Re: [Zope-dev] Memory Error

2003-06-23 Thread Andy McKay
There we go, occurred again. Its definitely the manipulating of catalog results, all the crashes are happening on zcatalog searches. There is over 530 Megs of Memory free at the time. But like I say its never occuring my other boxes so time to whip out some unit tests and the like ;) --

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread seb bacon
On Mon, 2003-06-23 at 09:20, Jamie Heilman wrote: I'll submit a fixed Examples.zexp but I need to know how its normally prepared, ownership, etc. Is there anything special I should do? No. Just go ahead and make the changes. It would be instructive for others reading the examples to add a

[Zope-dev] 2.6.2b3?

2003-06-23 Thread seb bacon
Just a quick repeat from last week in case it slipped from anyone's radar... Here is the important bit again: a) Any reason why I shouldn't merge BTree bugfixees into the 2.6 branch? b) If no, how about a 2.6.2b3? seb On Wed, 2003-06-18 at 17:25, seb bacon wrote: There lave been various

Re: [Zope-dev] funky side-effects, possible bug in HTTPRequest.py

2003-06-23 Thread Florent Guillaume
In article [EMAIL PROTECTED] you write: # Untrusted data *after* trusted data v = self.form.get(key, _marker) if v is not _marker: other[key] = v # *boom* return v That magical promotion of the key value to the other

Re: [Zope-dev] 2.6.2b3?

2003-06-23 Thread Casey Duncan
Post this to zodb-dev. -Casey On Monday 23 June 2003 05:12 am, seb bacon wrote: Just a quick repeat from last week in case it slipped from anyone's radar... Here is the important bit again: a) Any reason why I shouldn't merge BTree bugfixees into the 2.6 branch? b) If no, how about a

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread Casey Duncan
I would be in favor of making the Examples opt-in like the Zope tutorial. It seems silly to have it in evey ZODB by default. Make people add it if they want it. -Casey On Monday 23 June 2003 05:12 am, Jamie Heilman wrote: seb bacon wrote: No. Just go ahead and make the changes. It would

RE: [Zope-dev] 2.6.2b3?

2003-06-23 Thread Brian Lloyd
Tim says that this has been merged into the 2.6 branch (last week). Brian Lloyd[EMAIL PROTECTED] V.P. Engineering 540.361.1716 Zope Corporation http://www.zope.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of seb bacon Sent: Monday,

[Zope-dev] Re: Ordered Folder again

2003-06-23 Thread Yuppie
Hi! Florent Guillaume wrote: But FWIW, note that in Nuxeo CPS we've always been using a monkey patch that added ordering to Folder without any problem. (http://cvs.nuxeo.org/cgi-bin/viewcvs.cgi/OrderedFolderSupportPatch/) CPS doesn't subclass from PortalFolder? If CPS would have its own class

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread Kazuya FUKAMACHI
On Mon, 23 Jun 2003 01:20:35 -0700 Jamie Heilman [EMAIL PROTECTED] wrote: http://exploitlabs.com/files/advisories/EXPL-A-2003-009-zope.txt [snip] apps, and apart from 1 and 3 there are probably legitimate bugs there. related issues: CMFWiki, ZWiki, Plone and other products are also

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread Shane Hathaway
Andy McKay wrote: Casey Duncan wrote: I would be in favor of making the Examples opt-in like the Zope tutorial. It seems silly to have it in evey ZODB by default. Make people add it if they want it. +1 a simple How to add the examples to the ZODB at the top of the help would be good. Mind

[Zope-dev] Re: Ordered Folder again

2003-06-23 Thread Florent Guillaume
On Mon, 2003-06-23 at 17:17, Yuppie wrote: Florent Guillaume wrote: But FWIW, note that in Nuxeo CPS we've always been using a monkey patch that added ordering to Folder without any problem. (http://cvs.nuxeo.org/cgi-bin/viewcvs.cgi/OrderedFolderSupportPatch/) CPS doesn't subclass from

[Zope-dev] Re: Ordered Folder again

2003-06-23 Thread Yuppie
Hi Florent! Florent Guillaume wrote: CPS doesn't subclass from PortalFolder? If CPS would have its own class like PloneFolder in Plone, you could just mix in OrderSupport. We could, except that - we want to be useable with standard CMF objects Was just asking. I think you're doing the Right

[Zope-dev] Re: weak examples, weak exploits

2003-06-23 Thread Evan Simpson
Casey Duncan wrote: I would be in favor of making the Examples opt-in like the Zope tutorial. It seems silly to have it in evey ZODB by default. Make people add it if they want it. Many, many moons ago I created evan-examples-branch, which allows individual Products to offer sample code without

[Zope-dev] zopeinstall, error in zope2.7 cvs

2003-06-23 Thread PieterB
Hi, My first version of the zopeinstaller is available. It currently only build Python 2.2.3 and Zope 2.7, but I would like to enhance it to a full 'tinderbox'. See http://zwiki.org/PythonZopeTinderbox for details. It currently builds Python 2.2.3 from tarball and Zope 2.7 from CVS. It uses

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread Jamie Heilman
seb bacon wrote: The file upload vulnerability was fixed in version 1.3 of Examples.zexp, though. The reason it's still turning up in 2.6.x versions is probably due to upgrades. Therefore I suppose additionally there should be a patch which examines the ZODB on startup and prints a warning

Re: [Zope-dev] weak examples, weak exploits

2003-06-23 Thread Jamie Heilman
Jamie Heilman wrote: Then call it http://host/aww_shit_now_what=bold+flava' er, http://host/aww_shit_now_what?i=bold+flava' rather. -- Jamie Heilman http://audible.transient.net/~jamie/ Paranoia is a disease unto itself, and may I add, the person standing next to you may not