[JBoss JIRA] (WFWIP-229) Configuring JGroups encryption protocols produces deprecated configuration
by Yeray Borges (Jira)
[ https://issues.jboss.org/browse/WFWIP-229?page=com.atlassian.jira.plugin.... ]
Yeray Borges reopened WFWIP-229:
--------------------------------
Hello [~mjurc], I mistakenly tested this issue, so I', reopening it now to verify it.
Currently for CD17 is it not possible to configure ASYM_ENCRYPT via elytron, which means we are currently adding always the deprecated protocol. We need to work out JGroups in order to add this feature to the CD18 image.
My fault, my tests were done using SYM_ENCRYPT instead of ASYM_ENCRYPT and I incorrectly assumed they were correct.
> Configuring JGroups encryption protocols produces deprecated configuration
> --------------------------------------------------------------------------
>
> Key: WFWIP-229
> URL: https://issues.jboss.org/browse/WFWIP-229
> Project: WildFly WIP
> Issue Type: Bug
> Components: OpenShift
> Environment: The example has been produced with the following S2I environment variables:
> {code}
> OPENSHIFT_DNS_PING_SERVICE_NAME=ping-service
> JGROUPS_ENCRYPT_PROTOCOL=ASYM_ENCRYPT
> JGROUPS_CLUSTER_PASSWORD=foobar123
> OPENSHIFT_DNS_PING_SERVICE_PORT=8888
> JGROUPS_PING_PROTOCOL=dns.DNS_PING
> SCRIPT_DEBUG=true
> {code}
> Reporter: Michal Jurc
> Assignee: Yeray Borges
> Priority: Critical
>
> Any S2I configuration of ping protocols utilising encryption for protocols will result in deprecated configuration. S2I should not configure runtime to deprecated configuration by default, unless the user chooses to.
> {code:title=Example JGroups ASYM_ENCRYPT configuration}
> [standalone@localhost:9990 /] /subsystem=jgroups/stack=tcp/protocol=org.jgroups.protocols.ASYM_ENCRYPT:read-resource-description
> {
> "outcome" => "success",
> "result" => {
> "description" => "The configuration of a protocol within a protocol stac
> k.",
> "capabilities" => [{
> "name" => "org.wildfly.clustering.jgroups.protocol",
> "dynamic" => true,
> "dynamic-elements" => [
> "stack",
> "protocol"
> ]
> }],
> "deprecated" => {
> "since" => "5.0.0",
> "reason" => "Deprecated. Use protocol=ASYM_ENCRYPT instead."
> },
> "attributes" => {
> "module" => {
> "type" => STRING,
> "description" => "The module with which to resolve the protocol
> type.",
> "expressions-allowed" => true,
> "required" => false,
> "nillable" => true,
> "default" => "org.jgroups",
> "access-type" => "read-write",
> "storage" => "configuration",
> "restart-required" => "resource-services"
> },
> "properties" => {
> "type" => OBJECT,
> "description" => "The properties of this protocol.",
> "expressions-allowed" => true,
> "required" => false,
> "nillable" => true,
> "value-type" => STRING,
> "access-type" => "read-write",
> "storage" => "configuration",
> "restart-required" => "resource-services"
> },
> "socket-binding" => {
> "type" => STRING,
> "description" => "Defines the bind address/port used of the serv
> er socket used to receive messages from other cluster members.",
> "expressions-allowed" => false,
> "required" => false,
> "nillable" => true,
> "min-length" => 1L,
> "max-length" => 2147483647L,
> "deprecated" => {
> "since" => "5.0.0",
> "reason" => "Deprecated. Supports EAP 7.0 slaves."
> },
> "access-type" => "read-only",
> "storage" => "configuration"
> },
> "statistics-enabled" => {
> "type" => BOOLEAN,
> "description" => "Indicates whether or not this protocol will co
> llect statistics overriding stack configuration.",
> "expressions-allowed" => true,
> "required" => false,
> "nillable" => true,
> "access-type" => "read-write",
> "storage" => "configuration",
> "restart-required" => "resource-services"
> }
> },
> "operations" => undefined,
> "notifications" => undefined,
> "children" => {"property" => {
> "description" => "A JGroups protocol property.",
> "model-description" => undefined
> }}
> }
> }
> {code}
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (DROOLS-4635) [DMN Designer] Constraints shown just for original data type definition
by Jozef Marko (Jira)
[ https://issues.jboss.org/browse/DROOLS-4635?page=com.atlassian.jira.plugi... ]
Jozef Marko updated DROOLS-4635:
--------------------------------
Description: Issue found during DROOLS-3727 review however probably it is not related. Int he attached video there is shown, that when graph contains has just one match for the search query and user repeatedly press *next match*, the canvas is slowly scrolling. (was: Issue found during DROOLS-3727 review however probably it is not related. Int he attached picture there is shown the constraints of *tViolation* are shown just for the original definition. Not for other usages of that data type. It is not consistent for example with *Fee/Amount*)
> [DMN Designer] Constraints shown just for original data type definition
> -----------------------------------------------------------------------
>
> Key: DROOLS-4635
> URL: https://issues.jboss.org/browse/DROOLS-4635
> Project: Drools
> Issue Type: Bug
> Components: DMN Editor
> Affects Versions: 7.28.0.Final
> Reporter: Jozef Marko
> Assignee: Guilherme Gomes
> Priority: Major
> Labels: drools-tools
> Attachments: searching-result.webm
>
>
> Issue found during DROOLS-3727 review however probably it is not related. Int he attached video there is shown, that when graph contains has just one match for the search query and user repeatedly press *next match*, the canvas is slowly scrolling.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (DROOLS-4635) [DMN Designer] Constraints shown just for original data type definition
by Jozef Marko (Jira)
Jozef Marko created DROOLS-4635:
-----------------------------------
Summary: [DMN Designer] Constraints shown just for original data type definition
Key: DROOLS-4635
URL: https://issues.jboss.org/browse/DROOLS-4635
Project: Drools
Issue Type: Bug
Components: DMN Editor
Affects Versions: 7.28.0.Final
Reporter: Jozef Marko
Assignee: Guilherme Gomes
Attachments: searching-result.webm
Issue found during DROOLS-3727 review however probably it is not related. Int he attached picture there is shown the constraints of *tViolation* are shown just for the original definition. Not for other usages of that data type. It is not consistent for example with *Fee/Amount*
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (DROOLS-4635) [DMN Designer] Constraints shown just for original data type definition
by Jozef Marko (Jira)
[ https://issues.jboss.org/browse/DROOLS-4635?page=com.atlassian.jira.plugi... ]
Jozef Marko updated DROOLS-4635:
--------------------------------
Attachment: searching-result.webm
> [DMN Designer] Constraints shown just for original data type definition
> -----------------------------------------------------------------------
>
> Key: DROOLS-4635
> URL: https://issues.jboss.org/browse/DROOLS-4635
> Project: Drools
> Issue Type: Bug
> Components: DMN Editor
> Affects Versions: 7.28.0.Final
> Reporter: Jozef Marko
> Assignee: Guilherme Gomes
> Priority: Major
> Labels: drools-tools
> Attachments: searching-result.webm
>
>
> Issue found during DROOLS-3727 review however probably it is not related. Int he attached picture there is shown the constraints of *tViolation* are shown just for the original definition. Not for other usages of that data type. It is not consistent for example with *Fee/Amount*
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (DROOLS-4634) [DMN Designer] Constraints shown just for original data type definition
by Jozef Marko (Jira)
Jozef Marko created DROOLS-4634:
-----------------------------------
Summary: [DMN Designer] Constraints shown just for original data type definition
Key: DROOLS-4634
URL: https://issues.jboss.org/browse/DROOLS-4634
Project: Drools
Issue Type: Bug
Components: DMN Editor
Affects Versions: 7.28.0.Final
Reporter: Jozef Marko
Assignee: Guilherme Gomes
Attachments: Screenshot from 2019-10-10 14-35-24.png
Issue found during DROOLS-3727 review however probably it is not related. Int he attached picture there is shown the constraints of *tViolation* are shown just for the original definition. Not for other usages of that data type. It is not consistent for example with *Fee/Amount*
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (WFLY-12656) Document some quickstarts to use new openshift templates
by Nikoleta Ziakova (Jira)
Nikoleta Ziakova created WFLY-12656:
---------------------------------------
Summary: Document some quickstarts to use new openshift templates
Key: WFLY-12656
URL: https://issues.jboss.org/browse/WFLY-12656
Project: WildFly
Issue Type: Enhancement
Components: Documentation, Quickstarts
Reporter: Nikoleta Ziakova
Assignee: Eduardo Martins
A subset of openshift quickstarts can take benefit of chained build and usage of galleon offered by new template. This should be documented in README.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (WFWIP-237) Wildfly operator scale down stuck with wildfly18 image
by Ondrej Chaloupka (Jira)
[ https://issues.jboss.org/browse/WFWIP-237?page=com.atlassian.jira.plugin.... ]
Ondrej Chaloupka commented on WFWIP-237:
----------------------------------------
[~jmesnil] I see. There are different reasons as explained at #111. The #111 is not a trouble of the operator code but it's a configuration issue of networking between localhost and virtualbox machine. I can't see a solution without network configuration in scope of the current design.
> Wildfly operator scale down stuck with wildfly18 image
> ------------------------------------------------------
>
> Key: WFWIP-237
> URL: https://issues.jboss.org/browse/WFWIP-237
> Project: WildFly WIP
> Issue Type: Bug
> Components: OpenShift
> Reporter: Petr Kremensky
> Assignee: Jeff Mesnil
> Priority: Critical
> Labels: operator
> Attachments: logs.txt
>
>
> *quay.io/wildfly/wildfly-centos7:17.0*
> {noformat}
> $ docker run -ti quay.io/wildfly/wildfly-centos7:17.0 /bin/bash
> [jboss@1cc52cbad596 ~]$ echo $JBOSS_HOME
> /opt/jboss/wildfly
> [jboss@1cc52cbad596 ~]$ ll /opt/wildfly
> ls: cannot access /opt/wildfly: No such file or directory
> [jboss@1cc52cbad596 ~]$ ll /opt/jboss/wildfly
> total 540
> -rw-rw-r--. 1 jboss root 26530 Jun 11 12:46 LICENSE.txt
> -rw-rw-r--. 1 jboss root 2221 Jun 11 12:46 README.txt
> drwxrwxr-x. 3 jboss root 4096 Jun 11 12:46 appclient
> drwxrwxr-x. 4 jboss root 4096 Jun 11 12:46 bin
> -rw-rw-r--. 1 jboss root 2451 Jun 11 12:46 copyright.txt
> drwxrwxr-x. 6 jboss root 4096 Jun 11 12:46 docs
> -rw-rw-r--. 1 jboss root 489207 Jun 11 12:46 jboss-modules.jar
> drwxrwxr-x. 5 jboss root 4096 Jun 11 12:46 modules
> drwxrwxr-x. 5 jboss root 4096 Jun 11 12:46 standalone
> drwxrwxr-x. 2 jboss root 4096 Jun 11 12:46 welcome-content
> {noformat}
> *quay.io/wildfly/wildfly-centos7:18.0*
> {noformat}
> $ docker run -ti quay.io/wildfly/wildfly-centos7:18.0 /bin/bash
> [jboss@8a0a5cd2e76a ~]$ echo $JBOSS_HOME
> /opt/wildfly
> [jboss@8a0a5cd2e76a ~]$ ll /opt/wildfly
> total 540
> -rw-rw-r--. 1 jboss root 26530 Oct 4 09:15 LICENSE.txt
> -rw-rw-r--. 1 jboss root 2224 Oct 4 09:15 README.txt
> drwxrwxr-x. 3 jboss root 4096 Oct 4 09:15 appclient
> drwxrwxr-x. 4 jboss root 4096 Oct 4 09:15 bin
> -rw-rw-r--. 1 jboss root 2451 Oct 4 09:15 copyright.txt
> drwxrwxr-x. 7 jboss root 4096 Oct 4 09:15 docs
> -rw-rw-r--. 1 jboss root 489207 Oct 4 09:15 jboss-modules.jar
> drwxrwxr-x. 5 jboss root 4096 Oct 4 09:15 modules
> drwxrwxr-x. 5 jboss root 4096 Oct 4 09:16 standalone
> drwxrwxr-x. 2 jboss root 4096 Oct 4 09:15 welcome-content
> [jboss@8a0a5cd2e76a ~]$ ll /opt/jboss/wildfly
> ls: cannot access /opt/jboss/wildfly: No such file or directory
> {noformat}
> The JBOSS_HOME variable is hard coded in a operator code - https://github.com/wildfly/wildfly-operator/blob/master/build/Dockerfile#L4 (/opt/jboss/wildfly at the moment - operator doesn't work with wildfly18 image).
> *doesn't work* here means that scale down stuck due to:
> {noformat}
> {"level":"info","ts":1570603971.690961,"logger":"wildflyserver_controller","msg":"Statefulset was not scaled to the desired replica size 0 (current StatefulSet size: 1). Transaction recovery scaledown process has not cleaned all pods. Please, check status of the WildflyServer simple-jaxrs-wildfly","StatefulSet.Namespace":"pkremens-namespace","StatefulSet.Name":"simple-jaxrs-wildfly"}
> {noformat}
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months
[JBoss JIRA] (WFLY-12655) Exception with web.xml url-pattern
by Jive JIRA Integration (Jira)
[ https://issues.jboss.org/browse/WFLY-12655?page=com.atlassian.jira.plugin... ]
Jive JIRA Integration updated WFLY-12655:
-----------------------------------------
Forum Reference: https://developer.jboss.org/message/991059#991059
> Exception with web.xml url-pattern
> ----------------------------------
>
> Key: WFLY-12655
> URL: https://issues.jboss.org/browse/WFLY-12655
> Project: WildFly
> Issue Type: Bug
> Components: Web (Undertow)
> Affects Versions: 18.0.0.Final
> Reporter: Frank Heldt
> Assignee: Flavia Rainone
> Priority: Major
>
> Defining and securing 2 folders in a war with similar names given this Exception on deployment:
> 12:38:37,994 ERROR [org.jboss.msc.service.fail] (MSC service thread 1-3) MSC000001: Failed to start service jboss.deployment.unit."java-web-project.war".jboss.security.jacc: org.jboss.msc.service.StartException in service jboss.deployment.unit."java-web-project.war".jboss.security.jacc: WFLYSEC0012: Unable to start the JaccService service
> at org.jboss.as.security@18.0.0.Final//org.jboss.as.security.service.JaccService.start(JaccService.java:107)
> at org.jboss.msc@1.4.11.Final//org.jboss.msc.service.ServiceControllerImpl$StartTask.startService(ServiceControllerImpl.java:1739)
> at org.jboss.msc@1.4.11.Final//org.jboss.msc.service.ServiceControllerImpl$StartTask.execute(ServiceControllerImpl.java:1701)
> at org.jboss.msc@1.4.11.Final//org.jboss.msc.service.ServiceControllerImpl$ControllerTask.run(ServiceControllerImpl.java:1559)
> at org.jboss.threads@2.3.3.Final//org.jboss.threads.ContextClassLoaderSavingRunnable.run(ContextClassLoaderSavingRunnable.java:35)
> at org.jboss.threads@2.3.3.Final//org.jboss.threads.EnhancedQueueExecutor.safeRun(EnhancedQueueExecutor.java:1982)
> at org.jboss.threads@2.3.3.Final//org.jboss.threads.EnhancedQueueExecutor$ThreadBody.doRunTask(EnhancedQueueExecutor.java:1486)
> at org.jboss.threads@2.3.3.Final//org.jboss.threads.EnhancedQueueExecutor$ThreadBody.run(EnhancedQueueExecutor.java:1377)
> at java.base/java.lang.Thread.run(Thread.java:834)
> Caused by: java.lang.IllegalArgumentException: Invalid prefix pattern in URLPatternList
> at javax.security.jacc.api@2.0.0.Final//javax.security.jacc.URLPatternSpec.setURLPatternArray(URLPatternSpec.java:308)
> at javax.security.jacc.api(a)2.0.0.Final//javax.security.jacc.URLPatternSpec.<init>(URLPatternSpec.java:79)
> at javax.security.jacc.api(a)2.0.0.Final//javax.security.jacc.WebResourcePermission.<init>(WebResourcePermission.java:160)
> at org.wildfly.extension.undertow@18.0.0.Final//org.wildfly.extension.undertow.security.jacc.WarJACCService.createPermissions(WarJACCService.java:303)
> at org.wildfly.extension.undertow@18.0.0.Final//org.wildfly.extension.undertow.security.jacc.WarJACCService.createPermissions(WarJACCService.java:64)
> at org.jboss.as.security@18.0.0.Final//org.jboss.as.security.service.JaccService.start(JaccService.java:86)
> ... 8 more
> This is the corresponding part of the web.xml:
> <security-constraint>
> <web-resource-collection>
> <web-resource-name>Area</web-resource-name>
> <url-pattern>/area/*</url-pattern>
> </web-resource-collection>
> <auth-constraint>
> <role-name>role1</role-name>
> <role-name>role2</role-name>
> </auth-constraint>
> <user-data-constraint>
> <transport-guarantee>CONFIDENTIAL</transport-guarantee>
> </user-data-constraint>
> </security-constraint>
> <security-constraint>
> <web-resource-collection>
> <web-resource-name>Area 51</web-resource-name>
> <url-pattern>/area51/*</url-pattern>
> </web-resource-collection>
> <auth-constraint>
> <role-name>role1</role-name>
> </auth-constraint>
> <user-data-constraint>
> <transport-guarantee>CONFIDENTIAL</transport-guarantee>
> </user-data-constraint>
> </security-constraint>
> Looks like this only happens when the url-pattern starts with the same characters (eg /area/* and /area51/*).
> The same war under WildFly 17.0.1 works as expected.
--
This message was sent by Atlassian Jira
(v7.13.8#713008)
6 years, 9 months