[16:50:40] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c2 (10Bryan Davis) This is an occasional problem with file permissions on the shared NFS directories used for beta's image uploads: deployment-bastion:~ bd808$ ls -ld /data/project/... [16:51:38] !log Running `chmod -R =rwX .` in /data/project/upload7 [16:51:43] Logged the message, Master [17:35:42] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c3 (10Bryan Davis) 5NEW>3RESO/FIX p:5Unprio>3Normal a:3Bryan Davis Ran `chmod -R =rwX /data/project/upload7` to fix all file permissions. [17:41:40] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c4 (10Marc A. Pelletier) Be aware that doing so has given write permission to any authenticated user. This may not be a catastrophe in practice, but it has security impact. [17:44:26] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c5 (10Bryan Davis) (In reply to Marc A. Pelletier from comment #4) > Be aware that doing so has given write permission to any authenticated user. > This may not be a catastrophe in pract... [18:12:57] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c6 (10Marc A. Pelletier) NFSv4 doesn't actually require UID concordance so long as the user /name/ exists on the NFS server do that it doesn't fall back to numerical IDs - the proper sol... [18:22:13] 3Wikimedia Labs / 3deployment-prep (beta): File upload area resorts to 0777 permissions to for uploaded conent - 10https://bugzilla.wikimedia.org/73206 (10Bryan Davis) 3NEW p:3Unprio s:3normal a:3None (Bryan Davis from ) > Ran `chmod -R =rwX /d... [18:22:42] 3Wikimedia Labs / 3deployment-prep (beta): An inserted image gives 403 Forbidden - 10https://bugzilla.wikimedia.org/73102#c7 (10Bryan Davis) (In reply to Marc A. Pelletier from comment #6) > NFSv4 doesn't actually require UID concordance so long as the user /name/ > exists on the NFS server do that it doesn... [18:33:29] 3Wikimedia Labs / 3deployment-prep (beta): File upload area resorts to 0777 permissions to for uploaded conent - 10https://bugzilla.wikimedia.org/73206#c1 (10Bryan Davis) It should be sufficient for the MediaWiki runtime user (apache) to have read/write for the files and directories under the /data/project/u... [22:42:16] (03PS1) 10Ori.livneh: Add jobs for PyBal [integration/config] - 10https://gerrit.wikimedia.org/r/172180 [22:45:51] (03CR) 10jenkins-bot: [V: 04-1] Add jobs for PyBal [integration/config] - 10https://gerrit.wikimedia.org/r/172180 (owner: 10Ori.livneh)