#jogamp @ irc.freenode.net - 20130610 05:05:16 (UTC)


20130610 05:05:16 -CatOut- Previous @ http://jogamp.org/log/irc/jogamp_20130609172416.html
20130610 05:05:16 -CatOut- This channel is logged @ http://jogamp.org/log/irc/jogamp_20130610050516.html
20130610 05:57:38 * hharrison (~chatzilla@anon) Quit (Ping timeout: 245 seconds)
20130610 06:41:58 * monsieur_max (~maxime@anon) has joined #jogamp
20130610 07:50:00 * timvdalen (~tim@anon) has joined #jogamp
20130610 07:50:19 <timvdalen> Hi
20130610 07:50:35 <timvdalen> I have a question about bundling JOGL and GlueGen inside my JAR
20130610 07:50:43 <timvdalen> Does anyone here know if it is allowed?
20130610 08:26:40 * xranby_ac100 (~xranby@anon) has joined #jogamp
20130610 08:27:24 <xranby_ac100> timvdalen: yes it is allowed
20130610 08:28:37 <timvdalen> Awesome, thanks
20130610 08:29:59 <timvdalen> Then I will be on my way
20130610 08:30:04 * timvdalen (~tim@anon) Quit (Quit: bye, thanks!)
20130610 09:44:06 * [Mike] (~Mike]@anon) Quit ()
20130610 13:32:40 * jk4 (~jk4@anon) Quit (Ping timeout: 246 seconds)
20130610 13:33:44 * jk4 (~jk4@anon) has joined #jogamp
20130610 16:00:13 * monsieur_max (~maxime@anon) Quit (Quit: Leaving.)
20130610 16:49:26 * rmk0_ (~rmk0@anon) has joined #jogamp
20130610 16:52:34 * rmk0 (~rmk0@anon) Quit (Ping timeout: 255 seconds)
20130610 16:59:56 * monsieur_max (~maxime@anon) has joined #jogamp
20130610 17:00:19 <sgothel> Hi All ..
20130610 17:00:48 <sgothel> Xerxes .. you are online again ? Your blog server works it seems .. albeit slow
20130610 17:03:01 <sgothel> Hmm .. chat about JOAL CVE .. found security leak ? The one they found depends on the old OpenAL32 dll, which we no more deploy. Have to check for new openal-soft.
20130610 17:03:56 <sgothel> General securit audit w/ unit tests goes quite slow. At least I could reproduce the nice expected exception w/ an installed SecurityManager and unit test.
20130610 17:16:10 <xranby_ac100> sgothel: hi, i am trying to recover from a cold
20130610 17:16:35 <sgothel> oh .. good health
20130610 17:16:54 <sgothel> me removing old joal-natives-windows*jar files :)
20130610 17:16:58 <sgothel> (signed)
20130610 17:17:04 <xranby_ac100> openal-soft at lest checks if the address passed is known "registered" by openal-soft else returns error
20130610 17:17:23 <xranby_ac100> yes looks like the solution is not to host all old versions
20130610 17:17:24 <sgothel> very good .. so exploit won't work ..
20130610 17:17:35 <sgothel> have you tested ? :)
20130610 17:17:59 <sgothel> I will .. later otherwise
20130610 17:18:00 <xranby_ac100> i have only read the openal-soft sourcecode
20130610 17:18:04 <xranby_ac100> no real test
20130610 17:18:13 <sgothel> that is very good ofc!
20130610 17:18:56 <sgothel> me trying to setup a simple test bed .. unsure if thats sufficient, still verifying w/ signed jar and plugin
20130610 17:20:00 <sgothel> i.e. you get a temp dir via IOUtil .. but you cannot write: good. TODO: native lib loading, and the signed 'startup code' i.e. main .. applet-launcher
20130610 17:20:19 <sgothel> dunno how much should be validated
20130610 17:20:49 <xranby_ac100> openal-soft/OpenAL32/alBuffer.c line 249
20130610 17:21:15 <sgothel> there is this one nagging that startup code shall not reside in a signed jar package, due to possible attack vector iff the JVM impl. is buggy etc
20130610 17:23:01 <sgothel> right .. thats for 83316
20130610 17:25:20 <sgothel> alAuxiliaryEffectSlotf: similar
20130610 17:25:23 <sgothel> (the in progress CVE)
20130610 17:25:27 <sgothel> ok .. so I pull all old signed jars w/ old openal.dll
20130610 17:25:29 <sgothel> pull == delete :)
20130610 17:31:38 <sgothel> ok .. cleaned up history, archive/rc and archive/master
20130610 18:24:49 <xranby_ac100> time to move the jogamp-current?
20130610 18:27:00 <xranby_ac100> it is still pointing at the rc11 from nov 2013
20130610 18:27:27 <xranby_ac100> nov 1 2012
20130610 18:31:45 <sgothel> well .. I focus on 2.0.2 .. yes RCs are obsolete
20130610 18:45:01 <sgothel> for devs .. we have abbounced the archive/master signed jars to test
20130610 18:45:56 <sgothel> *announced
20130610 18:47:02 <sgothel> now better cont. w/ the other security issues ..
20130610 18:47:11 * rmk0_ salivates
20130610 18:47:11 <sgothel> will check native lib loading now
20130610 18:47:12 * rmk0_ is now known as rmk0
20130610 18:47:23 * rmk0 (~rmk0@anon) Quit (Changing host)
20130610 18:47:23 * rmk0 (~rmk0@anon) has joined #jogamp
20130610 18:47:26 <sgothel> well .. and you are all WELCOME to participate !
20130610 18:49:10 * monsieur_max (~maxime@anon) Quit (*.net *.split)
20130610 18:49:10 * odin_ (~Odin@anon) Quit (*.net *.split)
20130610 18:49:10 * rmk0 (~rmk0@anon) Quit (*.net *.split)
20130610 18:49:10 * jk4 (~jk4@anon) Quit (*.net *.split)
20130610 18:49:13 * xranby_ac100 (~xranby@anon) Quit (*.net *.split)
20130610 18:49:13 * xranby (~xranby@anon) Quit (*.net *.split)
20130610 18:49:17 * sgothel (~sven@anon) Quit (*.net *.split)
20130610 18:54:32 * [Mike] (~Mike]@anon) has joined #jogamp
20130610 18:54:32 * monsieur_max (~maxime@anon) has joined #jogamp
20130610 18:54:32 * rmk0 (~rmk0@anon) has joined #jogamp
20130610 18:54:32 * jk4 (~jk4@anon) has joined #jogamp
20130610 18:54:32 * xranby_ac100 (~xranby@anon) has joined #jogamp
20130610 18:54:32 * xranby (~xranby@anon) has joined #jogamp
20130610 18:54:32 * odin_ (~Odin@anon) has joined #jogamp
20130610 18:54:32 * sgothel (~sven@anon) has joined #jogamp
20130610 18:55:15 <sgothel> hohoho .. CatOut reconnected :)
20130610 21:05:46 * monsieur_max (~maxime@anon) Quit (Quit: Leaving.)
20130610 21:56:29 * void256 (~void@anon) has joined #jogamp
20130610 22:22:16 * hharrison (~chatzilla@anon) has joined #jogamp
20130610 22:57:05 * void256 (~void@anon) Quit (Remote host closed the connection)
20130610 23:29:07 * xranby_ac1001 (~xranby@anon) has joined #jogamp
20130610 23:31:07 * xranby_ac100 (~xranby@anon) Quit (Ping timeout: 264 seconds)
20130611 00:01:01 * hharrison (~chatzilla@anon) Quit (Quit: ChatZilla 0.9.90 [Firefox 22.0/20130528181031])
20130611 00:09:19 * xranby_ac1001 (~xranby@anon) Quit (Remote host closed the connection)
20130611 03:46:12 * hharrison (~chatzilla@anon) has joined #jogamp
20130611 04:36:37 * [Mike] (~Mike]@anon) Quit ()
20130611 05:05:16 -CatOut- Continue @ http://jogamp.org/log/irc/jogamp_20130611050516.html