Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Jan Cholasta
On 5.12.2013 13:31, Alexander Bokovoy wrote: On Thu, 05 Dec 2013, Petr Viktorin wrote: On 12/05/2013 11:15 AM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/3896. Patch 207 should fix build failures some of you were having after hardenening was

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Petr Viktorin
On 12/06/2013 11:52 AM, Jan Cholasta wrote: On 5.12.2013 13:31, Alexander Bokovoy wrote: On Thu, 05 Dec 2013, Petr Viktorin wrote: On 12/05/2013 11:15 AM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/3896. Patch 207 should fix build failures some

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Alexander Bokovoy
On Fri, 06 Dec 2013, Petr Viktorin wrote: On 12/06/2013 11:52 AM, Jan Cholasta wrote: On 5.12.2013 13:31, Alexander Bokovoy wrote: On Thu, 05 Dec 2013, Petr Viktorin wrote: On 12/05/2013 11:15 AM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/3896.

Re: [Freeipa-devel] [PATCHES] 0328-0329 test_integration: Support external names for hosts

2013-12-06 Thread Martin Kosek
On 12/03/2013 10:52 AM, Petr Viktorin wrote: Hello, Patch 0328 fixes the problem that I filed [4038] for: CA-less tests fail when run in some setups on Beaker. What the ticket says was premature diagnosis; I'll close the ticket as invalid. See commit message for the real problem. Patch

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Jan Cholasta
On 6.12.2013 12:57, Alexander Bokovoy wrote: On Fri, 06 Dec 2013, Petr Viktorin wrote: On 12/06/2013 11:52 AM, Jan Cholasta wrote: On 5.12.2013 13:31, Alexander Bokovoy wrote: On Thu, 05 Dec 2013, Petr Viktorin wrote: On 12/05/2013 11:15 AM, Jan Cholasta wrote: Hi, the attached patches fix

Re: [Freeipa-devel] [PATCH] 439 Allow kernel keyring CCACHE when supported

2013-12-06 Thread Martin Kosek
On 12/02/2013 05:20 PM, Alexander Bokovoy wrote: On Mon, 02 Dec 2013, Martin Kosek wrote: On 12/02/2013 04:05 PM, Petr Viktorin wrote: On 12/02/2013 03:42 PM, Simo Sorce wrote: On Mon, 2013-12-02 at 14:51 +0100, Petr Viktorin wrote: On 12/02/2013 02:01 PM, Martin Kosek wrote: On 12/02/2013

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Jan Cholasta
On 6.12.2013 13:31, Jan Cholasta wrote: On 6.12.2013 12:57, Alexander Bokovoy wrote: On Fri, 06 Dec 2013, Petr Viktorin wrote: On 12/06/2013 11:52 AM, Jan Cholasta wrote: On 5.12.2013 13:31, Alexander Bokovoy wrote: On Thu, 05 Dec 2013, Petr Viktorin wrote: On 12/05/2013 11:15 AM, Jan

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Petr Viktorin
On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: On Fri, 2013-11-29 at 16:51 +0100, Petr Viktorin wrote: I've updated the design with - updated schema (this time the OIDs are even reserved properly!) - longer attribute descriptions with examples - updated

[Freeipa-devel] [PATCH] 531 Fix license in some Web UI files

2013-12-06 Thread Petr Vobornik
Modified web ui files had incorrect GPLv2 headers instead of GPLv3 ones. All of the affected code is of FreeIPA origin. -- Petr Vobornik From 83300169da1e7a3a107a8a3c8c4f453380b5bcb1 Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Fri, 6 Dec 2013 14:08:07 +0100 Subject:

Re: [Freeipa-devel] Wiki by-component documentation

2013-12-06 Thread Martin Kosek
On 12/06/2013 09:40 AM, Petr Spacek wrote: On 5.12.2013 16:47, Martin Kosek wrote: Hello, Just wanted to let you know that I wrote 2 new by-component articles: http://www.freeipa.org/page/Directory_Server http://www.freeipa.org/page/PKI ... and extended

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Alexander Bokovoy
On Fri, 06 Dec 2013, Jan Cholasta wrote: However, even if writing to the pipe failed, we still need to wait until thread dies with pthread_join(). I think returning -1 here is premature. Fixed, updated patches attached. Also removed CFLAGS duplication, see patch 212. Thanks you! The build

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Petr Viktorin
On 12/06/2013 02:26 PM, Alexander Bokovoy wrote: On Fri, 06 Dec 2013, Jan Cholasta wrote: However, even if writing to the pipe failed, we still need to wait until thread dies with pthread_join(). I think returning -1 here is premature. Fixed, updated patches attached. Also removed CFLAGS

Re: [Freeipa-devel] [PATCHES] 206-209 Add default CFLAGS fix hardened build

2013-12-06 Thread Petr Spacek
On 6.12.2013 11:52, Jan Cholasta wrote: freeipa-jcholast-208.1-Add-stricter-default-CFLAGS-to-Makefile.patch From 85ad15d522274a711c87f92ed91889b781d7455e Mon Sep 17 00:00:00 2001 From: Jan Cholastajchol...@redhat.com Date: Wed, 4 Dec 2013 18:42:36 +0100 Subject: [PATCH 3/5] Add stricter

Re: [Freeipa-devel] [PATCH] 439 Allow kernel keyring CCACHE when supported

2013-12-06 Thread Simo Sorce
On Fri, 2013-12-06 at 13:42 +0100, Martin Kosek wrote: On 12/02/2013 05:20 PM, Alexander Bokovoy wrote: On Mon, 02 Dec 2013, Martin Kosek wrote: On 12/02/2013 04:05 PM, Petr Viktorin wrote: On 12/02/2013 03:42 PM, Simo Sorce wrote: On Mon, 2013-12-02 at 14:51 +0100, Petr Viktorin wrote:

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Simo Sorce
On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It would be very nice if you can add the resulting LDAP objects in the example, that will allow me to reason on the correctness of the

[Freeipa-devel] FreeIPA Continuous Integration Configuration

2013-12-06 Thread Petr Viktorin
Hello, As some of you are aware, I'm running a Jenkins instance for FreeIPA continuous integration in our lab here at Red Hat Brno. I'm currently porting the job definitions to jenkins-job-builder[0] for ease of management. This allowed me to strip out the private bits from the

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Petr Viktorin
On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It would be very nice if you can add the resulting LDAP objects in the example, that will allow me to

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Simo Sorce
On Fri, 2013-12-06 at 15:46 +0100, Petr Viktorin wrote: On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It would be very nice if you can add the

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Rob Crittenden
Simo Sorce wrote: On Fri, 2013-12-06 at 15:46 +0100, Petr Viktorin wrote: On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It would be very nice if you

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Petr Viktorin
On 12/06/2013 03:49 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 15:46 +0100, Petr Viktorin wrote: On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Martin Kosek
On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo Sorce wrote: It would be very nice if you can add the resulting LDAP objects in the example, that will allow me to

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Petr Viktorin
On 12/06/2013 03:54 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-12-06 at 15:46 +0100, Petr Viktorin wrote: On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin wrote: On 12/02/2013 02:29 PM, Simo

[Freeipa-devel] [PATCH] 0333 test_webui: Allow False values in configuration for no_ca, no_dns, has_trusts

2013-12-06 Thread Petr Viktorin
Hello, As I'm consolidating test job configuration, I learned that the line no_dns: False in WebUI test config has the same effect as `no_dns: True`. This is confusing, and it complicates generating the config. Patch is untested because I don't have the WebUI test environment set up

Re: [Freeipa-devel] [RFE] Permissions V2

2013-12-06 Thread Simo Sorce
On Fri, 2013-12-06 at 16:02 +0100, Petr Viktorin wrote: On 12/06/2013 03:49 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 15:46 +0100, Petr Viktorin wrote: On 12/06/2013 03:28 PM, Simo Sorce wrote: On Fri, 2013-12-06 at 14:14 +0100, Petr Viktorin wrote: On 12/02/2013 02:48 PM, Petr Viktorin

Re: [Freeipa-devel] [PATCH] 531 Fix license in some Web UI files

2013-12-06 Thread Simo Sorce
On Fri, 2013-12-06 at 14:19 +0100, Petr Vobornik wrote: Modified web ui files had incorrect GPLv2 headers instead of GPLv3 ones. All of the affected code is of FreeIPA origin. Ack. Simo. -- Simo Sorce * Red Hat, Inc * New York ___ Freeipa-devel

[Freeipa-devel] [PATCH][DOCS] Fix password synchronization manager explanation

2013-12-06 Thread Simo Sorce
The current text is wrong and misleading, can we expedite trickling this change all the way down all downstream documentation ? (Ie Fedora official user guides). Simo. -- Simo Sorce * Red Hat, Inc * New York From f24531982ae99cd53fede49cdfaa9b87459162f4 Mon Sep 17 00:00:00 2001 From: Simo Sorce

Re: [Freeipa-devel] Building FreeIPA on Debian Unstable

2013-12-06 Thread Adam Young
And...that was pretty much as far as I got. with the updated repo + updates from the ppa the build succeeds but tests fail, and those are harder for me to parse. Full build log at http://pastebin.com/G40VMENn Your first error is: Failure: ImportError (No module named samba) ... ERROR