public inbox for libc-alpha@sourceware.org
 help / color / mirror / Atom feed
* broken patchwork site
@ 2016-02-19  6:46 Mike Frysinger
  2016-02-19  8:28 ` Andreas Schwab
  2016-02-19 19:59 ` Carlos O'Donell
  0 siblings, 2 replies; 8+ messages in thread
From: Mike Frysinger @ 2016-02-19  6:46 UTC (permalink / raw)
  To: libc-alpha

[-- Attachment #1: Type: text/plain, Size: 1889 bytes --]

i tried to find the overseers mailing list, but while the sourceware.org
site says things like "contact the overseers mailing list", i can't seem
to actually find that mailing list.

i also looked at bugzilla for an "infra" component but to no avail.

the http://patchwork.sourceware.org/ website doesn't fully load for me.
it misrenders and the javascript console is full of:

2016-02-19 01:45:14.368 patchwork.sourceware.org/:14 Refused to apply inline 
style because it violates the following Content Security Policy directive: 
"default-src 'self' http: https:". Either the 'unsafe-inline' keyword, a hash 
('sha256-nG1xoudMpbJeELjsW3kHtsm60dn6+RFwjddORJI/bh0='), or a nonce 
('nonce-...') is required to enable inline execution. Note also that 'style-src' 
was not explicitly set, so 'default-src' is used as a fallback.

2016-02-19 01:45:14.368 patchwork.sourceware.org/:27 Refused to apply inline 
style because it violates the following Content Security Policy directive: 
"default-src 'self' http: https:". Either the 'unsafe-inline' keyword, a hash 
('sha256-VWkG3rR92tqWKwxTi7FGCwo0s3+n19OMWDS2+QN0eiU='), or a nonce 
('nonce-...') is required to enable inline execution. Note also that 'style-src' 
was not explicitly set, so 'default-src' is used as a fallback.

2016-02-19 01:45:14.368 patchwork.sourceware.org/:39 Refused to apply inline 
style because it violates the following Content Security Policy directive: 
"default-src 'self' http: https:". Either the 'unsafe-inline' keyword, a hash 
('sha256-matwEc6givhWX0+jiSfM1+E5UMk8/UGLdl902bjFBmY='), or a nonce 
('nonce-...') is required to enable inline execution. Note also that 'style-src' 
was not explicitly set, so 'default-src' is used as a fallback.

i guess it's because https://patchwork.sourceware.org/ doesn't have a
proper cert ?  it presents a cygwin.com cert to me ...
-mike

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 819 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19  6:46 broken patchwork site Mike Frysinger
@ 2016-02-19  8:28 ` Andreas Schwab
  2016-02-19  8:48   ` Mike Frysinger
  2016-02-19 19:59 ` Carlos O'Donell
  1 sibling, 1 reply; 8+ messages in thread
From: Andreas Schwab @ 2016-02-19  8:28 UTC (permalink / raw)
  To: libc-alpha

http://sourceware.org/ml/overseers/

Andreas.

-- 
Andreas Schwab, schwab@linux-m68k.org
GPG Key fingerprint = 58CA 54C7 6D53 942B 1756  01D3 44D5 214B 8276 4ED5
"And now for something completely different."

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19  8:28 ` Andreas Schwab
@ 2016-02-19  8:48   ` Mike Frysinger
  0 siblings, 0 replies; 8+ messages in thread
From: Mike Frysinger @ 2016-02-19  8:48 UTC (permalink / raw)
  To: Andreas Schwab; +Cc: libc-alpha

[-- Attachment #1: Type: text/plain, Size: 116 bytes --]

On 19 Feb 2016 09:28, Andreas Schwab wrote:
> http://sourceware.org/ml/overseers/

forwarded now ... thanks !
-mike

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 819 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19  6:46 broken patchwork site Mike Frysinger
  2016-02-19  8:28 ` Andreas Schwab
@ 2016-02-19 19:59 ` Carlos O'Donell
  2016-02-19 20:25   ` Maciej W. Rozycki
                     ` (2 more replies)
  1 sibling, 3 replies; 8+ messages in thread
From: Carlos O'Donell @ 2016-02-19 19:59 UTC (permalink / raw)
  To: libc-alpha

On 02/19/2016 01:46 AM, Mike Frysinger wrote:
> i tried to find the overseers mailing list, but while the sourceware.org
> site says things like "contact the overseers mailing list", i can't seem
> to actually find that mailing list.

I also saw this, and Siddhesh and I talked briefly about it,
but neither of us could fathom what was wrong.

Something has changed recently, but I don't remember exactly
when it stopped working properly. Just recently though, since
I haven't been looking at the page while working feverishly
on CVE-2015-7547.

Cheers,
Carlos.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19 19:59 ` Carlos O'Donell
@ 2016-02-19 20:25   ` Maciej W. Rozycki
  2016-02-19 21:00   ` Frank Ch. Eigler
  2016-02-23  4:33   ` Carlos O'Donell
  2 siblings, 0 replies; 8+ messages in thread
From: Maciej W. Rozycki @ 2016-02-19 20:25 UTC (permalink / raw)
  To: Carlos O'Donell; +Cc: libc-alpha

On Fri, 19 Feb 2016, Carlos O'Donell wrote:

> > i tried to find the overseers mailing list, but while the sourceware.org
> > site says things like "contact the overseers mailing list", i can't seem
> > to actually find that mailing list.
> 
> I also saw this, and Siddhesh and I talked briefly about it,
> but neither of us could fathom what was wrong.
> 
> Something has changed recently, but I don't remember exactly
> when it stopped working properly. Just recently though, since
> I haven't been looking at the page while working feverishly
> on CVE-2015-7547.

 Have you updated your web browser recently by any chance?  I've recently 
noticed the site does not render correctly under recent Firefox, but works 
just fine as it's used to with my old web browser.

 So I concluded it was browser breakage rather than a site problem and 
didn't even bother mentioning it anywhere, knowing what mess web browsers 
are, to say nothing of the fortnightly browser update pressure insanity.

 FWIW,

  Maciej

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19 19:59 ` Carlos O'Donell
  2016-02-19 20:25   ` Maciej W. Rozycki
@ 2016-02-19 21:00   ` Frank Ch. Eigler
  2016-02-23  4:50     ` Carlos O'Donell
  2016-02-23  4:33   ` Carlos O'Donell
  2 siblings, 1 reply; 8+ messages in thread
From: Frank Ch. Eigler @ 2016-02-19 21:00 UTC (permalink / raw)
  To: Carlos O'Donell; +Cc: libc-alpha

"Carlos O'Donell" <carlos@redhat.com> writes:

>[...]
> I also saw this, and Siddhesh and I talked briefly about it,
> but neither of us could fathom what was wrong.

This was due to the recentish addition of Content-Security-Policy:
headers to many parts of the sourceware.org web site, in order to
better protect web apps from vulnerabilities like XSS.  It looks as
though patchwork is not compatible with that, so this protection was
just removed there.

- FChE

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19 19:59 ` Carlos O'Donell
  2016-02-19 20:25   ` Maciej W. Rozycki
  2016-02-19 21:00   ` Frank Ch. Eigler
@ 2016-02-23  4:33   ` Carlos O'Donell
  2 siblings, 0 replies; 8+ messages in thread
From: Carlos O'Donell @ 2016-02-23  4:33 UTC (permalink / raw)
  To: libc-alpha

On 02/19/2016 02:59 PM, Carlos O'Donell wrote:
> On 02/19/2016 01:46 AM, Mike Frysinger wrote:
>> i tried to find the overseers mailing list, but while the sourceware.org
>> site says things like "contact the overseers mailing list", i can't seem
>> to actually find that mailing list.
> 
> I also saw this, and Siddhesh and I talked briefly about it,
> but neither of us could fathom what was wrong.
> 
> Something has changed recently, but I don't remember exactly
> when it stopped working properly. Just recently though, since
> I haven't been looking at the page while working feverishly
> on CVE-2015-7547.

... and now it's fixed. How odd.

Cheers,
Carlos.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: broken patchwork site
  2016-02-19 21:00   ` Frank Ch. Eigler
@ 2016-02-23  4:50     ` Carlos O'Donell
  0 siblings, 0 replies; 8+ messages in thread
From: Carlos O'Donell @ 2016-02-23  4:50 UTC (permalink / raw)
  To: Frank Ch. Eigler; +Cc: libc-alpha

On 02/19/2016 04:00 PM, Frank Ch. Eigler wrote:
> "Carlos O'Donell" <carlos@redhat.com> writes:
> 
>> [...]
>> I also saw this, and Siddhesh and I talked briefly about it,
>> but neither of us could fathom what was wrong.
> 
> This was due to the recentish addition of Content-Security-Policy:
> headers to many parts of the sourceware.org web site, in order to
> better protect web apps from vulnerabilities like XSS.  It looks as
> though patchwork is not compatible with that, so this protection was
> just removed there.

Thanks! That explains it.

c.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2016-02-23  4:50 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-02-19  6:46 broken patchwork site Mike Frysinger
2016-02-19  8:28 ` Andreas Schwab
2016-02-19  8:48   ` Mike Frysinger
2016-02-19 19:59 ` Carlos O'Donell
2016-02-19 20:25   ` Maciej W. Rozycki
2016-02-19 21:00   ` Frank Ch. Eigler
2016-02-23  4:50     ` Carlos O'Donell
2016-02-23  4:33   ` Carlos O'Donell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).