Re: [SSSD] Design Discussion: Improving AD provider access control

2013-09-16 Thread Pavel Březina
On 09/13/2013 02:57 PM, Jakub Hrozek wrote: Hi, I created a design page that describes a proposed way of improving the current AD provider access control. The main ticket that tracks the work is https://fedorahosted.org/sssd/ticket/2082 and the full design page can be found here: https://fedorah

Re: [SSSD] About managing branches: WAS: [Fwd: Re: [PATCH] nss: Add option to disable memcache]

2013-09-16 Thread Sumit Bose
On Fri, Sep 13, 2013 at 12:41:41PM -0400, Simo Sorce wrote: > I wonder if it wouldn't make sense to delay commits to stable branches > until the time to release comes ? > > Would it make it easier or harder to review and apply changes only at > release time ? I think it would be harder. Since som

Re: [SSSD] [PATCHES] Fix warnings

2013-09-16 Thread Lukas Slebodnik
On (22/07/13 11:43), Jakub Hrozek wrote: >On Fri, Jul 19, 2013 at 03:36:22PM +0200, Lukas Slebodnik wrote: >> On (19/07/13 10:29), Jakub Hrozek wrote: >> >On Thu, Jul 18, 2013 at 01:09:11PM +0200, Lukas Slebodnik wrote: >> >> ehlo, >> >> >> >> I tested some patches with old distro and I spotted wa

[SSSD] [PATCH] Add missing new line in DEBUG message

2013-09-16 Thread Lukas Slebodnik
ehlo, I found this simple problem, when I was testing Michal's patch for mmap_cache "Check slot validity before MC_SLOT_TO_PTR." Patch is attached. LS >From 89e47fd8d0bf67409a6848c2f22adebb9e83f29d Mon Sep 17 00:00:00 2001 From: Lukas Slebodnik Date: Mon, 16 Sep

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Pavel Březina
On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: ehlo, Attached patch resolves ticket #2075 LS Hi, minor nack. +ret = sdap_get_netgroup_primary_name(memctx, opts, attrs, dom, &name); +if (ret != EOK) { +DEBUG(SSSDBG_OP_FAILURE, ("Failed to get netgroup name\n")); +

Re: [SSSD] About managing branches: WAS: [Fwd: Re: [PATCH] nss: Add option to disable memcache]

2013-09-16 Thread Jakub Hrozek
On Fri, Sep 13, 2013 at 12:41:41PM -0400, Simo Sorce wrote: > I wonder if it wouldn't make sense to delay commits to stable branches > until the time to release comes ? > > Would it make it easier or harder to review and apply changes only at > release time ? > > Simo. > > -- > Simo Sorce * Red

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Lukas Slebodnik
On (16/09/13 11:01), Pavel Březina wrote: >On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: >>ehlo, >> >>Attached patch resolves ticket #2075 >> >>LS > >Hi, >minor nack. > >>+ret = sdap_get_netgroup_primary_name(memctx, opts, attrs, dom, &name); >>+if (ret != EOK) { >>+DEBUG(SSSDBG_OP

Re: [SSSD] setautomntenta autofs file not found

2013-09-16 Thread Jakub Hrozek
On Sat, Sep 14, 2013 at 12:17:29AM +0200, steve wrote: > On Fri, 2013-09-13 at 14:58 +0200, Jakub Hrozek wrote: > > > > > Great, I'm glad it works for you now! > > Hi > Thanks. Just one thing. We see that you support various schemas: > https://fedorahosted.org/sssd/wiki/DesignDocs/AutofsIntegrat

Re: [SSSD] [PATCH] Add missing new line in DEBUG message

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 10:47:55AM +0200, Lukas Slebodnik wrote: > ehlo, > > I found this simple problem, when I was testing Michal's patch for mmap_cache > "Check slot validity before MC_SLOT_TO_PTR." > > Patch is attached. > > LS ACK But instead of sending ind

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 11:01:36AM +0200, Pavel Březina wrote: > On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: > >ehlo, > > > >Attached patch resolves ticket #2075 > > > >LS > > Hi, > minor nack. > > >+ret = sdap_get_netgroup_primary_name(memctx, opts, attrs, dom, &name); > >+if (ret !=

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Lukas Slebodnik
On (16/09/13 12:15), Jakub Hrozek wrote: >On Mon, Sep 16, 2013 at 11:01:36AM +0200, Pavel Březina wrote: >> On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: >> >ehlo, >> > >> >Attached patch resolves ticket #2075 >> > >> >LS >> >> Hi, >> minor nack. >> >> >+ret = sdap_get_netgroup_primary_name(

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Pavel Březina
On 09/16/2013 12:15 PM, Jakub Hrozek wrote: On Mon, Sep 16, 2013 at 11:01:36AM +0200, Pavel Březina wrote: On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: ehlo, Attached patch resolves ticket #2075 LS Hi, minor nack. +ret = sdap_get_netgroup_primary_name(memctx, opts, attrs, dom, &name

Re: [SSSD] [PATCH] LDAP: Use primary cn to search netgroup

2013-09-16 Thread Lukas Slebodnik
On (16/09/13 12:24), Pavel Březina wrote: >On 09/16/2013 12:15 PM, Jakub Hrozek wrote: >>On Mon, Sep 16, 2013 at 11:01:36AM +0200, Pavel Březina wrote: >>>On 09/13/2013 04:52 PM, Lukas Slebodnik wrote: ehlo, Attached patch resolves ticket #2075 LS >>> >>>Hi, >>>minor nack. >>>

Re: [SSSD] About managing branches: WAS: [Fwd: Re: [PATCH] nss: Add option to disable memcache]

2013-09-16 Thread Simo Sorce
On Mon, 2013-09-16 at 11:10 +0200, Jakub Hrozek wrote: > On Fri, Sep 13, 2013 at 12:41:41PM -0400, Simo Sorce wrote: > > I wonder if it wouldn't make sense to delay commits to stable branches > > until the time to release comes ? > > > > Would it make it easier or harder to review and apply change

Re: [SSSD] Design Discussion: Improving AD provider access control

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 10:15:58AM +0200, Pavel Březina wrote: > On 09/13/2013 02:57 PM, Jakub Hrozek wrote: > >Hi, > > > >I created a design page that describes a proposed way of improving the > >current AD provider access control. The main ticket that tracks the work > >is https://fedorahosted.or

Re: [SSSD] [PATCHES] Fix warnings

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 10:35:07AM +0200, Lukas Slebodnik wrote: > On (22/07/13 11:43), Jakub Hrozek wrote: > >On Fri, Jul 19, 2013 at 03:36:22PM +0200, Lukas Slebodnik wrote: > >> On (19/07/13 10:29), Jakub Hrozek wrote: > >> >On Thu, Jul 18, 2013 at 01:09:11PM +0200, Lukas Slebodnik wrote: > >> >

Re: [SSSD] [PATCH] Use systemd-login session information to check if user is logged in

2013-09-16 Thread Jakub Hrozek
On Fri, Sep 13, 2013 at 12:42:46PM -0400, Simo Sorce wrote: > On Fri, 2013-09-13 at 17:14 +0200, Jakub Hrozek wrote: > > On Thu, Sep 12, 2013 at 07:10:38PM +0200, Jakub Hrozek wrote: > > > On Wed, Sep 11, 2013 at 05:47:31PM -0400, Simo Sorce wrote: > > > > On Wed, 2013-09-11 at 19:19 +0200, Jakub H

Re: [SSSD] [PATCH] Add missing new line in DEBUG message

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 12:13:52PM +0200, Jakub Hrozek wrote: > On Mon, Sep 16, 2013 at 10:47:55AM +0200, Lukas Slebodnik wrote: > > ehlo, > > > > I found this simple problem, when I was testing Michal's patch for > > mmap_cache > > "Check slot validity before MC_S

Re: [SSSD] [PATCHES] Fix warnings

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 03:37:56PM +0200, Jakub Hrozek wrote: > On Mon, Sep 16, 2013 at 10:35:07AM +0200, Lukas Slebodnik wrote: > > On (22/07/13 11:43), Jakub Hrozek wrote: > > >On Fri, Jul 19, 2013 at 03:36:22PM +0200, Lukas Slebodnik wrote: > > >> On (19/07/13 10:29), Jakub Hrozek wrote: > > >>

Re: [SSSD] [PATCH] man: improve sssd-sudo manual page

2013-09-16 Thread Jakub Hrozek
On Fri, Sep 13, 2013 at 03:49:25PM +0200, Pavel Březina wrote: > https://fedorahosted.org/sssd/ticket/2085 > From 2a6573c0ceeaaa51e155a01719bbb283164705cf Mon Sep 17 00:00:00 2001 > From: =?UTF-8?q?Pavel=20B=C5=99ezina?= > Date: Fri, 13 Sep 2013 15:48:10 +0200 > Subject: [PATCH] man: improve sssd

[SSSD] [PATCH] KRB5: Call umask before mkstemp in the krb5 child code

2013-09-16 Thread Jakub Hrozek
Found by Coverity. Not really a huge issue, but as already agreed in a private conversation, a nice-to-have. >From ad964e8d54f1a47ea0cf580a70de71f90f0f9140 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek Date: Mon, 16 Sep 2013 17:02:39 +0200 Subject: [PATCH] KRB5: Call umask before mkstemp in the krb5

[SSSD] [PATCH] Two minor man page patches

2013-09-16 Thread Jakub Hrozek
I found these minor issues in our man pages, when triaging support issues with Red Hat GSS earlier today. The first patch changes the subtitle of the man pages. I wasn't completely sure if the title is set to "SSSD config file" on purpose (after all they do describe the config file, just per-provi

Re: [SSSD] [PATCH] Add journald support

2013-09-16 Thread Jakub Hrozek
On Tue, Sep 10, 2013 at 07:35:05PM +0200, Jakub Hrozek wrote: > Hi, > > attached are two small patches I wrote when I was checking whether > Fedora's move to journald affects us or not. Patch #1 adds a new > configure option, that, if enabled, routes logging via journald's API. > No change in logg

Re: [SSSD] [PATCHES] simple access provider: support subdomain users and groups

2013-09-16 Thread Jakub Hrozek
On Thu, Sep 12, 2013 at 02:01:43PM +0200, Pavel Březina wrote: > On 09/10/2013 03:46 PM, Jakub Hrozek wrote: > >On Tue, Sep 03, 2013 at 12:42:21PM +0200, Pavel Březina wrote: > >>Patch 0001: I haven't used this one after all, but I still think it > >>is nice to have. It reduces amount of code dupli

Re: [SSSD] [PATCHES] simple access provider: support subdomain users and groups

2013-09-16 Thread Jakub Hrozek
On Mon, Sep 16, 2013 at 05:30:38PM +0200, Jakub Hrozek wrote: > On Thu, Sep 12, 2013 at 02:01:43PM +0200, Pavel Březina wrote: > > On 09/10/2013 03:46 PM, Jakub Hrozek wrote: > > >On Tue, Sep 03, 2013 at 12:42:21PM +0200, Pavel Březina wrote: > > >>Patch 0001: I haven't used this one after all, but

Re: [SSSD] [PATCH] Check slot validity before MC_SLOT_TO_PTR.

2013-09-16 Thread Michal Židek
On 09/14/2013 12:35 AM, Lukas Slebodnik wrote: On (13/09/13 19:17), Michal Židek wrote: On 09/13/2013 05:58 PM, Michal Židek wrote: Hello, This patch should add another line of defence against memory cache problems caused by accessing slot outside of bounds. Thanks Michal After discussion

Re: [SSSD] [PATCH] mmap_cache: Use two chains for hash collision.

2013-09-16 Thread Lukas Slebodnik
On (11/09/13 17:55), Simo Sorce wrote: >On Wed, 2013-09-11 at 21:21 +0200, Lukas Slebodnik wrote: >> On (11/09/13 12:50), Simo Sorce wrote: >> >On Wed, 2013-09-11 at 17:39 +0200, Lukas Slebodnik wrote: >> >> On (11/09/13 16:30), Michal Židek wrote: >> >> >On 09/11/2013 04:16 PM, Simo Sorce wrote: >