ZooKeeper_branch33_solaris - Build # 862 - Failure

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper_branch33_solaris/862/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 104778 lines...] [junit] 2014-04-22

[jira] [Commented] (ZOOKEEPER-1910) RemoveWatches wrongly removes the watcher if multiple watches exists on a path

2014-04-22 Thread Rakesh R (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-1910?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13976512#comment-13976512 ] Rakesh R commented on ZOOKEEPER-1910: - Thanks [~rgs] for the comments. {quote}Why

ZooKeeper_branch33 - Build # 1290 - Failure

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper_branch33/1290/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 123660 lines...] [junit] 2014-04-22 09:49:30,118 -

ZooKeeper-trunk - Build # 2298 - Still Failing

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper-trunk/2298/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 307453 lines...] [exec] Log Message Received:

[jira] [Commented] (ZOOKEEPER-723) ephemeral parent znodes

2014-04-22 Thread Rakesh R (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-723?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13976863#comment-13976863 ] Rakesh R commented on ZOOKEEPER-723: Hi folks, Both ZOOKEEPER-834 and this has

ZK CVE

2014-04-22 Thread Flavio Junqueira
Some of you may have noticed that there is a CVE entry for ZK: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0085 I've never perceived ZK as a project particularly strong on the security side, but I was wondering how folks in the list feel about creating a jira and working

ZooKeeper-trunk-jdk7 - Build # 851 - Still Failing

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper-trunk-jdk7/851/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 274289 lines...] [junit] 2014-04-22 16:43:41,568

Re: ZK CVE

2014-04-22 Thread Michi Mutsuzaki
That's a great idea. The link talks about one specific vulnerability (password being logged in a cleartext :( ), but I'm interested in securing ZooKeeper in general. I've seen projects staying away from ZooKeeper because it doesn't support SSL, for example. On Tue, Apr 22, 2014 at 9:32 AM,

Re: ZK CVE

2014-04-22 Thread Camille Fournier
We should at least address it in some way. A jira is probably in order. On Tue, Apr 22, 2014 at 12:32 PM, Flavio Junqueira f...@apache.org wrote: Some of you may have noticed that there is a CVE entry for ZK: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0085 I've never

[jira] [Assigned] (ZOOKEEPER-1416) Persistent Recursive Watch

2014-04-22 Thread Thawan Kooburat (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-1416?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thawan Kooburat reassigned ZOOKEEPER-1416: -- Assignee: Thawan Kooburat Persistent Recursive Watch

Re: Review Request 20448: ZOOKEEPER-1910: RemoveWatches wrongly removes the watcher if multiple watches exists on a path

2014-04-22 Thread Camille Fournier
--- This is an automatically generated e-mail. To reply, visit: https://reviews.apache.org/r/20448/#review41037 --- ./src/java/main/org/apache/zookeeper/ZooKeeper.java

Re: ZK CVE

2014-04-22 Thread Patrick Hunt
Agree. We should fix this. Would be worthy of a 3.4.7 imo. I'm having some trouble understanding the problem though. afaict from the linked bug/reports it seems that An admin user's password appeared in plaintext in binary log files. Do they mean to say in the txnlog? Or just in the log4j log?

Re: ZK CVE

2014-04-22 Thread Patrick Hunt
On Tue, Apr 22, 2014 at 10:14 AM, Michi Mutsuzaki mi...@cs.stanford.edu wrote: That's a great idea. The link talks about one specific vulnerability (password being logged in a cleartext :( ), but I'm interested in securing ZooKeeper in general. I've seen projects staying away from ZooKeeper

[jira] [Created] (ZOOKEEPER-1917) Apache Zookeeper logs cleartext admin passwords

2014-04-22 Thread Flavio Junqueira (JIRA)
Flavio Junqueira created ZOOKEEPER-1917: --- Summary: Apache Zookeeper logs cleartext admin passwords Key: ZOOKEEPER-1917 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-1917 Project:

Re: ZK CVE

2014-04-22 Thread Flavio Junqueira
I've created ZK-1917 for this. I think it is referring to the txn logs. If so, SSL encryption alone isn't going to do it. -Flavio On 22 Apr 2014, at 18:55, Patrick Hunt ph...@apache.org wrote: On Tue, Apr 22, 2014 at 10:14 AM, Michi Mutsuzaki mi...@cs.stanford.edu wrote: That's a great

[jira] [Commented] (ZOOKEEPER-1910) RemoveWatches wrongly removes the watcher if multiple watches exists on a path

2014-04-22 Thread Raul Gutierrez Segales (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-1910?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13977159#comment-13977159 ] Raul Gutierrez Segales commented on ZOOKEEPER-1910: --- Sounds

[jira] [Commented] (ZOOKEEPER-1910) RemoveWatches wrongly removes the watcher if multiple watches exists on a path

2014-04-22 Thread Raul Gutierrez Segales (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-1910?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13977163#comment-13977163 ] Raul Gutierrez Segales commented on ZOOKEEPER-1910: --- Just to

ZooKeeper-trunk-jdk8 - Build # 15 - Still Failing

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper-trunk-jdk8/15/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 265969 lines...] [junit] 2014-04-22 18:34:36,444

Re: ZK CVE

2014-04-22 Thread Patrick Hunt
Hm. Well the txnlogs didn't make much sense to me. If you have that level of access, well they you've got access to everything regardless. Shouldn't/wouldn't those files be protected by permissions on the datadir? Also, which password are we storing in the txnlog? The session password or truly

RE: ZK CVE

2014-04-22 Thread Flavio Junqueira
I think I know what they are talking about. Let me try to reproduce it, it might give us a bit more clarity on the matter. -Flavio -Original Message- From: Patrick Hunt [mailto:ph...@apache.org] Sent: Tuesday, April 22, 2014 7:47 PM To: DevZooKeeper Cc: Michi Mutsuzaki Subject: Re: ZK

ZooKeeper_branch34_jdk8 - Build # 13 - Failure

2014-04-22 Thread Apache Jenkins Server
See https://builds.apache.org/job/ZooKeeper_branch34_jdk8/13/ ### ## LAST 60 LINES OF THE CONSOLE ### [...truncated 218022 lines...] [junit] 2014-04-23 00:04:46,184

Re: ZK CVE

2014-04-22 Thread Ted Dunning
Encryption of data at rest is a good thing. It should be an orthogonal issue relative to wire level encryption. Sent from my iPhone On Apr 22, 2014, at 12:47, Patrick Hunt ph...@apache.org wrote: Hm. Well the txnlogs didn't make much sense to me. If you have that level of access, well

[jira] [Commented] (ZOOKEEPER-1910) RemoveWatches wrongly removes the watcher if multiple watches exists on a path

2014-04-22 Thread Rakesh R (JIRA)
[ https://issues.apache.org/jira/browse/ZOOKEEPER-1910?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13977838#comment-13977838 ] Rakesh R commented on ZOOKEEPER-1910: - OK got it. I could see an alternative