Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-20 Thread Maxim Nestratov
17.06.2016 17:13, Matt Riedemann пишет: On 6/9/2016 6:51 PM, Tony Breeds wrote: On Fri, Jun 10, 2016 at 08:24:34AM +1000, Michael Still wrote: On Fri, Jun 10, 2016 at 7:18 AM, Tony Breeds wrote: On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: Agreed, but it's the worked ex

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-17 Thread Matt Riedemann
On 6/9/2016 6:51 PM, Tony Breeds wrote: On Fri, Jun 10, 2016 at 08:24:34AM +1000, Michael Still wrote: On Fri, Jun 10, 2016 at 7:18 AM, Tony Breeds wrote: On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: Agreed, but it's the worked example part that we don't have yet, chicken

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-14 Thread Daniel P. Berrange
On Fri, Jun 10, 2016 at 09:51:03AM +1000, Tony Breeds wrote: > On Fri, Jun 10, 2016 at 08:24:34AM +1000, Michael Still wrote: > > On Fri, Jun 10, 2016 at 7:18 AM, Tony Breeds > > wrote: > > > > > On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: > > > > > > > Agreed, but it's the wo

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-13 Thread Angus Lees
One of the challenges with nova (and I'm working from some earlier conversations, not a first-hand reading of the code) is that we can't restrict file operations to any particular corner of the filesystem, because the location of the libvirt data is stored (only) in the database, and the database i

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-09 Thread Tony Breeds
On Fri, Jun 10, 2016 at 08:24:34AM +1000, Michael Still wrote: > On Fri, Jun 10, 2016 at 7:18 AM, Tony Breeds > wrote: > > > On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: > > > > > Agreed, but it's the worked example part that we don't have yet, > > > chicken/egg. So we can drop

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-09 Thread Michael Still
On Fri, Jun 10, 2016 at 7:18 AM, Tony Breeds wrote: > On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: > > > Agreed, but it's the worked example part that we don't have yet, > > chicken/egg. So we can drop the hammer on all new things until someone > does > > it, which sucks, or ho

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-09 Thread Tony Breeds
On Wed, Jun 08, 2016 at 08:10:47PM -0500, Matt Riedemann wrote: > Agreed, but it's the worked example part that we don't have yet, > chicken/egg. So we can drop the hammer on all new things until someone does > it, which sucks, or hope that someone volunteers to work the first example. I'll work

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-08 Thread Matt Riedemann
On 6/8/2016 5:51 PM, Michael Still wrote: This seems like the sort of thing we should document in the devref. I agree we shouldn't be doing any more of the old thing and should provide a worked example of the new thing. Michael -- Rackspace Australia __

Re: [openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-08 Thread Michael Still
+Angus On Thu, Jun 9, 2016 at 7:10 AM, Matt Riedemann wrote: > While sitting in Angus' cross-project session on oslo.privsep at the > Austin summit I believe I had a conversation with myself in my head that > Nova should stop adding new rootwrap filters and anything new should use > oslo.privsep

[openstack-dev] [nova] Initial oslo.privsep conversion?

2016-06-08 Thread Matt Riedemann
While sitting in Angus' cross-project session on oslo.privsep at the Austin summit I believe I had a conversation with myself in my head that Nova should stop adding new rootwrap filters and anything new should use oslo.privsep. For example: https://review.openstack.org/#/c/182257/ However,