08 | |
*** pandemicsyn has quit IRC | 21:09 | |
markmc | zul, you could really do with explaining why https://review.openstack.org/#/c/10266/ isn't appropriate for stable | 21:09 |
*** pandemicsyn has joined #openstack-dev | 21:09 | |
markmc | zul, haven't reviewed myself yet, but it "why" would even help me nevermind the author :) | 21:09 |
*** chenxu has quit IRC | 21:09 | |
*** ChanServ sets mode: +v pandemicsyn | 21:09 | |
*** chenxu has joined #openstack-dev | 21:10 | |
*** linmin has quit IRC | 21:10 | |
*** justinsb has quit IRC | 21:10 | |
*** justinsb has joined #openstack-dev | 21:10 | |
*** nati_ueno has quit IRC | 21:10 | |
*** linmin has joined #openstack-dev | 21:10 | |
*** hazmat has quit IRC | 21:10 | |
*** nati_ueno has joined #openstack-dev | 21:10 | |
*** pmyers has quit IRC | 21:11 | |
*** chmouel has quit IRC | 21:11 | |
*** sc68cal has joined #openstack-dev | 21:11 | |
*** pmyers has joined #openstack-dev | 21:11 | |
*** chmouel has joined #openstack-dev | 21:12 | |
*** lts has quit IRC | 21:13 | |
*** blufor has quit IRC | 21:13 | |
*** blufor has joined #openstack-dev | 21:13 | |
*** hazmat has joined #openstack-dev | 21:15 | |
*** hazmat has joined #openstack-dev | 21:15 | |
*** sc68cal has quit IRC | 21:15 | |
*** file has joined #openstack-dev | 21:20 | |
russellb | file: i see you over here, too. | 21:20 |
file | russellb, incorrect. | 21:20 |
*** lorin1 has quit IRC | 21:21 | |
*** steveb_ has joined #openstack-dev | 21:25 | |
zul | markmc: i did | 21:25 |
zul | my second comment in there | 21:25 |
markmc | zul, "please see http://wiki.openstack.org/StableBranch#Appropriate_Fixes" ? | 21:25 |
*** flaviamissi has quit IRC | 21:26 | |
zul | markmc: yeah it must have been early in the morning when i rejected that | 21:27 |
zul | markmc: yeah but i agree with your comment | 21:27 |
markmc | zul, ok | 21:27 |
markmc | zul, couple more that need looking at - https://review.openstack.org/#/c/10509/ and https://review.openstack.org/#/c/10510/ | 21:28 |
markmc | zul, both pretty minor | 21:28 |
zul | markmc: yep will get to them later tonight | 21:28 |
markmc | zul, thanks | 21:28 |
markmc | zul, btw, we're doing nova and keystone 2012.1.2 in case you missed last week's meeting | 21:29 |
markmc | zul, doing 2012.1.2 this week, I mean | 21:29 |
zul | when was the meeting? | 21:29 |
markmc | weekly openstack meeting | 21:29 |
zul | ok | 21:29 |
*** mokas has joined #openstack-dev | 21:36 | |
*** sandywalsh_ has joined #openstack-dev | 21:42 | |
*** sandywalsh has quit IRC | 21:43 | |
*** marktvoelker has quit IRC | 21:48 | |
*** sandywalsh_ has quit IRC | 21:49 | |
*** littleidea has quit IRC | 21:52 | |
*** littleidea has joined #openstack-dev | 21:52 | |
*** s0mik has quit IRC | 21:52 | |
*** matwood has joined #openstack-dev | 21:57 | |
*** matwood has quit IRC | 21:57 | |
jgriffith | zul: Killing me... can't find the problem with this attach http://paste.openstack.org/show/19797/ | 21:59 |
jgriffith | zul: I pulled in some of your rootwrap changes and matched some things up that you had in the nova patch that was missing | 21:59 |
jgriffith | zul: But no go still... attach call never makes it to the cinder side of things | 21:59 |
zul | jgriffith: this is running on precise? | 22:00 |
jgriffith | zul: Yes | 22:00 |
zul | jgriffith: any chance i can get acess to this machine? | 22:00 |
jgriffith | zul: Not directly, but you could grab bcwaldons vagrant script | 22:00 |
jgriffith | zul: That's what I'm using on this | 22:01 |
zul | jgriffith: where do i go? | 22:01 |
jgriffith | zul: did a apt-get update this morning | 22:01 |
*** kbringard has quit IRC | 22:01 | |
*** steveb_ has quit IRC | 22:01 | |
jgriffith | zul: https://github.com/bcwaldon/vagrant_devstack | 22:02 |
*** eglynn has quit IRC | 22:03 | |
jgriffith | zul: The docs are geared towards mac, but I'm using precise. Can look up the history on the ruby config stuff if you need it | 22:04 |
zul | jgriffith: can you pastebin your cinder vol-logs as well? | 22:04 |
jgriffith | zul: Sure... | 22:05 |
*** andrewsmedina has quit IRC | 22:05 | |
jgriffith | zul: http://paste.openstack.org/show/19798/ | 22:06 |
*** sacharya has quit IRC | 22:06 | |
*** dachary has quit IRC | 22:06 | |
*** dachary has joined #openstack-dev | 22:07 | |
*** EmilienM has left #openstack-dev | 22:07 | |
zul | jgriffith: what does sudo tgt-admin -s show? | 22:07 |
jgriffith | zul: nada | 22:07 |
zul | jgriffith: so thats probably why it cant connect :) | 22:08 |
jgriffith | zul: :) | 22:08 |
zul | jgriffith: lemme have a look at this later tonight and ill get back to you | 22:08 |
jgriffith | zul: sure | 22:08 |
zul | jgriffith: its technically eod for me | 22:08 |
jgriffith | zul: got ya | 22:08 |
jgriffith | zul: Catch me tomorrow and let me know, else I'll go back to tracing through it | 22:09 |
zul | ack | 22:09 |
*** markmc is now known as mcaway | 22:10 | |
*** anniec has quit IRC | 22:12 | |
*** anniec has joined #openstack-dev | 22:12 | |
*** steveb_ has joined #openstack-dev | 22:14 | |
*** andrewsmedina has joined #openstack-dev | 22:27 | |
*** spiffxp has quit IRC | 22:30 | |
*** zul has quit IRC | 22:31 | |
*** datsun180b has quit IRC | 22:32 | |
*** ExxonValdeez has joined #openstack-dev | 22:38 | |
*** rods has quit IRC | 22:48 | |
*** spiffxp has joined #openstack-dev | 22:48 | |
*** s0mik has joined #openstack-dev | 22:50 | |
*** anniec_ has joined #openstack-dev | 22:51 | |
*** anniec has quit IRC | 22:51 | |
*** anniec_ is now known as anniec | 22:51 | |
*** e1mer has joined #openstack-dev | 22:55 | |
*** Shrews has quit IRC | 22:55 | |
*** zul has joined #openstack-dev | 22:59 | |
*** zul has quit IRC | 22:59 | |
*** zul has joined #openstack-dev | 22:59 | |
*** mokas has quit IRC | 23:01 | |
*** s0mik has quit IRC | 23:01 | |
*** zhuadl has quit IRC | 23:03 | |
*** edygarcia has quit IRC | 23:05 | |
*** blamar has joined #openstack-dev | 23:06 | |
*** dolphm has quit IRC | 23:08 | |
*** dubsquared has quit IRC | 23:10 | |
*** sacharya has joined #openstack-dev | 23:10 | |
*** s0mik has joined #openstack-dev | 23:11 | |
*** asalkeld has quit IRC | 23:12 | |
*** asalkeld has joined #openstack-dev | 23:12 | |
*** matiu has quit IRC | 23:13 | |
*** danwent has quit IRC | 23:13 | |
*** mokas has joined #openstack-dev | 23:14 | |
*** s0mik has quit IRC | 23:15 | |
*** dachary has quit IRC | 23:17 | |
*** dachary has joined #openstack-dev | 23:17 | |
*** s0mik has joined #openstack-dev | 23:18 | |
*** danwent has joined #openstack-dev | 23:19 | |
*** matwood has joined #openstack-dev | 23:21 | |
*** Transformer has joined #openstack-dev | 23:27 | |
*** Transformer has left #openstack-dev | 23:31 | |
*** sc68cal has joined #openstack-dev | 23:37 | |
*** nunosantos has quit IRC | 23:40 | |
*** jakedahn is now known as jakedahn_zz | 23:44 | |
bcwaldon | mtaylor: | 23:46 |
mtaylor | bcwaldon: | 23:47 |
bcwaldon | mtaylor: do jenkins pre-approval tests get kicked off for draft reviews? | 23:47 |
mtaylor | bcwaldon: I do not believe that they do | 23:47 |
bcwaldon | mtaylor: dang | 23:47 |
mtaylor | bcwaldon: sorry - their quasi-secret nature would get subverted if they did | 23:48 |
bcwaldon | mtaylor: I've gotta run, but could you somehow make jenkins tests happen for https://review.openstack.org/#/c/10575/? | 23:48 |
bcwaldon | or I could just un-draft it? | 23:48 |
mtaylor | yah | 23:48 |
mtaylor | I can't see it | 23:48 |
mtaylor | it's sekrit!@ | 23:48 |
bcwaldon | mtaylor: ok, its public | 23:48 |
bcwaldon | mtaylor: running away now | 23:48 |
mikal | How do I run the glance command line client from python-glanceclient? | 23:52 |
*** mestery_ is now known as mestery | 23:54 | |
*** markmcclain has quit IRC | 23:55 | |
mtaylor | mikal: installed or uninstalled? | 23:55 |
mikal | Uninstalled, just in the git directory | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!