Re: [Linux-ha-dev] [ha-wg] Cluster Stack - Ubuntu Developer Summit

2011-05-05 Thread Ante Karamatic
U Čet, 05. 05. 2011., u 10:25 +0200, Florian Haas je napisao/la: > Andres already knows this, but FWIW I'll repost here that I'll be at UDS > in time for the cluster stack session at 12 noon on 5/12. I'll stay in > Budapest that evening and will probably join the Budapest sightseeing > tour that t

Re: [Linux-ha-dev] [Openais] An OCF agent for LXC (Linux Containers) - Linux-HA-Dev Digest, Vol 90, Issue 7

2011-05-05 Thread Dejan Muhamedagic
Hi, On Thu, May 05, 2011 at 09:17:13PM +0930, Darren Thompson wrote: > Team > > I stand corrected Looking at all the other ocf files, it does appear > that the initialisation setting are consistent (and hence assumed > correct). > > Oddly, the test environment I have setup is SLES11SP with

Re: [Linux-ha-dev] [Openais] An OCF agent for LXC (Linux Containers) - Linux-HA-Dev Digest, Vol 90, Issue 8

2011-05-05 Thread Florian Haas
On 2011-05-05 14:26, Darren Thompson wrote: >> Can you confirm that the current version is working for you and passes >> ocf-tester on your system? > > What is an ocf-tester??? http://www.linux-ha.org/doc/dev-guides/_testing_installing_and_packaging_resource_agents.html > I have been testing thi

Re: [Linux-ha-dev] [Openais] An OCF agent for LXC (Linux Containers) - Linux-HA-Dev Digest, Vol 90, Issue 8

2011-05-05 Thread Darren Thompson
Florian/Team Comments in-line... On Thu, 2011-05-05 at 05:47 -0600, linux-ha-dev-requ...@lists.linux-ha.org wrote: > Darren, > > can you please subscribe to the list as a normal subscriber rather > than > to just the digest, so we can keep this discussion in one thread? Ok, done... The dige

Re: [Linux-ha-dev] [Openais] An OCF agent for LXC (Linux Containers) - Linux-HA-Dev Digest, Vol 90, Issue 7

2011-05-05 Thread Darren Thompson
Team I stand corrected Looking at all the other ocf files, it does appear that the initialisation setting are consistent (and hence assumed correct). Oddly, the test environment I have setup is SLES11SP with the High Availability add-on and the path to the ocf directory is radically differen

Re: [Linux-ha-dev] New OCF RA: symlink

2011-05-05 Thread Andrew Beekhof
On Wed, May 4, 2011 at 4:36 PM, Lars Ellenberg wrote: >  Services running under Pacemaker control are probably "critical", >  so a malicious person with even only "stop" access on the CIB >  can do a DoS. I guess we have to assume people with any write access >  at all to the CIB are "trusted", an

Re: [Linux-ha-dev] ACLs and privilege escalation (was Re: New OCF RA: symlink)

2011-05-05 Thread Andrew Beekhof
On Thu, May 5, 2011 at 9:09 AM, Florian Haas wrote: > Rather than going into ACLs in more detail, I wanted to highlight that > however we limit access to the CIB, the resource agents still _execute_ > as root, so we will always have what would normally be considered a > privilege escalation issue.

Re: [Linux-ha-dev] [ha-wg] Cluster Stack - Ubuntu Developer Summit

2011-05-05 Thread Andrew Beekhof
On Thu, May 5, 2011 at 10:25 AM, Florian Haas wrote: > On 2011-04-26 19:33, Andres Rodriguez wrote: >> UDS' are open-to-public events, and I believe it would be great if >> upstream could participate and maybe even further the discussion about >> the Cluster Stack. For more information about UDS,

Re: [Linux-ha-dev] [ha-wg] Cluster Stack - Ubuntu Developer Summit

2011-05-05 Thread Florian Haas
On 2011-04-26 19:33, Andres Rodriguez wrote: > UDS' are open-to-public events, and I believe it would be great if > upstream could participate and maybe even further the discussion about > the Cluster Stack. For more information about UDS, please visit [1]. The > specific date/time for the Cluster

Re: [Linux-ha-dev] [Openais] An OCF agent for LXC (Linux Containers) - Linux-HA-Dev Digest, Vol 90, Issue 6

2011-05-05 Thread Florian Haas
Darren, can you please subscribe to the list as a normal subscriber rather than to just the digest, so we can keep this discussion in one thread? On 2011-05-05 04:47, Darren Thompson wrote: > Florian/Team > > There was an error in the GIT-Hub version that was causing my re-base > attempts to fai

[Linux-ha-dev] ACLs and privilege escalation (was Re: New OCF RA: symlink)

2011-05-05 Thread Florian Haas
Rather than going into ACLs in more detail, I wanted to highlight that however we limit access to the CIB, the resource agents still _execute_ as root, so we will always have what would normally be considered a privilege escalation issue. Now, we could agree on security guidelines for RAs, and som