*** Joins: kirillka (~Miranda@194-82-52-95.baltnet.ru) | 01:21 | |
*** Quits: siebrand (~beis@sm.xs4all.nl) (Read error: Connection reset by peer) | 01:57 | |
*** Joins: siebrand (~beis@sm.xs4all.nl) | 01:58 | |
*** Quits: mellen (~thansen@x1-6-00-22-02-00-0c-40.k253.webspeed.dk) (Ping timeout: 276 seconds) | 02:25 | |
*** Joins: davidinc_ (d5374b3d@gateway/web/freenode/ip.213.55.75.61) | 02:34 | |
*** Joins: Cupertino (~Cupez@unaffiliated/cupertino) | 02:37 | |
*** Joins: mellen (~thansen@x1-6-00-22-02-00-0c-40.k253.webspeed.dk) | 02:48 | |
*** Quits: kirillka (~Miranda@194-82-52-95.baltnet.ru) (Ping timeout: 258 seconds) | 02:48 | |
*** Quits: siebrand (~beis@sm.xs4all.nl) () | 02:53 | |
davidinc_ | Hi | 03:22 |
---|---|---|
davidinc_ | Ok finally I get the recent version of ManTweet pluigin | 03:22 |
davidinc_ | there is small bug Fatal error: Call to undefined function db_unixtimestamp() in /var/www/mantisbtd/plugins/ManTweet/mantweet_api.php on line 119 | 03:23 |
davidinc_ | this happens when you try to post | 03:23 |
davidinc_ | if I commit those lines it works | 03:24 |
davidinc_ | nuclear_eclipse: Any suggestion?? | 03:37 |
*** Joins: giallu (~giallu@fedora/giallu) | 04:02 | |
*** Joins: Al_Chapone (~chatzilla@ATuileries-152-1-70-86.w83-202.abo.wanadoo.fr) | 04:22 | |
*** Quits: dhx_m (~anonymous@c122-107-170-247.eburwd5.vic.optusnet.com.au) (Ping timeout: 258 seconds) | 04:50 | |
*** Joins: mantisbt_97477 (57a6663d@gateway/web/freenode/ip.87.166.102.61) | 04:52 | |
*** Joins: dhx_m (~anonymous@c122-107-170-247.eburwd5.vic.optusnet.com.au) | 04:54 | |
*** Joins: Rixie (~Rixie@0x4dd7390e.adsl.cybercity.dk) | 04:57 | |
*** Quits: mantisbt_97477 (57a6663d@gateway/web/freenode/ip.87.166.102.61) (Quit: Page closed) | 04:57 | |
*** Quits: davidinc_ (d5374b3d@gateway/web/freenode/ip.213.55.75.61) (Ping timeout: 252 seconds) | 05:05 | |
*** Joins: test_ (~chatzilla@p57A6663D.dip.t-dialin.net) | 05:07 | |
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 276 seconds) | 06:36 | |
*** Joins: giallu (~giallu@fedora/giallu) | 06:42 | |
*** Quits: Al_Chapone (~chatzilla@ATuileries-152-1-70-86.w83-202.abo.wanadoo.fr) (Ping timeout: 245 seconds) | 06:55 | |
CIA-100 | Mantisbt: roland master-1.2.x * r085097fc6861 /core/summary_api.php: Fix #12309: XSS issues when viewing Summary page | 07:24 |
*** Joins: davicinc (d5374b3d@gateway/web/freenode/ip.213.55.75.61) | 07:25 | |
CIA-100 | Mantisbt: roland * r61e90d0653f1 /core/summary_api.php: Fix #12309: XSS issues when viewing Summary page | 07:25 |
CIA-100 | Mantisbt: hickseydr * redb817991b99 /library/nusoap/ (class.wsdl.php nusoap.php): Fix #12312: NuSOAP web description XSS vulnerability | 08:01 |
CIA-100 | Mantisbt: hickseydr * rc4f0d68e287f /library/ (2 files in 2 dirs): Issue #12312: Provide patch for NuSOAP XSS fix and update README.libs | 08:01 |
CIA-100 | Mantisbt: hickseydr master-1.2.x * rbce955ce73a1 /library/ (2 files in 2 dirs): Issue #12312: Provide patch for NuSOAP XSS fix and update README.libs | 08:01 |
CIA-100 | Mantisbt: hickseydr master-1.2.x * r6b2e71539e59 /library/nusoap/ (class.wsdl.php nusoap.php): Fix #12312: NuSOAP web description XSS vulnerability | 08:01 |
dhx_m | nuclear_eclipse: any chance we could push out 1.2.3 when you get a free moment? | 08:06 |
dhx_m | giallu, micahg: you may want to ping NuSOAP package maintainers about the NuSOAP issue in case upstream takes a while to respond | 08:10 |
dhx_m | giallu, micahg: a patch is provided at http://www.mantisbt.org/bugs/view.php?id=12312 and the upstream report is at http://sourceforge.net/projects/nusoap/forums/forum/193579/topic/3834005 | 08:10 |
dhx_m | the patch is not thoroughly tested yet however | 08:12 |
*** Joins: Al_Chapone (~chatzilla@ATuileries-152-1-70-86.w83-202.abo.wanadoo.fr) | 08:13 | |
nuclear_eclipse | dhx_m: if I get a chance today or tomorrow I will | 08:14 |
dhx_m | nuclear_eclipse: thanks :) | 08:14 |
dhx_m | nuclear_eclipse: the change log is essentially "a few security fixes and minor bug fixes" | 08:15 |
dhx_m | nothing exciting this time | 08:15 |
nuclear_eclipse | the XSS in NuSOAP *is* the exciting part :P | 08:16 |
dhx_m | well... about 6 XSS issues of which 1-2 are exploitable by anyone, the other 4-5 require a rogue MantisBT administrator (highly unlikely) | 08:16 |
dhx_m | yep | 08:17 |
dhx_m | ah it seems Oliver Berger maintains NuSOAP in Debian (he has been involved with MantisBT development in the past months) | 08:19 |
dhx_m | I'll send a message | 08:19 |
*** Quits: test_ (~chatzilla@p57A6663D.dip.t-dialin.net) (Quit: ChatZilla 0.9.86 [Firefox 3.6.7/20100723203800]) | 08:39 | |
giallu | dhx_m, this is what we get for bundling libs | 09:05 |
dhx_m | giallu: it's an unpatched vulnerability in NuSOAP | 09:08 |
dhx_m | and I agree on bundling... it sucks (I have wanted to banish our bundled libraries for a long time) | 09:08 |
giallu | yeah. which would not force _us_ to release a new version | 09:08 |
giallu | if it wasn't there... | 09:08 |
nuclear_eclipse | giallu: if we didn't bundle libs, then everybody would bitch at us when either a) they can't figure out how to get it to work, or b) the installation process involves too much "download this, this, and this".... =\ | 09:08 |
dhx_m | giallu: the upshot is that we're 1000 times faster at patching it than NuSOAP :p | 09:09 |
dhx_m | nuclear_eclipse: I recon the bundled libraries should only be added at build time (rather than be bundled in our source tree) | 09:10 |
dhx_m | of course, that could make it harder for people to work with the git repository | 09:11 |
dhx_m | so we'd need to document an easy/proper way of setting up a MantisBT development environment | 09:11 |
nuclear_eclipse | dhx_m: except then either we need to maintain more repositories, or we would need to set up and maintain some sort of patch queue to apply to an upstream build... | 09:11 |
nuclear_eclipse | either way it gets a lot more complicated | 09:11 |
dhx_m | yep | 09:12 |
dhx_m | dropping outdated libraries would help too :) | 09:12 |
nuclear_eclipse | yeah, have fun with that :P | 09:12 |
dhx_m | I didn't offer my assistance btw :p | 09:12 |
nuclear_eclipse | exactly, everyone here dislikes the current bundled library situation, but nobody has the time or the right answer to fix it ;) | 09:14 |
*** Joins: daryn (~daryn@h158.249.190.173.static.ip.windstream.net) | 09:25 | |
giallu | anyway. I reported https://bugzilla.redhat.com/show_bug.cgi?id=629585 | 09:36 |
giallu | any other info for the packager? patch or something? | 09:36 |
giallu | ah sorry | 09:36 |
giallu | just saw the link | 09:36 |
*** Quits: Cupertino (~Cupez@unaffiliated/cupertino) (Quit: I give up...) | 10:04 | |
*** Quits: davicinc (d5374b3d@gateway/web/freenode/ip.213.55.75.61) (Ping timeout: 252 seconds) | 10:14 | |
*** Joins: lrojas (~lrojas@76.65.240.2) | 10:21 | |
*** Quits: lrojas (~lrojas@76.65.240.2) (Remote host closed the connection) | 10:22 | |
*** Joins: lrojas (~lrojas@76.65.240.2) | 10:22 | |
lrojas | nuclear_eclipse: morning! | 10:23 |
lrojas | nuclear_eclipse: are you by any chance awake? | 10:24 |
nuclear_eclipse | lrojas: at work right now, but ask away and I'll respond when I get the chance | 10:32 |
lrojas | nuclear_eclipse: thanks, i will try not to take up too much of your time, i am just trying to figure out how to configure the Source integration plugin for mantis | 10:36 |
lrojas | nuclear_eclipse: i enabled the SourceSVN and SourceWebSVN on top of meta and Source | 10:37 |
lrojas | but i am having issues making it "work", probably i am configuring it wrong... | 10:38 |
lrojas | can you please explain a bit what i need to set up for it to work with svn ? | 10:38 |
lrojas | all i can find on the web is related to 0.13, and 0.16 looks suficiently diferent that i am a bit lost | 10:39 |
nuclear_eclipse | lrojas: what server OS, what version of SVN are you using? | 10:42 |
lrojas | Server is Snow Leopard OS X 10.6.4, svn is 1.6.5 | 10:42 |
lrojas | and mantis 1.2.2 | 10:43 |
nuclear_eclipse | lrojas: a) make sure your PHP is configured to allow shell calls, b) make sure that `svn` is either in the web server's default path, or configure sourcesvn to tell it the full path to `svn`, and c) if you're using https/ssh, make sure the web server account can validate the server certificates | 10:46 |
nuclear_eclipse | if you've checked all three of those, then my only suggestion is to start adding debug output in sourcesvn to show the result of the `svn` shell calls and see if you can find any error messages that might clue in on the problem | 10:47 |
lrojas | nuclear_eclipse: that's one of the things i find weird about the 0.16 version, in the screenshots for the 0.13 i see the sourcesvn plugin has a link in it's name but in 0.16 that link is not there | 10:48 |
nuclear_eclipse | lrojas: the config options for sourcesvn have been merged into the basic source integration configuration screen | 10:49 |
lrojas | i tried there to put the path to the svn binary, ( my binary is at /svn/bin/svn ) but i get is an invalid location... | 10:52 |
lrojas | the error i get is : http://svnbook.red-bean.com/nightly/en/svn-book.html#svn.serverconfig.svnserve.sshtricks | 10:53 |
lrojas | *sigh* | 10:53 |
lrojas | sorry | 10:53 |
lrojas | is: Path to Subversion binary invalid or inaccessible | 10:54 |
lrojas | ahhh | 10:55 |
lrojas | hold on | 10:55 |
lrojas | since the www "user" has no home or nothing... shouldnt www have the standard path thus having svn on the path and /usr/bin/svn would be valid? | 10:56 |
*** Parts: Rixie (~Rixie@0x4dd7390e.adsl.cybercity.dk) | 11:10 | |
lrojas | nuclear_eclipse: when setting a repository of type SVN, can the url be file:///Path/to/repository ? | 11:18 |
lrojas | nuclear_eclipse: i ask because, we use svn over ssh it's usually svn+ssh | 11:18 |
lrojas | nuclear_eclipse: can the software handle svn+ssh for SVN or WebSVN repository types? if not, what is the propper url type for a server that is not running svnserve but gets launched on ssh connections | 11:47 |
lrojas | nuclear_eclipse: another more important question i think is, how do i make sure the plugin in mantis monitors svn commits so that commits get added automatically ? instead of having to import latest transactions always | 11:54 |
nuclear_eclipse | lrojas: any repo url should be fine as long as the web server's shell account can access that location | 11:58 |
*** Joins: siebrand (~beis@sm.xs4all.nl) | 11:58 | |
*** Quits: Al_Chapone (~chatzilla@ATuileries-152-1-70-86.w83-202.abo.wanadoo.fr) (Quit: ChatZilla 0.9.86 [Firefox 3.6.8/20100722155716]) | 12:09 | |
*** Joins: fanno (~b3g@193.3.95.240) | 12:22 | |
*** Joins: moto-moi (~hylke@cara.xs4all.nl) | 12:26 | |
*** Joins: Github (~Github@sh1-ext.rs.github.com) | 12:30 | |
Github | mantisbt: master-1.2.x Roland Becker * 085097f (1 files in 1 dirs): Fix #12309: XSS issues when viewing Summary page ... | 12:30 |
Github | mantisbt: master-1.2.x David Hicks * 6b2e715 (2 files in 1 dirs): Fix #12312: NuSOAP web description XSS vulnerability ... | 12:30 |
Github | mantisbt: master-1.2.x David Hicks * bce955c (1 files in 1 dirs): Issue #12312: Provide patch for NuSOAP XSS fix and update README.libs | 12:30 |
Github | mantisbt: master-1.2.x commits 2de04c7...bce955c - http://bit.ly/9cmYua | 12:30 |
*** Parts: Github (~Github@sh1-ext.rs.github.com) | 12:30 | |
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 240 seconds) | 13:09 | |
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 260 seconds) | 13:23 | |
*** Joins: paulr (~IceChat09@2001:470:9310:aaaa:549d:9b3e:9dc:89b4) | 14:00 | |
*** Joins: micahg (~micah@ubuntu/member/micahg) | 14:06 | |
*** Quits: micahg (~micah@ubuntu/member/micahg) (Read error: Connection reset by peer) | 15:13 | |
*** Joins: micahg (~micah@ubuntu/member/micahg) | 15:15 | |
*** Joins: pferate (~pferate@173-10-116-125-BusName-Washington.hfc.comcastbusiness.net) | 15:46 | |
*** Quits: micahg (~micah@ubuntu/member/micahg) (Quit: Leaving.) | 15:51 | |
*** Joins: micahg (~micah@ubuntu/member/micahg) | 15:52 | |
*** Quits: PennStater (Aaron@unaffiliated/pennstater) (Quit: Never look down on someone unless you're helping them up.) | 16:20 | |
*** Joins: PennStater (Aaron@unaffiliated/pennstater) | 16:20 | |
*** Quits: fanno (~b3g@193.3.95.240) (Read error: Connection reset by peer) | 16:48 | |
*** Joins: giallu (~giallu@fedora/giallu) | 16:56 | |
*** Quits: moto-moi (~hylke@cara.xs4all.nl) (Ping timeout: 240 seconds) | 17:22 | |
*** Quits: daryn (~daryn@h158.249.190.173.static.ip.windstream.net) (Quit: Ex-Chat) | 17:23 | |
lrojas | nuclear_eclipse: sorry to bother you, i got everything working.. just one more question | 18:00 |
lrojas | nuclear_eclipse: is there any way to make a commit hook in svn so that latest changes are automatically imported ? | 18:01 |
lrojas | nevr mind, just found the post_commit template inside the dir | 18:12 |
*** Quits: lrojas (~lrojas@76.65.240.2) (Remote host closed the connection) | 18:24 | |
*** Joins: fanno (~Morten@90.184.93.233) | 18:43 | |
*** Quits: paulr (~IceChat09@2001:470:9310:aaaa:549d:9b3e:9dc:89b4) (Quit: Some folks are wise, and some otherwise.) | 19:20 | |
CIA-100 | Mantisbt: giallu * rb91694764c8a /docbook/Admin_Guide/ (8 files in 2 dirs): Create skeleton for new xml based admin guide with publican. | 19:26 |
CIA-100 | Mantisbt: giallu * r72a1b5102e91 /docbook/Admin_Guide/en-US/ (14 files): Import former SGML manual | 19:26 |
CIA-100 | Mantisbt: giallu * r47d77d67f15c /docbook/Admin_Guide/en-US/Admin_Guide.xml: Hide generic preface stuff for now | 19:26 |
CIA-100 | Mantisbt: giallu * r8b23ec292c07 /docbook/Developers_Guide/ (8 files in 2 dirs): Add empty Developers Guide created with publican | 19:26 |
CIA-100 | Mantisbt: giallu * r23d138c70dbf /docbook/Developers_Guide/en-US/ (17 files): Convert SGML files to XML | 19:26 |
CIA-100 | Mantisbt: giallu * r09a2d8cd5c39 /docbook/ (36 files in 3 dirs): Remove old SGML manual | 19:26 |
giallu | whoa... spam! | 19:26 |
CIA-100 | Mantisbt: giallu * r2d0e00a4598c /docbook/Admin_Guide/en-US/ (4 files): replace "link" tag with "xref" for cross references | 19:26 |
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 258 seconds) | 19:43 | |
*** Quits: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de) (Remote host closed the connection) | 20:00 | |
*** Joins: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de) | 20:00 | |
*** Joins: daryn (~daryn@h209.152.16.98.dynamic.ip.windstream.net) | 20:55 | |
*** Quits: daryn (~daryn@h209.152.16.98.dynamic.ip.windstream.net) (Ping timeout: 245 seconds) | 21:05 | |
*** Joins: daryn (~daryn@h103.64.29.71.dynamic.ip.windstream.net) | 21:08 | |
*** Quits: daryn (~daryn@h103.64.29.71.dynamic.ip.windstream.net) (Ping timeout: 265 seconds) | 21:28 | |
*** Quits: micahg (~micah@ubuntu/member/micahg) (Ping timeout: 264 seconds) | 21:28 | |
*** Joins: micahg (~micah@ubuntu/member/micahg) | 22:25 | |
*** Quits: fanno (~Morten@90.184.93.233) (Read error: Connection reset by peer) | 23:36 |
Generated by irclog2html.py 2.9.2 by Marius Gedminas - find it at mg.pov.lt!