Re: [Zope-Coders] Re: [Zope-dev] DTML and REQUEST data changesaboutto be checked in

2002-08-12 Thread Shane Hathaway
Dieter Maurer wrote: Adrian Hungate writes: We should avoid sending the wrong message by making a hotfix for every little thing. Shane I'd like to second this. It was one of the contibuting factors in the decision of my former employers to opt for spectra instead

Re: [Zope-Coders] Re: [Zope-dev] DTML and REQUEST data changes about to be checked in

2002-08-12 Thread Toby Dickenson
On Friday 09 Aug 2002 4:33 pm, Tres Seaver wrote: Whithout the fix, virtually every Zope site in the world is vulnerable to URL-based cross-site scripting exploits. For instance, any URL which contains invalid form variable marshalling can generate an error page which includes the erroneous

Re: [Zope-Coders] Re: [Zope-dev] DTML and REQUEST data changesabout to be checked in

2002-08-12 Thread Adrian Hungate
I'd like to second this. It was one of the contibuting factors in the decision of my former employers to opt for spectra instead of a Zope solution (That already existed!!). I, in contrary, appreciate the openess and fast response with respect to security problems. I do not

Re: [Zope-Coders] Re: [Zope-dev] DTML and REQUEST data changes about to be checked in

2002-08-12 Thread Martijn Pieters
On Mon, Aug 12, 2002 at 03:51:24PM +0100, Toby Dickenson wrote: On Friday 09 Aug 2002 4:33 pm, Tres Seaver wrote: Whithout the fix, virtually every Zope site in the world is vulnerable to URL-based cross-site scripting exploits. For instance, any URL which contains invalid form variable

[Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Romain Slootmaekers
Yo, we had a nasty crash of our zope server that we use for a b2b web application. The Data.fs ZODB lost a significant amount of data. At this point, we restored the Data.fs from our last backup and the server is back up and running. (breathing relieved) What worries me is that we have no

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Joachim Werner
Hi! I know of exactly two cases that could really cause a ZODB loose data: if you reach the 2GB limit with a Python not compiled for larger files and if you reach the physical limit of your storage. That is, if your case doesn't add a third one ... Have you already tried the usual things, i.e.

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Toby Dickenson
On Monday 12 Aug 2002 4:50 pm, Joachim Werner wrote: Hi! I know of exactly two cases that could really cause a ZODB loose data: if you reach the 2GB limit with a Python not compiled for larger files and if you reach the physical limit of your storage. That is, if your case doesn't add a

Re: [Zope-dev] Follow up: Coroner's toolkit for zope, or how to figureout what went wrong.

2002-08-12 Thread Romain Slootmaekers
Toby Dickenson wrote: On Monday 12 Aug 2002 4:50 pm, Joachim Werner wrote: Hi! I know of exactly two cases that could really cause a ZODB loose data: if you reach the 2GB limit with a Python not compiled for larger files and if you reach the physical limit of your storage. That is, if your

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Jim Fulton
Romain Slootmaekers wrote: Yo, we had a nasty crash of our zope server that we use for a b2b web application. The Data.fs ZODB lost a significant amount of data. What sort of crash? Was this a hardware failure, or a software failure? At this point, we restored the Data.fs from our last

Re: [Zope-dev] Follow up: Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Chris McDonough
ReadConflictError: database read conflict error (oid bc8d, The conflict error you have likely has nothing to do with your data loss, it's a normal artifact of Zope operation. The first thing I would recommend trying today is shutting down, removing data.fs.index, and

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out whatwent wrong.

2002-08-12 Thread Romain Slootmaekers
Jim Fulton wrote: Romain Slootmaekers wrote: Yo, we had a nasty crash of our zope server that we use for a b2b web application. The Data.fs ZODB lost a significant amount of data. What sort of crash? Was this a hardware failure, or a software failure? software. basically, the server

Re: [Zope-dev] DTML and REQUEST data changes about to be checked in

2002-08-12 Thread Jim Fulton
Jeffrey P Shell wrote: On 8/9/02 8:43 AM, Toby Dickenson [EMAIL PROTECTED] wrote: ... Like I said before, this is probably a good feature. If it was available as a patch then I would probably use it on a number of my sites, and would recommend it to others. I would be very happy see it (or

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Jim Fulton
Romain Slootmaekers wrote: Jim Fulton wrote: Romain Slootmaekers wrote: Yo, we had a nasty crash of our zope server that we use for a b2b web application. The Data.fs ZODB lost a significant amount of data. What sort of crash? Was this a hardware failure, or a software failure?

[Zope-dev] site-layout question

2002-08-12 Thread Robert Rottermann
Hi, for the NZO effort I downloaded the site-layout product. Looking at the makefiles I see, that in cvs.mk we have a section # Zope versions src/Zope-2.5.0: CVS_REPOSITORY=${ZOPE_CVS_REPOSITORY} src/Zope-2.5.0: CVS_MODULE=Zope src/Zope-2.5.0: CVS_TAG=-r Zope-2_5_0-src src/Zope-2.5-head:

Re: [Zope-dev] site-layout question

2002-08-12 Thread Chris McDonough
Did you download NZO_SiteLayout or site-layout? I think they are different... The entries in cvs.mk are just there to let us switch between Zope versions as necessary by aliasing. - Original Message - From: Robert Rottermann [EMAIL PROTECTED] To: zope-dev [EMAIL PROTECTED] Sent:

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out whatwent wrong.

2002-08-12 Thread Romain Slootmaekers
Jim Fulton wrote: Romain Slootmaekers wrote: I think you are pretty far off here. You said you saw a read conflict. No conflict resolution is done for a read conflict. Further, from the very brief description of your DB class, it doesn't appear to use any objects that actually try to

Re: [Zope-dev] Coroner's toolkit for zope, or how to figure out what went wrong.

2002-08-12 Thread Toby Dickenson
On Monday 12 Aug 2002 11:31 pm, Romain Slootmaekers wrote: But we found something else: I included a script below that produces a stripped down analogy of our problem. (no zope needed, just ZODB, and you might wanna modify the first line to get it working) Ive read your sample, but not